Skip to contentAbout Fig Group

Cyber Essentials glossary

GDPR

The General Data Protection Regulation - EU and UK law governing processing of personal data. Applies to any organisation that processes personal data of EU/UK residents. GDPR requires data protection by design, breach notification within 72 hours, and documented lawful basis for processing.

Why this term matters for governance

Governance terms connect technical work to accountable business processes. They help prove that security controls are not one-off fixes, but managed activities with owners, review cycles, evidence, exceptions, and escalation paths.

A mature organisation links this term to policies, risk records, audit trails, management review, evidence collection, and improvement actions rather than leaving it as an isolated technical activity.

How Fig uses this term

Fig Group uses GDPR as part of a practical Cyber Essentials and compliance vocabulary. The purpose is to make assessment decisions easier to verify: what the term means, where it appears in evidence, which control it supports, and which buyer or assessor question it helps answer.

If this term affects your Cyber Essentials submission, treat it as an evidence question rather than a definition question. Document the relevant owner, system, configuration, policy, or workflow so an assessor can see how the control works in your environment.

Official sources and related guidance

For scheme interpretation, verify against official NCSC and IASME material. Fig's glossary is designed to translate those concepts into implementation language for UK organisations, MSPs, and procurement teams.

Fig Group is an IASME-licensed Cyber Essentials certification body (licence 325cdf33-3812-4082-bf8d-7dce7ac02977) that certifies UK organisations from £299.99 + VAT with a 6-hour turnaround guarantee and three free re-submissions. Learn more at /cyberessentials, see pricing at /pricing, or run the free readiness checker.