GDPR Defined in Plain Terms
The General Data Protection Regulation (GDPR) is the European Union law that governs how organisations collect, use and protect personal data. In force since 25 May 2018 as Regulation (EU) 2016/679, it applies to any organisation that handles the data of people in the EU wherever that organisation is based.
For security teams, one article matters most. GDPR Article 32 requires appropriate technical and organisational measures to keep personal data safe. That turns a data breach into a legal event not only an IT one and it is why the largest GDPR penalties so often follow a security failure.
Personal data means any information that relates to an identified or identifiable person from a name or email address to an IP address or location record. The regulation reaches beyond Europe under Article 3 so a Swedish supplier and a US cloud vendor can both fall in scope. The full consolidated text is published on EUR-Lex.
What GDPR Requires for Security
GDPR does not hand you a checklist of tools. It sets duties and expects you to choose measures that match the risk. Six of them shape day-to-day security work.
- Security of processing (Article 32): Appropriate technical and organisational measures from encryption and pseudonymisation to access control, backups and regular testing.
- Data protection by design and by default (Article 25): Build privacy and security into systems from the start rather than adding them later.
- Breach notification (Article 33): Report a personal data breach to the supervisory authority within 72 hours of becoming aware of it.
- Telling the people affected (Article 34): Inform data subjects without undue delay when a breach is likely to put them at high risk.
- Impact assessments (Article 35): Run a data protection impact assessment, known in Swedish as a konsekvensbedömning, before high-risk processing begins.
- The accountability principle (Article 5(2)): Keep records that show you meet these duties, because you have to be able to prove it.

In Sweden the supervisory authority is IMY, the Swedish Authority for Privacy Protection. A breach report goes to IMY and the 72-hour clock starts when you become aware of the breach well before you finish investigating it.
A konsekvensbedömning is required when processing is likely to be high risk, for example large-scale monitoring or handling sensitive data. IMY publishes a list of the processing that always needs one and running it early makes it a design tool rather than a late paperwork exercise.
Controllers, Processors and the DPO
GDPR splits responsibility between two roles and knowing which one you are decides what you owe.
A controller decides why and how personal data is processed. A processor acts on the controller’s instructions for example a payroll provider or a cloud host. Both carry security duties under Article 32 and a controller must put a written contract in place with every processor under Article 28.
The split does not let either side off the hook. A Swedish case in 2025 saw IMY fine a software supplier acting purely as a processor which shows the duty follows the data rather than the job title.
GDPR also gives people rights over their data. They can ask to see it, correct it, delete it under the right to erasure, move it to another provider under Article 20 and object to certain uses. They can also refuse a purely automated decision that has a significant effect on them under Article 22.
A data protection officer (DPO) is the person who oversees GDPR compliance and acts as the contact point for IMY. You must appoint one if you are a public authority, if your core activity is large-scale monitoring of people or if you process special category data at scale. Many organisations outside those triggers appoint one anyway to hold the duty in one place.
What GDPR Failures Cost
GDPR fines come in two tiers. Lower-tier breaches can reach 10 million euros or 2 percent of global annual turnover whichever is higher. Serious breaches such as ignoring the core principles or people’s rights, can reach 20 million euros or 4 percent.
The numbers are real. The largest GDPR fine to date is 1.2 billion euros issued to Meta by Ireland’s Data Protection Commission in May 2023 over unlawful data transfers to the United States.
Sweden is not a soft touch. IMY imposed 60.6 million kronor in fines during 2024 and its recent cases have turned on weak security rather than paperwork alone.
The fine is rarely the whole bill. A breach also brings incident response, notification to regulators and customers, legal costs, lost business and civil claims from the people whose data leaked. For most organisations those costs add up to far more than the fine.
Real-World Cases
British Airways
In 2018 an attacker broke into British Airways systems and quietly redirected customer payment details to a fraudulent site. Around 429,000 people were affected before the skimming was found.
The UK Information Commissioner’s Office found that BA had failed to secure the data as Article 32 requires. It first proposed 183 million pounds and issued a final fine of 20 million pounds in October 2020, the largest the ICO had issued under GDPR at the time.
The attacker got in through the credentials of a third-party supplier with remote access. Multi-factor authentication on that access together with tighter monitoring of outbound traffic would have closed the door the attack walked through.
