{"id":4204,"date":"2018-05-30T10:15:00","date_gmt":"2018-05-30T09:15:00","guid":{"rendered":"https:\/\/www.sage.com\/en-gb\/blog\/?p=4204"},"modified":"2026-01-29T10:37:20","modified_gmt":"2026-01-29T10:37:20","slug":"what-is-the-gdpr","status":"publish","type":"post","link":"https:\/\/www.sage.com\/en-gb\/blog\/what-is-the-gdpr\/","title":{"rendered":"What is the GDPR and what does it mean?"},"content":{"rendered":"<header class=\"entry-header has-dark-background-color entry-header--has-illustration entry-header--has-illustration--generic\">\n\t<div class=\"container\">\n\t\t<div class=\"entry-header__row row align-center\">\n\t\t\t<div class=\"col col-lg-7 col-xlg-6 entry-header__content\">\n\t\t\t\t\t\t\t<div class=\"component component-single-header\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"entry-header__misc text--subtitle text--uppercase text--small\">\n\t\t\t\t\t\t\t<a href=\"https:\/\/www.sage.com\/en-gb\/blog\/category\/strategy-legal-operations\/\" class=\"entry-header__link\">Strategy, Legal &amp; Operations<\/a>\t\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t<div class=\"entry-title-wrapper\">\n\t\t\t\t\t<h1 class=\"entry-title\">\n\t\t\t\t\t\tWhat is the GDPR and what does it mean?\t\t\t\t\t<\/h1>\n\t\t\t\t<\/div>\n\n\t\t\t\t\t\t\t\t\t<p class=\"entry-header__description\">\n\t\t\t\t\t\t\t\t\t\t\t<\/p>\n\t\t\t\t\n\t\t\t\t\n\t\t\t\t\n\t\t\t<\/div>\n\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/div>\n\t<div class=\"single-post-details container\">\n\t\t<div class=\"col\">\n\t\t\t<span class=\"posted-on \"><time class=\"entry-date published\" datetime=\"2018-05-30T10:15:00+01:00\">30 May, 2018<\/time><\/span><span class=\"reading-time\"> min read<\/span>\n\t\t<button\n\t\t\ttype=\"button\"\n\t\t\tclass=\"social-share-button button button--icon button--secondary js-social-share-button\"\n\t\t\tdata-share-title=\"What is the GDPR and what does it mean?\"\n\t\t\tdata-share-url=\"https:\/\/www.sage.com\/en-gb\/blog\/what-is-the-gdpr\/\"\n\t\t\tdata-share-text=\"Please read this interesting article\"\n\t\t>\n\t\t\t<span class=\"social-share-button__share-label\">Share<\/span>\n\t\t\t<span class=\"social-share-button__copy-label\" hidden>Copy Link<\/span>\n\t\t\t<span class=\"social-share-button__copy-tooltip\" aria-hidden=\"true\" hidden>Copied<\/span>\n\t\t<\/button>\n\n\t\t\t\t<\/div>\n\t<\/div>\n<\/header>\n\n\n\n<div class=\"wp-block-post-author has-dark-background-color alignfull\">\n\t<div class=\"container\">\n\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<div class=\"co-authors\">\n\t\t\t\t\t\n\t\t<div class=\"entry-author-wrapper\">\n\t\t\t<a class=\"entry-author\" href=\"https:\/\/www.sage.com\/en-gb\/blog\/author\/staceymcintosh\/\">\n\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.sage.com\/en-gb\/blog\/wp-content\/uploads\/sites\/10\/2018\/11\/Stacey-McIntosh-350-1.jpg\" class=\"entry-author__image\" alt=\"\" \/>\t\t\t\t<span class=\"entry-author__name\">Stacey McIntosh<\/span>\n\t\t\t<\/a>\n\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/div>\n<\/div>\n\n\n\n<p>Have you got questions about the <a href=\"https:\/\/www.sage.com\/en-gb\/blog\/gdpr-what-employers-need-to-know\/\">General Data Protection Regulation<\/a>, which came into force on 25 May 2018? Are people in your business asking &#8220;what is the GDPR&#8221; or &#8220;what does <a href=\"https:\/\/www.sage.com\/en-gb\/gdpr\/\">the GDPR<\/a> mean for our company&#8221;? To answer those questions and more, we have put some answers together to help your business with the legislation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-gdpr\"><strong>What is the GDPR?<\/strong><\/h2>\n\n\n\n<p>The General Data Protection Regulation (GDPR) is the European Union\u2019s new data protection legislation, which replaced the EU Data Protection Directive.<\/p>\n\n\n\n<p>The EU has worked on bringing data protection legislation in line with how data is used today. For example, the internet and social media didn\u2019t have as big as an effect on personal data as they did when the current legislation was brought in. The new legislation will reflect this.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-does-the-gdpr-mean\"><strong>What does the GDPR mean?<\/strong><\/h2>\n\n\n\n<p>The <a href=\"https:\/\/www.sage.com\/en-gb\/blog\/tag\/gdpr\/\">GDPR<\/a> means individuals will have more say over what businesses and organisations can do with their personal data. There are tougher fines for those businesses that don\u2019t comply with GDPR or don\u2019t report data breaches.