Skip to content

Glossary · Privacy & regulation

GDPR

Also called: General Data Protection Regulation, EU data protection law

The General Data Protection Regulation governs the processing of personal data relating to people in the EU and UK. For litigation its sharpest edges are the 72-hour breach notification clock, the need for a lawful basis before processing data for discovery, and the constraints on transferring personal data out of the EEA.

Why a US litigator runs into it

GDPR reaches processing by organisations established in the EU, and processing of data about people in the EU by organisations anywhere that offer them goods or services or monitor their behaviour. A US company with European employees, customers or subsidiaries is very often within scope for at least some of its data.

The collision with US discovery is structural rather than incidental. US procedure obliges broad production; GDPR requires a lawful basis for each processing activity, data minimisation, and transparency to the people whose data it is. Neither regime yields to the other, and the tension is managed rather than resolved.

The 72-hour clock

A controller must notify its supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it — not within 72 hours of completing the investigation.

That distinction is the thing organisations misjudge. Awareness is a lower threshold than certainty, and the regulation expressly contemplates notifying in phases as information develops. Waiting for a complete forensic picture before the first notification is a common and penalised error. Where the breach is likely to result in a high risk to individuals, they must be told too, without undue delay.

Discovery under GDPR constraints

The workable approach is procedural, and courts on both sides have grown familiar with it:

  • Process in region. Collect, filter and review inside the EEA, exporting only the material that survives relevance and privacy filtering.
  • Minimise before transfer. Aggressive culling by date, custodian and search parameters reduces the transferred set, which is both a compliance measure and a cost measure.
  • Redact or pseudonymise personal data not needed for the merits.
  • Use a protective order limiting downstream use and access.
  • Notify data subjects where required, which is frequently overlooked.

US courts assessing a foreign-law objection generally apply a comity analysis, and they respond far better to a party that has done this work and can show what it produced than to one asserting that GDPR simply forbids production. Blanket refusals rarely succeed.

Transfers out of the EEA

Transfers require an approved mechanism — an adequacy decision, standard contractual clauses with a transfer impact assessment, or a derogation. The derogation for establishing or defending legal claims exists and is genuinely available, but it is construed narrowly and is not a general licence to export a discovery set.

The overlap worth planning for

An organisation facing a single incident may owe notifications under GDPR, UK GDPR, US state statutes and sector regulators simultaneously, on different clocks and different thresholds. The deadlines do not wait for each other. Knowing in advance what personal data is held, where, and about whose residents is what makes that analysis fast — and most organisations discover during the incident that they cannot answer it.

From our work

Dealing with gdpr in a live matter?

Our examiners and testifying experts work these questions for a living. Tell us what you're facing.

Reviewed by Law & Forensics. See our editorial standards.