GDPR, or the General Data Protection Regulation, is an EU regulation on the protection of personal data, known in Poland as RODO. It regulates the principles of processing personal data of individuals, the obligations of companies, institutions, online stores, website administrators, organizations, and entities that use the data of customers, employees, users, or contractors. GDPR is not just a formality, a privacy policy, or a cookies notice. It is an entire system of rules designed to ensure that personal data is collected lawfully, used fairly, stored securely, shared only when there is a legal basis, and deleted when it is no longer needed.
What is GDPR?
GDPR is an EU regulation that defines how personal data may be collected, stored, used, transferred, secured, and deleted. Its purpose is to protect the privacy of individuals and to harmonize data processing rules across the European Union.
In practice, GDPR applies to almost every company, website, store, foundation, school, public office, organization, service provider, employer, and website administrator that deals with personal data of individuals. It is not only about large customer databases. Personal data also appears in contact forms, newsletters, online orders, e-mail correspondence, CRM systems, invoices, recruitment, monitoring, online analytics, and user panels.
GDPR does not prohibit the processing of data. However, it imposes conditions: data must be processed lawfully, for a specific purpose, within a limited scope, for a defined period, and with appropriate safeguards. The person whose data is concerned should know who processes their data, why, on what legal basis, for how long, and what rights they have.
In short: GDPR is not one consent or one document on a website. It is a set of principles, obligations, and procedures intended to ensure that personal data is processed fairly, securely, and only when there is a legal basis for doing so.
Who does GDPR apply to?
GDPR applies to entities that process personal data of individuals in connection with professional, business, public, social, or organizational activity. This may include a company, sole proprietorship, online store, clinic, school, public office, association, foundation, internet portal, marketing agency, software house, event organizer, or the owner of a website with a contact form.
It does not matter whether the company is large or small. A small business may also process the data of customers, employees, job candidates, website users, newsletter recipients, or people sending inquiries through a form. The scope of obligations may differ, but the scale of activity does not automatically exempt anyone from complying with data protection principles.
| Entity | Example of data | Typical GDPR situations |
|---|---|---|
| Online store | First name, last name, address, e-mail, phone number, order history | Order fulfillment, customer account, complaints, newsletter. |
| Company website | Data from a contact form, IP address, cookies | Handling inquiries, analytics, marketing, forms. |
| Employer | Data of employees, candidates, contractors | HR, recruitment, contracts, payroll, authorizations. |
| Foundation or association | Data of members, donors, volunteers | Membership service, donations, events, communication. |
| Internet portal | User accounts, comments, IP addresses, logs | Registration, moderation, security, statistics. |
| Marketing agency | Mailing databases, leads, clients' customer data | Campaigns, remarketing, newsletters, entrusted processing. |
What is personal data?
Personal data is information relating to an individual who can be identified directly or indirectly. It is not only a first name, last name, and national identification number. Personal data may also include an e-mail address, phone number, home address, customer number, user ID, IP address, location data, purchase history, payment data, photograph, voice recording, or information about a user's behavior in a service.
Not every piece of information will automatically be personal data in every context. The key question is whether a specific person can be identified based on that information or by combining it with other data. That is why an e-mail address in the form Adres poczty elektronicznej jest chroniony przed robotami spamującymi. W przeglądarce musi być włączona obsługa JavaScript, żeby go zobaczyć. will usually be personal data, and an apparently technical user identifier may also be personal data if it can link activity to a specific person.
| Type of data | Examples | Practical comment |
|---|---|---|
| Identification data | First name, last name, national ID number, document number | They directly identify a specific person. |
| Contact details | E-mail, phone number, mailing address | They most often appear in forms, contracts, and orders. |
| Technical data | IP address, cookie ID, logs, device ID | They may be personal data if they allow a user to be identified or profiled. |
| Transaction data | Purchase history, complaints, payments, orders | They are often processed by stores and CRM systems. |
| Special categories of data | Health, political opinions, religion, biometrics, sexual orientation | They require particular caution and usually a stronger legal basis. |
Practical note: it is a mistake to assume that personal data means only a national ID number, identity card number, and home address. In online activity, personal data very often also includes e-mail addresses, IP addresses, user IDs, cookies, and activity history.
