European Union · Regulation (EU) 2016/679

The GDPR, translated into things your team can actually do.

Eight years after it applied, the GDPR is still the benchmark much of the world copies, and still the regime organisations most often believe they have finished. This guide covers territorial scope and representatives, the seven principles, all six lawful bases and the Article 9 conditions, every one of the eight rights with the deadlines that attach to them, DPIAs and records, international transfers after Schrems II, cookies and ePrivacy, the 72-hour breach rule, and what the supervisory authorities have actually been fining organisations for.

Reviewed against the Regulation and current EDPB guidance on . Written by Shambhu Kumar, Vedhacon.

Articles 2, 3 and 4

Who it applies to, and in which role

Two questions decide almost everything that follows: does the Regulation reach you, and are you a controller or a processor.

Establishment in the Union

Article 3(1). If you process personal data in the context of the activities of an establishment in the EU, the GDPR applies, wherever in the world the processing itself happens. A branch, a subsidiary, even a single representative with real and effective activity can be enough, as the Court of Justice held in Weltimmo.

The targeting test

Article 3(2). No EU establishment is needed if you offer goods or services to people in the EU, paid or free, or monitor their behaviour there. Pricing in euro, translating your site, or running analytics and ad tracking on EU visitors will each point that way, as EDPB Guidelines 3/2018 set out.

Controller and processor

The controller decides the purposes and means. The processor acts only on documented instructions. A processor that starts deciding purposes becomes a controller for that processing, with every duty that follows. Joint controllers must agree their respective responsibilities in a transparent arrangement under Article 26.

The Article 27 representative

Caught by the targeting test and not established in the Union? You must designate, in writing, a representative in a member state where your data subjects are. They are the point of contact for individuals and authorities, and the requirement is widely under-observed by non-EU businesses. Narrow exemptions exist for occasional, low-risk processing.

What counts as personal data

Any information relating to an identified or identifiable living person. That reaches far wider than most teams assume: IP addresses, cookie identifiers, device IDs, location traces and pseudonymised records all qualify. Only genuinely anonymous data falls outside, and true anonymisation is harder than it sounds.

Accountability

Article 5(2) is the hinge of the whole Regulation. It is not enough to comply. You must be able to demonstrate compliance, which is why records, assessments, policies and logs are not bureaucracy here, they are the obligation itself.

A note on the EEA, and on what sits outside it. The GDPR applies across the 27 member states and, through the EEA Agreement, in Norway, Iceland and Liechtenstein. Switzerland is not in the EEA and runs its own revised FADP. The United Kingdom now applies the UK GDPR. Article 2 also carves out household activity, and law enforcement processing falls under the separate Law Enforcement Directive rather than this Regulation. If your footprint includes any of those, treat them as separate regimes that happen to look familiar.
Article 5

The seven principles

Every fine ever issued traces back to one of these. They are not aspirations, they are the enforceable core.

Lawfulness, fairness and transparencyArt 5(1)(a)

A valid basis, a use the individual would not find surprising or detrimental, and an honest account of what you are doing. Fairness is the limb most often forgotten, and the one regulators increasingly reach for in dark-pattern cases.

Purpose limitationArt 5(1)(b)

Collected for specified, explicit and legitimate purposes, and not further processed in a way incompatible with them. Reusing customer data to train a model is the compatibility question of the decade.

Data minimisationArt 5(1)(c)

Adequate, relevant and limited to what is necessary. The practical test is field by field: if the purpose survives without the field, the field should not be collected.

AccuracyArt 5(1)(d)

Accurate and, where necessary, kept up to date, with inaccurate data erased or rectified without delay. This bites hardest where data drives an automated decision about someone.

Storage limitationArt 5(1)(e)

Kept in identifiable form no longer than necessary. In practice this means a retention schedule that is actually enforced by the systems, not a policy document that describes deletion nobody performs.

Integrity and confidentialityArt 5(1)(f)

Appropriate technical and organisational security against unauthorised processing, accidental loss, destruction or damage. Article 32 then names the measures worth considering, including encryption and pseudonymisation.

