We want LI to be one of the friendliest places on the internet, where lawyers and law students help each other with their career related queries and occasionally discuss other stuff that might affect their lives too. In other words:
1. Be kind, respectful and helpful to each other.
2. Be bona fide, truthful, genuine and curious.
3. Assume the best intention of others.
Therefore, in using the site, you must agree to do your best to uphold these community guidelines.
Note that what you find here is written and moderated by anonymous people on the internet.
Therefore everything you read here is very likely unverified, rumour, speculation and/or downright false.
In continuing to read anything here, you must therefore agree not to take anything you read here as factual and that you will exercise due caution, diligence and common sense before acting on any information you may come across here.
You also agree to report any inaccurate or malicious comments with the buttons. Moderators take action within 24 hours, as required and appropriate under law.
Our full terms and conditions apply too.
Do you solemnly agree to all of the above?
It protects
1. Personal Data
GDPR protects personal data, meaning any information that can directly or indirectly identify a person.
Examples:
Basic identity info: name, address, ID numbers
Online data: IP addresses, cookies, location data, device IDs
Sensitive data: health information, genetics, biometrics, political opinions, religious beliefs, sexual orientation
🔹 2. Rights of Individuals (Data Subjects)
It gives people extensive rights over their data:
Right to be Informed – to know when and how their data is collected and used.
Right of Access – to request and receive a copy of their data.
Right to Rectification – to correct inaccurate or incomplete data.
Right to Erasure ("Right to be Forgotten") – to have data deleted when it’s no longer needed or consent is withdrawn.
Right to Restrict Processing – to limit how data is used in certain situations.
Right to Data Portability – to obtain data in a structured, machine-readable format and transfer it to another service.
Right to Object – to refuse processing for marketing, profiling, or research.
Rights on Automated Decision-Making & Profiling – protection from decisions made solely by algorithms (e.g., loan rejections).
3. Obligations for Organizations (Data Controllers & Processors)
GDPR requires businesses and organizations that handle EU citizens’ data to:
Collect data only for specific, explicit, and legitimate purposes.
Use the minimum data necessary (“data minimization”).
Ensure data is accurate and up to date.
Store data only for as long as necessary (“storage limitation”).
Apply strong security measures to protect data.
Obtain clear, informed, and unambiguous consent.
Notify authorities and users of data breaches within 72 hours.
Appoint a Data Protection Officer (DPO) in some cases.
4. Cross-Border Data Transfers
Data leaving the EU can only go to countries with adequate protection or under strict safeguards (e.g., Standard Contractual Clauses).
In comparison. How does India's Digital data protection act fare ?