What does processing personal data mean?
Processing personal data means practically any operation performed on data. It is not only active use of the data. Processing already includes collecting data, recording it in a system, storing it, organizing it, sending it, sharing it, retrieving it, analyzing it, updating it, copying it, archiving it, and deleting it.
In practice, a company processes data when it receives a message from a contact form, sends an invoice, maintains a customer account, fulfills an order, signs a user up for a newsletter, uses analytics, conducts recruitment, creates a list of event participants, or stores an employee's data in HR documentation.
| Activity | Is this data processing? | Example |
|---|---|---|
| Collecting data | Yes | Contact form, order form, account registration. |
| Storing data | Yes | Customer database, e-mail inbox, CRM system. |
| Sending messages | Yes | Newsletter, reply to an inquiry, message to a customer. |
| Sharing data | Yes | Transferring data to a courier, accountant, or hosting company. |
| Deleting data | Yes | Deleting a user account or deleting data after the retention period expires. |
The most important GDPR principles
GDPR is based on several fundamental principles. They are the starting point for assessing whether data is processed properly. It is not enough to have a privacy policy on the website. One must also actually follow the principles of lawfulness, transparency, data minimization, purpose limitation, accuracy, storage limitation, confidentiality, integrity, and accountability.
The most important change is a change in mindset. Personal data should not be collected "just in case", stored indefinitely, or used for purposes about which the person has not been informed. The controller should be able to explain why the data is needed, on what basis it is processed, and how it is protected.
| GDPR principle | What does it mean? | Practical example |
|---|---|---|
| Lawfulness | Data must have a legal basis for processing. | Performance of a contract, legal obligation, consent, or legitimate interest. |
| Fairness and transparency | The person should know what happens to their data. | A clear information notice and privacy policy. |
| Purpose limitation | Data is collected for a specific, defined purpose. | Data from a contact form is used to reply, not automatically for a newsletter. |
| Data minimization | Only data that is truly needed is collected. | An inquiry form should not require a national ID number. |
| Accuracy | Data should be up to date and correct. | A customer can update their delivery address or account details. |
| Storage limitation | Data is not kept longer than necessary. | Job candidate data is deleted after recruitment ends, unless there is another basis. |
| Integrity and confidentiality | Data must be protected against loss and unauthorized access. | Passwords, permissions, encryption, backups. |
| Accountability | The controller should be able to demonstrate compliance with the principles. | Documentation, registers, procedures, data processing agreements. |
In short: GDPR requires not only formal documents, but also real order in data management. You need to know what data you have, why you have it, where it is stored, who has access to it, who it is transferred to, and when it should be deleted.
Legal bases for processing data
Every processing of personal data must have a legal basis. This is one of the most important elements of GDPR. In practice, people often wrongly assume that consent is always required. Meanwhile, consent is only one of the legal bases. In many situations, data may, and sometimes must, be processed on another basis.
For an online store, the basis for processing customer data may be the performance of a contract, because without the data it is impossible to fulfill the order. For issuing an invoice, the basis will be a legal obligation. For pursuing claims, it may be legitimate interest. Consent, on the other hand, will be typical for a marketing newsletter, unless another appropriate basis exists and consents required under electronic communications rules are needed.
| Legal basis | When does it apply? | Example |
|---|---|---|
| Consent | When a person voluntarily agrees to a specific purpose. | Newsletter subscription, consent for selected marketing activities. |
| Performance of a contract | When data is necessary to conclude or perform a contract. | Order fulfillment, customer account service, service delivery. |
| Legal obligation | When the law requires data processing. | Accounting, invoices, tax obligations, employee documentation. |
| Vital interests | When processing protects the life or health of a person. | Emergency, medical, rescue situations. |
| Public task | When an entity performs tasks in the public interest. | Activities of public offices, public schools, or institutions. |
| Legitimate interest | When the controller has a legally justified purpose and the person's rights do not override it. | Pursuing claims, security, basic B2B contact, defense against abuse. |
Practical tip: do not ask for consent where processing results from a contract or legal obligation. Consent should be voluntary and withdrawable, so it is not a good solution for actions that must be performed anyway.