AccountabilityArt 5(2)

Responsible for, and able to demonstrate compliance with, all six above. When an authority opens a file, this is the principle that decides how the conversation goes.

Article 6

The six lawful bases

Map yours to controls

You need exactly one, chosen before processing begins and recorded. Switching basis later, particularly from consent to legitimate interests once consent is withdrawn, is not permitted.

ConsentArt 6(1)(a)

Freely given, specific, informed and unambiguous, by a clear affirmative act, and as easy to withdraw as to give. Not freely given where there is a clear imbalance, which is why it rarely works for employees, or where a service is conditioned on consent that is not necessary for it.

ContractArt 6(1)(b)

Necessary to perform a contract with the individual, or to take pre-contractual steps at their request. Necessary means objectively indispensable to that contract. The EDPB has made clear it does not stretch to behavioural advertising simply because the terms of service say so.

Legal obligationArt 6(1)(c)

Necessary to comply with a legal obligation under Union or member state law. A foreign law alone will not do, which is a recurring difficulty for global groups responding to non-EU authorities.

Vital interestsArt 6(1)(d)

Necessary to protect someone's life. Genuinely narrow, and intended for emergencies rather than general safety programmes.

Public taskArt 6(1)(e)

Necessary for a task carried out in the public interest or in the exercise of official authority, and laid down in law. The usual basis for public bodies, who in turn cannot rely on legitimate interests for their public tasks.

Legitimate interestsArt 6(1)(f)

The most flexible and the most misused. It requires a documented three-part test: a real and present interest, necessity, and a balance that does not override the individual's rights, weighing their reasonable expectations. Write it down before you rely on it, because you will be asked to produce it.

The most expensive mistake in this section. Treating consent as the safe default. Consent is the most fragile basis: it can be withdrawn at any moment, it must be logged, and once withdrawn you must stop. For most ordinary business processing, contract or a properly documented legitimate interests assessment is both more robust and more honest.
Articles 9 and 10

Special category data needs a second key

Processing this data is prohibited unless an Article 9(2) condition applies, in addition to an Article 6 basis. Two locks, not one.

What counts

Racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data used for identification, health, sex life and sexual orientation.

Explicit consent

A higher bar than ordinary consent. It must be an express statement, not merely an affirmative action, and it must name the special category data specifically.

Employment & social security

Permitted where authorised by Union or member state law with appropriate safeguards. This is where national divergence is widest, so check the local rule rather than the Regulation alone.

Health & public interest

Preventive or occupational medicine, medical diagnosis, health or social care, and public health, each subject to professional secrecy obligations.

Legal claims

Establishment, exercise or defence of legal claims, or courts acting in their judicial capacity.

Manifestly made public

Where the individual has manifestly made the data public themselves. Read narrowly: a post visible to a limited circle is not manifestly public.

Research & archiving

Scientific or historical research, statistics and archiving in the public interest, with the Article 89 safeguards including minimisation and pseudonymisation.

Criminal data, Article 10

Criminal convictions and offences are not special category data, but may only be processed under official authority or where authorised by law. Background screening needs a specific national footing.

The inference trap. Data becomes special category when it reveals one of these characteristics, not only when it states it. The Court of Justice confirmed in 2022 that data allowing sensitive information to be inferred is itself caught. A dietary preference, a pharmacy purchase or a gym membership can each cross that line.
Chapter III, Articles 12 to 22

All eight rights, and the clock on each

One month to respond, free of charge, extendable by two months for complex requests if you tell the person inside the first month.

1. To be informedArt 13, 14

A privacy notice covering identity and contact details, purposes and lawful basis, recipients, transfers, retention, the rights themselves, and the right to complain to a supervisory authority. Where data came from a third party rather than the individual, Article 14 adds the source and a one-month deadline to tell them.

2. Of accessArt 15

A copy of the personal data plus the surrounding information. The single most common request, and the single most common source of fines when mishandled. You may not demand a reason, and you may not charge unless the request is manifestly unfounded or excessive.

