The EU's GDPR Explained: Scope, Rules, and Compliance Guide
Understand the EU's GDPR: who it applies to, the seven core principles, data subject rights, penalties up to 20 million EUR, and how to comply.
If your website or app touches data from anyone in Europe, the EU's GDPR almost certainly applies to you. The EU's GDPR, formally the General Data Protection Regulation (Regulation (EU) 2016/679), is the world's most influential privacy law, and it reaches far beyond Europe's borders. Organizations from California startups to Singapore SaaS companies have had to rewrite their privacy policies, redesign their cookie banners, and rethink how they handle personal data because of it.
This guide breaks down what the regulation actually requires: who it covers, the principles behind it, the rights it grants, and the practical steps to comply. It is educational content, not legal advice, so consult a qualified attorney for guidance specific to your situation.
What Is the EU's GDPR?
The EU's GDPR is a European Union regulation that governs how organizations collect, use, store, and share personal data of people in the EU. It entered into force on May 25, 2018, replacing the 1995 Data Protection Directive (95/46/EC), and it applies directly in all 27 EU member states without needing national implementing laws.
Two things made the GDPR different from everything that came before it:
- Extraterritorial scope: Under Article 3, it applies to organizations anywhere in the world that offer goods or services to people in the EU or monitor their behavior.
- Serious penalties: Article 83 authorizes fines up to 20 million EUR or 4% of global annual turnover, whichever is higher.
The regulation covers personal data, which Article 4(1) defines broadly as any information relating to an identified or identifiable natural person. That includes names and email addresses, but also IP addresses, cookie identifiers, location data, and online handles. If a piece of data can be linked back to a person, directly or indirectly, the GDPR treats it as personal data.
The GDPR distinguishes two roles. A controller decides why and how personal data is processed (for example, the company running a webshop). A processor handles data on the controller's behalf (for example, an email service provider or hosting company). Both have obligations, but controllers carry the primary compliance burden.
Who Must Comply With the EU's GDPR
The GDPR's reach surprises many business owners. Article 3 sets out three triggers:
- Establishment in the EU: Any organization with an office, branch, or subsidiary in the EU is covered for all its processing, regardless of where the data subjects live.
- Offering goods or services to people in the EU: A US online store that ships to France, accepts euros, or offers a German-language site is covered, even with no EU presence.
- Monitoring behavior of people in the EU: Using analytics, advertising trackers, or profiling on EU visitors counts as monitoring. This is how a simple blog with Google Analytics can fall in scope.
There is no small-business exemption. The GDPR applies whether you process data for two customers or two million. Some obligations scale with risk (a company under 250 employees may be exempt from full record-keeping under Article 30(5) in limited cases), but the core rules apply to everyone.
If you serve both European and Californian users, note that the GDPR and CCPA work quite differently. The GDPR vs CCPA comparison covers how the opt-in and opt-out models diverge.
The Seven Principles Behind the Regulation
Article 5 sets out seven principles that every processing activity must satisfy. Regulators cite these principles constantly in enforcement decisions, so they are worth knowing by name:
- Lawfulness, fairness, and transparency: You need a legal basis for processing, and you must tell people what you are doing in clear language.
- Purpose limitation: Collect data for specified, explicit purposes. You cannot collect emails for order confirmations and quietly repurpose them for a marketing list.
- Data minimization: Collect only what you actually need. A newsletter signup does not need a date of birth.
- Accuracy: Keep personal data accurate and up to date, and correct or delete inaccurate data.
- Storage limitation: Keep data no longer than needed for the stated purpose, which means you need defined retention periods.
- Integrity and confidentiality: Protect data with appropriate security measures such as encryption and access controls (expanded in Article 32).
- Accountability: You must be able to demonstrate compliance, not just claim it. Documentation, records, and policies are how you prove it.
Legal Bases: When Processing Is Allowed
Under Article 6(1), you may only process personal data if at least one of six legal bases applies:
- Consent (Article 6(1)(a)): The person gave a freely given, specific, informed, and unambiguous indication of agreement. Pre-ticked boxes do not qualify (Article 7 and Recital 32).
- Contract (Article 6(1)(b)): Processing is needed to perform a contract with the person, like processing a shipping address to deliver an order.
- Legal obligation (Article 6(1)(c)): The law requires it, such as retaining invoices for tax purposes.
- Vital interests (Article 6(1)(d)): Processing protects someone's life. Rare in business contexts.