Consent under GDPR - when is it needed?
Consent is one of the best-known bases for data processing, but also one of the most frequently misused. For consent to be valid, it should be freely given, specific, informed, and unambiguous. It cannot be hidden in terms and conditions, forced, or bundled with other purposes in a way that prevents a person from making a real choice.
In practice, consent is often needed for marketing activities, newsletters, certain cookies, ad personalization, or additional purposes that are not necessary for the performance of a contract. Consent should not, however, be treated as a universal solution for everything.
A person who has given consent should be able to withdraw it. Withdrawal of consent should be as easy as giving it. If a user can subscribe to a newsletter through one form, they should have a simple way to unsubscribe, for example through an unsubscribe link or by contacting the controller.
| Feature of consent | What does it mean? | Mistake to avoid |
|---|---|---|
| Freely given | The person has a real choice. | Forcing marketing consent as a condition of purchase. |
| Specific | It relates to a defined purpose. | One consent for newsletter, ads, partners, and profiling at once. |
| Informed | The person knows what they are agreeing to. | Hiding information in long, unreadable terms. |
| Unambiguous | It results from an active action. | A pre-ticked checkbox. |
| Withdrawable | The person can withdraw consent. | No simple way to unsubscribe from a newsletter. |
Data controller and data processor
A data controller is an entity that determines the purposes and means of processing personal data. In simpler terms, the controller decides why data is collected and how it will be used. This may be a company, store owner, foundation, school, public office, company, sole proprietor, or event organizer.
A data processor processes data on behalf of the controller. It does not independently decide on the main purposes of processing, but performs specific activities on the controller's instructions. Examples include a hosting company, newsletter system, accounting office, external IT support, CRM provider, or an agency running an e-mail campaign on a client's database.
| Role | What does it do? | Example |
|---|---|---|
| Data controller | Determines the purposes and means of data processing. | An online store processing customer data. |
| Data processor | Processes data on behalf of the controller. | Hosting company, newsletter operator, accounting office. |
| Joint controllers | Jointly determine the purposes and means of processing. | Two entities carrying out a joint project with one participant database. |
In short: the controller is responsible for why and how data is processed. The processor performs specific activities on the controller's behalf and should act under a data processing agreement.
GDPR information obligation
One of the controller's basic obligations is to inform the person about the processing of their data. This is why websites include privacy policies, information clauses next to forms, recruitment notices, and information for customers, employees, or event participants.
The information obligation should be fulfilled in an understandable way. A person should not have to guess who processes their data, for what purpose, on what legal basis, to whom the data may be disclosed, and how long it will be stored. A very general statement such as "Your data will be processed in accordance with GDPR" is not enough, because it does not provide real information.
| Information element | What should be explained? |
|---|---|
| Controller | Who processes the data and how they can be contacted. |
| Purpose of processing | Why the data is collected and used. |
| Legal basis | On what basis the data is processed. |
| Recipients of data | To whom data may be transferred, such as hosting, accounting, or payment operators. |
| Storage period | How long the data will be stored or according to what criteria this will be determined. |
| Rights of the person | What rights the data subject has. |
| Right to lodge a complaint | Information about the possibility of filing a complaint with the supervisory authority. |
| Voluntary or mandatory provision of data | Whether providing data is required and what the consequences of not providing it are. |
Practical tip: a privacy policy should be written for a person, not only for a lawyer. The user should understand what happens to their data without reading several pages of official language.
