Back to glossary
Glossary
GDPR (UK GDPR)
UK data protection law governing how businesses must collect, store and protect personal data.
UK GDPR sets out legal obligations for how a business handles personal data — customers', employees', anyone's. That includes having a lawful basis to hold data, keeping it secure, only keeping it as long as necessary, and reporting serious data breaches within 72 hours. It's a legal compliance framework, not primarily a technical one, but good IT security practice (encryption, access control, backups) is usually what makes actual compliance achievable.
Related terms
Got a question that's not in the glossary?
Ask us directly — no jargon, straight answers.
Get in touch