GDPR
The GDPR (General Data Protection Regulation) is the EU-wide regulation that governs how personal data is handled. It sets out the legal basis, purpose and retention period under which companies may process data about customers, suppliers and employees.
The GDPR (General Data Protection Regulation, German DSGVO) is the central European regulation for protecting personal data. It has applied directly in all EU member states since 25 May 2018 and governs the conditions under which companies and public authorities may process data relating to an identifiable natural person – names, addresses, bank details, order histories or location data. At its core lies a prohibition subject to authorisation: processing personal data is generally forbidden unless a legal basis exists, such as consent, a contract or a statutory obligation.
The GDPR affects virtually every company that offers goods or services to people in the EU – regardless of where the company itself is based (the marketplace principle). It is especially relevant for ERP and inventory management systems, because large volumes of personal data from sales, purchasing and human resources converge there. Breaches can be penalised with fines of up to 20 million euros or 4 percent of worldwide annual turnover – whichever is higher.
At a glance
- EU-wide regulation, directly applicable since 25 May 2018
- Prohibition subject to authorisation: processing only with a legal basis
- Six principles including purpose limitation, data minimisation, storage limitation
- Extensive data-subject rights: access, rectification, erasure, data portability
- Fines up to EUR 20 million or 4% of worldwide annual turnover
What the GDPR governs and who it applies to
The GDPR protects personal data – any information that can be attributed to an identified or identifiable natural person. This includes obvious details such as name and email address, but also customer numbers, IP addresses or purchasing behaviour, provided it can be linked to a person. Purely corporate data (for example a company billing address without a contact person) is not covered; but as soon as a specific individual stands behind it, the regulation applies.
The territorial scope is broad. Under the marketplace principle, the GDPR applies to all companies that offer goods or services to people in the EU or monitor their behaviour – including providers from third countries. An online retailer based outside the EU that delivers to German customers is therefore just as subject to the GDPR as a purely domestic mid-sized business.
The principles of data processing
Article 5 of the GDPR sets out six central principles against which every processing operation must be measured. They form the benchmark for whether a data process is set up lawfully – and at the same time the criteria that supervisory authorities examine.
Lawfulness, purpose limitation and data minimisation
Data may only be processed on one of the legal bases named in Article 6 – most often contract performance, consent, a statutory obligation or legitimate interest. The principle of purpose limitation requires that data be used only for the defined purpose: an address collected for order processing may not simply be used for advertising. Data minimisation means collecting only the data that is actually necessary for the purpose.
Storage limitation and accountability
Personal data must be erased as soon as the purpose no longer applies and no statutory retention obligation remains. A tension arises here: commercial and tax retention obligations (for example under the German Commercial Code and Fiscal Code) require invoices and accounting documents to be kept for up to ten years – only afterwards does the erasure obligation take effect. Finally, accountability obliges companies to be able to demonstrate compliance with all principles, for instance through a record of processing activities.
Data-subject rights and obligations of companies
The GDPR equips data subjects with enforceable rights. These include the right of access to the data stored, the right to rectification of incorrect entries, the right to erasure ("right to be forgotten"), the right to restriction of processing, the right to data portability in a common format, and the right to object to certain processing. As a rule, a company must respond to a request within one month.
Set against these are concrete obligations. Companies must maintain a record of processing activities, implement technical and organisational measures (TOM) to protect the data, and generally report data breaches to the supervisory authority within 72 hours. Where processing is carried out by an external service provider – for example a cloud ERP provider or a fulfilment partner – a data processing agreement (DPA) under Article 28 must be concluded. Above certain thresholds, a data protection officer must also be appointed.
GDPR in the ERP system
An ERP system is one of the largest collection points for personal data in a company: the customer master, supplier contacts, order histories and often personnel data all reside here. This makes the ERP the central stage for GDPR implementation. In practice this means the regulation must be reflected in the system’s functions and processes – from collection through to erasure.
Key requirements are an authorisation concept (only authorised employees see personal data), audit-proof logging of access, and functions to handle access and erasure requests efficiently. Because tax retention obligations and the GDPR erasure obligation can collide, many systems work with an erasure concept based on blocking and anonymisation: documents are retained for the statutory period, but personal attributes are blocked or pseudonymised. With cloud ERP, the question of server location is added – processing outside the EU requires additional safeguards (such as standard contractual clauses).
Distinguishing GDPR, BDSG, GoBD and data security
In Germany the GDPR is supplemented by the Federal Data Protection Act (BDSG), which fills in national opening clauses – for example details on the data protection officer or on employee data protection. The GDPR takes precedence; the BDSG only regulates what the regulation expressly leaves to the member states.
The GDPR must be clearly distinguished from the GoBD (principles for proper bookkeeping): the GoBD aim at the traceability and immutability of tax-relevant data, while the GDPR aims at protecting personal data. The two can overlap but pursue different purposes. Likewise, data protection is not the same as data security: data security (encryption, access control, backups) is a means of implementing data protection, but not identical to it. The GDPR demands data security as one of several obligations.
DACH specifics
Within the DACH region the GDPR applies directly in Germany and Austria, each supplemented by national law – in Austria through the Data Protection Act (DSG). One difference lies in the supervisory structure: in Germany the data protection authorities are organised federally (the federal government and 16 states), while Austria has a single central data protection authority.
As a non-EU country, Switzerland is not bound by the GDPR, but with its revised Data Protection Act (revDSG, in force since September 2023) it has established a largely equivalent level of protection. For data exchange with Switzerland the European Commission recognises an adequate level of data protection, so transfers are possible without additional safeguards. Anyone operating across borders within the DACH region should nevertheless check which national special rules apply. This article provides a general overview and does not replace legal advice in individual cases.
Example
Example: an online retailer handles an erasure request
A mid-sized online retailer receives a request from a former customer to delete their data. In the ERP system the customer is stored with an address, order history and several paid invoices. Full erasure is not possible, because the invoices are subject to the ten-year tax retention obligation.
The retailer therefore uses the erasure concept of its system: the customer account is blocked for active processes (marketing, sales) and the contact details are anonymised, while the accounting documents remain audit-proof until the retention period expires. The operation is logged, and within one month the customer receives a response setting out which data is still retained and for what reason. In this way the GDPR erasure obligation and the tax retention obligation are reconciled in a legally compliant manner.
Frequently asked questions
Matching ERP systems
Related services
Sources
Questions about GDPR in your ERP project?
We advise vendor-neutrally – and implement it ourselves on request.