Personal data is part of almost every digital interaction. When you create an account, make an online purchase, subscribe to a newsletter, use an application, or simply browse a website, organizations may collect and process information relating to you.
The General Data Protection Regulation (GDPR) is the European Union’s main legal framework for protecting personal data. It gives individuals important rights over their personal information and establishes obligations for organizations that collect, use, store, share, or otherwise process personal data.
Formally known as Regulation (EU) 2016/679, the GDPR entered into force in 2016 and has applied since 25 May 2018.
It created a largely harmonized data-protection framework across the European Union and has become one of the world’s most influential data-protection laws.
What Is the GDPR?
The GDPR establishes rules for the processing of personal data relating to natural persons.
Personal data means any information relating to an identified or identifiable living person, referred to under the GDPR as a data subject.
Personal data can include:
- Name and surname
- Email address
- Home address
- Identification number
- Location data
- IP address and other online identifiers
- Cookie and advertising identifiers where they relate to an identifiable person
- Financial information
- Photographs and video recordings
- Biometric or genetic information
- Other information that can identify or be linked to an individual
The GDPR is not limited to information stored electronically. It can also apply to structured paper records where personal data forms part of, or is intended to form part of, a filing system.
Does GDPR Apply Outside the EU?
Yes.
One of the most important features of the GDPR is its territorial scope.
The GDPR applies to processing carried out in the context of the activities of an establishment of a controller or processor in the EU, regardless of whether the processing itself takes place in the EU.
It may also apply to organizations established outside the EU where they process personal data relating to individuals who are in the EU in connection with:
- Offering goods or services to them, whether or not payment is required; or
- Monitoring their behavior where that behavior takes place within the EU.
This means that an organization does not necessarily need to have an office in the EU to fall within the scope of the GDPR.
Why Was the GDPR Introduced?
Digital services, online platforms, cloud computing, mobile applications, analytics, advertising technologies, and other data-driven services have dramatically increased the amount of personal information organizations process.
The GDPR was introduced to strengthen the protection of individuals and modernize European data-protection rules for the digital environment.
It also aims to provide a more consistent framework for organizations operating across Europe.
A central element of the GDPR is transparency.
Organizations must provide individuals with appropriate information about how their personal data is processed. Depending on the circumstances, this can include:
- What personal data is collected
- Why it is collected and processed
- The legal basis for processing
- Who receives or has access to the data
- How long the data will be retained
- Whether the data may be transferred internationally
- What rights individuals have regarding their data
The Seven GDPR Principles
Article 5 of the GDPR establishes fundamental principles governing the processing of personal data.
1. Lawfulness, Fairness and Transparency
Personal data must be processed lawfully, fairly and transparently.
Organizations must have an appropriate lawful basis for processing and provide individuals with clear information about how their data is used.
2. Purpose Limitation
Personal data must be collected for specified, explicit and legitimate purposes and should not subsequently be used in ways that are incompatible with those purposes, subject to the exceptions provided by the GDPR.
3. Data Minimization
Organizations should process only personal data that is adequate, relevant and limited to what is necessary for the intended purpose.
Collecting information simply because it might become useful later can conflict with this principle.
4. Accuracy
Personal data must be accurate and, where necessary, kept up to date.
Reasonable steps should be taken to correct or erase inaccurate information without undue delay.
5. Storage Limitation
Personal data should generally not be kept in identifiable form for longer than necessary for the purposes for which it is processed.
Organizations should therefore establish appropriate data-retention and deletion rules.
6. Integrity and Confidentiality
Personal data must be protected through appropriate technical and organizational measures.
This includes protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
Examples may include access controls, encryption, secure backups, monitoring, employee awareness, vulnerability management, and incident-response procedures, depending on the risks involved.
7. Accountability
Organizations are responsible for complying with the GDPR principles and must be able to demonstrate compliance.
Accountability therefore requires more than stating that an organization complies with GDPR. Appropriate policies, procedures, responsibilities, controls, and evidence should support that claim.
What Rights Do Individuals Have Under GDPR?
The GDPR provides individuals with several important rights concerning their personal data.
These rights are not absolute in every situation. Their applicability can depend on the purpose and legal basis of processing and on specific exemptions provided by law.
Key rights include:
Right to Be Informed
Individuals have the right to receive information about how their personal data is collected and processed.
This information is commonly provided through a privacy notice.
Right of Access
Individuals can request confirmation as to whether their personal data is being processed and, where applicable, obtain access to that data and related information.
Right to Rectification
Individuals can request correction of inaccurate personal data and, where appropriate, completion of incomplete information.
Right to Erasure
In certain circumstances, individuals can request deletion of their personal data.
This is commonly known as the “right to be forgotten.”
However, the right is not absolute. Organizations may sometimes be required or permitted to retain information, including where retention is necessary to comply with a legal obligation or establish, exercise, or defend legal claims.
Right to Restrict Processing
Individuals may request that processing of their personal data be restricted in circumstances specified by the GDPR.
Right to Data Portability
Under certain conditions, individuals can receive personal data they have provided to an organization in a structured, commonly used and machine-readable format.
They may also be able to transfer that information to another organization.
Right to Object
Individuals may object to certain types of processing.
This is particularly important for direct marketing. Individuals have the right to object at any time to processing of their personal data for direct-marketing purposes, including related profiling.
