The EU General Data Protection Regulation (GDPR) is the law that defines, across all 27 Member States plus the three EEA states, what an organisation is and is not allowed to do with personal data about people in Europe. It replaced the patchwork of national rules that grew out of the 1995 Data Protection Directive and harmonised — to the extent that 30 jurisdictions can be harmonised — the rights of data subjects, the obligations of controllers and processors (the organisation that decides why and how data is used, and any supplier that handles it on that organisation’s instructions), the powers of supervisory authorities, and the rules on transferring personal data outside the EEA.
If you process personal data about anyone in the EU/EEA — customer email addresses, employee files, IP logs, CCTV footage, health records, anything that can be linked to an identified or identifiable person — this Regulation applies to you. It applied from 25 May 2018, has been in force ever since, and has produced enforcement actions running into the billion-euro range: Ireland’s Data Protection Commission fined Meta €1.2 billion in May 2023 over EU–US data transfers, and another €530 million was imposed on TikTok in May 2025 for the same category of breach.
This page is the canonical klarproof guide — every key claim is sourced directly to EUR-Lex, the European Data Protection Board (EDPB), the European Commission, or named national supervisors.
Quick facts
- Full name: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation)
- Adopted: 27 April 2016
- Published in OJ: 4 May 2016 (OJ L 119/1)
- Entered into force: 24 May 2016 (twentieth day after publication, per Article 99)
- Started to apply: 25 May 2018 (after a two-year transition period)
- Penalties: up to €10M or 2% of total worldwide annual turnover (lower tier — Article 83(4)); up to €20M or 4% of total worldwide annual turnover (higher tier — Article 83(5)/(6)); whichever is higher in each case
- Coordinating EU body: the European Data Protection Board (EDPB) — independent body composed of the heads of every national supervisory authority + the European Data Protection Supervisor (EDPS)
- EU institutions’ supervisor: the European Data Protection Supervisor (EDPS) — supervises personal data processing by EU institutions, bodies, offices and agencies; current Supervisor: Wojciech Wiewiórowski (took office 6 December 2019 for the 2019–2024 term; remains in post on an interim basis as of June 2026, pending appointment of a successor)
- EDPB Chair: Anu Talus (Finland, Data Protection Ombudsman); Deputy Chairs: Jelena Virant Burnik (Slovenia, Information Commissioner — elected December 2025) and Zdravko Vukić (Croatia)
- National enforcement: by the supervisory authority (DPA) in each Member State — CNIL in France, BfDI/Länder DPAs in Germany, AKI in Estonia, the Office of the Data Protection Ombudsman in Finland, Garante in Italy, AEPD in Spain, the Data Protection Commission in Ireland, etc.
What GDPR actually does
GDPR regulates the processing of personal data — meaning anything you do with information that can be linked to an identified or identifiable person: collecting it, storing it, looking at it, sharing it, deleting it, even pseudonymising it. The Regulation sets the baseline rules; sector-specific laws (ePrivacy, AML, employment, health) add layers on top.
Three things it does at the same time:
- Imposes obligations on the organisations that decide what to do with personal data (controllers) and on the organisations that handle data on their behalf (processors) — principles of processing, lawful bases, security, accountability, transparency.
- Grants enforceable rights to the people the data is about (data subjects) — access, rectification, erasure, restriction, portability, objection, the right not to be subject to fully automated decisions.
- Restricts data flows outside the EEA unless the destination country has been granted an “adequacy decision” or the transfer is protected by an instrument like Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs).
GDPR does not replace other EU privacy rules. The ePrivacy Directive (the “cookie law”) still governs cookies, electronic marketing and the confidentiality of communications. The EU AI Act governs how AI systems are built and supervised, while GDPR governs the personal data flowing through those systems — the two regulate the same product from different angles. See our AI Act pillar for the AI side.
What counts as “personal data”
The definition (Article 4(1)) is broader than most non-lawyers expect:
“Personal data” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
In practice, this includes everything that can reasonably be tied back to an individual: name, email, phone number, postal address, ID numbers, IP addresses (case law treats them as personal data when the controller has the legal means to identify the user), cookie identifiers, device fingerprints, photos and CCTV footage, biometric data, genetic data, location, health data, behavioural data, advertising IDs, and so on. Pseudonymised data is still personal data under GDPR — only truly anonymised data (irreversibly stripped of any link back to a person) falls out of scope.
A separate, stricter regime applies to special categories of personal data (Article 9) — see below.
Material and territorial scope
GDPR applies only to processing in the course of activities that engage with the EU/EEA market in some way.
