GDPR scope: personal data protection, not cybersecurity
GDPR protects personal data and data-subject rights; the main exam trap is confusing it with cybersecurity or platform-content laws.
Слушай тази страница (бета)
The GDPR is first and foremost about protecting personal data and the rights of individuals (data subjects) over that data. It covers how organisations collect, store, process, and share personal data, and gives people rights like access, rectification, and erasure. A concrete contrast: the GDPR is not a general cybersecurity law—it does not mandate firewalls or antivirus software—though it does require appropriate security measures to protect personal data. Similarly, it is not a platform-content law like the Digital Services Act (DSA), which focuses on illegal content and platform accountability. So if an exam scenario mentions hacking or content moderation, check whether the core issue is about personal data misuse or something else.
To avoid traps, remember three elimination tricks. First, if the question talks about protecting a company's trade secrets or intellectual property, the GDPR does not apply—that is a different area. Second, if the scenario involves a data breach, the GDPR kicks in only if personal data (e.g., names, emails, health info) is compromised; a breach of anonymised data or non-personal data falls outside its scope. Third, the GDPR applies to any organisation processing personal data of EU residents, regardless of where the organisation is based—so a US company targeting EU users is covered. When you see a question with 'personal data' and 'rights of individuals', that is your cue for the GDPR; if you see 'cybersecurity' or 'platform content', look elsewhere.
A quick way to test your understanding: ask yourself, 'Is the main concern here about someone's personal information and their control over it?' If yes, think GDPR. If the concern is about system security or harmful content, think other laws. One memory aid: GDPR = 'Give Data Protection Rights'—focus on the 'personal' and 'rights' parts, not the technical security details.
What is the GDPR mainly about?
Protection of personal data and rights of data subjects.