What is GDPR and what does it actually require?
GDPR is Regulation (EU) 2016/679, the EU law governing how organisations handle information about people since 25 May 2018. It forces you to know what personal data you hold, why you may hold it, who else touches it and when it is deleted, and to prove that on request. The binding text is the regulation itself and real edge cases are a lawyer's call; what follows is the working version that comes up in meetings.
Where it applies, and what counts as personal data
The regulation binds every member state directly but leaves room for national rules in about fifty places, which is why Latvia has its own layer in the Fizisko personu datu apstrades likums and why some details differ between countries. It applies if you are established in the EU, wherever your servers sit, and to companies outside the EU that sell to or track people here. B2B is not exempt: a named work email and a direct mobile number belong to a person.
Personal data is any information relating to an identified or identifiable person: IP addresses in your logs, cookie identifiers, an employee's phone number, a photograph of a face, a CV, camera footage. Pseudonymised data, where the name is swapped for a reversible ID, still counts. Article 9 adds stricter rules for health, biometrics, religion and ethnic origin. Most small companies are sure they hold none of that, then remember the sick notes in HR.
You are the controller, your host is the processor
The controller decides why and how data is processed; the processor only acts on instructions. Your hosting provider, payroll bureau and CRM vendor are processors. You are the controller, and the regulator and the individual come to you first. Processors carry direct duties too and can be fined themselves.
| Decision | Who makes it |
|---|---|
| Why the data is collected | You, the controller |
| Physical and network security | The provider |
| Answering an access request | You, with the provider's help |
| Whether a breach is notifiable | You |
Six lawful bases, and why consent is the wrong default
Every activity needs one of six bases from Article 6, picked before you start and named in your privacy notice. You cannot switch quietly when the first one fails.
| Basis | Typical use | The catch |
|---|---|---|
| Consent | Newsletters, non-essential cookies | Unbundled, and as easy to withdraw as to give |
| Contract | Delivering what the customer ordered | Not the marketing around it |
| Legal obligation | Invoices, tax, employment records | Needs a law, not a habit |
| Vital interests | Life and death | Almost never in business |
| Public task | Public bodies | Not for ordinary companies |
| Legitimate interests | Fraud prevention, network security, operations | Requires a documented balancing test |
Consent is the weakest of the six and the most abused. It can be withdrawn at any moment, taking the ground from under whatever you built on it, and between employer and employee the imbalance makes it hard to call free. Most of what companies collect consent for is really contract or legitimate interests. The cookie banner is a separate ePrivacy duty either way.
The rights people use, and the one month clock
People can ask for a copy of their data, correction, erasure, restriction and portability, and they can object. Objection to direct marketing is absolute; erasure is not, because data you must keep by law stays. You have one month, extendable by two more for a complex request if you say so inside the first month. Realistically it arrives from a former employee or a customer in a dispute and spans mailboxes, the CRM and backups at once. Nobody meets that deadline by improvising, which is why Article 30 asks for a record of your processing.
Article 28 and the data processing agreement
Whenever a processor touches personal data for you there must be a written contract, and Article 28 sets its contents: subject matter, duration, purpose, type of data and categories of people, plus mandatory clauses. Processing only on your documented instructions, confidentiality for staff, security measures, no sub-processor without your authorisation and on the same terms, help with data subject requests and breaches, deletion or return at the end, and audit rights for you.
"We host in the EU" is not a substitute. Location answers the transfer question and says nothing about instructions, sub-processors or deletion. A bank or an auditor wants the signed agreement and the sub-processor list, including backup and filtering vendors. Our data protection page sets out what we sign.
72 hours, and who has to be told
A breach goes to the supervisory authority without undue delay and, where feasible, within 72 hours of you becoming aware, unless it is unlikely to pose a risk to people. In Latvia that is Datu valsts inspekcija. The clock starts at reasonable certainty that something happened, not when the investigation ends. Where the risk is high you must tell the individuals too, unless strong encryption left the data unreadable.
A breach is not only a hacker: ransomware, a lost laptop, an email to the wrong recipient, a misconfigured bucket and permanent data loss all count. Your processor must tell you quickly but does not file with the regulator for you. Under NIS2, reporting runs on a separate and faster clock.
Transfers outside the EU after Schrems II
Sending data outside the EU, or letting someone outside look at it remotely, is a transfer and needs its own footing: an adequacy decision, standard contractual clauses or binding corporate rules. Schrems II struck down the Privacy Shield in 2020 and made the clauses conditional on assessing the destination country's surveillance law. The 2023 EU and US framework restored a route for certified American organisations, but it is being litigated and may not be the last word. Which is the honest argument for keeping data here: nothing to assess, nothing to redo when an instrument falls. That is why clients ask for a data centre in Riga rather than a cheaper region elsewhere.
Retention, the rule everyone ignores
Data may be kept only as long as the purpose needs it, yet in most companies the real retention period is forever: CVs from a hiring round years ago, a list built at a trade fair nobody remembers, backups holding people you deleted from production.
Good practice is a short schedule, category by category, with a legal reference where one exists. Latvian accounting rules require source documents for at least five years, so invoices are easy. Personnel and payroll records carry much longer archive obligations. Marketing data has no statutory period, so you set one and justify it. Regulators accept that you cannot cut one person out of an immutable backup set, provided your erasure procedure says so and a restore does not resurrect them.
Fines, and the risk that is actually likely
Two ceilings: up to 10 million euro or 2 percent of worldwide annual turnover, whichever is higher, for records, security and processor contracts, and up to 20 million or 4 percent for the principles, lawful basis, rights and transfers. Those numbers describe a hotel chain or a social network. For a normal company the sequence is different: an ex-employee or an annoyed customer complains, Datu valsts inspekcija writes with questions and a deadline, and you spend three weeks assembling documents you should have had. Individuals can also sue for compensation, and usually the commercial version bites first: a tender sends a data protection annex you cannot answer.
What a hosting provider can and cannot take off your plate
A provider can run the building and the network, control physical access, keep your data in one jurisdiction, sign the Article 28 agreement, name its sub-processors, tell you fast when something happens on its side, and supply the infrastructure controls: isolation, backups, filtering at the edge.
It cannot choose your lawful basis, write your privacy notice, keep your record of processing, set retention periods, find personal data inside your application, act as your data protection officer, or make a badly built system compliant. If your code writes card numbers into a log file, the data centre around it is irrelevant.
Where we fit is the narrow part: our own data centre in Riga on our own network, data staying in the EU under EU law, engineers reachable around the clock, and a data processing agreement we will sign. Everything above that line stays yours, and it pays to write that boundary down before an auditor asks.