GDPR Compliance

What is GDPR?

The General Data Protection Regulation (GDPR) is a European Union regulation designed to protect individuals’ personal data and strengthen their rights over how that data is collected, used, stored, and shared. It applies to the processing of personal data by organisations within the EU and, in certain circumstances, to organisations outside the EU that offer goods or services to individuals in the EU or monitor their behaviour.

The General Data Protection Regulation (GDPR) is a European Union regulation designed to protect individuals’ personal data and strengthen their rights over how that data is collected, used, stored, and shared. It applies to the processing of personal data by organisations within the EU and, in certain circumstances, to organisations outside the EU that offer goods or services to individuals in the EU or monitor their behaviour.

The GDPR establishes principles for responsible data processing, including lawfulness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability. It also gives individuals rights over their personal data, including rights to access, rectify, erase, restrict, and in certain circumstances, transfer or object to its processing.

Who Does GDPR Apply To?

  • The GDPR applies to organisations that process personal data in connection with activities carried out by an establishment in the European Union, regardless of where the data itself is processed. It can also apply to organisations established outside the EU when they offer goods or services to individuals in the EU or monitor their behaviour.
  • The regulation can therefore apply to businesses of different sizes and across different industries. Its applicability depends on the nature of the organisation’s activities and how personal data is processed, rather than simply on where the organisation is located or the nationality of the individuals whose data is being processed.
  • For businesses developing websites, mobile applications, and digital products for users or customers in the EU, understanding whether GDPR applies is an important part of planning how personal data is collected, processed, stored, shared, and protected.

What Does GDPR Require?

GDPR requires organisations to handle personal data lawfully, transparently, securely, and only for legitimate and defined purposes. It also places obligations on organisations to protect personal data, respect individual rights, assess privacy risks, and demonstrate compliance.

1. Data Minimisation and Purpose Limitation

Organisations should collect and process only the personal data necessary for a specific, legitimate purpose. Data should not be collected simply because it may be useful in the future, and it should not be reused for purposes that are incompatible with the original purpose.

2. Data Security

Organisations must implement appropriate technical and organisational measures to protect personal data against unauthorised access, unlawful processing, accidental loss, destruction, or damage. Depending on the risks involved, measures may include access controls, encryption, pseudonymisation, secure backups, and regular security testing.

3. Right to Erasure

Under certain circumstances, individuals can request the deletion of their personal data. However, the right to erasure is not absolute. Organisations may be permitted or required to retain information where specific legal obligations or other recognised exceptions apply.

4. Risk Management and Accountability

GDPR requires organisations to consider the risks associated with processing personal data and take appropriate measures to address them. Organisations must also be able to demonstrate that their processing activities comply with GDPR requirements.

5. Data Breach Notification

When a personal data breach is likely to pose a risk to individuals' rights and freedoms, the relevant supervisory authority must generally be notified without undue delay and, where feasible, within 72 hours of the organisation becoming aware of the breach. If the breach is likely to result in a high risk to affected individuals, they may also need to be informed. Where an organisation acts as a processor, it must notify the relevant controller of a personal data breach.

Steps to GDPR Compliance

Achieving GDPR compliance requires organisations to understand how personal data moves through their operations and establish appropriate processes for protecting it. The following steps can help businesses build a practical approach to GDPR compliance:

  • Identify the personal data you process: Determine what personal data is collected, where it comes from, why it is processed, where it is stored, and who can access it.
  • Define lawful processing: Identify the appropriate legal basis for each processing activity and ensure that users receive clear information about how their personal data is used.
  • Respect data subject rights: Establish processes for handling requests relating to access, rectification, erasure, restriction, portability, and objection within the applicable GDPR requirements.
  • Assess privacy and security risks: Evaluate the risks associated with processing activities and implement technical and organisational measures appropriate to those risks.
  • Review third-party processing: Identify service providers, processors, and other third parties that handle personal data and establish appropriate contractual and data-protection arrangements where required.
  • Prepare for data breaches: Maintain a documented incident-response process for identifying, containing, assessing, and reporting personal data breaches where notification is required.
  • Maintain compliance records: Document relevant processing activities, policies, assessments, decisions, and safeguards so the organisation can demonstrate accountability.

