Compliance shouldn't require a law degree.
Fines reach €20 million or 4% of worldwide turnover — yet most GDPR resources are written by lawyers, for lawyers. This book takes the other road.
Without a clear guide
- You ask for consent "just to be safe" — then someone withdraws it and your legal basis collapses.
- Marketing and tracking get bundled into your terms of service, where the EDPB says they cannot live.
- A breach hits and nobody knows the 72-hour clock already started ticking.
- Your privacy notice says "we may share data with partners for various purposes" — which tells regulators you don't know either.
- You buy tools before doing a gap analysis — the most common and most expensive compliance mistake.
After reading GDPR Made Simple
- You can name the one correct lawful basis for every processing purpose — and defend it.
- You know exactly what "objectively necessary for a contract" covers, straight from EDPB Guidelines 2/2019.
- You have a rehearsed breach-response playbook: assess, notify within 72 hours, warn, document.
- Your privacy notice maps every purpose to a basis, a retention period, and its recipients — in plain words.
- You follow the proven order: gap analysis → prioritized plan → policies → training → audits.
Written for the people who actually do the work.
Not a legal textbook. A working manual for the four roles the GDPR lands on hardest.
Business owners
Make your organization compliant without hiring a law firm for every question — and know when you genuinely do need a lawyer.
Developers & product teams
Privacy by design and by default, explained as engineering requirements: schema-level minimization, retention built into the software, consent that actually works.
Marketing teams
Mailing lists, cookies, analytics, and advertising — what needs consent, what can rest on legitimate interests, and where the absolute right to object applies.
Aspiring DPOs
A full chapter on professional DPO certification: the three exam domains, the open-book format, and how every part of this book maps to them.
Six parts. Twenty-two chapters. One system.
Each part builds on the last — read it cover to cover, or jump straight to the chapter you need. Every chapter ends with its essentials in one place.
- What the GDPR is and why it matters
- The vocabulary of data protection
- Who must comply: material & territorial scope
- The European data protection ecosystem
- The seven principles (Art. 5)
- The six lawful bases (Art. 6)
- Deep dive: contractual necessity for online services
- Special categories of data (Art. 9)
- The rights of data subjects (Arts. 12–22)
- Transparency & privacy notices
- Controllers, processors & joint controllers
- The Data Protection Officer
- Records of processing activities (Art. 30)
- The DPIA (Art. 35)
- Data protection by design & by default
- Technical & organizational measures
- Personal data breaches: the 72-hour playbook
- Transferring data outside the EU/EEA
- The gap analysis: knowing where you stand
- Policies, training & awareness
- Monitoring, audits & continual improvement
- Becoming a certified DPO: exam domains, format & preparation
- Glossary of 25+ key terms
- The GDPR Essentials Checklist
See the plain-language difference.
From Chapter 7 — the deep dive into EDPB Guidelines 2/2019 that most online businesses have never read, and almost all of them violate.
The classic example: home delivery vs. pick-up point
A customer buys a product online, pays by card, and asks for home delivery. Processing the card details for payment and the home address for delivery is objectively necessary to perform the sales contract — Article 6(1)(b) applies.
But if the same customer chooses delivery to a pick-up point, processing their home address is no longer necessary. The retailer must stop using the address or find a different lawful basis for it.
And if the retailer wants to build a profile of the customer's tastes and lifestyle from their browsing, that profiling is not necessary to complete the purchase — even if the contract mentions it. A different basis is required.
Built to be used, not just read.
Worked, real-world examples
The online retailer, the survey app breach, the fitness app storing heart-rate data, the subscription that ends — every abstract rule is shown in a concrete scenario.
The 72-hour breach playbook
What counts as a breach (it's not just hacks), when you must notify the authority, when you must warn the people affected, and what to document either way.
Sourced, not opinionated
Everything is grounded in the official GDPR text and EDPB guidance, with the exact article cited — so you can always verify the source yourself.
A compliance roadmap
Part V walks the proven order: gap analysis, maturity scoring, policy, training, audits, and the management review loop that keeps it alive.
DPO exam preparation
The certification chapter maps the book to the three exam competency domains and explains the open-book, scenario-based format — plus how to prepare for it.
The Essentials Checklist
A closing checklist that tests any organization — or any single project — against the essentials of all six parts. Run it before your next launch.
From the maker of GDPRGard.
One book. One price. No subscription.
Less than 20 minutes of a privacy lawyer's time — for a reference you'll use for years.
- The complete 38-page eBook (PDF, readable on any device)
- All 22 chapters across 6 parts — foundations to certification
- The full EDPB contractual-necessity deep dive (Chapter 7)
- Glossary of 25+ key terms in plain language
- The GDPR Essentials Checklist
- Free updates to the 2026 edition
The plain-language promise
If this book doesn't make the GDPR clearer than anything you've read before, email hello@gdprgard.eu within 14 days and you get every cent back. You don't even have to say why. That's how a compliance company should treat your money — and your data.
Before you ask.
What format is the eBook, and how do I get it?
It's a 38-page PDF, readable on any laptop, tablet, phone, or e-reader. You get the download link immediately after checkout, and a copy lands in your inbox so you never lose it.
How is this different from the free GDPRGard guide?
The free guide is a reference overview of the regulation. GDPR Made Simple is a complete, structured course in book form: 22 chapters that build on each other, the full deep dive into EDPB Guidelines 2/2019 on contractual necessity, an entire part on building and running a compliance program, a chapter on DPO certification, a glossary, and the GDPR Essentials Checklist.
Is this legal advice?
No — it's an educational guide, and it says so honestly. The GDPR interacts with national laws, court decisions, and the facts of each situation. For decisions with real legal consequences, consult a qualified data protection lawyer or your supervisory authority. What the book gives you is the fluency to have that conversation well.
I'm not a lawyer. Will I actually understand it?
That's the entire point of the book. It was written for business owners, developers, and marketers — every legal concept is translated into plain English, illustrated with a real scenario, and linked to its GDPR article so you can verify the source yourself.
Does it cover the UK GDPR too?
Yes — the book explains how the UK retained the regulation's substance after Brexit, how the ICO enforces it separately, and what organizations serving both markets need to watch as the two regimes gradually diverge.
Will this help me prepare for DPO certification?
Chapter 22 is dedicated to it: the three exam competency domains (and which parts of the book cover each), the 80-question open-book format, the experience requirements for the full credential, and a concrete preparation plan.
What if it's not for me?
Every purchase has a 14-day money-back guarantee. Email hello@gdprgard.eu and you get a full refund — no forms, no questions asked.
Do I get an invoice for my business?
Yes — a VAT invoice is issued automatically at checkout. Enter your company details and it's yours to expense.
Know what data you hold. Have an honest reason for it.
Master the five habits.
"Know what data you hold, have an honest reason for it, tell people the truth, keep it safe, and let it go when no longer needed. Master those five habits and the 99 articles start working for you." — from the closing chapter
Get GDPR Made Simple — €29