- Public task (Article 6(1)(e)): Relevant mainly for public authorities.
- Legitimate interests (Article 6(1)(f)): Your genuine business interest outweighs the person's rights, documented through a balancing test. Common for fraud prevention and basic analytics, but it never covers non-essential cookies.
A frequent mistake is treating consent as the default basis for everything. Consent can be withdrawn at any time under Article 7(3), which makes it fragile. Where contract or legitimate interests genuinely fit, they are usually the better foundation. Where consent is required, notably for non-essential cookies under Article 5(3) of the ePrivacy Directive, it must be collected before the cookies fire, which is why a compliant cookie consent banner matters.
Special categories of data (health, biometrics, religion, sexual orientation, and others listed in Article 9) are prohibited from processing unless a stricter condition applies, such as explicit consent.
Data Subject Rights Under the EU's GDPR
Chapter 3 of the regulation grants individuals eight enforceable rights, and you must respond to requests within one month (Article 12(3)):
- Right to be informed (Articles 13-14): People must be told what you collect and why, which is the job of your privacy policy.
- Right of access (Article 15): People can request a copy of their data and details about how it is processed, commonly called a subject access request.
- Right to rectification (Article 16): Incorrect data must be corrected.
- Right to erasure (Article 17): Also called the right to be forgotten. People can require deletion when the data is no longer needed or consent is withdrawn.
- Right to restrict processing (Article 18): Processing can be paused while a dispute is resolved.
- Right to data portability (Article 20): People can receive their data in a machine-readable format and move it to another provider.
- Right to object (Article 21): People can object to processing based on legitimate interests, and can always object to direct marketing.
- Rights around automated decision-making (Article 22): People can contest significant decisions made solely by algorithms.
Practically, this means you need an intake channel (usually the contact details in your privacy policy), an identity verification step, and internal processes to actually find and delete a person's data across your systems. For a deeper breakdown of each right and how to handle requests, see the guide to GDPR data subject rights.
Core Compliance Obligations for Businesses
Beyond respecting rights, the GDPR imposes operational duties. The most relevant for typical websites and online businesses:
Transparency and Privacy Notices
Articles 13 and 14 require you to disclose, at the point of collection: your identity and contact details, the purposes and legal bases for processing, recipients of the data, international transfers, retention periods, and all data subject rights. A generic template copied from a random site rarely covers your actual data practices. A privacy policy generator that builds the document from what your site actually collects gets you much closer to Article 13 compliance than boilerplate.
Security and Breach Notification
Article 32 requires security appropriate to the risk, such as encryption, pseudonymization, and access controls. If a breach occurs and risks people's rights, Article 33 gives you 72 hours to notify your supervisory authority, and Article 34 requires notifying affected individuals when the risk is high.
Records and Accountability
Article 30 requires records of processing activities (a ROPA): what data you hold, why, where it flows, and how long you keep it. Article 35 requires a data protection impact assessment (DPIA) before high-risk processing like large-scale profiling.
Data Protection Officers and Representatives
Article 37 requires appointing a data protection officer if your core activities involve large-scale monitoring or large-scale special category data. Public authorities always need one. Non-EU organizations in scope generally need an EU representative under Article 27.
Privacy Policy Generator
Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.
Generate NowProcessor Contracts
Whenever a vendor processes personal data for you, Article 28 requires a written data processing agreement covering security, sub-processors, and deletion at contract end. Audit your vendor list: your email platform, analytics tool, CRM, and host all likely qualify as processors.
Enforcement and Penalties: What Violations Cost
The EU's GDPR is enforced by national supervisory authorities: the CNIL in France, the DPC in Ireland, Germany's state-level authorities, and their counterparts across the EU, coordinated by the European Data Protection Board. Fines under Article 83 come in two tiers:
| Tier | Maximum fine | Example violations |
|---|---|---|
| Lower tier | 10 million EUR or 2% of global annual turnover | Missing records, no DPIA, breach notification failures |
| Upper tier | 20 million EUR or 4% of global annual turnover | No legal basis, ignoring data subject rights, unlawful transfers |
Enforcement is not theoretical. Notable penalties include:
- Meta: 1.2 billion EUR (2023, Irish DPC) for unlawful EU-US data transfers, the largest GDPR fine to date.
- Amazon: 746 million EUR (2021, Luxembourg) over advertising consent practices.
- Google: 50 million EUR (2019, CNIL) for lack of transparency and invalid consent for ad personalization.