Rights of data subjects
GDPR grants individuals a number of rights regarding their data. The controller should not only inform people about them, but also have a procedure for handling such requests. A user, customer, employee, or candidate may ask about their data, request its correction, deletion, restriction of processing, portability, or object to certain actions.
Not every request must always be fulfilled in full. For example, a customer may request deletion of their data, but some accounting documents must be stored due to legal obligations. The controller should, however, be able to respond by explaining what can be deleted, what cannot be deleted, and why.
| Right of the person | What does it mean? | Example |
|---|---|---|
| Right of access | A person may ask whether and what data is being processed. | A customer asks what data the store has. |
| Right to rectification | A person may request correction of inaccurate data. | Change of address, surname, or phone number. |
| Right to erasure | A person may request deletion of data in certain situations. | Unsubscribing from a newsletter and deleting marketing data. |
| Right to restriction of processing | Data may be temporarily blocked for some activities. | A dispute over the accuracy of data. |
| Right to data portability | A person may receive data in a structured format. | Transferring data between services. |
| Right to object | A person may object to certain forms of processing. | Objection to direct marketing. |
| Right to withdraw consent | A person may withdraw consent if processing is based on consent. | Unsubscribing from a newsletter. |
Personal data security
GDPR requires appropriate technical and organizational measures. This means that data must be protected not only by documents, but also by real safeguards. Their level should be adapted to the risk, type of data, scale of processing, available technologies, and potential consequences of a breach.
In a small company, security may mean strong passwords, backups, limited access to e-mail inboxes, website updates, an SSL certificate, and securing computers. In a larger organization, access procedures, authorization registers, encryption, system segmentation, audits, training, log monitoring, and security tests may be needed.
| Security area | Example actions |
|---|---|
| Access to data | User roles, authorizations, principle of least privilege. |
| Passwords and login | Strong passwords, 2FA, account lockout after multiple login attempts. |
| Website | CMS updates, plugin updates, theme updates, SSL certificate, backup. |
| Restricted access, caution with attachments, mailbox security. | |
| Backups | Regular backups, recovery testing, storage in a secure location. |
| Devices | System updates, antivirus, disk encryption, screen lock. |
| People | Training, procedures, phishing awareness, clear rules for working with data. |
Practical note: a privacy policy does not secure data. Data is secured by specific actions: updates, passwords, permissions, backups, access control, encryption, procedures, and reasonable limitation of the number of places where data is stored.
Personal data breach
A personal data breach is an event that leads to accidental or unlawful destruction, loss, alteration, disclosure of, or unauthorized access to data. This may include a customer database leak, sending an e-mail to the wrong recipient, losing a laptop, a website hack, accidental publication of a document, losing a USB drive, or a former employee retaining access to a system.
Not every breach will have the same severity. The risk to the rights and freedoms of individuals must be assessed. Accidental disclosure of a business e-mail address is different from a leak of medical data, document numbers, passwords, payment data, or a full purchase history.
In the event of a breach, the controller should know what happened, what data was affected, how many people are affected, what the possible consequences are, what corrective actions have been taken, and whether the supervisory authority and the affected persons must be notified.
| Example breach | Possible risk | What needs to be done? |
|---|---|---|
| Sending data to the wrong recipient | Disclosure of data to an unauthorized person. | Determine the scope of data, recipient, risk, and corrective actions. |
| Hack of an online store | Access to customer data, orders, accounts. | Secure the system, check logs, assess scale and reporting obligations. |
| Lost laptop | Access to files, e-mail, documents. | Check encryption, remote lock options, and type of data. |
| Public file with data | Unauthorized disclosure of data on the internet. | Remove the file, determine availability time, download scope, and risk. |
Practical rule: in the event of a breach, the worst thing is pretending that nothing happened. You need to quickly secure the situation, gather facts, assess the risk, document decisions, and check reporting obligations.
