Author: Rimsha Zafar
August 7, 2026

What is the General Data Protection Regulation (GDPR)? Your Go-To Compliance Guide

How confident is your organisation that it handles personal data the right way? With regulatory authorities issuing billions in fines and enforcement actions rising every year, getting data protection wrong is no longer a risk businesses can afford. The General Data Protection Regulation (GDPR) sits at the centre of this shift, setting clear rules for how personal data must be collected, stored, processed, and shared.

 

The General Data Protection Regulation (GDPR) is a comprehensive data privacy law adopted by the European Union in 2016 and enforced since 25 May 2018. It replaced the 1995 Data Protection Directive and brought a unified framework across all EU member states. The regulation applies not only to organisations within the EU but also to any business worldwide that offers goods or services to EU residents or monitors their behaviour.

 

This guide breaks down every essential aspect of the GDPR. From its seven core principles to the rights it grants individuals, from the roles it defines to the penalties it enforces, this blog covers what every business needs to understand. Continue reading!

What is the General Data Protection Regulation (GDPR)?

The General Data Protection Regulation is a binding legal framework that governs how organisations collect and process personal data of individuals within the European Economic Area (EEA).

Origin and Purpose of the GDPR

The European Parliament approved the GDPR on 14 April 2016, and it came into full effect on 25 May 2018. It replaced the outdated 1995 Data Protection Directive, which could not address the realities of cloud computing, social media, and global data flows. The regulation was designed to harmonise data privacy laws across Europe and give individuals greater control over their personal information.

 

Its primary purpose is twofold. First, it protects the fundamental rights and freedoms of natural persons, particularly their right to the protection of personal data. Second, it creates a single set of rules for all EU member states, removing the patchwork of national laws that previously made cross-border compliance complicated.

What Counts as Personal Data Under the GDPR

The GDPR defines personal data broadly. It includes any information relating to an identified or identifiable natural person. This covers obvious identifiers such as names, email addresses, and phone numbers. It also includes less obvious data points such as IP addresses, location data, cookie identifiers, and device fingerprints.

 

Special categories of personal data receive additional protection. These include racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, and data about sexual orientation. Processing these categories requires stricter legal justification.

How GDPR Differs from Previous Data Protection Laws

Unlike the 1995 Directive, the GDPR is a regulation, meaning it applies directly across all EU member states without needing national transposition. It introduced significantly higher penalties, mandatory breach notification, and the requirement for a Data Protection Officer in certain organisations. It also extended its territorial reach to non-EU businesses, making it one of the most far-reaching data privacy laws ever enacted.

Who Does the GDPR Apply To?

The territorial and material scope of the GDPR is deliberately broad, ensuring that personal data of EU residents receives consistent protection regardless of where the processing happens.

Territorial Scope

The GDPR applies to any organisation established in the EU, regardless of whether the actual data processing takes place inside or outside the EU. It also applies to organisations outside the EU if they offer goods or services to individuals in the EU or monitor the behaviour of individuals within the EU. This means a company based in the United States, Asia, or anywhere else must comply if it targets EU customers.

Material Scope

The regulation applies to the processing of personal data wholly or partly by automated means. It also covers non-automated processing of personal data that forms part of a filing system. However, it does not apply to purely personal or household activities, national security activities, or law enforcement processing covered by separate EU directives.

Businesses of All Sizes

There is no size exemption under the GDPR. Small businesses, startups, large corporations, public authorities, and non-profit organisations must all comply if they process personal data of EU residents. However, certain obligations, such as appointing a Data Protection Officer or maintaining records of processing, apply more specifically based on the nature and scale of processing activities.

The Seven Principles of the GDPR

Article 5 of the GDPR establishes seven principles that form the backbone of the entire regulation. Every processing activity must align with these principles.

Lawfulness, Fairness, and Transparency

Personal data must be processed lawfully, fairly, and in a transparent manner. Organisations need a valid legal basis before collecting any data. They must clearly inform individuals about what data is collected, why it is collected, and how it will be used. Privacy notices and policies must use clear, plain language that anyone can understand.

Purpose Limitation

Data must be collected for specified, explicit, and legitimate purposes. Once collected, it cannot be further processed in a manner incompatible with those original purposes. If an organisation wants to use data for a new purpose, it generally needs to obtain fresh consent or establish a new lawful basis for that processing.

Data Minimisation

Organisations must collect only the personal data that is adequate, relevant, and limited to what is necessary for the stated purpose. Collecting excessive information “just in case” is not permitted. This principle encourages businesses to regularly review what data they hold and remove anything that is no longer needed.

