1. Overview of GDPR
What is GDPR and why does it matter
The General Data Protection Regulation (GDPR) is a data protection law that came into force across the EU in May 2018. When the UK left the EU, it kept an equivalent law on the domestic statute book: the UK GDPR, which sits alongside the Data Protection Act 2018 (DPA 2018).
Together, the UK GDPR and DPA 2018 set the rules for how organisations in the UK must collect, use, store, and share personal data. The regulator that enforces this law in the UK is the Information Commissioner's Office (ICO).
Why it matters
Getting data protection wrong is not a small thing. The ICO can issue fines of up to £17.5 million or 4% of annual global turnover, whichever is higher, for the most serious breaches. Beyond fines, mishandling personal data damages trust, and trust is hard to win back once lost.
But GDPR is not just a compliance exercise. At its core it is a set of principles for treating people's information with the same care you would want your own treated with: collect only what you need, keep it safe, be honest about what you do with it, and give people control over it.
› Course contents
Principles
Rights of the individual
Legal bases for processing