Skip to main content

    Gdpr

    Glossary

    GDPR

    The General Data Protection Regulation (GDPR), incorporated into UK law as the UK GDPR, is the UK's primary data protection framework — governing how personal data about individuals is collected, stored, used, and shared.

    Key principles: lawfulness, fairness, and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability. Organisations must have a lawful basis for processing, must give individuals clear privacy information, must respond to data subject rights requests within 30 days, and must report serious breaches to the ICO within 72 hours. Fines can reach 4% of global turnover or £17.5 million, whichever is higher.

    Read deeper

    Hubs that cover this in depth

    Rajoka Insights

    Operating notes from a UK house of brands.

    A weekly note from Mehmood. House-of-brands strategy, UK operating, and what's working across the portfolio. No fluff.

    Delivered via Substack. Unsubscribe anytime.

    Explore Rajoka

    A family of firms. One operating standard.

    Pick a brand, pick a stage, or tell us your problem.