- H&M: 35.3 million EUR (2020, Hamburg) for unlawful employee monitoring.
Regulators also target small and mid-sized companies, typically with fines in the thousands to hundreds of thousands of euros for missing privacy notices, unlawful cookies, or ignored access requests. Beyond fines, authorities can order processing bans, and Article 82 lets individuals sue for damages.
How to Comply: A Practical Roadmap
You do not need a legal department to make meaningful progress. Work through these steps:
- Map your data. List every place you collect personal data: forms, accounts, checkout, analytics, cookies, email tools. Note what is collected, why, where it is stored, and who it is shared with.
- Assign a legal basis to each purpose. Contract for order fulfillment, legitimate interests for fraud prevention, consent for marketing cookies. Document the reasoning.
- Minimize and set retention periods. Delete fields you do not need and define how long each data category is kept.
- Publish a compliant privacy policy. Cover every Article 13 disclosure and keep it current as your tools change.
- Fix your cookie consent. Non-essential cookies must not fire before opt-in consent, and rejecting must be as easy as accepting.
- Sign DPAs with every processor. Check each vendor's data processing terms and international transfer safeguards, such as Standard Contractual Clauses for US providers.
- Prepare for rights requests and breaches. Create a simple internal procedure for the one-month response deadline and the 72-hour breach notification window.
- Review regularly. Every new marketing tool or script changes your compliance picture. This is where an automated compliance platform like TermsBox helps: its scanner detects new cookies and third-party services on your site, and for subscribers the hosted privacy and cookie policies update to reflect what the scan actually found.
The full GDPR compliance checklist expands each of these steps into concrete audit items.
Common Misconceptions About the EU's GDPR
A few persistent myths cause real compliance failures:
- "We are not in the EU, so it does not apply." False. Article 3(2) explicitly covers non-EU organizations targeting or monitoring people in the EU.
- "We only need consent." False. Consent is one of six legal bases, and often the weakest choice. Many businesses over-rely on it and then cannot process data when users withdraw.
- "A cookie banner makes us GDPR compliant." False. A banner addresses one narrow requirement. Legal bases, privacy notices, DPAs, security, and rights handling all remain.
- "GDPR bans data collection." False. It regulates collection. You can process extensive data lawfully if you are transparent, have a valid basis, and respect rights.
- "Small fines only hit big tech." False. National authorities routinely fine small companies for missing privacy policies, unlawful CCTV, and ignored access requests.
- "UK and EU rules are the same thing." Mostly but not exactly. The UK GDPR mirrors the EU regulation but is enforced separately by the ICO, so businesses serving both markets answer to two regimes.
Frequently Asked Questions
Does the EU's GDPR apply to companies outside the EU?
Yes. Under Article 3, the GDPR applies to any organization that offers goods or services to people in the EU or monitors their behavior, regardless of where the organization is based. A US e-commerce store selling to German customers must comply just like a company headquartered in Paris.
What counts as personal data under the EU's GDPR?
Article 4(1) defines personal data as any information relating to an identified or identifiable person. This includes obvious identifiers like names and email addresses, but also IP addresses, cookie IDs, device identifiers, and location data. Special categories like health and biometric data get extra protection under Article 9.
What are the maximum fines under the EU's GDPR?
Article 83 sets two tiers. Serious violations, such as processing without a legal basis or ignoring data subject rights, carry fines up to 20 million EUR or 4% of global annual turnover, whichever is higher. Lesser violations carry fines up to 10 million EUR or 2% of turnover.
Do I need consent for everything under GDPR?
No. Consent is only one of six legal bases in Article 6(1). You can also process data to perform a contract, meet a legal obligation, protect vital interests, perform a public task, or pursue legitimate interests. Consent is required for non-essential cookies and most marketing, but relying on it for everything is a common mistake.
Does a small business have to comply with the GDPR?
Yes. The GDPR has no revenue or size threshold, so a one-person blog collecting email addresses from EU visitors is covered. Small organizations get limited relief, such as an exemption from record-keeping under Article 30(5) for companies under 250 employees in some cases, but the core obligations still apply.
Is the UK still covered by the EU's GDPR?
Not directly. After Brexit, the UK adopted its own UK GDPR alongside the Data Protection Act 2018, enforced by the ICO. The rules are nearly identical, but if you serve both EU and UK users you technically fall under two parallel regimes and two sets of regulators.