What is GDPR?
The General Data Protection Regulation explained: requirements, who it applies to, and how to comply
Quick answer
The General Data Protection Regulation (GDPR) is the European Union's general data protection law. It governs how organizations process personal data and can also apply to organizations outside the EU when they offer goods or services to, or monitor the behavior of, people in the EU.
- Applicable since
- 25 May 2018
- Core principles
- 7, including accountability
- Maximum fine
- €20M or 4% of worldwide turnover
Reviewed against official sources on August 11, 2026. This guide is general information, not legal advice.
GDPR Definition
The General Data Protection Regulation (GDPR) is the European Union's main data protection regulation. It entered into force in 2016 and has applied since May 25, 2018, creating rights for individuals and obligations for organizations that process personal data.
GDPR replaced the 1995 Data Protection Directive and applies to all EU member states. It was designed to harmonize data privacy laws across Europe and give citizens more control over their personal information in the digital age.
Who Does GDPR Apply To?
GDPR can apply inside and outside the EU. Its territorial scope includes:
- Organizations established in the EU - regardless of where data processing occurs
- Organizations outside the EU - when they offer goods or services to people in the EU or monitor their behavior there
- Data processors - companies that process personal data on behalf of controllers
Example:
A US-based SaaS company that intentionally offers its service to people in the EU may fall within GDPR's territorial scope even without an EU office. Applicability depends on the facts, not simply whether an EU visitor can reach the website.
Key GDPR Principles
GDPR is built on seven core principles that govern how personal data must be processed:
Lawfulness, Fairness & Transparency
Data must be processed legally, fairly, and in a transparent manner
Purpose Limitation
Data collected for specified, explicit purposes only
Data Minimization
Collect only data that is necessary for the intended purpose
Accuracy
Keep personal data accurate and up to date
Storage Limitation
Keep data only as long as necessary
Integrity & Confidentiality
Ensure appropriate security of personal data
Accountability
Comply with the principles and be able to demonstrate that compliance
Data Subject Rights Under GDPR
GDPR grants individuals eight fundamental rights regarding their personal data:
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure ('right to be forgotten')
- Right to restrict processing
- Right to data portability
- Right to object
- Rights related to automated decision-making
GDPR Requirements for Organizations
The exact obligations depend on the processing, but common requirements include:
1. Identify a Lawful Basis
Every processing purpose needs a lawful basis. Consent is one of six bases, not a universal requirement. When consent is used, it must be freely given, specific, informed, and unambiguous.
2. Provide Privacy Notice
Clearly explain what data you collect, why, how long you keep it, and who you share it with. Must be written in plain language.
3. Implement Security Measures
Ensure appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or destruction.
4. Report Data Breaches
Notify the competent supervisory authority without undue delay and, where feasible, within 72 hours unless the breach is unlikely to risk people's rights and freedoms. Notify affected people when the breach is likely to create a high risk.
5. Appoint DPO (if required)
Public authorities and organizations whose core activities involve large-scale regular monitoring or large-scale processing of special-category or criminal-conviction data generally need a Data Protection Officer.
Put the requirements into practice
Draft the privacy disclosures your data map supports
Answer guided questions about your data, purposes, lawful bases, vendors, retention, and user rights. Review the resulting draft against your actual practices before publishing.
- Guided questions
- Editable draft
- Free to start
GDPR Penalties
GDPR violations can result in substantial fines:
Tier 1 Violations
Up to €10M or 2% of turnover
For violations like inadequate security measures or improper data processor contracts
Tier 2 Violations
Up to €20M or 4% of turnover
For serious violations like processing without consent or ignoring data subject rights
* Whichever amount is higher. The percentage is based on total worldwide annual turnover of the preceding financial year. Supervisory authorities consider the circumstances of each case and can use other corrective powers as well as fines.
Practical GDPR Compliance Steps
Use these steps to structure a GDPR review. A checklist or generated policy cannot establish compliance on its own:
- Data audit: Identify what personal data you collect, where it's stored, and who has access
- Legal basis: Determine the lawful basis for processing each type of data
- Privacy information: Document the disclosures people must receive under Articles 13 and 14
- Consent mechanisms: Where consent is the chosen basis, make it specific, informed, withdrawable, and properly recorded
- Data subject rights: Set up processes to handle access, deletion, and portability requests
- Security measures: Select technical and organizational controls appropriate to the processing risk
- Vendor management: Assess processors and put the required data-processing terms in place
- Training: Educate staff on GDPR requirements and data protection best practices
- Documentation: Maintain records of processing activities and compliance measures
Ready to document your practices
Create a privacy policy draft informed by your GDPR review
Use PolicyForge to organize the disclosures, then verify the draft against your data map, contracts, consent flows, and applicable legal requirements.
- Free to start
- Editable before publishing
- Not a substitute for legal advice
Related Articles
What is CCPA?
Learn about California's Consumer Privacy Act and how it compares to GDPR
What is EU AI Act?
Understand Europe's new AI regulation and compliance requirements
GDPR Compliance Tool
Review key GDPR considerations and identify policy disclosures to examine
GDPR for Small Businesses
Essential GDPR requirements for small business owners