<\/p>\n\n\n\n<p>Those fines could be as much as 4% of annual turnover or \u20ac20m, whichever is greater. In the UK, the Information Commissioner\u2019s Office (ICO) will be tasked with investigating data breaches or wrongdoings as far as the GDPR is concerned. It will also potentially issue fines.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-data-protection-bill\"><strong>What is the Data Protection Bill?<\/strong><\/h2>\n\n\n\n<p>The Data Protection Bill is the UK government\u2019s new data protection legislation and it was published on 13 September 2017. It will implement most of the GDPR legislation into UK law once it\u2019s been passed by Parliament.<\/p>\n\n\n\n<p>The bill is currently making its way through the House of Commons and House of Lords and they need to approve any amendments before the bill can become an Act of Parliament. Once passed, the Data Protection Bill will replace the Data Protection Act 1998.<\/p>\n\n\n\n<p>As an EU piece of legislation, the GDPR\u2019s data protection rules will be harmonised across the EU \u2013 although there is some flexibility on how countries implement GDPR, which is where the UK government comes in with the Data Protection Bill.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-does-gdpr-stand-for\"><strong>What does GDPR stand for?<\/strong><\/h2>\n\n\n\n<p>GDPR stands for General Data Protection Regulation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-when-does-the-gdpr-come-into-force\"><strong>When does the GDPR come into force?<\/strong><\/h2>\n\n\n\n<p>On 25 May 2018, the GDPR came into force across all EU member states.<\/p>\n\n\n\n<p>The GDPR was approved by the EU Parliament on 14 April 2016, following four years of preparation and debate. That approval required the EU member states to agree to the final text of the new legislation. However, businesses were given two years \u2013 until 25 May 2018 \u2013 to prepare for the changes. And from that date onwards, GDPR must be put into practice.<\/p>\n\n\n\n<p>According to research undertaken by Sage (as part of our GDPR customer survey in October 2017, which featured 100 respondents), 57% of UK business lack awareness of GDPR, while 60% didn&#8217;t know what it meant for their business.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-will-gdpr-affect-my-business\"><strong>Will GDPR affect my business?<\/strong><\/h2>\n\n\n\n<p>In a word, yes. Even if your business is completely au fait with the Data Protection Act 1998, the requirements of the GDPR surpass it, so you&#8217;d still have to take the necessary steps to be compliant.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"video-container-wrap -mode-full\"><div class=\"video-container\"><video\n\t\t\t\tclass=\"sage-video video-js vjs-default-skin \"\n\t\t\t\twidth=\"640\"\n\t\t\t\theight=\"360\"\n\t\t\t\tdata-setup='{ \"controls\": true, \"aspectRatio\" : \"16:9\", \"poster\": \"https:\/\/img.youtube.com\/vi\/Y7k04399RJ4\/maxresdefault.jpg\", \"techOrder\": [\"youtube\"], \"enablejsapi\": 1, \"origin\": \"https:\/\/www.sage.com\", \"sources\": [{ \"type\": \"video\/youtube\", \"src\": \"https:\/\/www.youtube.com\/watch?v=Y7k04399RJ4\"}], \"youtube\": { \"ytControls\": 0, \"cc_load_policy\": 3, \"modestbranding\": 1, \"hl\": \"en_GB\", \"playsinline\": 1 } }'\n\t\t\t\tcrossorigin=\"\"><\/video><\/div><\/div>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-a-data-controller\"><strong>What is a data controller?<\/strong><\/h2>\n\n\n\n<p>The person, public authority, agency or other body who, alone or jointly with others, determines the purposes and means of the processing of personal data. If you are collecting personal data for your own use and purposes, you are the controller and fully liable for being compliant with the GDPR, including all security.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-a-data-processor\"><strong>What is a data processor?<\/strong><\/h2>\n\n\n\n<p>A person, public authority, agency or other body who processes personal data on behalf of a controller (other than employees of that controller). If you are processing personal data on behalf of another organisation, you are the processor and must only act on the instructions of the controller organisation. The GDPR now imposes direct obligations on data processors, not just data controllers.