What is GDPR?
GDPR is the EU's data protection regulation: the common set of rules for how companies and public authorities may collect, store and process personal data. Personal data is any information that can be linked to a person: name, email, IP address, photos, salary data. Since virtually all businesses process that kind of data about customers and employees, virtually all are covered, regardless of size. In Denmark, the regulation is supplemented by the Danish Data Protection Act, and Datatilsynet (the Danish Data Protection Agency) supervises compliance.
The 7 core principles of GDPR
All processing of personal data must comply with seven principles:
- Lawfulness, fairness and transparency: there must be a lawful basis, and the data subjects must know what happens to their data.
- Purpose limitation: data is collected for explicit purposes and must not be reused for anything incompatible.
- Data minimisation: collect only what is necessary.
- Accuracy: data must be correct and kept up to date.
- Storage limitation: delete data when the purpose has been fulfilled.
- Integrity and confidentiality: data must be protected against unauthorised access, loss and leaks.
- Accountability: you must be able to document that you comply with the principles.
What does GDPR require of your IT?
Principles 6 and 7 are where GDPR turns into IT work. "Appropriate technical and organisational measures" means in practice:
- Access control: employees should only be able to access the data they need, with MFA and proper management of permissions.
- Encryption: of data both in transit and at rest, especially on portable devices.
- Backup and recovery: loss of personal data is also a breach: you must be able to restore data after an outage or ransomware.
- Logging and monitoring: so you can detect and document breaches. Personal data breaches must be reported to the Danish Data Protection Agency within 72 hours.
- Data processing agreements: with every supplier that processes data for you, from hosting to payroll systems.
GDPR and NIS2: what applies to you?
GDPR and NIS2 overlap, but each addresses its own concern: GDPR protects personal data and applies to almost everyone; NIS2 sets requirements for cybersecurity and continuity of supply in selected sectors. If you are covered by both, that is good news in disguise: the technical measures (risk management, access control, contingency planning, supplier management) are largely the same, so the work can be reused. See also IT compliance for the overall picture and the Cyber Resilience Act for the requirements on products.
Fines and supervision in Denmark
The Danish Data Protection Agency can issue criticism, orders and, in the most serious cases, recommend fines of up to 20 million euros or 4% of global annual turnover. Danish cases have typically concerned missing deletion, overly broad access to data and missing data processing agreements, in other words basic matters, not sophisticated attacks. The cheapest insurance is to have the fundamentals in order: who has access to what, where the data lives, and when it is deleted. Some organisations must also appoint a DPO.
How MI Support IT can help
We help with the technical side of GDPR: access control, encryption, backup, logging and documentation, as part of a coherent IT security effort and with IT advisory when the requirements need to be translated into practice. A review of your current security setup is a good place to start, or contact us for a no-obligation chat.