3. To rectificationArt 16

Correction of inaccurate data and completion of incomplete data, including by a supplementary statement. Article 19 then obliges you to tell every recipient, unless that proves impossible or disproportionate.

4. To erasureArt 17

The right to be forgotten, in six defined circumstances, including where data is no longer necessary or consent is withdrawn. Not absolute: it yields to freedom of expression, legal obligations, public health, archiving and legal claims. If you made the data public, you must take reasonable steps to inform other controllers.

5. To restrictionArt 18

A pause button. Where accuracy is contested, or an objection is being considered, you may store the data but not otherwise use it. Few systems are built to hold data in this state, which is why this right is so often quietly ignored.

6. To data portabilityArt 20

A structured, commonly used, machine-readable copy, and direct transmission to another controller where technically feasible. Narrower than access: it covers only data the individual provided, processed by automated means on consent or contract.

7. To objectArt 21

Against processing based on legitimate interests or public task, where you must stop unless you show compelling legitimate grounds that override. Against direct marketing the right is absolute: you must stop immediately, with no balancing and no exception.

8. Not to be subject to automated decisionsArt 22

Where a solely automated decision, including profiling, produces legal or similarly significant effects. Permitted only for contract necessity, authorisation by law, or explicit consent, and even then you must provide human intervention, an explanation and a route to contest. The Court's SCHUFA ruling confirmed that a credit score handed to a lender can itself be the decision.

Where organisations actually lose. Not on the law, on the logistics. Requests arrive at a random inbox, sit unlogged for three weeks, and the month expires before anyone has searched the backups, the ticketing system or the ex-employee's mailbox. Build the intake, the identity check and the search map before the first request arrives, not during it.
Chapter IV

What a compliant programme actually contains

Implementation service

Records of processing

Article 30 records, for controllers and processors alike. The exemption for organisations under 250 staff is far narrower than it appears and rarely applies in practice.

Data protection by design and by default

Article 25. Protection built in at the point of design, and the most privacy-friendly setting applied by default. The default limb is the one regulators test, because it is visible from outside.

DPIAs

Article 35 where processing is likely to result in a high risk, and Article 36 prior consultation with the authority where residual risk stays high.

Security of processing

Article 32. Measures appropriate to the risk, with pseudonymisation, encryption, resilience, restoration and a process for regularly testing effectiveness named expressly.

Breach notification

Articles 33 and 34, plus an internal register of every breach including those you decide not to report, with the reasoning recorded.

Processor contracts

Article 28 terms with every processor, authorisation for sub-processors, and genuine diligence rather than a countersigned template nobody read.

Articles 37 to 39

When you need a Data Protection Officer

DPO as a service

Public authority or body

Mandatory, with the sole exception of courts acting in their judicial capacity. A single DPO may serve several public bodies where size and structure allow.

Large-scale monitoring

Where core activities require regular and systematic monitoring of individuals on a large scale. Adtech, behavioural analytics, connected devices and location services routinely qualify.

Large-scale special category

Where core activities involve special category or criminal data at scale. Healthcare, insurance and background screening sit squarely here.

Three things people get wrong about the role. First, national law can add thresholds, and Germany's headcount rule catches many organisations the Regulation alone would not. Second, the DPO must be independent, cannot be dismissed for performing the role, and must report to the highest management level, so appointing the Head of IT or the General Counsel usually creates a conflict of interest. Third, appointing a DPO voluntarily binds you to all of Articles 37 to 39 anyway.
Article 28

Every processor contract needs these terms

Not optional drafting. Article 28(3) lists them, and an authority reading your DPA will check for each one.

