GDPR - practical guide to personal data protection

United KingdomGDPR, or the General Data Protection Regulation, is an EU regulation on the protection of personal data, known in Poland as RODO. It regulates the principles of processing personal data of individuals, the obligations of companies, institutions, online stores, website administrators, organizations, and entities that use the data of customers, employees, users, or contractors. GDPR is not just a formality, a privacy policy, or a cookies notice. It is an entire system of rules designed to ensure that personal data is collected lawfully, used fairly, stored securely, shared only when there is a legal basis, and deleted when it is no longer needed.

What is GDPR?

GDPR stands for the General Data Protection Regulation, the EU regulation on the protection of personal data. In Poland, the same legal act is referred to as RODO - Rozporządzenie o Ochronie Danych Osobowych.

GDPR is an EU regulation that defines how personal data may be collected, stored, used, transferred, secured, and deleted. Its purpose is to protect the privacy of individuals and to harmonize data processing rules across the European Union.

In practice, GDPR applies to almost every company, website, store, foundation, school, public office, organization, service provider, employer, and website administrator that deals with personal data of individuals. It is not only about large customer databases. Personal data also appears in contact forms, newsletters, online orders, e-mail correspondence, CRM systems, invoices, recruitment, monitoring, online analytics, and user panels.

GDPR does not prohibit the processing of data. However, it imposes conditions: data must be processed lawfully, for a specific purpose, within a limited scope, for a defined period, and with appropriate safeguards. The person whose data is concerned should know who processes their data, why, on what legal basis, for how long, and what rights they have.

In short: GDPR is not one consent or one document on a website. It is a set of principles, obligations, and procedures intended to ensure that personal data is processed fairly, securely, and only when there is a legal basis for doing so.

Who does GDPR apply to?

GDPR applies to entities that process personal data of individuals in connection with professional, business, public, social, or organizational activity. This may include a company, sole proprietorship, online store, clinic, school, public office, association, foundation, internet portal, marketing agency, software house, event organizer, or the owner of a website with a contact form.

It does not matter whether the company is large or small. A small business may also process the data of customers, employees, job candidates, website users, newsletter recipients, or people sending inquiries through a form. The scope of obligations may differ, but the scale of activity does not automatically exempt anyone from complying with data protection principles.

EntityExample of dataTypical GDPR situations
Online storeFirst name, last name, address, e-mail, phone number, order historyOrder fulfillment, customer account, complaints, newsletter.
Company websiteData from a contact form, IP address, cookiesHandling inquiries, analytics, marketing, forms.
EmployerData of employees, candidates, contractorsHR, recruitment, contracts, payroll, authorizations.
Foundation or associationData of members, donors, volunteersMembership service, donations, events, communication.
Internet portalUser accounts, comments, IP addresses, logsRegistration, moderation, security, statistics.
Marketing agencyMailing databases, leads, clients' customer dataCampaigns, remarketing, newsletters, entrusted processing.

What is personal data?

Personal data is information relating to an individual who can be identified directly or indirectly. It is not only a first name, last name, and national identification number. Personal data may also include an e-mail address, phone number, home address, customer number, user ID, IP address, location data, purchase history, payment data, photograph, voice recording, or information about a user's behavior in a service.

Not every piece of information will automatically be personal data in every context. The key question is whether a specific person can be identified based on that information or by combining it with other data. That is why an e-mail address in the form Adres poczty elektronicznej jest chroniony przed robotami spamującymi. W przeglądarce musi być włączona obsługa JavaScript, żeby go zobaczyć. will usually be personal data, and an apparently technical user identifier may also be personal data if it can link activity to a specific person.

Type of dataExamplesPractical comment
Identification dataFirst name, last name, national ID number, document numberThey directly identify a specific person.
Contact detailsE-mail, phone number, mailing addressThey most often appear in forms, contracts, and orders.
Technical dataIP address, cookie ID, logs, device IDThey may be personal data if they allow a user to be identified or profiled.
Transaction dataPurchase history, complaints, payments, ordersThey are often processed by stores and CRM systems.
Special categories of dataHealth, political opinions, religion, biometrics, sexual orientationThey require particular caution and usually a stronger legal basis.

