Skip to content
Knowledge base Updated: February 5, 2026

What is GDPR and What Are the Key Data Protection Principles in the European Union?

GDPR is not just bureaucracy and marketing consents. It's a fundamental change in the approach to personal data that affects almost every company in Europe. Misunderstanding its principles is a direct path to losing customer trust and multi-million fines. How to practically translate complicated legal language into actionable business practices?

Since May 2018, four letters – GDPR – have dominated discussions about law, business, and technology throughout Europe. The General Data Protection Regulation was a legislative earthquake that forever changed the rules of the game in personal data processing. For many entrepreneurs, it became synonymous with complicated procedures, endless documentation, and omnipresent consent checkboxes. However, reducing GDPR solely to a bureaucratic obligation is a huge mistake. At its core, GDPR is an attempt to restore fundamental balance in the digital world – giving people control over their own information and placing responsibility on organizations for its proper and transparent use.

Understanding and, more importantly, practical implementation of GDPR principles is no longer an option, but an absolute foundation for legal and ethical business conduct in the European Union. It’s not a one-time project to “check off,” but a continuous process that must become an integral part of organizational culture and daily operations. This guide aims to demystify GDPR and translate its key concepts into practical, understandable language that will help every company, regardless of its size, navigate this complex but extremely important legal landscape.

Quick navigation

📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać

What is GDPR and why was it introduced?

GDPR (General Data Protection Regulation) is a European Union regulation that unified and modernized regulations on the protection of personal data of natural persons throughout the EU. It was introduced to replace the outdated and fragmented directive from 1995, which did not fit the realities of the internet age, social media, and Big Data. The main goals of GDPR are twofold. First, the goal is to strengthen and unify the rights of individuals, giving them greater control over who, what, and why does with their information. Second, the goal is to facilitate the free flow of personal data within the EU single market by creating one coherent and directly applicable set of regulations. The introduction of very high financial penalties is intended to ensure that these regulations are treated with due seriousness by organizations.

What basic principles of personal data processing does GDPR define?

At the heart of the entire regulation is Article 5, which formulates seven fundamental principles. They constitute a decalogue that every organization must follow. Personal data must be processed:

  • Lawfully, fairly, and in a transparent manner.
  • For specific, explicit, and legitimate purposes (purpose limitation).
  • In a manner that is adequate, relevant, and limited to what is necessary (data minimization).
  • Accurately (accuracy).
  • For no longer than is necessary (storage limitation).
  • In a manner that ensures appropriate security (integrity and confidentiality).
  • In accordance with the accountability principle.

What is personal data according to GDPR and what information is protected?

The definition of personal data in GDPR (Article 4) is extremely broad. Personal data is “any information relating to an identified or identifiable natural person.” The key phrase here is “identifiable.” This means that personal data is not only information that directly points to someone (like name and surname or national identification number), but also any information that, alone or in combination with other data, allows identification of a given person. In practice, personal data includes: name, surname, residential address, email address, phone number, ID number, but also computer IP address, location data, browser cookie identifier, and even information about physical, physiological, genetic, mental, economic, cultural, or social characteristics.

GDPR clearly states that data processing is legal only when it is based on at least one of six precisely defined legal bases (Article 6). In a business context, the most common bases are: consent, contract performance, legal obligation, and legitimate interest. Choosing the appropriate legal basis is a key decision that determines further obligations and rights.

What rights do customers have under GDPR?

GDPR grants individuals a wide range of rights that allow them to exercise control over their data. The most important include the right of access to data, right to rectification, right to erasure (“right to be forgotten”), right to restriction of processing, right to data portability, and right to object. Your company must have implemented procedures that allow for efficient and timely exercise of these rights.

What is the principle of lawfulness, fairness, and transparency?

This is the first and most important GDPR principle. Lawfulness means that every processing must have a solid legal basis. Fairness means that data cannot be processed in a way that would be unfair or harmful to the person. Transparency requires the controller to clearly, concisely, and understandably inform people about all aspects of processing their data. This principle is implemented in practice through the information obligation.

