Data Protection and GDPR

Plain-English answers to the most common questions about personal data, data protection and GDPR — including how the rules now differ between the UK and the EU, and the newer laws that sit alongside them.

What is personal data?

Personal data is any data that can identify a specific individual — either directly, or indirectly by combining it with other information.

What is data protection?

Data protection is the process of keeping personal data safe from misuse.

Why is data protection important?

Data protection matters because of the harm that can be done to people using data about them.

Crimes like identity theft and phishing rely on misusing data. Historically, data about people’s race, ethnicity and political views has been used to persecute them. The purpose of data protection law is to make sure organisations keep people’s data safe, so it isn’t misused in these ways.

What is GDPR?

GDPR stands for “General Data Protection Regulation”. It is an EU law on privacy and data protection, in force since 2018, covering people in the European Union and European Economic Area.

GDPR is intended to give people more control over their data by requiring organisations to be transparent about what they do with personal information. Organisations that don’t comply can be fined up to €20 million, or 4% of global annual turnover if that is greater.

It applies to organisations based in the EU, and to organisations anywhere in the world that hold data on people in the EU.

Does GDPR still apply in the UK?

Not the EU version. After Brexit the UK kept an equivalent law of its own, usually called UK GDPR, which sits alongside the Data Protection Act 2018 and is enforced by the Information Commissioner’s Office. It was amended by the Data (Use and Access) Act 2025.

In practice the two regimes remain close, and an organisation compliant with one is usually most of the way to complying with the other. But they are now separate laws that can diverge, and the maximum UK fine is expressed in sterling: £17.5 million or 4% of global turnover, whichever is greater.

If you handle data on people in both the UK and the EU, you need to think about both.

When did GDPR come into force?

GDPR came into effect on 25 May 2018.

What are the 7 principles of GDPR?

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality (security)
  • Accountability

What data is protected by GDPR?

GDPR protects personal data. Examples include:

  • Your name
  • Your email address
  • Your home address
  • Unique identification numbers, such as a National Insurance number
  • Location data from your phone
  • The IP address of your computer, tablet or phone
  • Cookies on your devices
  • Your medical records
  • Genetic data
  • Biometrics, such as fingerprints or images of your face
  • Data about your race, ethnic origin or sexuality
  • Data about your political or religious affiliations
  • Trade union membership

The last few categories are treated as special category data and need a stronger legal basis before they can be processed at all.

What is a data subject?

“Data subject” is the legal term for the person that some data is about.

What is a data breach?

A data breach is when data ends up in the hands of someone who doesn’t have permission to access it.

That can happen deliberately, if an attacker breaks into an organisation’s systems and steals data. It can also happen accidentally — an employee leaving a laptop on a train, or emailing a spreadsheet to the wrong recipient.

Are data breaches on the rise?

Reported breaches have risen substantially since GDPR came into force. Whether actual breaches have risen is a harder question, and the honest answer is that nobody really knows.

The reason is that the reporting rules changed at the same time as the counting started. GDPR requires organisations to notify their regulator of qualifying breaches within 72 hours; before 2018, most had no such duty. So a rising line on a chart partly measures breaches, and partly measures the growth of an obligation to admit to them. Treat year-on-year comparisons that straddle 2018 with suspicion.

Some large breaches that shaped how the public thinks about this:

  • Yahoo! (2013–14, disclosed 2016) – every one of its roughly 3 billion accounts was affected, the largest breach on record
  • Equifax (2017) – attackers exploited an unpatched vulnerability to reach the records of about 147 million people
  • Marriott (disclosed 2018) – an intrusion into the Starwood guest reservation database exposed data on hundreds of millions of guests
  • British Airways (2018) – attackers harvested payment details by redirecting customers to a fraudulent site
  • TalkTalk (2015) – an attack affecting a portion of its customer base, and an early test of UK regulatory response

Are data processors liable for GDPR fines?

Yes. Under GDPR, data processors as well as data controllers can be fined. This was a change from the previous Data Protection Act regime, under which liability sat with the controller.

Fines for processors are up to €10 million or 2% of global turnover, whichever is greater — half the maximum that applies to the most serious controller breaches.

Do I need a checkbox on contact forms under GDPR?

Maybe. GDPR says nothing about checkboxes specifically — it sets a standard, not a design.

The standard is that consent must be specific, informed, freely given and unambiguous, and that you must make clear what you intend to do with the data. If you plan to send marketing, an unticked checkbox with clear wording is a practical way to meet that standard.

Note that consent is only one of six lawful bases. If you are simply replying to an enquiry someone sent you, you may not need consent at all — and asking for it when you don’t need it creates its own problems.

Are Google Forms GDPR compliant?

Google Forms can be used in a GDPR-compliant way, but the tool doesn’t make you compliant — how you use it does.

This question used to turn on whether personal data could lawfully be sent to a US company at all. The Court of Justice of the EU struck down the Privacy Shield framework in 2020 in the Schrems II judgment, and in 2022 several European regulators found specific uses of Google Analytics unlawful on transfer grounds. That uncertainty was largely resolved by the EU–US Data Privacy Framework, adopted in 2023, which Google participates in.

So the transfer question is, for now, settled. What remains your responsibility: having a lawful basis for collecting the data, telling people what you will do with it, collecting no more than you need, and being able to honour requests to access or delete it.

What other EU digital laws should I know about?

GDPR is no longer the whole picture. Since it was written, the EU has added several laws that sit alongside it:

  • Digital Services Act (DSA) – obligations on online platforms around illegal content, transparency and advertising, fully applicable from 2024
  • Digital Markets Act (DMA) – competition rules for designated “gatekeeper” platforms, applicable from 2024
  • AI Act – a risk-based framework for artificial intelligence, in force from 2024 and phasing in obligations from 2025
  • Data Act – rules on access to and sharing of data generated by connected products and services

The UK has taken a different route, with the Online Safety Act covering some of the same ground as the DSA, and no general AI statute so far.

Last reviewed August 2026. Since this page was first written, the UK has left the EU and now has its own data protection regime, and the EU has added several further digital laws alongside GDPR. This is general information, not legal advice.