GDPR for Technology Teams
GDPR is the European Union's framework for protecting personal data. Technology teams use it to shape how systems collect, use, share, secure, retain, and delete information about people.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — GDPR for Technology Teams
The GDPR is the part where privacy stops being a policy-shaped cloud and starts making demands of systems. It governs processing of personal data, and processing is an impressively broad word: collecting, storing, using, sharing, changing, and deleting can all qualify. A name is not required for the data to matter; an online identifier or a revealing combination of attributes can be enough.
The useful mental model is purpose first. Before asking where a field goes, establish why the processing exists and the approved legal basis for it. That purpose is a boundary, not a decorative label for a database table. A dataset that was useful for one feature does not quietly become available to every future feature, no matter how eagerly the dashboard waves at it.
Then make a data flow map. Follow personal data from collection through services, stores, queues, logs, analytics, exports, support tools, and backups. The primary database is only one stop on this journey. The surprise is that privacy work becomes hardest where systems have been most successful at copying data around. A deletion that clears one account row is not much help if an index, warehouse, or restore process promptly remembers it again.
Roles matter because they decide who is accountable for which actions. A controller decides why and how processing happens; a processor acts on the controller's behalf. The label on a contract does not settle this. Neither does outsourcing storage: the controller still owns the decisions about purpose, retention, and risk.
The seven principles provide the repeated questions. Is the use tied to its purpose? Does every field need to exist? Can a correction reach derived copies? Does retention actually end? Can the organization show evidence? Privacy by design puts those questions into architecture. Privacy by default makes the initial settings collect less, share less, and expose less. This is less glamorous than a magic compliance badge, but it has the advantage of working.
When something goes wrong, a personal data breach can affect confidentiality, integrity, or availability. Escalate early, map the affected systems and people, and preserve the timeline and evidence. A data protection impact assessment belongs before high-risk processing, not beside the launch cake crumbs.
Read the intro for the full system model and its limits. Use the slides to keep the purpose-to-evidence path in view. The cheatsheet is the operational reference for rights, retention, breaches, DPIAs, vendors, and transfers. Field Notes covers the awkward places where an apparently complete control usually turns out to be only the first stop.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://eur-lex.europa.eu/eli/reg/2016/679/oj
Supports
- GDPR definitions, scope, principles, legal bases, roles, and rights
- Controller and processor duties
- Data protection by design and by default
- Security, personal data breach, DPIA, and transfer requirements
- Quiz answers and infographic terminology
- https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/principles-gdpr_en
Supports
- Seven processing principles and accountability
- Purpose limitation, minimization, accuracy, storage limitation, and security
- Plain-language explanation of data protection by design and by default
- Reference-link rationale and infographic principles
- https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/obligations_en
Supports
- Controller obligations, transparency, breach response, and DPIA overview
- Technology-team operating checkpoints
- https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations/obligations/controllerprocessor/what-data-controller-or-data-processor_en
Supports
- Controller, joint-controller, and processor distinctions
- Processor contracts, subprocessors, and termination handling
- Vendor-review guidance and quiz answer
- https://commission.europa.eu/law/law-topic/data-protection/information-individuals_en
Supports
- Information, access, rectification, erasure, restriction, portability, and objection
- Personal data breach effects on individuals
- Rights-execution workflow and reference-link rationale
- https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-42019-article-25-data-protection-design-and_en
Supports
- Effectiveness of data protection by design and by default
- Early and continuing application of principles and safeguards
- Reference-link rationale
- https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations/obligations/what-data-breach-and-what-do-we-have-do-case-data-breach_en
Supports
- Confidentiality, integrity, and availability breach definition
- Processor escalation and controller notification thresholds
- Seventy-two-hour notification rule and communication for high risk
- Quiz answer, reference-link rationale, and infographic timeline
- https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/obligations/when-data-protection-impact-assessment-dpia-required_en
Supports
- High-risk trigger and recurring DPIA examples
- Assessment before processing, living-tool treatment, and prior consultation
- Quiz answer, reference-link rationale, and infographic trigger
- https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en
Supports
- Standard contractual clauses as safeguards for transfers outside the EEA
- Modernized controller and processor transfer modules
- Transfer quiz answer and reference-link rationale
- https://github.com/sindresorhus/awesome
Supports
- Starting point for awesome-list discovery
- https://github.com/asmaier/awesome-gdpr-services
Supports
- Discovery of Matomo, Plausible, and Passbolt as relevant ecosystem resources
- https://matomo.org/guide/manage-matomo/privacy/
Supports
- Matomo guides covering data collection, privacy settings, anonymization, consent, retention, notices, security, and data-subject rights
- Matomo Awesome Links rationale
- https://plausible.io/docs
Supports
- Plausible installation, team roles, exports, event collection, and compliance documentation
- Plausible Awesome Links rationale
- https://www.passbolt.com/docs/
Supports
- Passbolt user, administration, hosting, API, and incident documentation
- Passbolt Awesome Links rationale
- https://www.passbolt.com/docs/user/introduction/how-passbolt-secures-your-data/
Supports
- Passbolt client-side encryption and access model
- Passbolt Awesome Links rationale
- https://commission.europa.eu/law/law-topic/data-protection_en
Supports
- 1995 Directive, 2010 reform communication, 2012 proposal, 2016 adoption and entry into force, 2018 applicability, and 2020 application report timeline events
- https://www.edpb.europa.eu/system/files/2026-02/edpb_cef-report_2025_right-to-erasure_en.pdf
Supports
- Practical deletion constraints and controlled handling of data pending permanent erasure
- https://www.onetrust.com/products/data-privacy-management/
Supports
- OneTrust Landscape entry
- https://trustarc.com/products/individual-rights-manager/
Supports
- TrustArc Landscape entry
- https://www.datagrail.io/platform/
Supports
- DataGrail Landscape entry
- https://transcend.io/data-privacy/
Supports
- Transcend Landscape entry
- https://securiti.ai/solutions/data-privacy/
Supports
- Securiti Landscape entry
- https://bigid.com/data-privacy/
Supports
- BigID Landscape entry
- https://www.osano.com/platform
Supports
- Osano Landscape entry
- https://www.ketch.com/data-controls
Supports
- Ketch Landscape entry