Required termWhat it must say
Documented instructionsThe processor acts only on the controller's documented instructions, including on transfers, unless required otherwise by law, in which case it must tell you first.
ConfidentialityEveryone authorised to process the data is bound by confidentiality, whether by contract or statute.
SecurityThe processor takes all measures required by Article 32 in its own right, not merely as an extension of yours.
Sub-processorsNo sub-processor without prior specific or general written authorisation, with notice of changes and a chance to object, and the same obligations flowed down.
Assistance with rightsThe processor helps you respond to data subject requests by appropriate technical and organisational measures.
Assistance with dutiesHelp with security, breach notification, DPIAs and prior consultation, taking account of what the processor knows and can see.
Deletion or returnAt the end of the service, delete or return all personal data at your choice, and delete existing copies unless law requires retention.
Audit and informationMake available everything needed to demonstrate compliance, and allow and contribute to audits and inspections.
Sub-processors are where the chain breaks. Your processor's processor is still processing your data, and you remain accountable for it. Ask for the list, watch the change notices, and check that the onward terms are genuinely equivalent rather than merely referenced.
Articles 35 and 36

DPIA, assessing risk before you process

Get the DPIA template

Mandatory where processing is likely to result in a high risk to individuals, and sound practice for any significant new use of personal data. Where the residual risk remains high after mitigation, Article 36 requires you to consult your supervisory authority before processing begins.

When it is required

Article 35(3) names three cases: systematic and extensive automated evaluation producing legal or similarly significant effects, large-scale special category or criminal data, and large-scale systematic monitoring of a publicly accessible area. Your own authority then publishes a list of further high-risk operations, and the WP248 nine criteria are the working test in between.

What it must contain

A systematic description of the processing and purposes including any legitimate interest, an assessment of necessity and proportionality, an assessment of the risks to rights and freedoms, and the measures envisaged to address them. The DPO's advice must be sought and recorded.

The DPIA in eight steps

1

Screen

Run the threshold test and record the outcome even when the answer is no.

2

Describe

Map the processing, data flows, purposes, systems, processors and transfers.

3

Test necessity

Lawful basis, purpose limitation, minimisation and proportionality, field by field.

4

Consult

The DPO, security, legal, and where appropriate the data subjects themselves.

5

Assess risk

Likelihood and severity of harm to people, not disruption to the business.

6

Mitigate

Minimisation, encryption, retention limits, access control, contractual terms.

7

Sign off

Record residual risk. If still high, consult the authority under Article 36.

8

Review

Revisit when the processing, the processors or the risk changes.

Article 30

RoPA, records of processing activities

Get the RoPA workbook

The first document an authority asks for, and the one that makes every other duty answerable. It is also the fastest way to discover what your organisation is actually doing with personal data, which is rarely what the policy says.

Article 30 fieldWhat it recordsControllerProcessor
Identity and contactsController, any joint controller, the representative and the DPO.YesYes
PurposesThe purposes of each processing activity.YesNo
CategoriesCategories of data subjects and of personal data, flagged where special category.YesCategories of processing only
RecipientsCategories of recipients, including processors and third countries.YesNo
TransfersThird-country transfers and the safeguard relied on, with documentation for Article 49 cases.YesYes
RetentionEnvisaged time limits for erasure of each category, where possible.YesNo
Security measuresA general description of the Article 32 technical and organisational measures.YesYes
OwnerThe named person accountable for this activity. Not required by Article 30, but see the note below.Good practiceGood practice
RoPA first, then DPIA. The RoPA tells you what you process. The DPIA tells you whether the risk is acceptable. Build the record first, then run assessments on the high-risk activities it surfaces. The last row is the one field the Regulation does not require but every mature programme keeps, because a record without a named owner never gets updated.
Chapter V, Articles 44 to 50

Sending data outside the EEA

Transfer route finder

Remote access counts. So does support from a non-EEA team, and storage in a region that merely fails over abroad. If someone outside the EEA can see the data, you have a transfer, and you need a route.

Adequacy decisionsArt 45

The simplest route. The Commission has recognised, among others, Andorra, Argentina, Canada for commercial organisations, the Faroe Islands, Guernsey, Israel, the Isle of Man, Japan, Jersey, New Zealand, the Republic of Korea, Switzerland, the United Kingdom and Uruguay. Adequacy is reviewed periodically and can be withdrawn, so do not treat it as permanent.

