Compliance

GDPR

General Data Protection Regulation

The General Data Protection Regulation is the European Union's data protection framework, governing how organisations collect, process, store, protect, and disclose personal data belonging to individuals in the EU.

Why GDPR matters in a Microsoft estate

GDPR matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.

How GDPR shows up in practice

It is built around a defined set of core principles: lawfulness, fairness and transparency in how data is used; purpose limitation, meaning data collected for one stated purpose should not simply be reused for an unrelated one without a fresh lawful basis; data minimisation, collecting only what is genuinely needed rather than accumulating data speculatively; accuracy; storage limitation, meaning personal data should not be retained indefinitely once its original purpose no longer requires it; and integrity and confidentiality, the security obligation to protect data against unauthorised access, loss, or damage.

GDPR grants individuals, referred to as data subjects, specific enforceable rights over their own data, including the right of access to obtain a copy of data held about them, the right to rectification of inaccurate data, the right to erasure in defined circumstances, often called the right to be forgotten, and the right to data portability. Organisations processing personal data need documented, workable processes actually capable of honouring these rights within the regulation's response deadlines, not merely a policy stating that they will. A distinction that matters operationally is between a data controller, the organisation that determines why and how personal data is processed, and a data processor, an organisation that processes data on the controller's behalf and instruction, such as a cloud or software vendor.

The two roles carry different specific obligations, and a single organisation is frequently both simultaneously for different data sets it handles. Since the UK's departure from the EU, GDPR as such no longer applies directly within the UK; a near-identical framework, UK GDPR, now governs data processing carried out within the UK specifically, and organisations operating across both jurisdictions need to track compliance against both frameworks, since they are closely aligned in substance but are legally distinct instruments that can diverge over time.

Related terms

Glossary