What Does GDPR Mean for Your Mobile App?

GDPR compliance should be considered throughout the lifecycle of a mobile application, from planning and data collection to storage, sharing, and deletion. Developers and businesses need to understand what personal data the app processes, why it is needed, who can access it, and how it is protected. Key considerations include:

Privacy by Design

Privacy should be considered from the earliest stages of application development rather than added after the product is built. Collect only the personal data necessary for the app's intended functionality and incorporate appropriate privacy and security measures into the architecture and development process.

Lawful Data Collection and Consent

Mobile applications should have a valid legal basis for processing personal data. Consent may be appropriate for certain processing activities, but it is not the legal basis for every type of data processing. Where consent is relied upon, it should be freely given, specific, informed, and unambiguous, with users able to withdraw it where applicable.

Transparency and Visibility

Users should receive clear information about what personal data the application collects, why it is processed, how long it may be retained, and who it may be shared with. An up-to-date privacy notice should reflect the application's actual data-processing practices.

Responding to Data Subject Requests

Applications and supporting business processes should allow organisations to respond to applicable data subject requests, including requests for access, rectification, erasure, restriction, portability, or objection. The appropriate process will depend on the nature and legal basis of the processing.

Right to Erasure in Mobile Apps

Where an applicable erasure request is made, businesses should have a process for deleting personal data from relevant systems. This may require coordinating deletion across application databases, backups, and third-party services, subject to applicable legal retention requirements and GDPR exceptions.

Third-Party Services and SDKs

Analytics platforms, payment services, cloud providers, advertising technologies, social integrations, and other SDKs may process personal data on behalf of or alongside an application. Businesses should understand what data these services receive and establish appropriate data-protection arrangements where required.

Data Breach Response and Notification

A mobile application should have an incident-response process for identifying and assessing personal data breaches. Where GDPR notification requirements apply, the organisation should be prepared to meet the applicable notification timelines and communicate with affected parties where required.

Data Protection Officer

A Data Protection Officer (DPO) is mandatory only in specific circumstances defined by GDPR, such as certain large-scale, regular and systematic monitoring activities or large-scale processing of special categories of personal data. Having a mobile application does not, by itself, require an organisation to appoint a DPO.

Encryption and Data Storage

Appropriate security measures should protect personal data both during transmission and, where appropriate, while stored. Secure communications using current encryption protocols, access controls, secure storage practices, and appropriate retention policies can help reduce privacy and security risks.

Data Collection and Processing Records

Businesses should maintain appropriate documentation of their personal-data processing activities. This can help demonstrate accountability and provide visibility into what data the application collects, why it is processed, where it is stored, and which parties may have access to it.

Our Approach to GDPR Compliance

At Konstant Infosolutions, we consider data protection and privacy requirements when designing and developing digital products. Our approach focuses on helping businesses build applications with appropriate data-handling, privacy, and security considerations based on their specific business requirements and the nature of the data being processed.

Privacy Documentation

We help ensure that privacy considerations are reflected in the documentation supporting a digital product. Depending on the application's data-processing activities and business requirements, this may include a Privacy Policy, Terms of Service, cookie disclosures, and relevant operational or data-protection documentation. These materials should clearly explain how personal data is collected, used, stored, shared, and retained, while remaining consistent with the application's actual data-processing practices.

Cookies

We help businesses consider the appropriate use of cookies and similar tracking technologies within their websites and applications. Depending on their purpose and type, cookies may require user consent and clear disclosure. We can help incorporate appropriate cookie consent and preference mechanisms based on the technologies and data-processing activities involved.

Third-Party Tools and Services

We consider the data flows associated with third-party services and integrations used within digital products. This may include analytics platforms, cloud services, payment providers, communication tools, and other external services. We help businesses understand what data these integrations may process and identify relevant privacy and data-protection considerations when incorporating them into an application.