Marriott
Marriott discovered in 2018 that attackers had been inside the Starwood reservation system since 2014, four years before anyone noticed. Around 339 million guest records were exposed worldwide.
The breach was inherited. Marriott bought Starwood in 2016 and took on the compromised systems without spotting the intruder. The ICO issued a final fine of 18.4 million pounds in October 2020 for insufficient security and weak due diligence.
Basic detection would have surfaced four years of unauthorised access long before it did. So would a proper security review of the systems Marriott acquired since a merger inherits the seller’s risks along with its assets.
SportAdmin
In January 2025 attackers used an SQL injection to break into SportAdmin, a Swedish platform used by sports clubs. The personal data of more than 2.1 million people leaked, most of them children and young players.
SportAdmin was a processor, handling data on behalf of the clubs. IMY still fined it 6 million kronor finding it had failed to put appropriate security measures in place under Article 32.
SQL injection is one of the oldest web weaknesses and is well understood. Parameterised queries and input validation are standard secure-coding practice and they shut down injection attacks like this one.
GDPR, AI and the Wider Rulebook
GDPR does not sit on its own. Its security duties overlap with other EU rules and for many Swedish organisations several apply at once.
The security measures in NIS2 Article 21 and GDPR Article 32 cover much of the same ground from encryption and access control to breach detection and staff training. GDPR then adds duties NIS2 does not such as data subject rights, a DPO and impact assessments. For the Swedish transposition, see our guide to NIS2 compliance.

Reporting can double up. A ransomware attack that exposes personal data is both a GDPR breach and for essential and important entities, a reportable cyber incident under Cybersäkerhetslagen. The personal data breach goes to IMY within 72 hours. Since 1 July 2026 the cyber incident goes to the national cyber security centre at FRA which took over that role from MCF (formerly MSB).
Financial firms answer to more. Under DORA, Swedish financial entities report major ICT incidents to Finansinspektionen and must show operational resilience. Where DORA applies it takes precedence over NIS2. Our guide to DORA compliance covers the overlap.
AI raises fresh GDPR questions. Training a model on personal data still needs a lawful basis and data minimisation and using AI to make decisions about people brings Article 22 into play. The EU AI Act adds its own obligations on top so an AI system can owe duties under both laws at once.
An ISO 27001 management system is a practical way to evidence much of what Article 32 expects.
Data Transfers and Where Your Data Lives
Where your data physically sits is only half the question. GDPR restricts sending personal data outside the EU and who can legally reach the data matters as much as the location of the server.
In 2020 the Court of Justice of the EU struck down the Privacy Shield transfer deal in its Schrems II ruling. It kept standard contractual clauses alive but said organisations must check whether foreign law undermines them before relying on them.
The replacement, the EU-US Data Privacy Framework, took effect in 2023 and remains valid in 2026. It survived a first legal challenge when the EU General Court upheld it in September 2025 though that ruling is under appeal at the Court of Justice, so its future is not settled.
This is where the US CLOUD Act bites. A provider under US jurisdiction can be compelled to hand over data even when the servers sit in Europe which is why serious buyers weigh who controls a service and which laws bind it alongside the country on the data centre map.
How to Build GDPR-Ready Security
GDPR compliance is mostly good security done deliberately and written down. Start with these.
- Map your personal data. You cannot protect or minimise what you have not located so record what you hold, where it lives and who can reach it.
- Collect less and keep it for less time. Data you do not hold cannot leak.
- Encrypt personal data at rest and in transit and manage the keys properly.
- Lock down access with multi-factor authentication and least privilege, the gap the British Airways attackers walked through.
- Patch and test your applications including for injection flaws like the one behind the SportAdmin breach.
- Monitor for intrusions so a breach is caught in hours rather than the years Marriott lost.
- Test your backups by restoring them because availability is part of Article 32.
- Run a konsekvensbedömning before any high-risk processing.
- Vet your processors and put an Article 28 contract in place with each one.
- Rehearse the 72-hour breach drill so the report to IMY is ready before you need it.
- Review your data transfers and know which safeguard each one relies on.
None of this is exotic. It is the same security hygiene that stops most attacks applied with GDPR’s duties in mind and documented so you can prove it. To see how these controls map to the regulation, our GDPR compliance page lays it out.