Standard Contractual ClausesArt 46(2)(c)

The 2021 modular SCCs, covering controller to controller, controller to processor, processor to processor and processor to controller. Choose the right module, complete the annexes properly, and pair them with a transfer impact assessment. The pre-2021 clauses are no longer valid.

Transfer impact assessmentSchrems II

Since the Court invalidated Privacy Shield in July 2020, signing SCCs is not enough on its own. You must assess whether the law and practice of the destination country, particularly government access powers, undermine the clauses, and add supplementary measures such as strong encryption with keys held in the EEA where they do.

EU-US Data Privacy FrameworkArt 45

Adopted in July 2023, it permits transfers to US organisations that self-certify to the Framework and appear on the active list. Verify certification before relying on it, keep checking that it is maintained, and keep an SCC fallback ready, because this is the third such arrangement and the previous two were annulled.

Binding Corporate RulesArt 47

For transfers inside a corporate group, approved by a lead supervisory authority through the consistency mechanism. Powerful and durable once in place, but typically a multi-year process, so worth starting only if intra-group flows are substantial and permanent.

DerogationsArt 49

Explicit consent to the specific transfer with its risks spelled out, contract necessity, important public interest, legal claims, vital interests. Read by the EDPB as genuinely exceptional: occasional, non-repetitive, limited in number. They are not a lawful architecture for routine flows.

Start with the map, not the mechanism. Most transfer problems are discovered late because nobody knew the transfer existed. Before choosing a route, list every vendor, every sub-processor, every support location and every backup region. The mechanism is the easy part once the map is honest.
ePrivacy Directive 2002/58/EC

Cookies, trackers and the banner problem

The most visible compliance surface you have, the one every visitor sees first, and the one regulators can assess without opening an investigation.

Two laws, working together

The ePrivacy Directive governs storing or reading anything on a user's device, and requires consent unless it is strictly necessary for a service the user requested. The GDPR then supplies the standard that consent must meet. Note the reach: this covers pixels, local storage, SDKs and device fingerprinting, not only cookies.

What a compliant banner does

Sets nothing but strictly necessary cookies before a choice is made. Offers reject as prominently as accept, on the first layer. Uses no pre-ticked boxes and no implied consent from scrolling. Names the purposes and the third parties. Makes withdrawal as easy as giving. And records the consent so you can prove it.

COMMON FAILURE

Accept-only banners

A prominent accept button with reject buried two clicks deeper. The most frequently penalised pattern in Europe.

COMMON FAILURE

Firing before choice

Analytics and ad tags loading on page render, while the banner is still asking. Trivial for a regulator to verify.

COMMON FAILURE

Legitimate interests for ads

Claiming legitimate interests for tracking that ePrivacy already requires consent for. The two do not substitute.

COMMON FAILURE

No withdrawal route

A banner that never returns and a policy page with no way to change your mind. Withdrawal must be as easy as consent.

And ePrivacy is a Directive, not a Regulation. That means it is implemented separately in each member state, so the detail genuinely differs: France and Germany have been the most active enforcers, and the long-promised ePrivacy Regulation has still not replaced it. Check the national rule for each market you operate in.
Articles 33 and 34

The 72-hour clock

Breach response service

To the supervisory authority

Without undue delay and, where feasible, within 72 hours of becoming aware. Unless the breach is unlikely to result in a risk to rights and freedoms. If you miss 72 hours you still notify, with reasons for the delay. Notification in stages is expressly permitted where you do not yet have all the facts.

To affected individuals

Without undue delay where the breach is likely to result in a high risk to them, in clear and plain language. Not required if the data was rendered unintelligible, such as by strong encryption, if you have since ensured the high risk will not materialise, or if it would involve disproportionate effort, in which case a public communication will do.

The internal register

Article 33(5) requires you to document every personal data breach, the facts, the effects and the remedial action, including those you decide not to report. That register is how you demonstrate the decision was reasoned rather than convenient.

Response, end to end

1

Detect

Awareness starts the clock, and a processor's awareness is imputed to you.

2

Assess

Risk to individuals, using the EDPB severity criteria. Do not let this delay notification.

3

Notify

Your lead authority within 72 hours, in stages if necessary.

