About this module
GDPR can sound abstract until it touches normal work. This lesson translates the basics into employee behavior: what controllers and processors do, why every use of personal data needs a lawful basis, and how principles like fairness, transparency, purpose limitation, minimization, and accuracy shape daily decisions. Learners also cover prohibited behaviors, including unauthorized sharing, consumer apps, personal devices, and role-inappropriate access. The 72-hour breach reporting deadline makes fast escalation essential. If someone handles EU resident data, the habit is simple: use approved tools, apply need-to-know access, and report concerns immediately.
Key takeaways
Welcome. In this module you'll learn the core requirements of GDPR and exactly what they mean for your day-to-day work.
GDPR stands for the General Data Protection Regulation. It came into force on 25 May 2018 and sets strict rules on how personal data must be collected, stored, and used — applying to every organisation that handles data about EU residents.
GDPR distinguishes between two key roles. A Data Controller is any organisation that determines why and how personal data is processed.
As a company we are a controller — we decide what data we collect and what we do with it. A Data Processor handles data on the controller's behalf — for example a cloud provider or payroll supplier.
Both roles carry legal obligations. Regardless of your job title, if you handle personal data, GDPR applies to you.
The penalties for non-compliance are severe. Regulators can impose fines of up to twenty million euros, or four percent of a company's total worldwide annual revenue — whichever amount is larger.
No organisation can afford to ignore GDPR. GDPR requires every act of data processing to have a lawful basis.
There are six: consent from the individual, a contractual necessity, a legal obligation on the organisation, protection of vital interests, a public task, or a legitimate interest — where the individual's rights do not override the organisation's need. The first principle is lawfulness, fairness, and transparency.
Every time we use someone's data there must be a legal basis, it must be fair, and the person must know it is happening. Purpose limitation means we can only use data for the reason it was originally collected.
If a customer gives us their email for order updates, we cannot use it for marketing without a separate legal basis. Data minimisation means collecting only what is strictly necessary.
Accuracy means keeping records correct and deleting data that is out of date. Both reduce our risk and respect individuals' rights.
There are four behaviours that are strictly prohibited under GDPR. Never share personal data with people who do not have authorisation.
Never use personal email or consumer apps to send customer data. Never save personal data to an unencrypted personal device.
And never access records that are outside your role. GDPR gives individuals a powerful set of rights over their own data.
They can request access to everything we hold on them, ask us to correct errors, demand erasure in certain circumstances, restrict how we use their data, receive it in a portable format, or object to processing.
When you receive a data subject request, escalate it to the privacy team immediately — we have strict deadlines to meet. These are the five habits every employee must build.
Lock your screen whenever you step away. Use only company-approved tools.
Apply a strict need-to-know rule — if it is not your data to see, do not look at it. Shred printed personal data.
And report anything suspicious to the privacy team without delay. Under GDPR, when a personal data breach is discovered the clock starts immediately.
The organisation has just 72 hours to report it to the data protection authority. If individuals face high risk, they must be told directly too.
That timeline only works if employees report incidents the moment they spot them. Enforcement is real and growing.
More than fourteen hundred fines have been issued across Europe since GDPR came into force. Regulators are actively investigating organisations of every size.
Compliance is not optional — it is a legal obligation with serious financial and reputational consequences. If you think a breach has occurred, act quickly and carefully.
Stop what you are doing. Write down exactly what happened.
Tell your manager and the privacy team immediately — every minute counts. Do not discuss it with others before the team has assessed it.
And cooperate fully with the investigation that follows. GDPR is everyone's responsibility.
Know the rules. Apply them every day.
And protect the people whose data we hold. Complete the assessment now to earn your GDPR Basics certificate and continue to the next module.