Entrusting personal data processing
Entrusting personal data processing occurs when the controller transfers data to another entity that is to process it on the controller's behalf. In practice, this happens very often. Data may go to a hosting company, e-mail provider, newsletter system, accounting office, CRM provider, e-commerce platform, IT company, marketing agency, or customer service tool provider.
In such a situation, a data processing agreement is usually needed. It should define, among other things, the subject and duration of processing, the nature and purpose of operations, the type of data, categories of persons, processor obligations, security rules, the possibility of using sub-processors, and how cooperation ends.
| Service | May it require entrusted processing? | Why? |
|---|---|---|
| Website hosting | Yes | The provider may have technical access to data in the system. |
| Newsletter system | Yes | It stores and processes the subscriber database. |
| Accounting office | Often yes | It processes data from invoices, contracts, and accounting documents. |
| CRM | Yes | It stores customer data, leads, and contact history. |
| Marketing agency | Depends on the cooperation model | It may work on customer databases or campaign data. |
GDPR on a website
A website very often processes personal data, even if the owner thinks that it "does not collect anything". Data may appear through a contact form, comments, account registration, store, newsletter, analytics, chat, cookies, server logs, advertising systems, embedded maps, videos, remarketing pixels, or integrations with external services.
That is why a website should have a well-thought-out privacy policy, proper clauses next to forms, a cookie consent mechanism, properly configured analytics, secured forms, an SSL certificate, a limited number of unnecessary scripts, and clear information about data recipients. It is also important whether data is transferred outside the European Economic Area and on what basis.
| Website element | GDPR risk | What to check? |
|---|---|---|
| Contact form | Collecting name, e-mail, phone number, and message content. | Information clause, purpose, legal basis, form security. |
| Newsletter | Direct marketing and subscriber database. | Consent, double opt-in, unsubscribe option, proof of consent. |
| Analytics | Identifiers, cookies, IP addresses, user behavior. | Scope of data, consent, configuration, tool provider. |
| Online store | Orders, payments, deliveries, complaints. | Terms and conditions, privacy policy, processors, retention periods. |
| Comments | Publication of data, IP address, comment content. | Moderation, user information, data deletion. |
| Online chat | Conversation content, contact data, provider integrations. | Data processing agreement, clause, scope of data, conversation history. |
GDPR, cookies, and marketing consents
Cookies are often confused with all of GDPR, but they are only one element of online privacy. Cookies may be technical, analytical, marketing, personalization-related, or connected with external services. Not all of them require the same approach. Cookies necessary for the operation of a website are treated differently from files used for advertising, tracking, or analytics.
In practice, a cookie banner should give the user a real choice, not just inform them that the website uses cookies. The user should be able to accept, reject, or configure consent categories if the website uses files that are not necessary for its basic operation. Consents should not be pre-selected, forced, or hidden behind an unreadable interface.
| Type of cookies | Example | Comment |
|---|---|---|
| Necessary | Cart, login, session security | Usually needed for the website to function. |
| Analytical | Measuring visits, user behavior | They require caution and proper consent configuration. |
| Marketing | Remarketing, advertising pixels, profiling | They usually require explicit consent before activation. |
| Personalization | Remembering user preferences | It must be clearly explained what they are used for. |
| External | Maps, videos, social media, chats | They may involve transferring data to other providers. |
Practical note: simply showing a bar saying "we use cookies" is not enough if the website loads analytical, advertising, or tracking tools without a real decision by the user.
What GDPR documents are worth preparing?
GDPR documentation should result from real processes in the company, not be a ready-made package copied without understanding. Different documents will be needed in an online store, others on a small service website, others in a company employing staff, and still others in an organization processing sensitive data or large user databases.
