GDPR
In Short
The General Data Protection Regulation governs the processing of personal data of people in the European Union. It requires a lawful basis for every processing activity, grants individuals enforceable rights over their data, and applies to organizations outside the EU that process EU residents' data.
Definition
GDPR is built on seven principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Accountability is the one that changes daily practice, because it requires an organization to be able to demonstrate compliance rather than merely assert it.
Every processing activity needs a lawful basis — consent, contract, legal obligation, vital interests, public task, or legitimate interests. Consent is only one option and often the weakest in an employment setting, where the power imbalance makes freely given consent difficult to establish. Contract and legitimate interests are more commonly appropriate for workforce processing.
The controller determines why and how data is processed; the processor acts on the controller's instructions. The distinction drives obligations, and a SaaS vendor is typically a processor for customer data while remaining a controller for its own.
Data subject rights include access, rectification, erasure, restriction, portability, and objection, generally answerable within one month. Special category data — health, ethnicity, biometrics, union membership — requires an additional condition beyond the lawful basis.
Why It Matters
For workforce systems the practical consequences are concrete: purpose limitation constrains reuse of recruitment data for unrelated programs, storage limitation requires defined retention, and access rights require the ability to locate everything held about a specific person.
Cross-border transfer is the other recurring issue. Moving personal data outside the EU requires a valid transfer mechanism, which makes data location a design constraint rather than an operational detail.
How QueryTek Uses It
QueryTek applies data minimisation, tenant-scoped access, and bounded documented retention so customers can meet controller obligations. QueryTek acts as processor for customer data under the customer agreement. This is evaluation literacy, not legal advice.
Related Terms