The goal of the presentation is to have a quick walkthrough for security requirements when developing and running a solution for internet treatment, that could be of help to both developers and administrators of such services and secondarily, to summarize the most important changes that will arise with the General Data Protection Regulation (GDPR) from the European Parliament, the Council of the European Union and the European Commission that comes into effect from 25 May 2018. Methods: We will first list the general features related to security in an internet treatment platform, from both the physical and software aspect, with details for some of them and examples on how to implement these features. In the second part of the presentation we will tackle the changes that are coming with the enforcement of GDPR, including responsibility, sanctions, patient rights etc. and what is needed to adapt our current solutions to the new regulations. Conclusions: Security is an important aspect of all services for internet treatment, that usually requires a lot of allocated resources, both of technical and decisional nature and the involved actors must keep themselves updated with the latest requirements and laws. The introduction of GDPR brings some updates that find some of the internet actors well prepared and only needing little accommodation to the new regulations, whilst other actors will need to invest comprehensive resources to comply with the new requirements.