Practical note: it is a mistake to assume that personal data means only a national ID number, identity card number, and home address. In online activity, personal data very often also includes e-mail addresses, IP addresses, user IDs, cookies, and activity history.

What does processing personal data mean?

Processing personal data means practically any operation performed on data. It is not only active use of the data. Processing already includes collecting data, recording it in a system, storing it, organizing it, sending it, sharing it, retrieving it, analyzing it, updating it, copying it, archiving it, and deleting it.

In practice, a company processes data when it receives a message from a contact form, sends an invoice, maintains a customer account, fulfills an order, signs a user up for a newsletter, uses analytics, conducts recruitment, creates a list of event participants, or stores an employee's data in HR documentation.

ActivityIs this data processing?Example
Collecting dataYesContact form, order form, account registration.
Storing dataYesCustomer database, e-mail inbox, CRM system.
Sending messagesYesNewsletter, reply to an inquiry, message to a customer.
Sharing dataYesTransferring data to a courier, accountant, or hosting company.
Deleting dataYesDeleting a user account or deleting data after the retention period expires.

The most important GDPR principles

GDPR is based on several fundamental principles. They are the starting point for assessing whether data is processed properly. It is not enough to have a privacy policy on the website. One must also actually follow the principles of lawfulness, transparency, data minimization, purpose limitation, accuracy, storage limitation, confidentiality, integrity, and accountability.

The most important change is a change in mindset. Personal data should not be collected "just in case", stored indefinitely, or used for purposes about which the person has not been informed. The controller should be able to explain why the data is needed, on what basis it is processed, and how it is protected.

GDPR principleWhat does it mean?Practical example
LawfulnessData must have a legal basis for processing.Performance of a contract, legal obligation, consent, or legitimate interest.
Fairness and transparencyThe person should know what happens to their data.A clear information notice and privacy policy.
Purpose limitationData is collected for a specific, defined purpose.Data from a contact form is used to reply, not automatically for a newsletter.
Data minimizationOnly data that is truly needed is collected.An inquiry form should not require a national ID number.
AccuracyData should be up to date and correct.A customer can update their delivery address or account details.
Storage limitationData is not kept longer than necessary.Job candidate data is deleted after recruitment ends, unless there is another basis.
Integrity and confidentialityData must be protected against loss and unauthorized access.Passwords, permissions, encryption, backups.
AccountabilityThe controller should be able to demonstrate compliance with the principles.Documentation, registers, procedures, data processing agreements.

In short: GDPR requires not only formal documents, but also real order in data management. You need to know what data you have, why you have it, where it is stored, who has access to it, who it is transferred to, and when it should be deleted.

Every processing of personal data must have a legal basis. This is one of the most important elements of GDPR. In practice, people often wrongly assume that consent is always required. Meanwhile, consent is only one of the legal bases. In many situations, data may, and sometimes must, be processed on another basis.

For an online store, the basis for processing customer data may be the performance of a contract, because without the data it is impossible to fulfill the order. For issuing an invoice, the basis will be a legal obligation. For pursuing claims, it may be legitimate interest. Consent, on the other hand, will be typical for a marketing newsletter, unless another appropriate basis exists and consents required under electronic communications rules are needed.

Legal basisWhen does it apply?Example
ConsentWhen a person voluntarily agrees to a specific purpose.Newsletter subscription, consent for selected marketing activities.
Performance of a contractWhen data is necessary to conclude or perform a contract.Order fulfillment, customer account service, service delivery.
Legal obligationWhen the law requires data processing.Accounting, invoices, tax obligations, employee documentation.
Vital interestsWhen processing protects the life or health of a person.Emergency, medical, rescue situations.
Public taskWhen an entity performs tasks in the public interest.Activities of public offices, public schools, or institutions.
Legitimate interestWhen the controller has a legally justified purpose and the person's rights do not override it.Pursuing claims, security, basic B2B contact, defense against abuse.

Practical tip: do not ask for consent where processing results from a contract or legal obligation. Consent should be voluntary and withdrawable, so it is not a good solution for actions that must be performed anyway.

Consent is one of the best-known bases for data processing, but also one of the most frequently misused. For consent to be valid, it should be freely given, specific, informed, and unambiguous. It cannot be hidden in terms and conditions, forced, or bundled with other purposes in a way that prevents a person from making a real choice.

