GDPR
GDPR (General Data Protection Regulation) is a comprehensive data protection and privacy law enacted by the European Union (EU).
It governs how organizations collect, process, store, and share personal data of individuals within the EU.
GDPR applies to:
- Organizations operating in the EU
- Organizations outside the EU that handle EU residents’ data
Personal data is highly sensitive, especially in health systems.
GDPR ensures:
- Protection of individual privacy
- Transparency in data use
- Accountability of organizations
- Secure handling of sensitive data
Key Principles of GDPR
1. Lawfulness, Fairness, and Transparency
Data must be processed legally and transparently.
2. Purpose Limitation
Data should only be collected for specific, legitimate purposes.
3. Data Minimization
Only necessary data should be collected.
4. Accuracy
Data must be kept accurate and up to date.
5. Storage Limitation
Data should not be kept longer than necessary.
6. Integrity and Confidentiality
Data must be protected against unauthorized access or loss.
7. Accountability
Organizations must demonstrate compliance with GDPR.
Personal Data vs Sensitive Data
Personal Data
Any information that can identify a person:
- Name
- Phone number
- IP address
Special Category (Sensitive) Data
Includes:
- Health data
- Genetic data
- Biometric data
- Religious or political beliefs
Health systems must apply stricter protections for this data.
Data Subject Rights
Individuals have the right to:
- Access their data
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
Compliance Requirements
Organizations must:
- Appoint a Data Protection Officer (DPO) (in many cases)
- Conduct Data Protection Impact Assessments (DPIA)
- Report data breaches within 72 hours
- Maintain data processing records
Penalties
Non-compliance can result in:
- Fines up to €20 million or 4% of annual global turnover
- Legal consequences
- Reputational damage
GDPR vs Other Standards
| Standard | Purpose |
|---|---|
| GDPR | Data privacy and protection law |
| HIPAA | US health data protection law |
| ISO 27001 | Information security management |
Relevance for Nepal
Even outside the EU, GDPR matters if:
- You handle EU citizen data
- You build global digital health products
- You integrate with international systems
GDPR principles are also considered best practice for data protection globally.