GDPR in Plain English: What Every Business Must Know
The Regulation Everyone Fears (But Shouldn't)
Since coming into force in May 2018, GDPR has generated over €4.5 billion in fines. Yet for most SMEs, compliance is straightforward once you understand what the regulation actually requires.
The Six Core Obligations
1. Lawful Basis for Processing
Every time you collect or use personal data, you need a valid legal reason. The most common are consent, contract, and legitimate interest.
2. Data Minimisation
Only collect the data you actually need. If you don't need a user's phone number to deliver a service, don't ask for it.
3. Individual Rights
Data subjects have the right to access, correct, delete, and port their data. Your processes must be able to fulfil these requests within 30 days.
4. Breach Notification
If you suffer a data breach, you must notify the relevant supervisory authority within 72 hours — and affected individuals if the breach poses a high risk.
5. Data Protection by Design
Privacy must be built into your systems and processes from the start, not bolted on afterwards.
6. Staff Training
This is the obligation most frequently cited in enforcement actions. The GDPR explicitly requires that staff who handle personal data receive regular, documented training.
The Training Gap
According to the ICO and AEPD, inadequate staff training is cited as a contributing factor in over 40% of GDPR enforcement cases. Training doesn't need to be lengthy — short, frequent, engaging modules consistently outperform annual classroom sessions.
Download our GDPR Compliance Checklist for a step-by-step action plan.