4

Communicate

Affected individuals where the risk is high, in plain language.

5

Record

Register the breach, the reasoning and the remediation, reportable or not.

72 hours includes weekends. It is not three working days. A Friday evening discovery is due by Monday evening, which is precisely when the people who can authorise a notification are hardest to reach. Decide now who assesses, who signs off and who files, and rehearse it once, because nobody makes these decisions well at two in the morning.
Chapter VI, Articles 51 to 59

Find your supervisory authority

Thirty regulators across the EU and EEA. Search to find yours, and note which one is your lead authority if you operate in several.

🇦🇹AustriaDatenschutzbehörde, DSB
🇧🇪BelgiumData Protection Authority, APD / GBA
🇧🇬BulgariaCommission for Personal Data Protection
🇭🇷CroatiaAZOP
🇨🇾CyprusOffice of the Commissioner
🇨🇿CzechiaÚOOÚ
🇩🇰DenmarkDatatilsynet
🇪🇪EstoniaAndmekaitse Inspektsioon
🇫🇮FinlandData Protection Ombudsman
🇫🇷FranceCNIL
🇩🇪GermanyBfDI plus 16 state authorities
🇬🇷GreeceHellenic DPA
🇭🇺HungaryNAIH
🇮🇪IrelandData Protection Commission, DPC
🇮🇹ItalyGarante per la protezione dei dati
🇱🇻LatviaData State Inspectorate
🇱🇹LithuaniaState DP Inspectorate
🇱🇺LuxembourgCNPD
🇲🇹MaltaIDPC
🇳🇱NetherlandsAutoriteit Persoonsgegevens
🇵🇱PolandUODO
🇵🇹PortugalCNPD
🇷🇴RomaniaANSPDCP
🇸🇰SlovakiaOffice for Personal Data Protection
🇸🇮SloveniaInformation Commissioner
🇪🇸SpainAEPD
🇸🇪SwedenIMY
🇳🇴NorwayDatatilsynet, EEA
🇮🇸IcelandPersónuvernd, EEA
🇱🇮LiechtensteinDatenschutzstelle, EEA

No match. Try a country name, or an abbreviation such as CNIL, AEPD or Garante.

The one-stop shop, and its limits. If you carry out cross-border processing, the authority of your main establishment acts as lead, which gives you a single point of contact. But local authorities keep competence over purely local matters, and the EDPB can and does override a lead authority through the consistency mechanism. Choosing an establishment for a friendlier regulator is a strategy that has aged badly.
Two omissions, on purpose. Germany has a federal commissioner and sixteen state authorities, and which one supervises you depends on where you are established and whether you are public or private, so treat "Germany" as a starting point rather than an answer. And the EDPS supervises the EU institutions themselves under a separate regulation, not ordinary businesses.
Article 83

Two tiers, and what they have cost

€10m or 2%
Lower tier, Article 83(4)
Whichever is higher, of total worldwide annual turnover of the preceding financial year. Records, security, breach notification, DPIAs, data protection by design, DPO and processor obligations, and certification bodies.
€20m or 4%
Upper tier, Article 83(5)
Whichever is higher. The principles, lawful basis and conditions for consent, data subject rights, the Chapter V transfer rules, and non-compliance with an order from a supervisory authority.

Turnover is measured against the whole undertaking in the competition-law sense, not the entity that made the mistake, so a local subsidiary's error is weighed against group revenue. Beyond fines, an authority can order you to stop processing altogether, which is usually the greater commercial risk, and individuals hold a separate right to compensation under Article 82.

LARGEST TO DATE

€1.2 billion

Ireland's DPC against Meta in May 2023, for continuing EU to US transfers on SCCs after Schrems II without adequate supplementary measures.

ADVERTISING

€746 million

Luxembourg's CNPD against Amazon in 2021, concerning behavioural advertising and the basis relied on for it.

CHILDREN

€345 million

Ireland's DPC against TikTok in 2023, over default public settings on child accounts and the family pairing feature.