In practice, consent is often needed for marketing activities, newsletters, certain cookies, ad personalization, or additional purposes that are not necessary for the performance of a contract. Consent should not, however, be treated as a universal solution for everything.

A person who has given consent should be able to withdraw it. Withdrawal of consent should be as easy as giving it. If a user can subscribe to a newsletter through one form, they should have a simple way to unsubscribe, for example through an unsubscribe link or by contacting the controller.

Feature of consentWhat does it mean?Mistake to avoid
Freely givenThe person has a real choice.Forcing marketing consent as a condition of purchase.
SpecificIt relates to a defined purpose.One consent for newsletter, ads, partners, and profiling at once.
InformedThe person knows what they are agreeing to.Hiding information in long, unreadable terms.
UnambiguousIt results from an active action.A pre-ticked checkbox.
WithdrawableThe person can withdraw consent.No simple way to unsubscribe from a newsletter.

Data controller and data processor

A data controller is an entity that determines the purposes and means of processing personal data. In simpler terms, the controller decides why data is collected and how it will be used. This may be a company, store owner, foundation, school, public office, company, sole proprietor, or event organizer.

A data processor processes data on behalf of the controller. It does not independently decide on the main purposes of processing, but performs specific activities on the controller's instructions. Examples include a hosting company, newsletter system, accounting office, external IT support, CRM provider, or an agency running an e-mail campaign on a client's database.

RoleWhat does it do?Example
Data controllerDetermines the purposes and means of data processing.An online store processing customer data.
Data processorProcesses data on behalf of the controller.Hosting company, newsletter operator, accounting office.
Joint controllersJointly determine the purposes and means of processing.Two entities carrying out a joint project with one participant database.

In short: the controller is responsible for why and how data is processed. The processor performs specific activities on the controller's behalf and should act under a data processing agreement.

GDPR information obligation

One of the controller's basic obligations is to inform the person about the processing of their data. This is why websites include privacy policies, information clauses next to forms, recruitment notices, and information for customers, employees, or event participants.

The information obligation should be fulfilled in an understandable way. A person should not have to guess who processes their data, for what purpose, on what legal basis, to whom the data may be disclosed, and how long it will be stored. A very general statement such as "Your data will be processed in accordance with GDPR" is not enough, because it does not provide real information.

Information elementWhat should be explained?
ControllerWho processes the data and how they can be contacted.
Purpose of processingWhy the data is collected and used.
Legal basisOn what basis the data is processed.
Recipients of dataTo whom data may be transferred, such as hosting, accounting, or payment operators.
Storage periodHow long the data will be stored or according to what criteria this will be determined.
Rights of the personWhat rights the data subject has.
Right to lodge a complaintInformation about the possibility of filing a complaint with the supervisory authority.
Voluntary or mandatory provision of dataWhether providing data is required and what the consequences of not providing it are.

Practical tip: a privacy policy should be written for a person, not only for a lawyer. The user should understand what happens to their data without reading several pages of official language.

Rights of data subjects

GDPR grants individuals a number of rights regarding their data. The controller should not only inform people about them, but also have a procedure for handling such requests. A user, customer, employee, or candidate may ask about their data, request its correction, deletion, restriction of processing, portability, or object to certain actions.

Not every request must always be fulfilled in full. For example, a customer may request deletion of their data, but some accounting documents must be stored due to legal obligations. The controller should, however, be able to respond by explaining what can be deleted, what cannot be deleted, and why.

Right of the personWhat does it mean?Example
Right of accessA person may ask whether and what data is being processed.A customer asks what data the store has.
Right to rectificationA person may request correction of inaccurate data.Change of address, surname, or phone number.
Right to erasureA person may request deletion of data in certain situations.Unsubscribing from a newsletter and deleting marketing data.
Right to restriction of processingData may be temporarily blocked for some activities.A dispute over the accuracy of data.
Right to data portabilityA person may receive data in a structured format.Transferring data between services.
Right to objectA person may object to certain forms of processing.Objection to direct marketing.
Right to withdraw consentA person may withdraw consent if processing is based on consent.Unsubscribing from a newsletter.

Personal data security

GDPR requires appropriate technical and organizational measures. This means that data must be protected not only by documents, but also by real safeguards. Their level should be adapted to the risk, type of data, scale of processing, available technologies, and potential consequences of a breach.

In a small company, security may mean strong passwords, backups, limited access to e-mail inboxes, website updates, an SSL certificate, and securing computers. In a larger organization, access procedures, authorization registers, encryption, system segmentation, audits, training, log monitoring, and security tests may be needed.

Security areaExample actions
Access to dataUser roles, authorizations, principle of least privilege.
Passwords and loginStrong passwords, 2FA, account lockout after multiple login attempts.
WebsiteCMS updates, plugin updates, theme updates, SSL certificate, backup.
E-mailRestricted access, caution with attachments, mailbox security.
BackupsRegular backups, recovery testing, storage in a secure location.
DevicesSystem updates, antivirus, disk encryption, screen lock.
PeopleTraining, procedures, phishing awareness, clear rules for working with data.

Practical note: a privacy policy does not secure data. Data is secured by specific actions: updates, passwords, permissions, backups, access control, encryption, procedures, and reasonable limitation of the number of places where data is stored.

Personal data breach

A personal data breach is an event that leads to accidental or unlawful destruction, loss, alteration, disclosure of, or unauthorized access to data. This may include a customer database leak, sending an e-mail to the wrong recipient, losing a laptop, a website hack, accidental publication of a document, losing a USB drive, or a former employee retaining access to a system.

Not every breach will have the same severity. The risk to the rights and freedoms of individuals must be assessed. Accidental disclosure of a business e-mail address is different from a leak of medical data, document numbers, passwords, payment data, or a full purchase history.

In the event of a breach, the controller should know what happened, what data was affected, how many people are affected, what the possible consequences are, what corrective actions have been taken, and whether the supervisory authority and the affected persons must be notified.

Example breachPossible riskWhat needs to be done?
Sending data to the wrong recipientDisclosure of data to an unauthorized person.Determine the scope of data, recipient, risk, and corrective actions.
Hack of an online storeAccess to customer data, orders, accounts.Secure the system, check logs, assess scale and reporting obligations.
Lost laptopAccess to files, e-mail, documents.Check encryption, remote lock options, and type of data.
Public file with dataUnauthorized disclosure of data on the internet.Remove the file, determine availability time, download scope, and risk.

Practical rule: in the event of a breach, the worst thing is pretending that nothing happened. You need to quickly secure the situation, gather facts, assess the risk, document decisions, and check reporting obligations.

Entrusting personal data processing

Entrusting personal data processing occurs when the controller transfers data to another entity that is to process it on the controller's behalf. In practice, this happens very often. Data may go to a hosting company, e-mail provider, newsletter system, accounting office, CRM provider, e-commerce platform, IT company, marketing agency, or customer service tool provider.

In such a situation, a data processing agreement is usually needed. It should define, among other things, the subject and duration of processing, the nature and purpose of operations, the type of data, categories of persons, processor obligations, security rules, the possibility of using sub-processors, and how cooperation ends.

ServiceMay it require entrusted processing?Why?
Website hostingYesThe provider may have technical access to data in the system.
Newsletter systemYesIt stores and processes the subscriber database.
Accounting officeOften yesIt processes data from invoices, contracts, and accounting documents.
CRMYesIt stores customer data, leads, and contact history.
Marketing agencyDepends on the cooperation modelIt may work on customer databases or campaign data.

GDPR on a website

A website very often processes personal data, even if the owner thinks that it "does not collect anything". Data may appear through a contact form, comments, account registration, store, newsletter, analytics, chat, cookies, server logs, advertising systems, embedded maps, videos, remarketing pixels, or integrations with external services.

That is why a website should have a well-thought-out privacy policy, proper clauses next to forms, a cookie consent mechanism, properly configured analytics, secured forms, an SSL certificate, a limited number of unnecessary scripts, and clear information about data recipients. It is also important whether data is transferred outside the European Economic Area and on what basis.

Website elementGDPR riskWhat to check?
Contact formCollecting name, e-mail, phone number, and message content.Information clause, purpose, legal basis, form security.
NewsletterDirect marketing and subscriber database.Consent, double opt-in, unsubscribe option, proof of consent.
AnalyticsIdentifiers, cookies, IP addresses, user behavior.Scope of data, consent, configuration, tool provider.
Online storeOrders, payments, deliveries, complaints.Terms and conditions, privacy policy, processors, retention periods.
CommentsPublication of data, IP address, comment content.Moderation, user information, data deletion.
Online chatConversation content, contact data, provider integrations.Data processing agreement, clause, scope of data, conversation history.

GDPR, cookies, and marketing consents

Cookies are often confused with all of GDPR, but they are only one element of online privacy. Cookies may be technical, analytical, marketing, personalization-related, or connected with external services. Not all of them require the same approach. Cookies necessary for the operation of a website are treated differently from files used for advertising, tracking, or analytics.

In practice, a cookie banner should give the user a real choice, not just inform them that the website uses cookies. The user should be able to accept, reject, or configure consent categories if the website uses files that are not necessary for its basic operation. Consents should not be pre-selected, forced, or hidden behind an unreadable interface.

Type of cookiesExampleComment
NecessaryCart, login, session securityUsually needed for the website to function.
AnalyticalMeasuring visits, user behaviorThey require caution and proper consent configuration.
MarketingRemarketing, advertising pixels, profilingThey usually require explicit consent before activation.
PersonalizationRemembering user preferencesIt must be clearly explained what they are used for.
ExternalMaps, videos, social media, chatsThey may involve transferring data to other providers.

Practical note: simply showing a bar saying "we use cookies" is not enough if the website loads analytical, advertising, or tracking tools without a real decision by the user.

What GDPR documents are worth preparing?

GDPR documentation should result from real processes in the company, not be a ready-made package copied without understanding. Different documents will be needed in an online store, others on a small service website, others in a company employing staff, and still others in an organization processing sensitive data or large user databases.

The basis is to determine what data is processed, for what purposes, on what legal bases, for how long, where it is stored, who has access to it, and to whom it is transferred. Only on this basis can policies, clauses, registers, procedures, and agreements be prepared.

DocumentWhat is it for?When is it especially important?
Privacy policyInforms website users about data processing.For forms, cookies, newsletters, stores, analytics.
Information clausesFulfill the information obligation in specific processes.Contact, recruitment, contracts, events, newsletter.
Record of processing activitiesOrganizes data processing processes.In organizations with many processes or larger data scale.
Data processing agreementsRegulate cooperation with data processors.Hosting, accounting, newsletter, CRM, IT, marketing.
Breach procedureDefines actions in case of a leak or data loss.In every organization that processes personal data.
Processing authorizationsDefine who has access to data and to what extent.For employees, editors, customer service, accounting.
Data retention policyDefines how long data is stored.For customer databases, recruitment, newsletters, documents.

The most common GDPR mistakes

The most common GDPR mistakes result from treating data protection as a one-time formal obligation. A company publishes a privacy policy, copies several consents, adds a cookie bar, and considers the matter closed. Meanwhile, GDPR requires real data management, not just the presence of documents on a website.

Collecting too much data
Forms often require data that is not needed for the given purpose. The more data you collect, the greater the responsibility and risk.

Asking for consent for everything
Consent is not a universal basis. For an order, invoice, or contract performance, another legal basis will often be more appropriate.

No clear privacy policy
The document is too general, outdated, or does not describe the real tools used on the website.

Incorrect cookie banner
The website loads analytics and advertising before consent or does not give the user a real possibility to refuse.

No data processing agreements
Data goes to hosting, CRM, newsletter systems, accounting, or agencies, but there are no organized cooperation rules.

Storing data indefinitely
Newsletter databases, candidate data, old leads, and form messages remain in systems for years without justification.

Excessively broad access
Every employee has access to everything instead of only the data needed for their work.

No breach procedure
When an incident occurs, no one knows who makes decisions, what to document, and whether the breach must be reported.

Practical note: the biggest mistake is having documents that do not describe reality. A privacy policy must correspond to what actually happens with data on the website and in the company.

GDPR in practice

In practice, GDPR implementation should begin with a simple data audit. You need to list what data is collected, where it comes from, where it goes, who has access to it, to whom it is transferred, how long it is stored, and on what basis it is processed. Only then can you assess what documents, consents, agreements, and safeguards are needed.