Accuracy

Personal data must be accurate and kept up to date. Organisations must take every reasonable step to ensure that inaccurate data is erased or rectified without delay. This requires implementing processes that allow individuals to update their information and that flag outdated records for review.

Storage Limitation

Personal data must not be kept for longer than necessary. Organisations need clear retention policies that define how long different types of data will be stored. Once the retention period expires, data must be securely deleted or anonymised so it can no longer identify individuals.

Integrity and Confidentiality

Appropriate technical and organisational measures must protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. This includes encryption, access controls, regular security testing, and staff training. The level of security must match the sensitivity of the data and the risks involved.

Accountability

The controller must be able to demonstrate compliance with all the above principles. This goes beyond simply following the rules. Organisations must document their processing activities, conduct impact assessments where necessary, implement data protection by design, and maintain evidence that they take their obligations seriously.

Six Lawful Bases for Processing Personal Data

Article 6 of the GDPR sets out six lawful bases. At least one must apply before any processing activity begins. The correct basis depends on the context and purpose of the processing.

Consent

The individual has given clear, affirmative user consent to the processing of their personal data for one or more specific purposes. Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes, silence, or inactivity do not qualify. Organisations must make it as easy to withdraw consent as it was to give it.

Contract

Processing is necessary for the performance of a contract with the individual or to take steps at their request before entering into a contract. For example, an online retailer needs to process a customer’s address to deliver an order.

Legal Obligation

Processing is necessary to comply with a legal obligation to which the controller is subject. This covers situations where an organisation must process data to meet requirements under EU or member state law, such as employment law, tax obligations, or anti-money laundering regulations.

Vital Interests

Processing is necessary to protect the vital interests of the data subject or another person. This basis is typically reserved for life-or-death situations, such as medical emergencies where the individual cannot provide consent.

Public Task

Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This basis is most relevant for public authorities and bodies carrying out functions mandated by law.

Legitimate Interests

Processing is necessary for the legitimate interests of the controller or a third party, provided those interests are not overridden by the rights and freedoms of the individual. This is the most flexible basis but requires a documented balancing test. Organisations must assess their interest, the necessity of the processing, and any impact on the individual.

Rights of Data Subjects Under the GDPR

The GDPR empowers individuals with a robust set of rights over their personal data. Organisations must have processes in place to handle these rights requests within one month.

Right to Be Informed

Individuals have the right to know how their data is being collected and used. Organisations must provide clear, concise, and accessible privacy notices at the point of data collection. These notices must explain the purpose of processing, the lawful basis, retention periods, and the individual’s rights.

Right of Access

Data subjects can request confirmation of whether their data is being processed and, if so, access to that data. This is commonly known as a Subject Access Request (SAR). Organisations must respond within one month and provide the data in a commonly used electronic format.

Right to Rectification

Individuals can request corrections to inaccurate or incomplete personal data. Organisations must act on these requests without undue delay and inform any third parties with whom the data has been shared.

Right to Erasure (Right to Be Forgotten)

Under certain conditions, individuals can request the deletion of their personal data. This applies when the data is no longer necessary for its original purpose, when consent is withdrawn, or when the data has been unlawfully processed. However, this right is not absolute and can be overridden by legal obligations or public interest considerations.

Right to Restrict Processing

Individuals can request that their data is stored but not actively processed. This applies when the accuracy of data is contested, when processing is unlawful but the individual prefers restriction over erasure, or when the organisation no longer needs the data but the individual needs it for legal claims.

Right to Data Portability

Data subjects can request their personal data in a structured, commonly used, machine-readable format and have it transferred to another controller. This right applies when processing is based on consent or contract and carried out by automated means.

Right to Object

Individuals can object to processing based on legitimate interests or public task grounds. They also have an absolute right to object to processing for direct marketing purposes. When an objection to direct marketing is received, processing must stop immediately.

Rights Related to Automated Decision-Making

Individuals have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. Organisations must provide meaningful information about the logic involved and allow individuals to request human intervention.

Key Roles and Responsibilities Under the GDPR

The GDPR clearly defines the responsibilities of different parties involved in data processing to ensure accountability at every level.

Data Controller

The data controller determines the purposes and means of processing personal data. Controllers bear primary responsibility for compliance. They must implement appropriate technical and organisational measures, maintain records of processing activities, and respond to data subject requests. When engaging a processor, the controller must ensure a data processing agreement is in place.

Data Processor

A data processor processes personal data on behalf of the controller. Processors must only act on documented instructions from the controller. They are required to implement appropriate security measures, assist the controller with data subject requests and breach notifications, and maintain their own records of processing. Processors are also directly liable for certain GDPR violations.

