Skip to main content

What's the GDPR?

The General Data Protection Regulation (GDPR) is a European privacy law that governs how organisations collect, store, and process personal data.

Written by Gareth Burroughes
Updated this week

The GDPR came into force on 25 May 2018 and applies to any organisation that offers goods or services to people in the European Union (EU), or that collects and analyses data tied to EU residents. Regardless of where that organisation is based.


How Dotdigital supports GDPR compliance

Dotdigital has extensive experience in data protection and privacy compliance. Here's what you can expect:

  • Platform functionality
    The platform includes tools to help you meet your GDPR obligations, covering deletion, rectification, transfer, access, and objection to the processing of personal data.

  • Contractual commitments
    Your relationship with Dotdigital is supported by contractual commitments covering security standards, support, and breach notifications in line with GDPR requirements.

  • Guidance and resources
    Dotdigital shares information gathered through Data Protection Authorities and other reputable organisations to help you understand your compliance obligations.


Your GDPR obligations

GDPR compliance is a shared responsibility. The regulation applies to any organisation that processes EU residents' data. Including those based outside the EU. As a Dotdigital customer, you're responsible for understanding and meeting your own obligations under the regulation.

Key areas that may require changes to your organisation's practices include:

  • Greater data access and deletion rights for individuals

  • Risk assessment procedures

  • A Data Protection Officer role, required for many organisations

  • Data breach notification processes

For full details on how Dotdigital approaches data security and privacy, visit the Trust Center.

Additional information

Did this answer your question?