northdan.
Vezi pagina în română

IT Glossary

What is GDPR?

The EU's personal data regulation: rules for any company that collects data about people — which is to say, every company.

If your company has employees, individual customers, a contact form or security cameras — and it has — then it processes personal data and falls under GDPR, the EU regulation in force since 2018 and the de facto global benchmark for privacy law. Strip away the folklore about fines and the core is reasonable: collect people's data on a legal basis (contract, legal obligation, legitimate interest or consent — which is only one of the options, not a universal requirement), for declared purposes, no more than needed and for no longer than needed, protect it sensibly, and honor people's enforceable rights to see, correct or delete what you hold. For a small or mid-sized business, workable compliance is a finite package: an inventory of what data you process and where it flows, honest privacy notices for customers and staff, processing agreements with the vendors who touch your data (accountants, hosting, marketing agencies), common-sense technical measures — restricted access, strong passwords, laptop encryption, backups — and a procedure for handling incidents and requests. Regulators do fine small firms, typically for avoidable negligence: exposed databases, marketing without consent, excessive employee monitoring. But fear is the weaker motivator; increasingly, demonstrable data hygiene is a commercial asset, because corporate clients demand it in vendor audits before they sign anything.

Let’s talk about your project

Message us on WhatsApp or send an email — you talk directly to a developer.

office@northdan.com · +40 752 070 247

Why it matters for your business

Legal risk kept under control

Baseline compliance — documented, not perfect — drastically reduces exposure to fines and to complaints from individuals.

A passport to corporate clients

Large companies' vendor questionnaires include GDPR as standard — the firm with its homework done passes; the other loses contracts.

Less data, cleaner systems

The minimization the regulation demands creates useful order: fewer stale, pointless records mean lower risk and simpler systems.

Frequently asked questions

Does my small company need a DPO (data protection officer)?

Most likely not — a DPO is mandatory for public authorities, large-scale systematic monitoring or massive processing of sensitive data. What you need regardless: one internal person who owns the topic — inventory, policies, responding to requests — even without the official title and its bureaucracy.

Do we need consent for everything — even invoicing?

No — that is the most widespread GDPR myth: invoicing rests on legal obligation, employee data on the employment contract, and many processing activities on legitimate interest. Consent is typically required for marketing (newsletters) and non-essential cookies — and once requested it must be genuine: freely given, specific and easy to withdraw.

What do we do when a customer asks us to delete all their data?

Verify identity, respond within a month, and delete whatever you have no obligation to keep — noting that invoices and accounting records stay (tax law overrides the deletion request), while marketing profiles and data without a retention basis go. The procedural key is knowing where the customer's data lives across your systems — exactly what a timely inventory solves.