Data Protection Officer (DPO)

Appointing a DPO is mandatory for public authorities, organisations whose core activities involve large-scale systematic monitoring, and those processing special categories of data on a large scale. 

 

The DPO advises the organisation on compliance, monitors adherence to the regulation, cooperates with supervisory authorities, and acts as a contact point for data subjects. The DPO must operate independently and report directly to the highest level of management.

GDPR Consent Requirements

When consent is the chosen lawful basis, the GDPR sets strict conditions. Understanding the difference between opt-in vs opt-out mechanisms is fundamental to getting consent right.

Conditions for Valid Consent

Consent must be freely given, meaning the individual faces no penalty or disadvantage for refusing. It must be specific to each processing purpose. It must be informed, with clear explanations of what the individual is agreeing to. And it must be unambiguous, requiring a clear affirmative action such as ticking an unticked box or clicking an acceptance button.

Consent for Children

The GDPR provides special protections for children’s data. For information society services, consent is valid only if the child is at least 16 years old, though member states may lower this threshold to 13. For younger children, consent must be given or authorised by the holder of parental responsibility. Organisations must make reasonable efforts to verify parental consent in such cases.

Withdrawing Consent

Individuals must be able to withdraw consent at any time, and the process for withdrawal must be as easy as the process for giving consent. Organisations must inform individuals of this right before they consent. Once consent is withdrawn, all processing that relied on that consent must stop immediately, though data processed before the withdrawal remains lawful.

Data Breach Notification Under the GDPR

Articles 33 and 34 of the GDPR establish strict obligations for reporting personal data breaches. These rules ensure rapid response and transparency when security incidents occur.

The 72-Hour Notification Rule

Controllers must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. If notification cannot be made within 72 hours, the controller must provide a reasoned justification for the delay.

Notifying Affected Individuals

Controllers must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. If notification cannot be made within 72 hours, the controller must provide a reasoned justification for the delay.

Documentation Requirements

Regardless of whether a breach is reportable, controllers must document every personal data breach. This includes the facts of the breach, its effects, and the remedial actions taken. This documentation allows supervisory authorities to verify compliance during audits and investigations.

International Data Transfers

The GDPR restricts the transfer of personal data outside the EEA to ensure that the level of protection travels with the data. Organisations must use approved mechanisms for cross-border data flows.

Adequacy Decisions

The European Commission can determine that a third country offers an adequate level of data protection. Transfers to countries with an adequacy decision can proceed without additional safeguards. As of 2026, countries with adequacy decisions include the United Kingdom, Japan, South Korea, Canada (for commercial organisations), and the United States (under the EU-US Data Privacy Framework).

Standard Contractual Clauses (SCCs)

In the absence of an adequacy decision, organisations can rely on Standard Contractual Clauses approved by the European Commission. The modernised 2021 SCCs cover four modules: controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller. A Transfer Impact Assessment (TIA) must accompany SCCs to evaluate whether the destination country’s laws undermine the protection provided.

Binding Corporate Rules (BCRs)

Multinational organisations can adopt Binding Corporate Rules to govern intra-group transfers of personal data outside the EEA. BCRs require approval from a lead supervisory authority and must include enforceable data subject rights, compliance audit mechanisms, and cooperation procedures with data protection authorities.

GDPR Penalties and Enforcement

The GDPR introduced a two-tier penalty structure with significant financial consequences. Enforcement has intensified steadily since 2018.

Lower Tier Penalties

Violations related to technical and organisational measures, records of processing, breach notification, and data protection impact assessments can result in fines of up to EUR 10 million or 2% of global annual turnover, whichever is higher. Organisations operating GDPR for SaaS platforms must pay particular attention to these obligations.

Upper Tier Penalties

More severe violations, including breaches of data processing principles, data subject rights, or international transfer rules, can attract fines of up to EUR 20 million or 4% of global annual turnover, whichever is higher.

Notable Enforcement Actions

Total fines have exceeded EUR 7.1 billion since enforcement began. The largest single fine was EUR 1.2 billion against Meta Platforms Ireland in May 2023 for unlawful EU-US data transfers. TikTok received a EUR 530 million fine in May 2025 for unlawful EU-China data transfers. Amazon was fined EUR 746 million in 2021 for ad targeting without valid consent. These cases demonstrate that regulators are prepared to use the full weight of the GDPR’s penalty provisions.

Data Protection Impact Assessments (DPIAs)

A DPIA is a process designed to identify and minimise data protection risks. The GDPR mandates DPIAs in specific circumstances before processing begins.

