Every time you order food online, fill up a college admission form, or sign up for a new app, you leave behind a trail of personal information. Who controls that trail? Who can see it, sell it, or delete it? The European Union answered these questions with one of the most influential laws in the digital economy: the General Data Protection Regulation, or GDPR. For students of business information systems, understanding GDPR is not just an academic exercise. It is the blueprint that most modern data protection laws, including India’s own privacy law, are built on.
Table of Contents
- What exactly is the GDPR
- Why the old directive was not enough
- What counts as personal data
- The seven core principles of GDPR
- Rights that GDPR gives individuals
- The right of access
- The right to be forgotten
- Other key rights
- Who is accountable: controllers and processors
- Penalties for non-compliance
- Why GDPR matters for Indian businesses
- GDPR and India’s own privacy law
- Bringing it all together
What exactly is the GDPR
The GDPR is a regulation adopted by the European Union to give individuals control over their personal data and to create one consistent set of privacy rules across all EU member states. It came into force in May 2018 and replaced the older Data Protection Directive of 1995, which had left each country free to interpret data protection rules differently. That patchwork approach made compliance confusing for businesses and left gaps in protection for citizens.
Why the old directive was not enough
The 1995 Directive was written before smartphones, social media, or cloud computing existed. As technology evolved and data breaches became routine news, EU lawmakers realised that a directive open to national interpretation could not keep up. The GDPR fixed this by being a regulation, not a directive, meaning it applies directly and uniformly in every EU country without needing separate national laws to enforce it.
What counts as personal data
One of GDPR’s biggest contributions is how broadly it defines personal data. It is not limited to your name or address. The regulation covers biometric identifiers like fingerprints and facial scans, genetic data, IP addresses, location data, and even online identifiers such as cookies. If a piece of information can directly or indirectly identify a living person, GDPR treats it as personal data that deserves protection. This wider definition matters for any business handling customer records, HR files, or app usage logs, since far more information falls under legal scrutiny than most people assume.
The seven core principles of GDPR
Article 5 of the regulation lays out the principles that every organisation must follow when processing personal data. The European Commission summarises these as the foundation of the entire law.
| Principle | What it means |
|---|---|
| Lawfulness, fairness, and transparency | Data must be collected and used legally, fairly, and in a way the individual understands. |
| Purpose limitation | Data can only be used for the specific purpose it was collected for. |
| Data minimisation | Only the data that is actually necessary should be collected. |
| Accuracy | Personal data must be kept correct and updated. |
| Storage limitation | Data should not be stored longer than necessary. |
| Integrity and confidentiality | Data must be secured against unauthorised access or loss. |
| Accountability | Organisations must be able to prove they follow all the above. |
The UK’s Information Commissioner’s Office notes that accountability is considered the principle that ties all the others together, since it forces companies to actually demonstrate compliance rather than simply claim it.
Rights that GDPR gives individuals
GDPR shifts power toward the individual, referred to in the law as the “data subject.” Instead of businesses deciding unilaterally what happens to your data, you get a defined set of rights you can actively exercise.
The right of access
Under Article 15, anyone can ask an organisation whether it is processing their personal data and request a copy of that data. This is often called a Subject Access Request, and companies typically must respond within a month.
The right to be forgotten
Also known as the right to erasure, this allows individuals to request deletion of their personal data under specific conditions, such as when the data is no longer needed for its original purpose or consent has been withdrawn. As GDPR.eu explains, this right is not absolute. Organisations can refuse deletion if they have a legal obligation to retain the data or a public interest reason to keep it.
Other key rights
- Right to rectification – correcting inaccurate data.
- Right to restrict processing – pausing how data is used without deleting it.
- Right to data portability – moving your data to another service provider in a usable format.
- Right to object – stopping processing for purposes like direct marketing.
- Rights around automated decision-making – protection against being profiled by algorithms without human review.
Who is accountable: controllers and processors
GDPR splits responsibility between two roles. A data controller is the organisation that decides why and how personal data is processed, such as a bank deciding to collect customer income details for loan approval. A data processor is any entity that processes data on the controller’s behalf, like a cloud hosting company storing that bank’s records. Both parties are legally accountable under GDPR, which is a significant shift from older laws that often placed responsibility only on the controller. This dual accountability pushes vendors and outsourcing partners, including many Indian IT and BPO firms working with European clients, to build privacy safeguards directly into their contracts and systems.
Penalties for non-compliance
GDPR enforces its rules with serious financial consequences. Violations can result in fines of up to โฌ20 million or 4 percent of a company’s global annual turnover, whichever amount is higher. This structure means the penalty scales with the size of the business, making it a genuine deterrent for large multinational corporations rather than a minor cost of doing business.
Why GDPR matters for Indian businesses
GDPR does not stay within EU borders. It applies to any organisation, anywhere in the world, that processes the personal data of people located in the EU, whether by offering goods and services to them or by monitoring their online behaviour. This means an Indian e-commerce company shipping to European customers, or an IT services firm processing European client data, must comply just as a Berlin-based company would.
GDPR and India’s own privacy law
India passed its own comprehensive privacy law, the Digital Personal Data Protection Act, in August 2023. The two laws share the same goal but differ in scope and structure.
| Aspect | GDPR | DPDP Act |
|---|---|---|
| Scope | All personal data, digital and offline | Digital personal data only |
| Key roles | Controller and processor | Data fiduciary and data processor |
| Individual referred to as | Data subject | Data principal |
| Maximum penalty | Up to 4% of global turnover | Up to โน250 crore, as a fixed cap |
According to a comparison by law firm AZB & Partners, one of the sharpest differences is scope: GDPR covers offline records that are part of a structured filing system, while the DPDP Act applies only to data that is digital or has been digitised. Legal analysts at Global Privacy & Security Compliance Blog also point out that the DPDP Act carries its own extraterritorial reach, applying to any digital processing of Indian residents’ data even when the company offering goods or services is based outside India. For commerce students, this comparison is a useful case study in how regulatory ideas travel and get adapted across different legal and economic contexts.
Bringing it all together
GDPR reshaped how businesses everywhere think about personal data. It forced companies to move from treating data collection as a free resource to treating it as something individuals have real, enforceable rights over. For anyone entering business, IT, or e-commerce roles, understanding these obligations is no longer optional. Every system that stores customer information, from a college’s student portal to a multinational’s CRM software, now operates in the shadow of frameworks like GDPR and its Indian counterpart.
What do you think? As more countries introduce GDPR-style laws, do you think Indian businesses are ready to meet these compliance standards, or will smaller companies struggle with the cost of building these systems? And between strict penalties and strong individual rights, which do you think does more to actually change how companies behave?
References
- https://gdpr.eu/what-is-gdpr/
- https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/principles-gdpr_en
- https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/
- https://gdpr.eu/right-to-be-forgotten/
- https://www.azbpartners.com/bank/indian-data-protection-law-versus-gdpr-a-comparison/
- https://www.globalprivacyblog.com/2023/12/indias-digital-personal-data-protection-act-2023-vs-the-gdpr-a-comparison/
Leave a Reply