Skip to main content

Compliance

What is GDPR (General Data Protection Regulation)?

GDPR is the EU's data protection regulation for how companies process personal data. See the 7 core principles, the IT requirements and the fines.

In short

GDPR (General Data Protection Regulation) is the EU's common set of rules for the processing of personal data.

The regulation has applied since 25 May 2018 and covers virtually all Danish businesses, because almost everyone processes personal data about customers, employees or suppliers. GDPR is built on seven core principles, including lawfulness, data minimisation, accuracy and (most importantly for IT) integrity and confidentiality: the data must be protected with appropriate technical and organisational measures.

In practice, that means requirements for access control, encryption, backup, logging and agreements with every supplier that processes data on your behalf. Datatilsynet, the Danish Data Protection Agency, supervises compliance in Denmark and can recommend fines of up to 4% of global annual turnover or 20 million euros. GDPR is therefore not only a legal project but very much an IT project.

MI Support IT helps Danish businesses with the technical side of GDPR compliance.

Back to the glossary

What is GDPR?

GDPR is the EU's data protection regulation: the common set of rules for how companies and public authorities may collect, store and process personal data. Personal data is any information that can be linked to a person: name, email, IP address, photos, salary data. Since virtually all businesses process that kind of data about customers and employees, virtually all are covered, regardless of size. In Denmark, the regulation is supplemented by the Danish Data Protection Act, and Datatilsynet (the Danish Data Protection Agency) supervises compliance.

The 7 core principles of GDPR

All processing of personal data must comply with seven principles:

  1. Lawfulness, fairness and transparency: there must be a lawful basis, and the data subjects must know what happens to their data.
  2. Purpose limitation: data is collected for explicit purposes and must not be reused for anything incompatible.
  3. Data minimisation: collect only what is necessary.
  4. Accuracy: data must be correct and kept up to date.
  5. Storage limitation: delete data when the purpose has been fulfilled.
  6. Integrity and confidentiality: data must be protected against unauthorised access, loss and leaks.
  7. Accountability: you must be able to document that you comply with the principles.

What does GDPR require of your IT?

Principles 6 and 7 are where GDPR turns into IT work. "Appropriate technical and organisational measures" means in practice:

  • Access control: employees should only be able to access the data they need, with MFA and proper management of permissions.
  • Encryption: of data both in transit and at rest, especially on portable devices.
  • Backup and recovery: loss of personal data is also a breach: you must be able to restore data after an outage or ransomware.
  • Logging and monitoring: so you can detect and document breaches. Personal data breaches must be reported to the Danish Data Protection Agency within 72 hours.
  • Data processing agreements: with every supplier that processes data for you, from hosting to payroll systems.

GDPR and NIS2: what applies to you?

GDPR and NIS2 overlap, but each addresses its own concern: GDPR protects personal data and applies to almost everyone; NIS2 sets requirements for cybersecurity and continuity of supply in selected sectors. If you are covered by both, that is good news in disguise: the technical measures (risk management, access control, contingency planning, supplier management) are largely the same, so the work can be reused. See also IT compliance for the overall picture and the Cyber Resilience Act for the requirements on products.

Fines and supervision in Denmark

The Danish Data Protection Agency can issue criticism, orders and, in the most serious cases, recommend fines of up to 20 million euros or 4% of global annual turnover. Danish cases have typically concerned missing deletion, overly broad access to data and missing data processing agreements, in other words basic matters, not sophisticated attacks. The cheapest insurance is to have the fundamentals in order: who has access to what, where the data lives, and when it is deleted. Some organisations must also appoint a DPO.

How MI Support IT can help

We help with the technical side of GDPR: access control, encryption, backup, logging and documentation, as part of a coherent IT security effort and with IT advisory when the requirements need to be translated into practice. A review of your current security setup is a good place to start, or contact us for a no-obligation chat.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.