How does the principle of purpose limitation and data minimization work in practice?

Purpose limitation means that you cannot collect data “just in case” or “because it might be useful someday.” The purpose must be specific and clearly defined before data collection begins. If you collect an email address for newsletter delivery, you cannot then use it for profiling without a new, separate legal basis. Data minimization is inseparably linked to this and states that you can only collect data that is absolutely necessary to achieve that specific purpose. If you only need an email address for newsletter delivery, you should not ask for date of birth or phone number.

What data security obligations does GDPR impose?

Article 32 of GDPR requires implementation of “appropriate technical and organizational measures” to ensure a level of security appropriate to the risk. Technical measures are specific technologies such as encryption, pseudonymization, access control based on the Principle of Least Privilege, multi-factor authentication (MFA), firewalls, antivirus/EDR systems, and backup systems. Organizational measures are processes and procedures such as information security policies, formal incident response plans, and above all regular security awareness training for all employees.

What is the accountability principle and how must entrepreneurs comply with it?

The accountability principle (Article 5(2)) is one of the biggest changes introduced by GDPR. It states that the data controller is not only responsible for complying with all principles but must also be able to demonstrate that they comply. In practice, this means the need to maintain detailed documentation such as a Record of Processing Activities, having documented policies and procedures, and gathering evidence of fulfilling obligations (e.g., training records, audit results, incident handling documentation).

Consent is one of the six legal bases for processing. For it to be valid, GDPR sets very high requirements. It must be freely given, specific, informed, and unambiguous. It must constitute a “clear affirmative action.” This means that pre-ticked checkboxes are invalid. Consent must also be easy to withdraw, and this process cannot be more difficult than giving consent. Most importantly, the controller must be able to prove that they obtained valid consent from a given person.

What are the consequences of GDPR violation?

The consequences can be extremely severe. GDPR introduced two tiers of administrative fines. For some violations, the fine can amount to up to 10 million euros or up to 2% of total annual worldwide turnover from the previous year. For the most serious violations, the fine can reach up to 20 million euros or up to 4% of total annual worldwide turnover. In addition to administrative fines, the company faces civil claims from persons who suffered damage and enormous reputational damage.

When and how to notify about a personal data breach?

GDPR imposes a very rigorous 72-hour deadline for reporting a personal data breach to the supervisory authority. In case of a breach that may result in a risk to the rights or freedoms of natural persons, the controller must report it without undue delay. If additionally the risk to persons is high, the persons whose data are concerned must also be informed about the breach. Having a practiced Incident Response Plan is crucial to meet these short deadlines.

What technical and organizational measures are required for GDPR compliance?

GDPR explicitly mentions encryption as one of the examples of “appropriate technical measures.” This protection must be ensured on two levels. Protection of data in transit means that every transmission of personal data over public networks (internet) or even internal ones must be protected using strong cryptographic protocols such as TLS 1.2 or 1.3. Sending data in plain text is unacceptable. Protection of data at rest means that data stored on media (disks in laptops, servers, backups) should also be encrypted. This helps minimize damage in case of physical equipment theft.

How long can personal data be stored under GDPR?

The storage limitation principle states that data can only be stored as long as is necessary for the purposes for which they were collected. Data cannot be stored indefinitely “just in case.” Every company must define and document retention periods for individual data categories. For example, recruitment data can be stored until the end of the process, invoice data for the period required by tax regulations, and video monitoring data for a period no longer than necessary to ensure security. After this period expires, data must be permanently deleted or anonymized.

Learn key terms related to this article in our cybersecurity glossary:

  • Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
  • SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
  • Backup — Backup, also known as a backup copy or safety copy, is the process of creating…
  • Network Security — Network security is a set of practices, technologies, and strategies aimed at…
  • Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…

Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist