TechKnowSurge
NIST NICE K0678 NIST NICE K0681 CompTIA Security+ 5.4 ISC2 CISSP 1.4
VideoSecurityFree

General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) is a European Union privacy law enacted in 2018 that governs how organizations collect, process, and protect personal data — with penalties reaching up to 4% of global revenue or 20 million euros for non-compliance.

Complete this video to capture a CTF flag worth 1 point.

About this video

GDPR, enacted in 2018, is the European Union's primary data privacy regulation, designed to give individuals greater control over how their personal data is collected and used. Organizations subject to GDPR include any entity with an office in the EU, those offering goods or services to EU residents, and those that monitor or track EU residents' behavior. Non-compliance carries significant financial risk, with penalties reaching up to 4% of annual global revenue or 20 million euros, whichever is greater. Even organizations that fall outside these thresholds are advised to address GDPR in their privacy policies and to begin building compliant practices, particularly as other countries and U.S. states continue to enact privacy laws modeled closely on the regulation. GDPR is structured around seven principles that define responsible data handling. Lawfulness, fairness, and transparency require that data collection be consent-based, clearly communicated, and tied to a legitimate purpose. Purpose limitation holds that data can only be used for the reason it was originally collected. Data minimization means collecting only what is strictly necessary for that purpose. Accuracy places responsibility on the organization to keep collected data correct and up to date. Storage limitation requires that data be retained only as long as necessary for its intended use or as required by law. The final two principles address security and accountability. Integrity and confidentiality require that organizations take appropriate measures to protect data from both internal and external threats. Accountability goes a step further, requiring organizations to actively document and demonstrate that they are following all applicable rules — compliance must be provable, not just practiced. Together, these principles form a framework that prioritizes individual privacy rights while placing clear, enforceable obligations on the organizations that handle personal data.

What you'll learn

What's covered

GDPR Overview

Aligned to

NIST NICE
K0678 Knowledge of privacy laws and regulations
K0681 Knowledge of privacy principles and practices
CompTIA Security+
5.4 Summarize elements of effective security compliance.
ISC2 CISSP
1.4 Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context

Key terms

General Data Protection Regulation
GDPR
A European Union regulation that establishes comprehensive data protection and privacy rights for individuals within the EU and EEA, and imposes obligations on organizations that process EU residents' personal data regardless of where the organization is located. GDPR introduced concepts such as data minimization, the right to erasure, and mandatory breach notification.
Data Subject
An individual whose personal data is being collected and processed by another party.
Lawfulness, Fairness, and Transparency
A GDPR principle requiring that data collection and processing be legally justified, conducted honestly, and clearly communicated to the data subject.
Purpose Limitation
A GDPR principle that restricts the use of collected data strictly to the purpose originally stated at the time of collection.
Data Minimization
The practice of collecting and retaining only the sensitive data necessary for legitimate business purposes, reducing exposure and liability.
Storage Limitation
A GDPR principle requiring that personal data be retained only for as long as necessary to fulfill its stated processing purpose.
Accountability
The obligation of an individual or department to answer for the custody, use, and safekeeping of an assigned asset.
Confidentiality
The principle that information is accessible only to those authorized to access it.

Topics

Gdpr Data Privacy Regulatory Compliance Data Protection Privacy Law Cybersecurity Governance

Transcript

What GDPR Is

When it comes to regulations, one of the biggest considerations is the General Data Protection Regulation, or GDPR.

GDPR was put into place in 2018 and designed to protect those residents living in the European Union. The law is really designed around privacy and people's data.

Who Has to Comply

Your organization must comply with GDPR if it has any kind of office over in the European Union, if it's offering any goods or services to European Union residents, or if you're tracking or monitoring any information on European Union residents.

However, I still recommend you give at least some consideration to GDPR even if you don't have to comply, even if you're not selling goods and services to European Union residents. They can still find their way to your website. So I would, at the very least, if you're not marketing towards European Union residents, put in your privacy policy some sort of disclaimer that you're not marketing your goods and services towards European Union residents.

The other consideration I'd have is that there are a lot of other countries and states and a lot of other places that are creating laws and regulations that mimic or are copying a lot of what GDPR has. So even if you're not compliant with it right now, you're probably going to have to be compliant with it to a certain degree in the future. You may as well just tackle it now and start making sure that it's incorporated into your policies.

The penalties with GDPR can be fairly drastic. It can be up to 4% of the revenue or 2 million EUR, whichever is greater.

The Seven Principles

GDPR has seven different principles: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability.

The idea behind lawfulness, fairness and transparency is that whatever data you're collecting and processing on a data subject -- and a data subject is whoever the information is about -- if you're collecting and processing data, you get their consent first, that you are doing it with full transparency, and that you're stating the purpose of what it is that you're processing it for. And it's done within the interest of them or the general public, and it's for a specific purpose and done under the laws.

The second principle is purpose limitation. That is, you're going to limit the use and the processing of that data to what was originally stated. You can't collect the data and then later on decide that you want to change what the purpose of that data is and use that data for something else.

The third principle, of data minimization, is that you're not going to collect more data than is necessary to carry out that purpose.

The principle of accuracy is pretty straightforward, and that is that the data you're collecting and processing is accurate. You are responsible, your organization is responsible, to maintain the accuracy and ensure that accuracy.

The principle of storage limitation is that you are keeping data only for the time that it needs to be processed and is usable, or, if there are certain areas where you are required to keep it for a certain length of time, that you keep it for that length of time.

The principle of security is that you're taking the necessary steps to protect the data, that you're keeping it confidential, and you're keeping it safe from both internal and external threats.

Then there's the purpose of accountability: that you are responsible to prove that you actually are following the rules and regulations. That is, you must keep documentation and proof.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →