Back to glossary
Glossary

GDPR (UK GDPR)

UK data protection law governing how businesses must collect, store and protect personal data.

UK GDPR sets out legal obligations for how a business handles personal data — customers', employees', anyone's. That includes having a lawful basis to hold data, keeping it secure, only keeping it as long as necessary, and reporting serious data breaches within 72 hours. It's a legal compliance framework, not primarily a technical one, but good IT security practice (encryption, access control, backups) is usually what makes actual compliance achievable.

Related terms

Got a question that's not in the glossary?

Ask us directly — no jargon, straight answers.

Get in touch