Skip to main content
DocumentMS

Glossary

GDPR

Also called: General Data Protection Regulation, UK GDPR

The General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime. For a document system the practical consequences are lawful basis, retention limits, security measures, and support for subject access and erasure requests.

GDPR explained

Controller and processor

The organisation that decides why documents are held is the controller. A vendor holding them on that organisation's instructions is a processor. The split determines who answers a data subject, who sets retention, and who is liable for what — and conflating the two is the most common confusion in vendor conversations.

Storage limitation

Personal data must be kept no longer than necessary for the purpose. In a document system that is the retention schedule, which is why data protection and records management are the same problem approached from two directions. An organisation with no retention schedule is not complying with storage limitation, whatever its security posture.

The two rights that create work

Subject access requires finding everything about one person across the whole estate, within a month. Erasure requires deleting it unless an obligation prevails — and that conflict is common rather than exceptional.

Both are retrieval problems before they are legal ones, which is why organisations with scattered documents find the deadlines harder than organisations with a controlled repository.

Article 32 security

Appropriate technical and organisational measures, judged against the risk. Encryption, pseudonymisation, access control, and the ability to restore availability are named explicitly, and "appropriate" means proportionate rather than maximal.

FAQ

GDPR: common questions

Does the GDPR require us to delete documents?

It requires you not to keep personal data longer than necessary, which in practice means having and applying a retention schedule. It does not prescribe periods — those come from your own purposes and other legal obligations.

Does the UK GDPR differ from the EU version?

Substantively they are very close. The differences that matter operationally are the supervisory authority, the transfer mechanism used for exports, and some divergence in guidance rather than in the text.

A 30-minute session with a solutions engineer, using a folder structure and approval chain that resemble yours — not a generic demonstration tenant.