COOKIES

€150 million

France's CNIL against Google in 2021, because refusing cookies took more clicks than accepting them. The banner really is enforced.

How the amount is decided. Article 83(2) lists eleven factors, including the nature, gravity and duration of the infringement, whether it was intentional or negligent, action taken to mitigate the damage, the degree of responsibility having regard to Articles 25 and 32, relevant previous infringements, the degree of cooperation, the categories of data affected, and whether the infringement was self-reported. Cooperation and prompt notification measurably reduce outcomes. General information, not legal advice.
Article 4

Definitions glossary

Twenty terms that decide arguments. Search to filter.

Personal data

Any information relating to an identified or identifiable living person, directly or indirectly, including by reference to an identifier such as a name, number, location or online identifier.

Processing

Any operation performed on personal data, automated or not, from collection and storage through to consultation, disclosure and erasure. Simply holding data is processing.

Controller

The person or body that determines the purposes and means of processing, alone or jointly. Determined by fact, not by what the contract calls you.

Processor

A body that processes personal data on behalf of the controller, on documented instructions and nothing more.

Joint controllers

Two or more controllers who jointly determine purposes and means. They must agree their respective responsibilities in a transparent arrangement, the essence of which is made available to individuals.

Special category data

Racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic and biometric data for identification, health, sex life and sexual orientation.

Consent

A freely given, specific, informed and unambiguous indication of wishes, by a statement or clear affirmative action. Silence, inactivity and pre-ticked boxes do not qualify.

Personal data breach

A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Loss of availability counts, so ransomware qualifies even with no exfiltration.

Supervisory authority

The independent public authority in each member state responsible for monitoring application of the Regulation.

Lead supervisory authority

For cross-border processing, the authority of your main establishment, acting as your single point of contact under the one-stop-shop mechanism.

Main establishment

Where your central administration sits, or where the decisions about purposes and means are actually taken. Substance, not registered address.

DPIA

A data protection impact assessment, required by Article 35 where processing is likely to result in a high risk to individuals.

DPO

A Data Protection Officer, mandatory for public bodies and for large-scale monitoring or special category processing. Independent and reporting to the highest management level.

Pseudonymisation

Processing so data can no longer be attributed to a person without additional information kept separately. A safeguard, not an exit: pseudonymised data is still personal data.

Anonymisation

Irreversible de-identification such that no one can re-identify the person by any means reasonably likely to be used. Genuinely anonymous data falls outside the GDPR entirely, but the bar is high.

Profiling

Any automated processing that evaluates personal aspects of a person, such as performance at work, economic situation, health, preferences, reliability, behaviour, location or movements.

Representative

A person in the Union designated in writing by a non-EU controller or processor under Article 27, to act as the addressee for authorities and individuals.

Third country

Any country outside the EEA. Since 2021 that includes the United Kingdom, which currently benefits from an adequacy decision.

EDPB

The European Data Protection Board, composed of the national authorities. It issues guidelines and resolves disputes between authorities through the consistency mechanism.

Recitals

The 173 numbered paragraphs before the articles. Not binding in themselves, but they explain intent and are routinely relied on by authorities and courts.

No matching term. Try consent, controller, breach, profiling or transfer.

