The GDPR basics
Understand the data, the principles and who is responsible.
GDPR overview
General Data Protection Regulation
- GDPR sets rules for the use of personal data and protects people’s rights.
- EU GDPR and UK GDPR are related but separate legal regimes.
- The rules can apply to businesses outside Europe serving people there.
- Everyone handling personal data contributes to compliance.
Further context & references
EU GDPR and UK GDPR are separate legal regimes. The applicable rules depend on the organisation, the people whose data it uses and the processing involved.
Personal data in everyday work
Personal data
- Customer names, emails and IP addresses
- Quiz answers linked to a person or session
- Merchant contacts, support tickets and exports
Processing
- Opening a submission to troubleshoot
- Sending answers to a connected integration
- Downloading, editing or deleting a CSV
Further context & references
Personal data can identify someone directly or through a combination of details. Viewing, storing, exporting, sharing and deleting personal data are all forms of processing.
GDPR principles in daily work
Lawful and transparent use
Primarily the merchant’s responsibility for quiz data
The merchant explains why it collects personal data, how it will use it and the lawful basis for doing so. Its privacy information should make clear how Lantern and enabled integrations fit into that processing. Lantern handles quiz data under the merchant’s documented instructions.
Purpose and minimisation
Primarily the merchant’s responsibility for quiz configuration
The merchant chooses the purpose of the quiz and collects only the data needed for that purpose. It also decides which integrations should receive the answers. Our team uses only the records needed for an authorised task and avoids unnecessary access, exports or copies.
Accuracy and retention
Lantern’s responsibility when handling the data
We support corrections and deletion under verified merchant instructions, follow the applicable retention rules and use approved procedures to remove or anonymise data. We avoid introducing errors when handling records. The merchant remains responsible for the accuracy and retention decisions it controls.
Security
Lantern’s responsibility for its processing
We protect personal data from loss, misuse and unauthorised access. This includes secure logins, restricted access, encryption and confidential handling. Each team member follows the company’s security procedures and promptly reports suspected incidents.
Further context & references
Data protection principles apply throughout the processing lifecycle. Controllers determine the purposes and lawful basis. Processors follow documented instructions and have their own security and other legal duties.
The merchant and Lantern have different roles
Merchant: controller
- Chooses quiz questions and purposes
- Decides what to collect and share
- Handles notices, lawful basis and customer rights
Lantern: processor
- Processes quiz data under instructions
- Operates and secures the service
- Provides controls and assistance to the merchant
App Attic Ltd also acts as a controller for its own business data.
Further context & references
A controller decides the purposes and means of processing. A processor handles personal data on the controller’s behalf. An organisation can have different roles for different processing activities.
Configuration responsibility and processor duties
The merchant decides
- Whether each question is necessary
- Its lawful basis and consent approach
- Which integrations receive answers
- Whether a data protection impact assessment is needed
Lantern’s processor duties
- Follow authorised processing instructions
- Maintain appropriate security and confidentiality
- Help the merchant fulfil individuals’ rights
- Notify the merchant of personal data breaches
- Use authorised subprocessors under written agreements
What rights can a person exercise?
People can ask what personal data is held about them, how it is used and for a copy of that data. They can ask for incorrect data to be corrected and, where the right applies, for their data to be deleted. Other rights can include restricting processing, objecting to particular uses and receiving data in a portable format.
For quiz data, the merchant leads the response as controller. Lantern helps locate, export, correct or delete records under verified instructions. A deletion request does not automatically override a legal requirement to retain data.
What does incident response mean for Lantern?
If we become aware of a personal data breach affecting a merchant’s data, we must notify that merchant without undue delay, and no later than 72 hours after awareness, and provide the information needed to support its response. Team members report suspected incidents immediately through the internal incident route or their team lead.
What is a subprocessor agreement?
A subprocessor is a provider that handles personal data on Lantern’s behalf to help deliver the service, such as Google Cloud or Tinybird. Lantern needs the merchant’s prior specific or general written authorisation to use subprocessors.
Lantern must put a written agreement in place with each subprocessor, requiring equivalent data protection obligations for the work it performs. These include limits on data use, confidentiality, security and assistance with relevant privacy obligations. Where the merchant gives general authorisation, planned provider changes require notice and an opportunity to object.
Lantern remains responsible to the merchant for its subprocessors’ processing obligations. The team must use approved providers and escalate requests to introduce a new tool or share data with a new provider.
Further context & references
Processors assist controllers with individual rights and notify them of personal data breaches without undue delay. Engaging a subprocessor requires prior specific or general written authorisation and a written contract imposing equivalent data protection obligations.
Sensitive data needs additional protection
Sensitive personal data such as health information, religious or philosophical beliefs, and information about a person’s sex life or sexual orientation receives additional protection under GDPR. These categories are known as special category data.
Misuse or disclosure can create particular risks to people, including discrimination. That is why GDPR requires additional justification and safeguards for processing this information.
The merchant is responsible for identifying an Article 6 lawful basis and a separate Article 9 condition for the special category data it chooses to collect and use through its quiz.
Marketing consent alone does not establish permission to process special category data. Lantern’s team should understand the additional sensitivity and continue to apply our confidentiality, security and processing obligations.
Further context & references
Special category data requires an Article 6 lawful basis and a separate Article 9 condition. Health information, religious or philosophical beliefs, sex life and sexual orientation fall within these protected categories.