Data Protection by Design

Organisations must implement appropriate technical and organisational measures at the design stage of any processing activity. This means considering privacy implications during system architecture, software development, and business process design. 

 

Techniques like pseudonymisation, encryption, and data minimisation should be embedded into products and services from the beginning. A robust cookie consent management platform is one practical example of building compliance into website operations.

Data Protection by Default

By default, organisations must ensure that only personal data necessary for each specific purpose is processed. This applies to the amount of data collected, the extent of processing, the storage period, and accessibility. Default settings on products and services must be privacy-friendly, ensuring individuals are not required to take action to protect their own data.

Practical Implementation

Implementing privacy by design involves conducting DPIAs during project planning, adopting privacy-enhancing technologies, training development teams on data protection principles, and regularly reviewing systems for compliance. 

 

Organisations should maintain documentation showing how these principles have been applied throughout the lifecycle of every product and service.

Steps to Achieve GDPR Compliance

Building a GDPR compliance programme requires a structured approach. The following steps provide a practical roadmap for organisations at any stage of their compliance journey.

Conduct a Data Audit

Map every type of personal data your organisation collects, processes, stores, and shares. Identify where data originates, where it flows, who has access, and how long it is retained. This audit forms the foundation of your Records of Processing Activities (ROPA), which the GDPR requires controllers and processors to maintain.

Establish Lawful Bases

For each processing activity identified in the audit, determine and document the appropriate lawful basis. Review consent mechanisms to ensure they meet the GDPR’s strict requirements. Conduct legitimate interest assessments where that basis is relied upon. Ensure that privacy notices accurately reflect the lawful bases used.

Implement Technical and Organisational Measures

  • Deploy encryption for data at rest and in transit
  • Implement role-based access controls to limit data access
  • Establish incident response procedures for data breaches
  • Conduct regular penetration testing and vulnerability assessments
  • Ensure proper GDPR Staff Training across all departments

Review Third-Party Agreements

Ensure all data processors have signed Data Processing Agreements (DPAs) that meet GDPR requirements. Review contracts with sub-processors. Assess international transfer mechanisms for any data shared with organisations outside the EEA. Monitor processor compliance through audits and documented assurances.

GDPR and Cookie Compliance

While the ePrivacy Directive specifically governs cookies, the GDPR reinforces and strengthens cookie consent requirements. Together, they require organisations to obtain proper consent before placing non-essential cookies. Understanding how to build a compliant cookie policy is a critical part of meeting these obligations.

What the GDPR Requires for Cookies

Cookies that identify individuals or track behaviour constitute personal data under the GDPR. Analytics cookies, advertising cookies, and social media cookies all require explicit opt-in consent before being placed on a user’s device. Strictly necessary cookies, such as those required for website functionality, do not require consent but must still be disclosed.

Cookie Consent Banners

A compliant cookie consent banner must clearly explain what cookies are used, their purposes, and provide granular options for acceptance or rejection. The banner must not use deceptive design patterns or make it harder to reject cookies than to accept them. Businesses using platforms like Shopify should consider how GDPR compliance applies to their cookie practices.

Record-Keeping for Cookie Consent

Organisations must maintain records of when and how consent was obtained for cookie usage. This includes recording the timestamp of consent, the version of the consent notice shown, and the specific choices made by the user. These records serve as evidence of compliance during regulatory audits.

How the GDPR Compares to Other Data Privacy Laws

The GDPR has influenced data privacy legislation around the world. Understanding how it compares helps organisations operating across multiple jurisdictions manage compliance efficiently.

GDPR vs CCPA

The California Consumer Privacy Act takes an opt-out approach, while the GDPR requires opt-in consent for most data processing. The GDPR’s definition of personal data is broader, and its penalties are significantly higher. Organisations often compare GDPR vs CCPA to determine which requirements apply to their operations.

GDPR vs UK Data Protection

Following Brexit, the UK adopted the UK GDPR, which mirrors the EU GDPR closely. The UK has an adequacy decision from the European Commission, allowing data to flow freely between the UK and the EEA. However, the UK is considering reforms through its Data Use and Access Act, which may create divergence over time.

GDPR's Global Influence

Countries including Brazil (LGPD), India (DPDPA), South Africa (POPIA), and Thailand (PDPA) have modelled their data protection laws on the GDPR. Many US states have also drawn from GDPR principles when drafting consumer privacy legislation. This global influence means that GDPR compliance often provides a strong baseline for meeting requirements in other jurisdictions.

