The practical GDPR guide for IT teams

Understand what the General Data Protection Regulation requires - and how to implement it technically across endpoints, devices, and internal systems.

Published 3 March 2026 · Last reviewed 27 July 2026

What is the General Data Protection Regulation?

The General Data Protection Regulation (GDPR) is a European Union data protection law that came into effect on 25 May 2018. It governs how organisations collect, process, store, and secure personal data of individuals within the EU and EEA.

It applies to:

  • EU-based organisations
  • Non-EU companies processing EU resident data
  • SaaS providers handling EU personal data
  • Organisations offering goods or services to EU individuals

Source: GDPR.eu - Official GDPR resource guide

Why GDPR lands on the IT team

  • You must know where personal data exists.
  • You must secure it appropriately.
  • You must respond to DSARs within one month (extendable by up to two further months for complex or numerous requests).
  • You must demonstrate compliance when audited.
  • You must reduce risk of breach exposure.

Under GDPR, fines can reach

€20 million

or 4% of global annual turnover - whichever is higher

Lower-tier infringements are capped at €10 million or 2% of global annual turnover, whichever is higher.

Source: gdpr.eu/fines

The articles that directly impact IT infrastructure

Article 5 - Principles relating to processing of personal data

  • Data minimisation
  • Integrity and confidentiality
  • Accountability

Source: gdpr.eu/article-5-principles-of-data-processing/

Article 30 - Records of processing activities

  • Categories of personal data
  • Storage locations
  • Processing purposes
  • Recipients

Source: gdpr.eu/article-30-records-of-processing-activities/

Article 32 - Security of processing

  • Encryption
  • Access controls
  • Risk assessment
  • Ongoing evaluation

Source: gdpr.eu/article-32-security-of-processing/

Data subject access requests (DSARs)

Individuals have the right to:

  • Access their personal data
  • Request correction
  • Request erasure (where applicable)
  • Restrict processing

Organisations must respond within one month, extendable by up to two further months for complex or numerous requests (GDPR Art. 12(3)).

Source: gdpr.eu/article-15-right-of-access

The operational challenge is not legal interpretation - it is locating all personal data across endpoints, archives, shared drives, and mailboxes.

Common technical GDPR failures

Shared drive sprawl
Old laptops with exported data
Unencrypted backups
Email archives
Shadow IT storage
Manual spreadsheet inventories

Most GDPR risk is invisible until you scan for it.

A practical implementation framework

  1. 1

    Discover personal data across enrolled devices

    Scan the workstations, servers, and shared storage your team has enrolled, and get a list of real files rather than an estimate.

  2. 2

    Categorise and deduplicate findings

    Group findings by data type, severity, and location to eliminate noise.

  3. 3

    Link findings to DSAR workflows

    Connect discovered data to subject access request pipelines for rapid response.

  4. 4

    Act on what the scan found

    Delete what has no business purpose, move what does, and tighten access where it is too broad. EmberHound reports; your team changes the files.

  5. 5

    Export audit-ready evidence

    Generate reports from the findings and the scan history behind them, for internal review or an auditor.

How EmberHound supports GDPR compliance

EmberHound deploys lightweight agents to your endpoints that scan locally - no data ever leaves the device. Findings are reported as masked metadata, enabling region-aware detection, article mapping, DSAR linkage, and audit-ready evidence exports without centralising sensitive data.

Frequently asked questions

Yes. The UK operates under UK GDPR, which mirrors EU GDPR post-Brexit.

Yes, if you process EU resident data - regardless of where your organisation is based.

Any information that can identify an individual directly or indirectly, including names, email addresses, IP addresses, and device identifiers.

Yes. GDPR applies regardless of organisation size if you process personal data of EU residents.

Stop guessing where personal data exists.

Start a GDPR scan today.

Your cookie choices

We use cookies to run this site, measure how it is used, and to advertise on other platforms. You can accept or refuse each purpose separately.

Keeps you signed in and remembers this choice. Always on.

Google Analytics, Sentry and Vercel. Which pages are used, and what breaks.

LinkedIn, X and Meta pixels, loaded through Google Tag Manager.

Cookie policy