EU Data Protection

    What is GDPR?

    The General Data Protection Regulation explained: requirements, who it applies to, and how to comply

    Reviewed: August 202610 min read
    Quick answer

    Quick answer

    The General Data Protection Regulation (GDPR) is the European Union's general data protection law. It governs how organizations process personal data and can also apply to organizations outside the EU when they offer goods or services to, or monitor the behavior of, people in the EU.

    Applicable since
    25 May 2018
    Core principles
    7, including accountability
    Maximum fine
    €20M or 4% of worldwide turnover

    Reviewed against official sources on August 11, 2026. This guide is general information, not legal advice.

    GDPR Definition

    The General Data Protection Regulation (GDPR) is the European Union's main data protection regulation. It entered into force in 2016 and has applied since May 25, 2018, creating rights for individuals and obligations for organizations that process personal data.

    GDPR replaced the 1995 Data Protection Directive and applies to all EU member states. It was designed to harmonize data privacy laws across Europe and give citizens more control over their personal information in the digital age.

    Who Does GDPR Apply To?

    GDPR can apply inside and outside the EU. Its territorial scope includes:

    • Organizations established in the EU - regardless of where data processing occurs
    • Organizations outside the EU - when they offer goods or services to people in the EU or monitor their behavior there
    • Data processors - companies that process personal data on behalf of controllers

    Example:

    A US-based SaaS company that intentionally offers its service to people in the EU may fall within GDPR's territorial scope even without an EU office. Applicability depends on the facts, not simply whether an EU visitor can reach the website.

    Key GDPR Principles

    GDPR is built on seven core principles that govern how personal data must be processed:

    Lawfulness, Fairness & Transparency

    Data must be processed legally, fairly, and in a transparent manner

    Purpose Limitation

    Data collected for specified, explicit purposes only

    Data Minimization

    Collect only data that is necessary for the intended purpose

    Accuracy

    Keep personal data accurate and up to date

    Storage Limitation

    Keep data only as long as necessary

    Integrity & Confidentiality

    Ensure appropriate security of personal data

    Accountability

    Comply with the principles and be able to demonstrate that compliance

    Data Subject Rights Under GDPR

    GDPR grants individuals eight fundamental rights regarding their personal data:

    • Right to be informed
    • Right of access
    • Right to rectification
    • Right to erasure ('right to be forgotten')
    • Right to restrict processing
    • Right to data portability
    • Right to object
    • Rights related to automated decision-making

    GDPR Requirements for Organizations

    The exact obligations depend on the processing, but common requirements include:

    1. Identify a Lawful Basis

    Every processing purpose needs a lawful basis. Consent is one of six bases, not a universal requirement. When consent is used, it must be freely given, specific, informed, and unambiguous.

    2. Provide Privacy Notice

    Clearly explain what data you collect, why, how long you keep it, and who you share it with. Must be written in plain language.

    3. Implement Security Measures

    Ensure appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or destruction.

    4. Report Data Breaches

    Notify the competent supervisory authority without undue delay and, where feasible, within 72 hours unless the breach is unlikely to risk people's rights and freedoms. Notify affected people when the breach is likely to create a high risk.

    5. Appoint DPO (if required)

    Public authorities and organizations whose core activities involve large-scale regular monitoring or large-scale processing of special-category or criminal-conviction data generally need a Data Protection Officer.

    Put the requirements into practice

    Draft the privacy disclosures your data map supports

    Answer guided questions about your data, purposes, lawful bases, vendors, retention, and user rights. Review the resulting draft against your actual practices before publishing.

    • Guided questions
    • Editable draft
    • Free to start

    GDPR Penalties

    GDPR violations can result in substantial fines:

    Tier 1 Violations

    Up to €10M or 2% of turnover

    For violations like inadequate security measures or improper data processor contracts

    Tier 2 Violations

    Up to €20M or 4% of turnover

    For serious violations like processing without consent or ignoring data subject rights

    * Whichever amount is higher. The percentage is based on total worldwide annual turnover of the preceding financial year. Supervisory authorities consider the circumstances of each case and can use other corrective powers as well as fines.

    Practical GDPR Compliance Steps

    Use these steps to structure a GDPR review. A checklist or generated policy cannot establish compliance on its own:

    1. Data audit: Identify what personal data you collect, where it's stored, and who has access
    2. Legal basis: Determine the lawful basis for processing each type of data
    3. Privacy information: Document the disclosures people must receive under Articles 13 and 14
    4. Consent mechanisms: Where consent is the chosen basis, make it specific, informed, withdrawable, and properly recorded
    5. Data subject rights: Set up processes to handle access, deletion, and portability requests
    6. Security measures: Select technical and organizational controls appropriate to the processing risk
    7. Vendor management: Assess processors and put the required data-processing terms in place
    8. Training: Educate staff on GDPR requirements and data protection best practices
    9. Documentation: Maintain records of processing activities and compliance measures

    Ready to document your practices

    Create a privacy policy draft informed by your GDPR review

    Use PolicyForge to organize the disclosures, then verify the draft against your data map, contracts, consent flows, and applicable legal requirements.

    • Free to start
    • Editable before publishing
    • Not a substitute for legal advice

    Related Articles

    What is CCPA?

    Learn about California's Consumer Privacy Act and how it compares to GDPR

    What is EU AI Act?

    Understand Europe's new AI regulation and compliance requirements

    GDPR Compliance Tool

    Review key GDPR considerations and identify policy disclosures to examine

    Blog Post

    GDPR for Small Businesses

    Essential GDPR requirements for small business owners