For a website, the basis will be a privacy policy, proper clauses next to forms, a compliant cookie mechanism, CMS security, backups, agreements with providers, and organization of external tools. For a store, orders, payments, deliveries, complaints, invoices, and customer accounts will also be relevant. For an employer, HR processes, recruitment, authorizations, and document retention periods will be important.

GDPR works best when it is part of everyday management, not an add-on at the end of a project. A new form, new plugin, new CRM system, new mailing campaign, or new analytics tool should immediately raise questions: what data are we collecting, why, on what basis, where does it go, does the user know about it, and how can we protect it?

StepWhat to do?Result
1. Data mapList processes, systems, forms, and databases.You know where data is processed.
2. Purposes and basesDefine the purpose and legal basis for each process.Data is not processed randomly.
3. Informing peoplePrepare a privacy policy and information clauses.Users know what happens to their data.
4. ProvidersCheck hosting, newsletter, CRM, accounting, and other tools.You know to whom data is entrusted or disclosed.
5. SafeguardsSet passwords, 2FA, backups, permissions, and updates.The risk of breaches decreases.
6. RetentionDefine when data is deleted or anonymized.Data is not kept indefinitely.
7. ProceduresPrepare handling of requests and breaches.The company knows how to respond in practice.

GDPR is not a single set of website terms, but a system of responsible personal data management. It requires a legal basis for processing, transparent information for individuals, limiting the scope of data, ensuring security, controlling access, proper agreements with providers, responding to data subject requests, and readiness for breaches. Properly implemented GDPR should not paralyze a company. It should organize data, reduce risk, increase user trust, and ensure that the organization knows what it does with the information it receives from people.

FAQ - GDPR

What is GDPR?
GDPR stands for the General Data Protection Regulation, the EU regulation on personal data protection. In Poland, the same legal act is known as RODO.
Are GDPR and RODO the same thing?
Yes. GDPR is the English name, and RODO is the Polish name of the same EU regulation on personal data protection.
Does every website need a privacy policy?
If a website processes personal data, for example through a contact form, newsletter, cookies, analytics, store, or user account, it should clearly inform users about the rules of data processing. In practice, this is most often done through a privacy policy.
Is consent needed for every data processing activity?
No. Consent is only one legal basis. Data may also be processed for the performance of a contract, compliance with a legal obligation, performance of a public task, protection of vital interests, or based on the controller's legitimate interest.
Is an e-mail address personal data?
Very often yes, especially if it allows a specific person to be identified, for example if it contains a first and last name or is linked to a user account, order, or contact history.
Is an IP address personal data?
An IP address may be personal data if, in a given context, it allows a person to be identified or linked to certain activity. That is why logs, analytics, and tracking tools also require attention in the context of GDPR.
Does a small company also have to comply with GDPR?
Yes, if it processes personal data. A small scale of activity may affect the scope of documentation and risk, but it does not exempt a company from the basic principles of data protection.
What is the difference between a data controller and a data processor?
The controller determines the purposes and means of data processing. The processor performs operations on data on behalf of the controller, for example as a hosting provider, accounting office, newsletter operator, or CRM provider.
Does a contact form require GDPR consent?
It does not always require separate consent. Often an appropriate processing basis, such as replying to an inquiry, and a clear information clause are enough. However, a person from a contact form should not be automatically added to a newsletter without an appropriate basis.
Does a newsletter require consent?
In practice, a marketing newsletter usually requires explicit consent and an easy unsubscribe option. It is also worth keeping proof of subscription, such as the date, source of consent, and e-mail address.
Is a cookie banner enough for GDPR compliance?
No. A cookie banner concerns only part of website activity. GDPR also covers forms, newsletters, stores, user accounts, analytics, security, the information obligation, data subject rights, and agreements with providers.
What should be done when a user wants their data deleted?
You need to check what data is processed, on what basis, and whether it can be deleted. Some data, such as accounting documents, may need to be stored further due to legal obligations.
Do you need a data processing agreement with hosting?
Very often yes, because the hosting provider may have technical access to data stored on the website, in the database, e-mail, or backups.
What is the biggest GDPR mistake?
The biggest mistake is treating GDPR as a one-time document. Data protection requires real organization: knowledge of data, legal bases, providers, safeguards, retention periods, and procedures.