GDPR Compliance concerns how an organization processes personal data. Reader questions prompted my series about the database controls that can help.

GDPR has applied since May 25, 2018. My study covered its 99 articles across 11 chapters. I then focused on topics relevant to data professionals. The mapping below supports discussion with the organization’s privacy and security owners.
| Article | Topic | SQL Server contribution and limit |
|---|---|---|
| 25 | Data protection by design and default | Least-privilege permissions, authentication and data minimization support the application design. Masking alone is not an access-control boundary. |
| 30 | Records of processing activities | SQL Audit can provide technical evidence; it does not replace the organization’s record of purposes, categories, recipients and retention. |
| 32 | Security of processing | Encryption, access controls, resilient availability and tested restore processes can be parts of risk-appropriate measures. |
| 33 | Breach notification | Detection and audit evidence support an incident process; a database alert does not itself notify the supervisory authority. |
| 35 | Impact assessment | A DPIA is an assessment and documented process where required. Temporal tables or an audit configuration are not a DPIA by themselves. |
Identify personal data, purposes, legal basis, access, transfers and retention across the application and its copies. Erasure rights have conditions and exceptions. They don’t require immediate deletion of every trace, including legally required records. Backups and restores need a policy for handling requests.
Authentication, permissions, row-level security, TLS, TDE, Always Encrypted, auditing and recovery features serve different purposes. Their deployment requirements also differ. Select them for the specific threat and data flow. Test behavior and performance rather than treating features as a compliance certificate.
My Jump Start discussion covered practical SQL Server features, backup strategy, performance impact and next steps. A technical consultation can support that work. The legal assessment remains with the appropriate organizational owners.
Reference: European Commission guidance for organizations.
Reference: Conditions for individual rights.
Related reading
A database security feature is not proof of GDPR compliance, it is one control within a wider organizational assessment.
Published by Pinal Dave on SQLAuthority. More of my work at pinaldave.com.
Discover more from SQL Authority with Pinal Dave
Subscribe to get the latest posts sent to your email.




