GDPR Compliance Explained: What It Means for the Platform

The General Data Protection Regulation (GDPR) is a European Union data protection law that defines how personal data must be collected, stored, processed, and deleted for individuals in the EU. This article explains what GDPR is, how it affects your RapidPro workspace, and the key rights it provides to individuals.

Quick Setup Checklist

Use this checklist to understand GDPR basics and identify the RapidPro features that support common GDPR requests.

  1. Understand what GDPR covers and why it matters.
  2. Review the key rights GDPR gives to individuals (erasure, access, portability, objection).
  3. Use RapidPro features that support GDPR-aligned workflows (exports, deletion, workspace deletion).
  4. Troubleshoot common GDPR-related requests (delete a contact, export data, hosting questions).
1
What GDPR is

The General Data Protection Regulation (GDPR) is a European Union data protection law that came into effect on May 25, 2018. It establishes how personal data must be collected, stored, processed, and deleted for individuals in the EU.

GDPR was adopted to strengthen privacy rights and create consistent data protection standards across EU member states. Because GDPR applies broadly and includes strict obligations, many online services updated their privacy policies and data-handling processes when it took effect.

2
How GDPR helps individuals

GDPR grants specific rights to individuals whose personal data is processed, including:

  • Right to erasure: request permanent deletion of personal data
  • Right of access: request access to personal data held about them
  • Right to data portability: request an export of personal data in a machine-readable format
  • Right to object: object to certain uses of personal data

These rights apply to personal data stored by any organization that processes data for EU residents.

3
How GDPR affects your RapidPro workspace

To align with GDPR principles, RapidPro includes protections and features designed to support common privacy and compliance workflows, such as:

  • Shortened data retention for live message data
  • Downloadable archives in machine-readable formats to support data portability
  • The ability to permanently delete individual contact records
  • The option to request full workspace deletion
[CAPTURE: Account or data export interface showing data download options.]
4
If you are not in the EU

While GDPR is an EU regulation, many organizations apply GDPR-inspired standards globally. This means that even if your workspace or contacts are outside the EU, you may still benefit from improved data protection practices and privacy controls.

If you’re unsure how GDPR applies to your specific use case or workspace configuration, contact support using the widget in the bottom-right corner of your browser.

Common Issues & Fixes

I need to delete a contact permanently

Explanation: GDPR supports the right to erasure.

Fix: Use RapidPro’s contact deletion features to permanently remove the contact record.

I want a copy of my data

Explanation: GDPR supports data portability.

Fix: Use the export tools available in your workspace to download archived data.

I’m unsure where my data is stored

Explanation: Hosting and storage details are documented separately.

Fix: Review the Data Security and Hosting: AWS Infrastructure, FIPS Compliance, and Encryption article for infrastructure details.