The basis is to determine what data is processed, for what purposes, on what legal bases, for how long, where it is stored, who has access to it, and to whom it is transferred. Only on this basis can policies, clauses, registers, procedures, and agreements be prepared.
| Document | What is it for? | When is it especially important? |
|---|---|---|
| Privacy policy | Informs website users about data processing. | For forms, cookies, newsletters, stores, analytics. |
| Information clauses | Fulfill the information obligation in specific processes. | Contact, recruitment, contracts, events, newsletter. |
| Record of processing activities | Organizes data processing processes. | In organizations with many processes or larger data scale. |
| Data processing agreements | Regulate cooperation with data processors. | Hosting, accounting, newsletter, CRM, IT, marketing. |
| Breach procedure | Defines actions in case of a leak or data loss. | In every organization that processes personal data. |
| Processing authorizations | Define who has access to data and to what extent. | For employees, editors, customer service, accounting. |
| Data retention policy | Defines how long data is stored. | For customer databases, recruitment, newsletters, documents. |
The most common GDPR mistakes
The most common GDPR mistakes result from treating data protection as a one-time formal obligation. A company publishes a privacy policy, copies several consents, adds a cookie bar, and considers the matter closed. Meanwhile, GDPR requires real data management, not just the presence of documents on a website.
Collecting too much data
Forms often require data that is not needed for the given purpose. The more data you collect, the greater the responsibility and risk.
Asking for consent for everything
Consent is not a universal basis. For an order, invoice, or contract performance, another legal basis will often be more appropriate.
No clear privacy policy
The document is too general, outdated, or does not describe the real tools used on the website.
Incorrect cookie banner
The website loads analytics and advertising before consent or does not give the user a real possibility to refuse.
No data processing agreements
Data goes to hosting, CRM, newsletter systems, accounting, or agencies, but there are no organized cooperation rules.
Storing data indefinitely
Newsletter databases, candidate data, old leads, and form messages remain in systems for years without justification.
Excessively broad access
Every employee has access to everything instead of only the data needed for their work.
No breach procedure
When an incident occurs, no one knows who makes decisions, what to document, and whether the breach must be reported.
Practical note: the biggest mistake is having documents that do not describe reality. A privacy policy must correspond to what actually happens with data on the website and in the company.
GDPR in practice
In practice, GDPR implementation should begin with a simple data audit. You need to list what data is collected, where it comes from, where it goes, who has access to it, to whom it is transferred, how long it is stored, and on what basis it is processed. Only then can you assess what documents, consents, agreements, and safeguards are needed.
For a website, the basis will be a privacy policy, proper clauses next to forms, a compliant cookie mechanism, CMS security, backups, agreements with providers, and organization of external tools. For a store, orders, payments, deliveries, complaints, invoices, and customer accounts will also be relevant. For an employer, HR processes, recruitment, authorizations, and document retention periods will be important.
GDPR works best when it is part of everyday management, not an add-on at the end of a project. A new form, new plugin, new CRM system, new mailing campaign, or new analytics tool should immediately raise questions: what data are we collecting, why, on what basis, where does it go, does the user know about it, and how can we protect it?
| Step | What to do? | Result |
|---|---|---|
| 1. Data map | List processes, systems, forms, and databases. | You know where data is processed. |
| 2. Purposes and bases | Define the purpose and legal basis for each process. | Data is not processed randomly. |
| 3. Informing people | Prepare a privacy policy and information clauses. | Users know what happens to their data. |
| 4. Providers | Check hosting, newsletter, CRM, accounting, and other tools. | You know to whom data is entrusted or disclosed. |
| 5. Safeguards | Set passwords, 2FA, backups, permissions, and updates. | The risk of breaches decreases. |
| 6. Retention | Define when data is deleted or anonymized. | Data is not kept indefinitely. |
| 7. Procedures | Prepare handling of requests and breaches. | The company knows how to respond in practice. |
GDPR is not a single set of website terms, but a system of responsible personal data management. It requires a legal basis for processing, transparent information for individuals, limiting the scope of data, ensuring security, controlling access, proper agreements with providers, responding to data subject requests, and readiness for breaches. Properly implemented GDPR should not paralyze a company. It should organize data, reduce risk, increase user trust, and ensure that the organization knows what it does with the information it receives from people.