Glossary

GDPR (General Data Protection Regulation)

The General Data Protection Regulation (GDPR) is a data protection law that sets rules for how organizations collect, use, store, and manage personal data. It applies to organizations that process personal data in situations covered by the regulation. GDPR came into effect on May 25, 2018.

What Does GDPR Protect?

GDPR protects personal data, which includes information that relates to an individual. Common examples include:

  • Names and email addresses
  • Phone numbers and postal addresses
  • IP addresses and online identifiers
  • Location and account information
  • Other information relating to an individual

What Are the Main GDPR Principles?

Organizations that process personal data must follow several core principles, including:

  • Lawfulness, fairness, and transparency: Personal data must be processed lawfully and handled transparently.
  • Purpose limitation: Data should be collected for specific, clear, and legitimate purposes.
  • Data minimization: Only the personal data necessary for the stated purpose should be collected.
  • Accuracy: Personal data should be accurate and kept up to date where necessary.
  • Storage limitation: Data should not be retained longer than necessary for its purpose.
  • Security: Appropriate measures should protect personal data from unauthorized access, loss, or misuse.

Why Does GDPR Matter for Email Data?

Email addresses are commonly used in customer, prospect, and subscriber records. When organizations collect and manage this type of data, GDPR requirements can affect how the information is obtained, used, stored, and retained.

Organizations also need to consider the rights of individuals when handling their personal data.