The practical GDPR guide for IT teams
Understand what the General Data Protection Regulation requires - and how to implement it technically across endpoints, devices, and internal systems.
Published 3 March 2026 · Last reviewed 27 July 2026
What is the General Data Protection Regulation?
The General Data Protection Regulation (GDPR) is a European Union data protection law that came into effect on 25 May 2018. It governs how organisations collect, process, store, and secure personal data of individuals within the EU and EEA.
It applies to:
- EU-based organisations
- Non-EU companies processing EU resident data
- SaaS providers handling EU personal data
- Organisations offering goods or services to EU individuals
Why GDPR lands on the IT team
- You must know where personal data exists.
- You must secure it appropriately.
- You must respond to DSARs within one month (extendable by up to two further months for complex or numerous requests).
- You must demonstrate compliance when audited.
- You must reduce risk of breach exposure.
Under GDPR, fines can reach
€20 million
or 4% of global annual turnover - whichever is higher
Lower-tier infringements are capped at €10 million or 2% of global annual turnover, whichever is higher.
Source: gdpr.eu/fines
The articles that directly impact IT infrastructure
Article 5 - Principles relating to processing of personal data
- Data minimisation
- Integrity and confidentiality
- Accountability
Article 30 - Records of processing activities
- Categories of personal data
- Storage locations
- Processing purposes
- Recipients
Source: gdpr.eu/article-30-records-of-processing-activities/
Article 32 - Security of processing
- Encryption
- Access controls
- Risk assessment
- Ongoing evaluation
Data subject access requests (DSARs)
Individuals have the right to:
- Access their personal data
- Request correction
- Request erasure (where applicable)
- Restrict processing
Organisations must respond within one month, extendable by up to two further months for complex or numerous requests (GDPR Art. 12(3)).
Source: gdpr.eu/article-15-right-of-access
The operational challenge is not legal interpretation - it is locating all personal data across endpoints, archives, shared drives, and mailboxes.
Common technical GDPR failures
Most GDPR risk is invisible until you scan for it.
A practical implementation framework
- 1
Discover personal data across enrolled devices
Scan the workstations, servers, and shared storage your team has enrolled, and get a list of real files rather than an estimate.
- 2
Categorise and deduplicate findings
Group findings by data type, severity, and location to eliminate noise.
- 3
Link findings to DSAR workflows
Connect discovered data to subject access request pipelines for rapid response.
- 4
Act on what the scan found
Delete what has no business purpose, move what does, and tighten access where it is too broad. EmberHound reports; your team changes the files.
- 5
Export audit-ready evidence
Generate reports from the findings and the scan history behind them, for internal review or an auditor.
How EmberHound supports GDPR compliance
EmberHound deploys lightweight agents to your endpoints that scan locally - no data ever leaves the device. Findings are reported as masked metadata, enabling region-aware detection, article mapping, DSAR linkage, and audit-ready evidence exports without centralising sensitive data.
Frequently asked questions
Where to go next
This guide covers what the regulation asks. These cover what to do about it.
Personal data discovery
How EmberHound finds personal data on company devices, and how the DSAR search works.
See the productEU AI Act guide
The other regulation lean teams are being asked about: risk tiers, roles, and when each part applies.
Read the guideBlog
Sixteen posts on subject requests, records of processing, retention, card data, and the EU AI Act, each citing its sources.
Read the blog