Glossary
GDPR
Also called: General Data Protection Regulation, UK GDPR
The General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime. For a document system the practical consequences are lawful basis, retention limits, security measures, and support for subject access and erasure requests.
GDPR explained
Controller and processor
The organisation that decides why documents are held is the controller. A vendor holding them on that organisation's instructions is a processor. The split determines who answers a data subject, who sets retention, and who is liable for what — and conflating the two is the most common confusion in vendor conversations.
Storage limitation
Personal data must be kept no longer than necessary for the purpose. In a document system that is the retention schedule, which is why data protection and records management are the same problem approached from two directions. An organisation with no retention schedule is not complying with storage limitation, whatever its security posture.
The two rights that create work
Subject access requires finding everything about one person across the whole estate, within a month. Erasure requires deleting it unless an obligation prevails — and that conflict is common rather than exceptional.
Both are retrieval problems before they are legal ones, which is why organisations with scattered documents find the deadlines harder than organisations with a controlled repository.
Article 32 security
Appropriate technical and organisational measures, judged against the risk. Encryption, pseudonymisation, access control, and the ability to restore availability are named explicitly, and "appropriate" means proportionate rather than maximal.
FAQ
GDPR: common questions
Does the GDPR require us to delete documents?
It requires you not to keep personal data longer than necessary, which in practice means having and applying a retention schedule. It does not prescribe periods — those come from your own purposes and other legal obligations.
Does the UK GDPR differ from the EU version?
Substantively they are very close. The differences that matter operationally are the supervisory authority, the transfer mechanism used for exports, and some divergence in guidance rather than in the text.
Related terms
- 21 CFR Part 1121 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures in regulated life sciences.
- Business associate agreementA business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf.
- Data processing addendumA data processing addendum is the contract between a controller and a processor governing how personal data is handled.
- eIDASeIDAS is the EU regulation establishing a framework for electronic identification and trust services.
- ESIGN ActThe ESIGN Act is the US federal statute giving electronic signatures and records the same legal effect as paper, provided the parties intended to sign and consented to transact electronically.
- Golden threadThe golden thread is the requirement, introduced by the UK Building Safety Act 2022, to create and maintain accurate building safety information for higher-risk buildings throughout their life.
Última revisión: 28 de agosto de 2026. Browse the full glossary.