Automated Decision-Making and Profiling
The GDPR provides specific protections regarding decisions based solely on automated processing, including profiling, where those decisions produce legal effects or similarly significantly affect an individual.
Where applicable, additional safeguards may be required.
What Does GDPR Mean for Businesses?
GDPR compliance involves much more than publishing a privacy policy or displaying a cookie banner.
An organization should understand:
- What personal data it processes
- Where that data comes from
- Why the data is processed
- What lawful basis supports the processing
- Where the data is stored
- Who can access it
- Which processors and other recipients receive it
- Whether it is transferred internationally
- How long it is retained
- What risks the processing creates
- What safeguards protect it
Depending on the organization’s activities, additional GDPR requirements may also apply.
Records of Processing Activities
Controllers and processors may be required to maintain Records of Processing Activities (ROPA) describing their personal-data processing.
The GDPR contains a limited exemption concerning organizations employing fewer than 250 people. However, this should not be interpreted as a general exemption for small businesses.
Record-keeping obligations can still apply depending on the nature and risk of the processing, including where processing is not occasional or involves certain categories of sensitive personal data.
Data Protection Impact Assessments
A Data Protection Impact Assessment (DPIA) is required where a type of processing is likely to result in a high risk to individuals’ rights and freedoms.
A DPIA helps an organization identify privacy risks and determine appropriate measures before or while implementing higher-risk processing activities.
Data Protection by Design and by Default
GDPR compliance should be incorporated into systems and business processes from the beginning rather than added only after a product or service has been developed.
The GDPR therefore requires appropriate measures for data protection by design and by default.
By default, organizations should process only the personal data necessary for each specific purpose.
Managing Data Processors
Many organizations rely on external providers for services such as:
- Cloud hosting
- Payroll
- Email marketing
- Software-as-a-Service
- Customer support
- IT services
- Analytics
Where another organization processes personal data on behalf of a controller, appropriate GDPR requirements must be addressed.
Controllers must use processors that provide sufficient guarantees regarding appropriate technical and organizational measures, and the relationship must generally be governed by a contract or other legal act meeting GDPR requirements.
Personal Data Breaches
Organizations should have processes for identifying, assessing, documenting, and responding to personal data breaches.
Where a personal data breach is likely to result in a risk to individuals’ rights and freedoms, the controller generally must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
Where the breach is likely to result in a high risk to individuals, affected individuals may also need to be informed without undue delay, subject to the exceptions established by the GDPR.
Importantly, not every security incident is necessarily a personal data breach, and not every personal data breach requires notification. Organizations need a process for assessing each incident against the GDPR requirements.
When Is a Data Protection Officer Required?
Certain organizations must appoint a Data Protection Officer (DPO).
A DPO is generally mandatory where:
- Processing is carried out by a public authority or body, except courts acting in their judicial capacity;
- The organization’s core activities require regular and systematic monitoring of individuals on a large scale; or
- Its core activities consist of large-scale processing of special categories of personal data or personal data relating to criminal convictions and offenses.
Organizations may also appoint a DPO voluntarily.
Are Small Businesses Exempt From GDPR?
No. Small businesses are not automatically exempt from GDPR.
GDPR applicability depends primarily on the organization’s processing activities rather than simply its size.
Some obligations contain specific exceptions or proportionality considerations, but a small organization processing personal data can still be subject to many of the same fundamental requirements as a large enterprise.
Each organization should therefore determine which GDPR requirements apply to its particular processing activities.
GDPR Compliance Is More Than a Privacy Policy
A common mistake is to treat GDPR compliance as a documentation exercise.
Having a privacy notice, cookie banner, or GDPR policy does not by itself demonstrate compliance.
An effective GDPR compliance program typically involves areas such as:
- Personal-data inventory and data mapping
- Records of Processing Activities
- Lawful-basis assessments
- Privacy notices
- Consent management where consent is relied upon
- Data-subject rights procedures
- Data-retention requirements
- Processor and third-party management
- Data Protection Impact Assessments
- Privacy by design and by default
- Information-security controls
- Personal-data breach management
- International data-transfer controls
- Employee awareness and training
- Governance, monitoring, and compliance evidence
The exact requirements depend on the organization’s role, activities, processing operations, and associated risks.
Why GDPR Still Matters
GDPR has fundamentally changed how organizations approach privacy, information governance, cybersecurity, and personal-data management.
Its influence extends beyond the European Union. Organizations outside the EU may fall within its territorial scope, while GDPR principles have also influenced data-protection laws and privacy practices around the world.
For individuals, GDPR provides important rights and greater transparency concerning how personal information is used.
For organizations, it establishes responsibilities requiring data protection to become part of everyday governance, business processes, technology, information security, third-party management, and risk management.
As organizations increasingly adopt cloud services, artificial intelligence, analytics, automation, and other data-driven technologies, understanding how personal data is collected, processed, shared, retained, and protected remains essential.
GDPR compliance is ultimately about demonstrating that personal data is processed lawfully, fairly, transparently, securely, and responsibly.
Disclaimer: This article provides general information about the General Data Protection Regulation and does not constitute legal advice. Organizations should consult Regulation (EU) 2016/679, applicable national legislation, guidance from the relevant data-protection supervisory authorities, and qualified professionals when determining their specific legal obligations.