Questions we are asked most

GDPR, answered directly

Does the GDPR apply to my company if we are not in the EU?
Very possibly. Article 3(2) reaches you if you offer goods or services to people in the EU, whether or not you charge them, or if you monitor their behaviour, which covers most analytics and advertising tracking. Establishment in Europe is not required. If you are caught this way, you must also appoint a written representative in the Union under Article 27, an obligation a great many non-EU businesses have simply never actioned.
Is consent always the safest lawful basis?
No, and treating it as such is the most common structural mistake we see. Consent can be withdrawn at any moment, must be recorded, and cannot be relied upon where there is an imbalance of power, which rules it out for most employee data. For ordinary commercial processing, contract necessity or a properly documented legitimate interests assessment is usually both more durable and more honest about what is actually happening.
Can we charge for a subject access request, or refuse one?
Ordinarily no on both counts. The first copy is free and you must respond within one month, extendable by two for complex or numerous requests provided you explain the extension inside the first month. You may charge a reasonable fee or refuse only where a request is manifestly unfounded or excessive, and the burden of demonstrating that sits squarely with you. You may not ask why they want it.
Our vendor had the breach. Is that our problem?
Yes. As controller you remain accountable, and the processor's awareness of the breach is treated as your awareness, so your 72-hour clock starts when they find out, not when they get round to telling you. That is precisely why Article 28 requires the contract to oblige them to notify you without undue delay, and why the notification timeline in your DPA deserves more attention than it usually receives.
Can we still use US cloud providers?
Yes, with a route and documentation. Either the provider is certified under the EU-US Data Privacy Framework, which you should verify on the active list rather than assume, or you rely on the 2021 SCCs supported by a transfer impact assessment and supplementary measures where the assessment calls for them. Keep the SCC path ready regardless: this is the third transatlantic arrangement, and the previous two were struck down.
Does the GDPR apply to B2B data and work email addresses?
Yes. A named individual at a company is still an identifiable living person, so firstname.lastname@company.com is personal data. What changes is the analysis, not the application: a legitimate interests assessment for B2B outreach will often succeed where the same processing aimed at consumers would not. Separately, the ePrivacy rules on electronic marketing still apply and differ by member state.
How does the GDPR apply to AI and training data?
Fully, and at three points. Training needs a lawful basis and must satisfy purpose limitation, which is where reuse of customer data usually fails. Outputs that identify or evaluate people engage the rights, including Article 22 where a decision is effectively automated. And personal data absorbed into a model raises real difficulties for erasure and accuracy. The EU AI Act sits on top of all this rather than replacing any of it.
We are a small company. Is any of this proportionate to us?
The obligations apply regardless of size, but the expected effort scales with risk. A twelve-person firm processing ordinary customer data needs a genuine record of processing, a clear notice, a lawful basis for each activity, a retention schedule, sound vendor contracts and a breach plan. It does not need the apparatus of a bank. The Article 30 exemption for under-250 staff is far narrower than most people believe and almost never applies, because regular processing takes you straight back out of it.
Comparison

GDPR against UK GDPR, DPDP and CCPA

All jurisdiction guides
DimensionEU GDPRUK GDPRDPDP Act, IndiaCCPA / CPRA
Lawful groundsSix bases including legitimate interestsThe same sixConsent or a certain legitimate useNotice and opt-out, not a basis model
Sensitive dataSpecial categories, Article 9Same, plus UK conditionsNo separate categoryRight to limit use of SPI
Individual rightsEight, including portability and objectionEight, materially the sameAccess, correction, erasure, nominationKnow, delete, correct, opt out
Response deadlineOne month, plus twoOne month, plus twoPublished period, max 90 days45 days, plus 45
Breach reporting72 hours where risk is likely72 hours, to the ICOEvery breach, plus 72-hour reportSeparate state breach law
TransfersAdequacy, SCCs, BCRs, derogationsUK IDTA or the AddendumNegative list of restricted countriesNo specific transfer regime
DPOMandatory in three casesSame three casesOnly for Significant Data FiduciariesNot required
Maximum penalty€20m or 4% of global turnover£17.5m or 4%Up to ₹250 crorePer-violation civil penalties
RegulatorOne per member state, EDPB aboveICOData Protection Board of IndiaCPPA
If GDPR is your baseline. You are further ahead on most regimes than you think, and further behind on a few than you expect. The genuine gaps when expanding are India's absence of legitimate interests, which forces consent where Europe permitted a balancing test; the under-18 children's threshold there; China's separate consent and localisation rules; and the fact that US state laws turn on opt-out signals your website must actually honour.
How we help

From gap assessment to demonstrable compliance

We map your processing to the Regulation obligation by obligation, build the RoPA, DPIAs, notices, consent flows, transfer documentation and breach playbooks, and prepare the evidence that proves the programme works when a supervisory authority asks. Practitioners, not a template pack.

Get a GDPR gap assessment Compare with the DPDP Act