<\/p>\n\n\n\n<div class=\"single-cta\">\n\t<div class=\"single-cta__positioner\">\n\t\t<div class=\"single-cta__wrapper has-dark-background-color\">\n\t\t\t<div class=\"single-cta__content\">\n\t\t\t\t\t\t\t\t<h2 class=\"single-cta__title h3\">GDPR<\/h2>\n\n\t\t\t\t\t\t\t\t\t<div class=\"single-cta__description\">\n\t\t\t\t\t\t<p><!-- wp:paragraph --><\/p>\n<p>Need help with meeting your GDPR obligations and making sure your businesses processes are working in the correct way? Here&#8217;s what you need to know.<\/p>\n<p><!-- \/wp:paragraph --><\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a\n\t\t\t\t\t\thref=\"https:\/\/www.sage.com\/en-gb\/gdpr\/\"\n\t\t\t\t\t\tclass=\"single-cta__button button button--primary\"\n\t\t\t\t\t\t\t\t\t\t\t\t\tid=\"cta-id-3269\"\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\tdata-button-location=\"cta_box\"\n\t\t\t\t\t\t\t\t\t\t\t>Find out more<\/a>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<img decoding=\"async\" width=\"1440\" height=\"810\" src=\"https:\/\/www.sage.com\/en-gb\/blog\/wp-content\/uploads\/sites\/10\/2023\/09\/GettyImages-1478421401.jpg\" class=\"single-cta__image\" alt=\"Working on business priorities\" loading=\"lazy\" srcset=\"https:\/\/www.sage.com\/en-gb\/blog\/wp-content\/uploads\/sites\/10\/2023\/09\/GettyImages-1478421401.jpg 1440w\" sizes=\"auto, (min-width: 48em) 33vw, 100vw\" \/>\t\t\t<\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-personal-data\"><strong>What is personal data?<\/strong><\/h2>\n\n\n\n<p>This includes but isn\u2019t limited to a name, an identification number, location data, or an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-three-things-your-business-should-do-now\"><strong>Three things your business should do now<\/strong><\/h2>\n\n\n\n<p>Our Sage Business Experts shared some useful tips as they were preparing for the GDPR, which you will find useful if you need help with the GDPR. Here\u2019s what they had to say:<\/p>\n\n\n\n<p>Nicky Larkin, founder and managing director of <a href=\"https:\/\/goringeaccountants.co.uk\/\">Goringe Accountants<\/a>: \u201cIf you realise GDPR is going to be a big requirement for your business \u2013 and obviously it\u2019s tight now because of the deadline \u2013 use an external consultant.\u201d<\/p>\n\n\n\n<p>Keith Tully, a partner at <a href=\"https:\/\/www.realbusinessrescue.co.uk\/\">Real Business Rescue<\/a>: \u201cDon\u2019t panic.&nbsp;There is a wealth of information to help you and your business prepare, much of which is completely free.\u201d<\/p>\n\n\n\n<p>Steve Johnson, owner of Graphite Web Solutions: \u201cThe <a href=\"https:\/\/ico.org.uk\/\">ICO website<\/a> has a great checklist for data controllers that should help businesses step through the questions you need to consider.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-three-articles-you-should-read-now-on-the-gdpr\"><strong>Three articles you should read now on the GDPR<\/strong><\/h2>\n\n\n\n<p>We have written a series of articles that will help you and your business with the GDPR.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A guide for small businesses: <a href=\"https:\/\/www.sage.com\/en-gb\/blog\/gdpr-guide-small-businesses\/\">https:\/\/www.sage.com\/en-gb\/blog\/gdpr-guide-small-businesses\/<\/a><\/li>\n\n\n\n<li>A GDPR checklist: <a href=\"https:\/\/www.sage.com\/en-gb\/blog\/gdpr-12-important-things\/\">https:\/\/www.sage.com\/en-gb\/blog\/gdpr-12-important-things\/<\/a><\/li>\n\n\n\n<li>What employers need to know: <a href=\"https:\/\/www.sage.com\/en-gb\/blog\/gdpr-what-employers-need-to-know\/\">https:\/\/www.sage.com\/en-gb\/blog\/gdpr-what-employers-need-to-know\/<\/a><\/li>\n<\/ul>\n\n\n\n<div class=\"single-cta gated-content\">\n\t<div class=\"single-cta__positioner\">\n\t\t<div class=\"single-cta__wrapper has-dark-background-color\">\n\t\t\t<div class=\"single-cta__content\">\n\t\t\t\t\t\t\t\t<h2 class=\"single-cta__title h3\">Implementing GDPR: Lessons learned from UK businesses<\/h2>\n\n\t\t\t\t\t\t\t\t\t<div class=\"single-cta__description\">\n\t\t\t\t\t\t<p>Want to get more insights from businesses on the GDPR? Download this guide, read the stories of the business owners and get up to speed today.