Skip to content
atlas
← Back to the entry

What GDPR is and who it applies to

The General Data Protection Regulation, Regulation (EU) 2016/679, has applied since 25 May 2018. Unlike NIS2 it is a regulation, so it applies directly in every member state. National law only fills in the gaps the regulation leaves open; in Denmark that is the Data Protection Act (databeskyttelsesloven), and the supervisory authority is Datatilsynet.

GDPR applies to anyone who processes personal data - any information about an identified or identifiable living person - in an organised way. There is no size threshold and no sector list: a two-person webshop, a municipality and a hospital are all covered. Two roles matter:

GDPR also reaches organisations outside the EU when they offer goods or services to people in the EU or monitor their behaviour.

The key requirements

Article 5 - the principles. Everything else in GDPR follows from these:

Principle In plain terms
Lawfulness, fairness and transparency Have a legal basis, do not surprise people, tell them what you do
Purpose limitation Collect for specified purposes and do not reuse for something incompatible
Data minimisation Only what is necessary for the purpose
Accuracy Keep it correct and up to date
Storage limitation Delete or anonymise when no longer needed
Integrity and confidentiality Protect it with appropriate security
Accountability (Art. 5(2)) Be able to demonstrate that you comply

Article 6 lists the six legal bases (consent, contract, legal obligation, vital interests, public task and legitimate interests). Article 9 adds stricter rules for special categories such as health data, and data subjects have rights under Articles 15-22: access, rectification, erasure, restriction, portability and objection.

Article 25 - data protection by design and by default. Protection must be built into systems and processes from the start, and the default settings must process only what is necessary. For a coordinator this means getting into projects early, not reviewing them the week before go-live.

Article 28 - processors. When a supplier processes personal data for you, a written data processing agreement is mandatory. It must state, among other things, that the processor acts only on documented instructions, keeps staff bound by confidentiality, implements Article 32 security, uses sub-processors only with authorisation, assists with data-subject rights and breaches, and deletes or returns data at the end. The controller must also follow up - for example by reviewing audit reports from the supplier.

Article 30 - records of processing activities. A register of what data you process, why, about whom and for how long. It is the backbone of most GDPR work.

Article 32 - security of processing. Controller and processor must implement “appropriate technical and organisational measures” matched to the risk. The article mentions pseudonymisation and encryption, ongoing confidentiality, integrity, availability and resilience, the ability to restore data after an incident, and regular testing of the measures. This is where GDPR meets ISO 27001 and the CIS Controls.

Articles 33 and 34 - personal data breaches.

Who When What
Controller → Datatilsynet (Art. 33) Without undue delay, and where feasible within 72 hours of becoming aware Notify unless the breach is unlikely to result in a risk to people
Processor → controller (Art. 33(2)) Without undue delay Tell the controller so the clock can start
Controller → affected people (Art. 34) Without undue delay When the breach is likely to result in a high risk
Controller (Art. 33(5)) Always Document every breach internally, reported or not

Article 35 requires a data protection impact assessment for high-risk processing, and Article 37 requires a data protection officer in certain cases, such as public authorities. Article 83 sets two tiers of maximum fines: up to EUR 10 million or 2 % of global annual turnover, and up to EUR 20 million or 4 % for breaches of the principles and rights - in both cases whichever is higher. In Denmark, fines are as a rule set by the courts after Datatilsynet has reported a case to the police.

How GDPR connects to the other frameworks

What a coordinator actually does with it

Common misunderstandings

Atlas is in beta.