← Glossary

GDPR

GDPR is the EU's data protection law, requiring appropriate security of personal data and notification of personal data breaches to supervisory authorities within 72 hours of awareness.

Updated

The General Data Protection Regulation (Regulation (EU) 2016/679) is the EU's data protection law: it governs how organizations collect, use, protect and delete personal data, with fines up to EUR 20 million or 4% of global turnover for the most serious violations. For security teams, its sharpest edge is Article 33: personal data breaches must be reported to the supervisory authority within 72 hours of awareness. Guidance is published by the European Data Protection Board.

Key facts:

  • GDPR applies to any organization processing EU residents' personal data, regardless of where the organization sits.
  • Security of processing (Article 32) requires measures appropriate to the risk, and regulators consistently treat email protection as baseline.
  • Most reportable personal data breaches begin as email incidents: phishing, mailbox compromise or misdirected data, which makes the 72-hour clock an email detection problem.

The duties that touch security teams

Lawful basis, transparency and data subject rights are the privacy lawyers' domain. Security teams own: appropriate technical measures (Article 32), breach detection and the 72-hour notification (Articles 33-34), processor oversight (who processes your data, under what agreement), and data minimization in practice, including knowing where personal data actually flows. That last duty collides directly with shadow IT and shadow AI: personal data pasted into an unsanctioned AI tool or synced by an unapproved app is a GDPR event no policy document prevented.

The 72-hour clock is a detection problem

You cannot report what you have not noticed. The breach notification timeline starts at awareness, and regulators expect organizations to become aware promptly. For email-borne breaches, including business email compromise, the practical difference between a controlled notification and a late one is whether the mailbox compromise or phishing incident was detected in hours or discovered weeks later in the damage. See also NIS2 for a parallel EU regime with the same clock discipline, and the EU AI Act for how AI use layers on top.

Where email security fits, honestly

No product makes an organization GDPR compliant; lawful bases, agreements, registers and rights processes are organizational. What Sentaro contributes: protection of the channel where most personal data breaches start, early detection that starts the 72-hour clock with facts (what was accessed, whose data, when), visibility into which third-party apps and AI tools hold access to mail and files (your processor reality, not just your processor list), and evidence for the accountability principle.

This page is general guidance, not legal advice.

Questions we get asked.

What is GDPR in simple terms?

The EU's data protection law: organizations must handle personal data lawfully, transparently and securely, respect individuals' rights, and report breaches quickly, with heavy fines for failures.

What counts as a personal data breach under GDPR?

Any security incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to personal data, including a compromised mailbox containing personal data.

What is the 72-hour rule?

Article 33 requires notifying the supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to risk individuals' rights. Late notification requires justification.

How does email security relate to GDPR?

Email is where most breaches begin and where much personal data lives. Protecting it addresses Article 32's security requirement, and fast detection is what makes the 72-hour notification achievable.

Does GDPR apply to AI tools employees use?

Yes. Personal data entered into any AI tool is processing under GDPR, and the organization remains responsible even when the tool was never approved, which is why shadow AI is a compliance issue, not just a security one.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.