What are the basic GDPR rules?

What are the basic GDPR rules?

What Are the Basic GDPR Rules?

Most people have clicked “accept all” on a cookie banner without thinking twice about what they were actually agreeing to. The General Data Protection Regulation, better known as GDPR, is the legal framework that sits behind those banners and governs how organisations collect, store, and use personal data across the UK and Europe. Understanding the basic GDPR rules is not just a box-ticking exercise for compliance officers. It matters for anyone who runs a business, handles customer data, or simply wants to know their rights.

GDPR came into force in May 2018 and represented the most significant overhaul of data protection law in a generation. In the UK, it continues to apply through the UK GDPR framework following the country’s departure from the European Union, sitting alongside the Data Protection Act 2018.

What Is GDPR? A Plain-English Guide for Beginners

 

If you have ever heard the phrase “GDPR” and assumed it was something only lawyers needed to understand, you are not alone. At its core, GDPR is a set of rules designed to give individuals greater control over their personal data and to hold organisations accountable for how they handle it. Personal data covers any information that can identify a living person, from a name and email address to an IP address or location data.

The regulation applies to any organisation that processes personal data, regardless of size or sector. A sole trader collecting customer email addresses is subject to the same legal framework as a multinational corporation managing millions of records. The scale of obligations may differ, but the underlying principles are the same for everyone.

Looking for some data support? Speak with a member of our Professional Data Team Here

GDPR Compliance

The 7 Main Principles of GDPR Explained

The foundation of GDPR rests on seven core principles that govern how personal data must be handled. These principles are not optional guidelines but legal requirements, and they apply at every stage of the data lifecycle from collection through to deletion.

GDPR PrincipleWhat It Means in Practice
Lawfulness, Fairness and TransparencyData must be processed legally, fairly, and with full openness to the individual
Purpose LimitationData collected for one purpose cannot be repurposed without a valid legal basis
Data MinimisationOnly the data genuinely needed for the stated purpose should be collected
AccuracyData must be kept accurate and up to date, with inaccuracies corrected promptly
Storage LimitationData should not be kept longer than necessary for its original purpose
Integrity and ConfidentialityData must be kept secure against loss, damage, or unauthorised access
AccountabilityOrganisations must be able to demonstrate compliance with all the above principles

The seventh principle, accountability, is particularly significant because it shifts the burden of proof onto the organisation. It is not enough to claim you are compliant; you must be able to show it through documentation, policies, and demonstrable practices.

What Are the Main GDPR Rules Businesses Must Follow?

Beyond the seven principles, GDPR sets out a series of practical rules that organisations must follow in their day-to-day operations. One of the most important is the requirement to have a lawful basis for processing data. There are six lawful bases available under GDPR, including consent, legitimate interests, and contractual necessity, and organisations must identify and document which basis applies before they begin processing.

Individuals also hold a set of rights under GDPR that organisations are legally obliged to respect. These include the right to access their own data, the right to have inaccurate data corrected, and the right to have data deleted in certain circumstances, often referred to as the right to be forgotten. Handling these rights correctly, within the required timeframes and without obstruction, is one of the most common areas where organisations fall short.


Data table: Individual rights under UK GDPR and response timeframes

Individual RightTime Limit to RespondNotes
Right of Access (Subject Access Request)1 month (extendable by 2 months)Free of charge in most cases
Right to Rectification1 monthMust correct inaccurate or incomplete data
Right to Erasure1 monthNot absolute; depends on lawful basis used
Right to Restrict Processing1 monthData retained but not actively processed
Right to Data Portability1 monthApplies where processing based on consent or contract
Right to ObjectMust stop processing immediatelyApplies to direct marketing without exception
Rights Related to Automated Decision-Making1 monthIncludes right to human review of automated decisions

The 7 Golden Rules of Data Protection and How They Apply to UK Organisations

The phrase “seven golden rules of data protection” is sometimes used interchangeably with GDPR’s seven principles, and in practice they refer to the same framework. What matters for UK businesses is how these rules translate into everyday decisions. Choosing not to collect a customer’s date of birth when only their postcode is needed, for example, reflects the data minimisation principle in action. Retaining supplier invoices for seven years to meet HMRC requirements reflects storage limitation balanced against a separate legal obligation.

The accountability principle deserves particular attention for smaller organisations who may assume GDPR is primarily a concern for large corporations. Maintaining a simple record of processing activities (ROPA), having a clear privacy notice on your website, and training staff on data handling basics are all practical ways to demonstrate accountability without a dedicated compliance team. The Information Commissioner’s Office (ICO) provides free guidance specifically tailored to small and medium-sized businesses navigating these requirements.

How GDPR Enforcement Works in the UK

The ICO is the UK’s independent data protection regulator and holds significant powers to investigate complaints and issue fines. Under UK GDPR, the maximum financial penalty for the most serious infringements is £17.5 million or 4% of global annual turnover, whichever is higher. Lower-tier penalties of up to £8.7 million or 2% of global turnover apply to less severe breaches, such as failures in record-keeping or notification obligations.

