Cyber Security Awareness Blog | The Security Company

GDPR Compliance Guide | Free eBook | TSC

Written by The Security Company | Jul 21, 2026 7:03:21 AM

Explore the TSC eBook on GDPR, covering data protection principles, individual rights, breach reporting and the role of the DPO.

Understanding GDPR: What every employee in your organisation needs to know

The ICO receives an average of 1,276 data breach reports every month. Since its introduction in May 2018, GDPR has resulted in enforcement action against organisations including British Airways and Marriott International. The financial and reputational consequences of non-compliance are severe.

This eBook cuts through the legal complexity and explains data protection law in plain language. From subject access requests to breach reporting timelines, it covers everything your employees need to understand their responsibilities and protect personal data every day.

In this free eBook, you'll discover:

What GDPR is, why it was introduced and how it applies to your organisation
The principles of GDPR and what they mean for how personal data must be handled
What counts as personal data and the special categories that require extra protection
Individual rights under GDPR, including subject access requests and erasure rights
Non-compliance: ICO fines, enforcement notices and reputational damage
How to report a data breach within GDPR's mandatory 72-hour notification window
The role of your Data Protection Officer (DPO) and when one is required
Practical guidance for employees on handling personal data securely every day

Strengthen GDPR compliance across your organisation

Build a culture of data protection with TSC's GDPR awareness training, eLearning and human risk solutions. Help every employee understand their responsibilities, reduce compliance risk and protect personal data.

View the eBook Book a demo

GDPR - FAQ

What is GDPR and who does it apply to?

GDPR (General Data Protection Regulation) is EU legislation that governs how organisations collect, store and process personal data. It applies to any organisation handling the data of EU citizens, regardless of where that organisation is based, and in the UK sits alongside the Data Protection Act 2018. Non-compliance can result in fines of up to €20 million or 4% of global annual turnover, whichever is greater.

How long do you have to report a data breach under GDPR?

Breaches involving personal or special category data that pose a risk to people's rights and freedoms must be reported to the ICO within 72 hours of discovery. The ICO receives an average of 1,276 data breach reports every month, so employees need to recognise and escalate a suspected breach immediately rather than waiting to be sure.

What is a Subject Access Request (SAR)?

A subject access request lets an individual ask an organisation for a free copy of the personal data it holds about them. Under GDPR, organisations must respond within 30 days, and individuals also have the right to have inaccurate data corrected or erased entirely - often called the "right to be forgotten".

Related pages

Human Risk Platform
Products & Services