Home Learn
Start here

Personal data protection explained for everyone

A practical guide to understanding whether the law applies to your organisation, what it requires, the key terms you need to know, who should be involved, and where to start.

What personal data protection is really about

At its simplest, personal data protection is about how organisations handle information about people. Organisations need a good reason to collect and use personal data, they need to be clear about what they are doing with it, they need to protect it, and they need to respect people's rights.

That is the core idea. The differences between countries are mostly about who is covered, what organisations must do, what rights people have, who enforces the rules, and what happens when those rules are broken.

Two things surprise people most. First, these laws apply to ordinary organisations, not just tech companies: a clinic with patient records, a school with parent contacts, a shop with a mailing list, or an employer with staff records. Second, these regulations can apply across borders. An organisation may have to follow another country's regulations even when it is based somewhere else, depending on who it serves, what it does with personal data, and where those people are located.

Does this apply to you?

If any of these are true, at least one data protection law already covers what you do.

You keep names, emails, phone numbers or addresses: for customers, staff, job applicants, donors, patients, or students.

You have customers, users or employees in another country: that country's law may reach you even if you have no office there.

You use analytics, advertising, email marketing or a CRM: these collect and share personal data by design.

You handle sensitive information: health, biometrics, financial details, religion, political views, or anything about children.

Someone else processes data for you: a payroll provider, cloud host, or agency. Their handling is still your responsibility.

Almost every organisation ticks at least one box. The useful question is therefore not whether a law applies, but which one. You can start with the country where your people are, using the country index.

The words you will hear

The vocabulary that makes every country page, contract, and regulator letter readable.

Personal data
Any information that identifies a living person, directly or indirectly e.g a name, an email, an ID number, a location, even an IP address in many jurisdictions.
Data subject
The person the data is about. Laws grant them rights; you owe them duties.
Controller
The organisation that decides why and how data is processed. Most legal obligations land here. This is usually you as a company.
Processor
Anyone handling data on the controller's instructions e.g a cloud host, payroll firm, or agency. They carry their own duties too.
Lawful basis
The legal reason you are allowed to process data at all: consent, a contract, a legal obligation, vital interests, public task, or legitimate interests.
Consent
One lawful basis among several and often the weakest, because it must be freely given, specific, informed, and as easy to withdraw as it was to give.
Privacy notice
The public statement telling people what you collect, why, who you share it with, how long you keep it, and how to reach you. Usually the first thing a regulator checks.
Data Protection Officer (DPO)
The person accountable for privacy day to day. Mandatory above certain thresholds in many countries; South Africa calls the equivalent role an Information Officer.
Supervisory authority
The regulator that enforces the law, receives breach reports and complaints, and issues fines. Every country page names yours.
Personal data breach
Any incident where data is lost, stolen, altered, or exposed (not only hacking). A misdirected email counts. Most laws set a reporting deadline; 72 hours is the most common.
DPIA
A Data Protection Impact Assessment: a written risk assessment done before starting something high-risk, such as large-scale profiling or new surveillance technology.
Cross-border transfer
Sending personal data to another country, including simply using a cloud service hosted abroad. Most laws restrict this unless safeguards are in place.
Adequacy decision
A formal finding that another country protects data to an equivalent standard, letting data flow there freely. Few countries hold one.
Standard Contractual Clauses (SCCs)
Pre-approved contract terms that bind whoever receives your data abroad to protect it properly. The main workaround where no adequacy decision exists.
Retention
How long you keep data. "Forever" is not a lawful answer, you are expected to set a period tied to the purpose, and then delete.
RoPA
Records of Processing Activities: your internal inventory of what data you hold, why, where it lives, and who it is shared with. Several laws require it; everyone benefits from it.

Who you will be talking to

Privacy work is a team work. These are the people involved and when to bring them in.

From day one

Whoever runs your data

Your engineers, analysts, or IT provider are the only people who truly know where personal data lives, who can reach it, and what your tools quietly collect. No privacy programme survives without them.

From day one

An accountable owner

One named person responsible for privacy e.g a Data Protection Officer where the law requires it, otherwise simply whoever will answer for it. Many countries mandate the role above a size or risk threshold.

Before you sign anything

Your vendors and processors

Every tool that touches customer data needs a written agreement covering what they may do with it and where it goes. Ask before adopting, not after.

At the decision points

A privacy lawyer or licensed consultancy

For binding advice, cross-border contracts, filings, and audits. Some countries license specific firms for this e.g Nigeria's DPCOs file compliance audits on your behalf, for instance.

When required or when in doubt

Your regulator

Not only an enforcer. Supervisory authorities publish guidance, run registration portals, and answer questions. You will also contact them to report a breach. Each country page links yours directly.

How to start with minimal effort

You do not need a compliance department. These steps are ordered so the cheapest, highest-value work comes first.

130 minutes

Find out which law applies

Look up the country where your customers, staff or users are. Note the regulator, the breach deadline, and whether you must register. Open the country index →

2An afternoon

Write down what you collect

A single spreadsheet: what personal data you hold, why you have it, where it lives, who can see it, and who you share it with. This is the seed of a RoPA and makes every later step easier.

3An hour

Name someone accountable

Even where the law does not demand a DPO, pick a person. Privacy that belongs to everyone belongs to no one.

4A day

Publish a plain-language privacy notice

Say what you collect, why, who you share it with, how long you keep it, what rights people have, and how to contact you. Write it for a customer, not a court.

5A week

Delete what you should not have, lock down the rest

Old exports, abandoned spreadsheets, shared logins. Reduce who can reach personal data to those who need it, and set retention periods so data expires on purpose.

6Half a day

Agree what happens if there is a breach

One page: who is told first, who decides whether it is reportable, who contacts the regulator, and the deadline. Deciding this calmly in advance is worth more than any policy document.

7Ongoing

Then, and only then, scale up

Vendor agreements, transfer mechanisms such as SCCs, DPIAs for high-risk projects, registration and audits where required. By now you will know which of these you actually need.

Where to go next

Now that you know the shape of it, let's get specific.

Further reading

Official sources, guidance, and communities for privacy professionals.