It is worth noting that the ICO’s approach is generally graduated and takes organisational size and intent into account. A small business that has made a genuine effort to comply but makes an administrative error is unlikely to face the same response as a large organisation that has wilfully ignored its obligations. That said, data breaches that affect large numbers of individuals, particularly where sensitive categories of data are involved, are treated seriously regardless of the size of the organisation responsible. Organisations experiencing a personal data breach that is likely to pose a risk to individuals must notify the ICO within 72 hours under UK GDPR Article 33.

What Are the Basic GDPR Rules? Bringing It All Together

Understanding what the basic GDPR rules are is the first step towards building a genuinely compliant organisation rather than one that simply goes through the motions. The seven principles provide the philosophical backbone, the individual rights framework sets out your practical obligations to the people whose data you hold, and the accountability principle ties it all together by demanding that you can evidence your approach. Compliance is not a one-off project but an ongoing commitment to handling data responsibly.

For businesses operating across the UK, the practical implications of GDPR are felt in everything from how a new client’s details are entered into a CRM system to how long old email lists are retained. Getting the basics right, clear privacy notices, documented lawful bases, trained staff, and a process for handling rights requests, makes the more complex aspects of compliance considerably more manageable. Many organisations find that treating GDPR not as a burden but as a framework for building customer trust actually strengthens their client relationships over time.

The regulation is, at its heart, about respect: respect for the individuals behind the data points, and respect for the responsibility that comes with holding information about people. Organisations that approach GDPR with that mindset tend to find compliance far less daunting than those who treat it purely as a legal obstacle.

  • The seven GDPR principles (lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability) form the legal foundation for all data processing activities in the UK.
  • Individuals hold specific enforceable rights under UK GDPR, including the right to access their data, the right to erasure, and the right to object to processing, all of which must be responded to within defined timeframes.
  • UK GDPR is enforced by the ICO, which can issue fines of up to £17.5 million for serious breaches, making genuine compliance a business priority rather than an optional extra.

What Are the Basic GDPR Rules: Frequently Asked Questions

What does GDPR stand for?

GDPR stands for General Data Protection Regulation. It is a piece of legislation that sets out how personal data must be collected, stored, and used by organisations operating in the UK and European Union.

What is personal data under GDPR?

Personal data is any information that can directly or indirectly identify a living individual. This includes obvious identifiers like names and email addresses, as well as less obvious ones such as IP addresses, location data, and device identifiers.

Who does GDPR apply to in the UK?

UK GDPR applies to any organisation, regardless of size or sector, that processes personal data about individuals in the UK. This includes sole traders, charities, and public bodies, not just large corporations.

What are the six lawful bases for processing data under GDPR?

The six lawful bases are consent, contract, legal obligation, vital interests, public task, and legitimate interests. Organisations must identify and document which basis applies before they begin processing personal data; you can learn more on the ICO's lawful basis guidance page.

What is a Subject Access Request?

A Subject Access Request (SAR) is a formal request by an individual to access the personal data an organisation holds about them. Organisations must respond free of charge within one month in the majority of cases.

What is the right to be forgotten under GDPR?

The right to be forgotten, formally known as the right to erasure, allows individuals to request that their personal data be deleted. It is not an absolute right and does not apply where there is a legal obligation to retain the data.

What counts as a GDPR breach?

A personal data breach is any security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Not every breach requires notification to the ICO, only those likely to pose a risk to individuals' rights and freedoms.

How long can organisations keep personal data?

GDPR does not set fixed retention periods. Organisations must determine how long data is needed for its original purpose and delete it once that period has passed, unless another legal obligation requires longer retention.

What is a Data Protection Officer (DPO)?

A Data Protection Officer is a designated individual responsible for overseeing an organisation's GDPR compliance. Appointing a DPO is mandatory for public authorities, organisations carrying out large-scale systematic monitoring, or those processing special category data at scale.

What are special categories of data under GDPR?

Special category data includes particularly sensitive information such as health data, racial or ethnic origin, political opinions, religious beliefs, biometric data, and sexual orientation. Processing this type of data requires both a lawful basis and an additional condition under Article 9 of UK GDPR.

What is the accountability principle in GDPR?

The accountability principle requires organisations to take responsibility for their data processing activities and to demonstrate compliance proactively. This means keeping records, implementing policies, training staff, and being able to evidence all of the above to regulators.

What is a Privacy Notice?

A Privacy Notice (sometimes called a Privacy Policy) is a document that explains to individuals how and why their personal data is collected and used. Under GDPR, it must be written in plain, clear language and must be provided at the point of data collection. For a broader overview of the regulation, the Wikipedia page on GDPR provides useful background context.

What happens if an organisation ignores GDPR?

The ICO can investigate complaints, issue enforcement notices, and impose fines of up to £17.5 million or 4% of global annual turnover for the most serious infringements. Reputational damage is often a greater practical concern for smaller businesses than financial penalties.

Does GDPR apply to paper records as well as digital data?

Yes. UK GDPR applies to personal data held in structured paper filing systems as well as digital formats. If paper records are organised in a way that allows easy retrieval of information about individuals, they fall within the scope of the regulation.