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a\n\t\t\t\t\t\thref=\"#gate-bd7e5bca-51df-4b7b-816e-26cf4d8ba1a6\"\n\t\t\t\t\t\tclass=\"single-cta__button button button--primary\"\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t>Get your guide<\/a>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<img decoding=\"async\" width=\"999\" height=\"666\" src=\"https:\/\/www.sage.com\/en-gb\/blog\/wp-content\/uploads\/sites\/10\/2018\/03\/GDPR-CTA-cover.jpg\" class=\"single-cta__image\" alt=\"\" loading=\"lazy\" srcset=\"https:\/\/www.sage.com\/en-gb\/blog\/wp-content\/uploads\/sites\/10\/2018\/03\/GDPR-CTA-cover.jpg 999w\" sizes=\"auto, (min-width: 48em) 33vw, 100vw\" \/>\t\t\t<\/div>\n<\/div>\n\n\n<div class=\"single-cta\">\n\t<div class=\"single-cta__positioner\">\n\t\t<div class=\"single-cta__wrapper has-dark-background-color\">\n\t\t\t<div class=\"single-cta__content\">\n\t\t\t\t\t\t\t\t<h2 class=\"single-cta__title h3\">Subscribe to the Sage Advice newsletter<\/h2>\n\n\t\t\t\t\t\t\t\t\t<div class=\"single-cta__description\">\n\t\t\t\t\t\t<p>Join more than 500,000 UK readers and get the best business admin strategies and tactics, as well as actionable advice to help your company thrive, in your inbox every month.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a\n\t\t\t\t\t\thref=\"#gate-b1a63862-3fa0-4a5e-bb67-c76b88bbc6b8\"\n\t\t\t\t\t\tclass=\"single-cta__button button button--primary\"\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t>Subscribe now<\/a>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<img decoding=\"async\" width=\"1440\" height=\"810\" src=\"https:\/\/www.sage.com\/en-gb\/blog\/wp-content\/uploads\/sites\/10\/2022\/04\/GettyImages-1073797282-1-1440x810.jpg\" class=\"single-cta__image\" alt=\"\" loading=\"lazy\" srcset=\"https:\/\/www.sage.com\/en-gb\/blog\/wp-content\/uploads\/sites\/10\/2022\/04\/GettyImages-1073797282-1-1440x810.jpg 1440w\" sizes=\"auto, (min-width: 48em) 33vw, 100vw\" \/>\t\t\t<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Have you got questions about the General Data Protection Regulation, which came into force on 25 May 2018? Are people in your business asking &#8220;what is the GDPR&#8221; or &#8220;what does the GDPR mean for our company&#8221;? To answer those questions and more, we have put some answers together to help your business with the [&hellip;]<\/p>\n","protected":false},"author":346,"featured_media":11535,"menu_order":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sage_video":true,"post_featured_image_hide":false,"footnotes":""},"categories":[9],"tags":[117,41],"business_type":[4,3],"lilypad":[],"context":[],"industry":[],"persona":[73,74,75],"imagine_tag":[138,91,109],"coauthors":[353],"class_list":["post-4204","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategy-legal-operations","tag-gdpr","tag-hr-process","business_type-small-business","business_type-medium-sized-business"],"sage_meta":{"region":"en-gb","author_name":"Stacey McIntosh","featured_image":"https:\/\/www.sage.com\/en-gb\/blog\/wp-content\/uploads\/sites\/10\/2022\/04\/GettyImages-1149029523.jpg","imagine_tags":{"138":"GDPR","91":"Growing business","109":"Small business"}},"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Sage Advice UK","distributor_original_site_url":"https:\/\/www.sage.com\/en-gb\/blog","push-errors":false,"_links":{"self":[{"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/posts\/4204","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/users\/346"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/comments?post=4204"}],"version-history":[{"count":0,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/posts\/4204\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/media\/11535"}],"wp:attachment":[{"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/media?parent=4204"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/categories?post=4204"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/tags?post=4204"},{"taxonomy":"business_type","embeddable":true,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/business_type?post=4204"},{"taxonomy":"lilypad","embeddable":true,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/lilypad?post=4204"},{"taxonomy":"context","embeddable":true,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/context?post=4204"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/industry?post=4204"},{"taxonomy":"persona","embeddable":true,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/persona?post=4204"},{"taxonomy":"imagine_tag","embeddable":true,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/imagine_tag?post=4204"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.sage.com\/en-gb\/blog\/api\/wp\/v2\/coauthors?post=4204"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}