The EU General Data Protection Regulation (GDPR) is eighteen months old today but, as seasoned practitioners will know, data protection law has been around for several decades.
What the GDPR has done is put a strict obligation on all controllers to demonstrate that they comply with the law. The GDPR refers to this as the accountability principle in Article 5 (2) but there is no detailed explanation of what this means on the face of the law itself. In practice, it amounts to an organisation putting in place a governance framework which sets out how the organisation meets its responsibilities under the law. What this looks like will differ for different organisations. Continue reading








