Skip to main content

GDPR

GDPR (General Data Protection Regulation) is a comprehensive data protection and privacy law enacted by the European Union (EU).

It governs how organizations collect, process, store, and share personal data of individuals within the EU.

GDPR applies to:

  • Organizations operating in the EU
  • Organizations outside the EU that handle EU residents’ data

Personal data is highly sensitive, especially in health systems.

GDPR ensures:

  • Protection of individual privacy
  • Transparency in data use
  • Accountability of organizations
  • Secure handling of sensitive data

Key Principles of GDPR​

1. Lawfulness, Fairness, and Transparency​

Data must be processed legally and transparently.


2. Purpose Limitation​

Data should only be collected for specific, legitimate purposes.


3. Data Minimization​

Only necessary data should be collected.


4. Accuracy​

Data must be kept accurate and up to date.


5. Storage Limitation​

Data should not be kept longer than necessary.


6. Integrity and Confidentiality​

Data must be protected against unauthorized access or loss.


7. Accountability​

Organizations must demonstrate compliance with GDPR.


Personal Data vs Sensitive Data​

Personal Data​

Any information that can identify a person:

  • Name
  • Email
  • Phone number
  • IP address

Special Category (Sensitive) Data​

Includes:

  • Health data
  • Genetic data
  • Biometric data
  • Religious or political beliefs

Health systems must apply stricter protections for this data.


Data Subject Rights​

Individuals have the right to:

  • Access their data
  • Correct inaccurate data
  • Request deletion ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing

Compliance Requirements​

Organizations must:

  • Appoint a Data Protection Officer (DPO) (in many cases)
  • Conduct Data Protection Impact Assessments (DPIA)
  • Report data breaches within 72 hours
  • Maintain data processing records

Penalties​

Non-compliance can result in:

  • Fines up to €20 million or 4% of annual global turnover
  • Legal consequences
  • Reputational damage

GDPR vs Other Standards​

StandardPurpose
GDPRData privacy and protection law
HIPAAUS health data protection law
ISO 27001Information security management

Relevance for Nepal​

Even outside the EU, GDPR matters if:

  • You handle EU citizen data
  • You build global digital health products
  • You integrate with international systems

GDPR principles are also considered best practice for data protection globally.