Contact ussales@ventavid.com
VentaVid

Glossary

Our sales with video glossary is here to help you gain an understanding of specific video and marketing terms

GDPR - General Data Protection Regulation

In this article

GDPR explained: what the General Data Protection Regulation actually requires

The General Data Protection Regulation (GDPR) is Regulation (EU) 2016/679, the European Union law that governs how organisations process personal data about people in the EU. It sets out principles for processing, requires a lawful basis for every use of that data, gives individuals enforceable rights, and backs all of it with administrative fines.

It has applied since 25 May 2018, under Article 99. The UK kept a near-identical text after Brexit, the UK GDPR, read alongside the Data Protection Act 2018 and enforced by its own regulator.

What does the GDPR cover?

Personal data, meaning any information relating to an identified or identifiable living person, and the organisations that decide how it is used (controllers) or handle it on their behalf (processors).

What catches evidence-heavy teams out is how wide "personal data" runs. A photograph of a damaged vehicle carries a number plate. A capture of a kitchen carries the inside of someone's home. Device identifiers, IP addresses and precise location are in scope too. None of that looks like a database record, and all of it is regulated the same way.

For insurers

See the damage before you decide

Send one link. Get guided, verified claim video back. No app, no account.

Customer filming damage with her phone

The principles in Article 5

  • Lawfulness, fairness and transparency. A basis, no hidden processing, and people told what is happening.
  • Purpose limitation. Collected for specified, explicit and legitimate purposes, and not reused for something incompatible.
  • Data minimisation. "Adequate, relevant and limited to what is necessary", covered in full under data minimisation.
  • Accuracy. Kept correct and, where necessary, up to date.
  • Storage limitation. Kept in identifiable form "no longer than is necessary", which is the whole basis of data retention policy.
  • Integrity and confidentiality. Appropriate security against unauthorised access, loss and damage.

Article 5(2) adds accountability, and it changes how the rest behaves: the controller must be able to demonstrate compliance. In front of a regulator, being compliant and being unable to show it are close to the same position.

The six lawful bases in Article 6

Every processing activity needs exactly one, chosen and documented before you start:

  • Consent, freely given for one or more specific purposes.
  • Contract, where processing is necessary to perform a contract with the person or to take pre-contractual steps at their request.
  • Legal obligation, where a law the controller is subject to requires it.
  • Vital interests, protecting someone's life.
  • Public task, a task in the public interest or under official authority.
  • Legitimate interests, pursued by the controller or a third party, "except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject".

You cannot switch basis later to rescue a decision already challenged. And consent is often the wrong choice in claims and inspection work: it is withdrawable, and it sits awkwardly where the person needs a decision from you. Contract or legitimate interests usually fit the real relationship better.

What rights does a data subject have?

Chapter 3 sets out the rights: to be informed (Articles 13 and 14), of access (15), to rectification (16), to erasure (17), to restriction of processing (18), to data portability (20), to object (21), and not to be subject to a solely automated decision with legal or similarly significant effects (22).

Two of these bite hardest on evidence files. A subject access request can reach the video and photos held on a case, not only the correspondence. And erasure is not absolute: Article 17(3) disapplies it where processing is necessary "for the establishment, exercise or defence of legal claims". That is the exemption a contested file rests on, and it is narrower than "we would rather keep it".

Does the GDPR apply to non-EU organisations?

Frequently, yes. Article 3(1) catches processing "in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not".

Article 3(2) goes further and reaches organisations with no EU establishment at all, where they process the data of people who are in the Union and the activity relates to "the offering of goods or services, irrespective of whether a payment of the data subject is required" to those people, or to "the monitoring of their behaviour as far as their behaviour takes place within the Union".

So a US claims administrator handling files for European policyholders is generally in scope, wherever its servers sit. If the data then leaves the EU, Chapter 5 adds a separate transfer question.

How large can a GDPR fine be?

Two tiers, each the higher of a fixed sum or a percentage of global turnover:

  • Article 83(4): "up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover", covering obligations such as security, records, and data protection by design.
  • Article 83(5): "up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover", covering the Article 5 principles, the lawful bases, data subject rights and international transfers.

The ceiling is not theoretical. Ireland's Data Protection Commission fined Meta Ireland 1.2 billion euro in a decision adopted on 12 May 2023, over EU to US transfers under Article 46(1). Fines are not the whole exposure either: an order to suspend a processing activity usually hurts an operation more than the cheque does.

What GDPR compliance is not

There is no badge that discharges your obligations. When a supplier describes itself as GDPR-compliant, that is a statement about its own product. Under Article 5(2) the accountability stays with you as controller.

The questions that matter are duller. Is there a written processing agreement. Who are the sub-processors. Where does the data physically sit. What is the transfer mechanism if it leaves the EU. Can retention be configured, and does it cover exports and backups. That last one is where compliance and evidence integrity meet, because the retention window and the dispute horizon get decided in the same conversation.

For insurers

See the damage before you decide

Send one link. Get guided, verified claim video back. No app, no account.

Customer filming damage with her phone

See the damage before you decide

Send one link, get guided, verified claim video back. No app, no account.