Final Thoughts

The General Data Protection Regulation has fundamentally changed how organisations handle personal data. Its seven principles, eight data subject rights, and strict enforcement framework create clear obligations for every business that processes EU residents’ data. Compliance is not optional and not a one-time task. It requires ongoing commitment, documented processes, and the right tools. Organisations that treat GDPR as a foundation for responsible data governance will build stronger trust, avoid costly penalties, and operate with greater confidence across borders.

Simplify Your GDPR Compliance with Seers

Managing GDPR compliance across consent, cookies, data rights, and documentation can feel overwhelming. Seers provides an all-in-one compliance platform that automates consent management, cookie scanning, privacy policy generation, and data subject request handling. Whether you need a consent management platform, a cookie banner, or a complete compliance solution, Seers makes it simple.

START FREE TODAY

Frequently Asked Questions (FAQs)

Does the GDPR apply to businesses outside the European Union?

The GDPR applies to any organisation worldwide that offers goods or services to individuals in the EU or monitors their behaviour within the EU. Territorial scope extends beyond EU borders based on the nature of the processing activity, not the physical location of the business. Non-EU companies must appoint an EU representative if they fall within scope.

What is the difference between a data controller and a data processor under the GDPR?

A data controller determines why and how personal data is processed. A data processor handles personal data on the controller’s behalf, following the controller’s documented instructions. Both carry distinct legal obligations. Controllers bear primary compliance responsibility, while processors must implement security measures and maintain processing records as mandated by the regulation.

How long do organisations have to respond to a data subject access request?

Organisations must respond to a data subject access request within one calendar month of receiving it. This deadline can be extended by two additional months for complex or numerous requests. The controller must inform the data subject of the extension and the reasons for the delay within the initial one-month period.

Can an organisation rely on legitimate interests as a lawful basis for all processing activities?

Legitimate interests cannot serve as a blanket justification for all processing. Each activity requires a separate legitimate interest assessment that balances the organisation’s interest against the individual’s rights and freedoms. If the individual’s rights outweigh the organisation’s interest, another lawful basis must be identified or the processing cannot proceed.

What qualifies as a personal data breach under the GDPR?

A personal data breach is any security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. This includes cyberattacks, accidental data exposure, lost devices containing personal data, and sending information to the wrong recipient. Not every breach requires supervisory authority notification.

Are small businesses exempt from GDPR compliance requirements?

The GDPR does not provide a blanket exemption for small businesses. All organisations processing personal data of EU residents must comply with the regulation’s core principles and obligations. Certain administrative requirements, such as appointing a Data Protection Officer or conducting a DPIA, depend on the nature and scale of processing rather than the organisation’s size.

What happens if an organisation fails to report a data breach within 72 hours?

Failing to notify the supervisory authority within 72 hours without a justified reason can result in fines of up to EUR 10 million or 2% of global annual turnover. The notification must still be submitted as soon as possible with a written explanation for the delay. Repeated failure to report breaches may attract additional enforcement actions and increased scrutiny.

How does the GDPR handle the processing of children's personal data?

The GDPR sets the age of digital consent at 16 years, though member states can lower it to 13. For children below the applicable age, consent must be given or authorised by a parent or legal guardian. Organisations offering information society services to children must make reasonable efforts to verify that consent comes from someone with parental responsibility.

What is a Data Protection Impact Assessment and when is it mandatory?

A Data Protection Impact Assessment is a structured process for evaluating the risks of a data processing activity. It becomes mandatory when processing is likely to result in high risk to individuals, such as large-scale profiling, processing of special category data, or systematic monitoring of public areas. The assessment must be completed before the processing begins.

Can personal data be transferred outside the European Economic Area under the GDPR?

Personal data can be transferred outside the EEA through approved mechanisms. These include adequacy decisions by the European Commission, Standard Contractual Clauses, Binding Corporate Rules, and specific derogations for occasional transfers. Each mechanism must ensure that the transferred data receives a level of protection essentially equivalent to that within the EEA.

 

Rimsha Zafar

Rimsha is a Senior Content Writer at Seers AI with over 5 years of experience in advanced technologies and AI-driven tools. Her expertise as a research analyst shapes clear, thoughtful insights into responsible data use, trust, and future-facing technologies.

ORCIDResearchGateGoogle ScholarLinkedIn 

Unlock Accurate Insights with Google Consent Mode v2

Is Your Website at Risk of Losing Conversions?


Take our Free Cookie Audit and find out

Ready to Build Trust and Drive Business Growth?

Join 50,000+ websites using Seers.Ai to turn compliance into trust, insights, & measurable business growth.