Material scope (Article 2)
The Regulation covers the processing of personal data wholly or partly by automated means and the processing other than by automated means of personal data which form part of a filing system (paper records organised in a structured way). It does not apply to:
- Processing by a natural person in the course of a purely personal or household activity (your contact list, your family photos)
- Processing for the purposes of the prevention, investigation, detection or prosecution of criminal offences — that’s covered by the Law Enforcement Directive (Directive (EU) 2016/680) instead
- Processing by EU institutions, bodies, offices and agencies — that’s covered by Regulation (EU) 2018/1725, enforced by the EDPS
Territorial scope (Article 3)
GDPR is extraterritorial. It applies to:
- Processing of personal data in the context of the activities of an establishment of a controller or processor in the Union — regardless of whether the processing itself takes place inside or outside the EU. A US-based subsidiary of an EU company, doing processing on a Frankfurt server, is in scope. So is an EU branch of a non-EU company processing on a server in Singapore.
- Processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing relates to:
- The offering of goods or services to those data subjects in the Union (paid or free), or
- The monitoring of their behaviour as far as their behaviour takes place within the Union.
The second branch is what brings non-EU companies into scope without any physical presence in Europe. A US SaaS company that lets European users sign up and pay in euros is offering services to EU data subjects. An ad-tech company outside the EU that profiles EU users via cookies is monitoring their behaviour. Both must comply.
The seven principles (Article 5)
GDPR is built on seven principles. Every other rule in the Regulation either implements or refines one of these:
| Principle | What it means in practice |
|---|---|
| Lawfulness, fairness, transparency | Every processing operation needs a lawful basis; people must know what’s being done with their data |
| Purpose limitation | You collect data for a specific declared purpose; you can’t quietly repurpose it for something incompatible |
| Data minimisation | Collect only what’s adequate, relevant and limited to what’s necessary for the purpose |
| Accuracy | Keep personal data accurate and up to date; correct or delete inaccurate data without delay |
| Storage limitation | Keep personal data in identifiable form only as long as the purpose requires; then anonymise or delete |
| Integrity and confidentiality | Protect personal data with appropriate technical and organisational measures (encryption, access controls, pseudonymisation, etc.) |
| Accountability | The controller must not just comply but be able to demonstrate compliance — through records, policies, DPIAs, training, audits |
The accountability principle is the one that produced most of the procedural plumbing in the rest of the Regulation: records of processing (Article 30), DPIAs (Article 35), DPO appointments (Articles 37–39), data protection by design and by default (Article 25). If you’re ever audited, the supervisory authority will ask you to show your records, not just describe your intentions.
The six lawful bases (Article 6)
You cannot process personal data unless at least one of the six lawful bases applies. They are:
| Basis | Article 6(1) | Typical use |
|---|---|---|
| Consent | (a) | Marketing emails, optional cookies, profiling, voluntary surveys |
| Contract | (b) | Performing a contract the data subject is party to (account creation, order fulfilment) |
| Legal obligation | (c) | Tax records, AML/KYC checks, employment law records |
| Vital interests | (d) | Emergency situations to protect someone’s life |
| Public task | (e) | Processing by public authorities or in the exercise of official authority |
| Legitimate interests | (f) | Fraud prevention, internal administration, network security — only after a documented balancing test that confirms the controller’s interest does not override the data subject’s rights |
A few traps practitioners hit repeatedly:
- Consent has to meet the GDPR standard: freely given, specific, informed, unambiguous, by clear affirmative action. Pre-ticked boxes don’t count. Consent that bundles many purposes into one click does not count. People must be able to withdraw consent as easily as they gave it.
- “Legitimate interests” is not a free pass. It requires a documented balancing test. The Irish Data Protection Commission’s €390 million fine on Meta in January 2023 turned on Meta’s attempt to use “contract” (Article 6(1)(b)) — and later “legitimate interests” — as the basis for behavioural advertising on Facebook and Instagram, where the EDPB ruled the only valid basis was consent.
- Public-sector controllers cannot use “legitimate interests” — Article 6(1)(f) is unavailable to public authorities acting in their public-interest tasks.
Special categories of personal data (Article 9)
A subset of personal data carries higher risk and is prohibited from processing by default, unless one of ten specific exceptions in Article 9(2) applies. The special categories are:
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade-union membership
- Genetic data
- Biometric data for the purpose of uniquely identifying a natural person (face recognition, fingerprint matching — but ordinary photos are not automatically biometric)
- Data concerning health
- Data concerning a person’s sex life or sexual orientation
The most commonly used Article 9(2) gateways are explicit consent ((a)), processing necessary in the field of employment, social security and social protection ((b)), processing for medical and public-health purposes ((h) and (i)), and processing for scientific research ((j)) — each subject to additional safeguards in Member State law.
A separate provision, Article 10, restricts the processing of personal data relating to criminal convictions and offences to either an authority’s official capacity or where authorised by Member State law.
Controller and processor — the two key roles
GDPR distinguishes two regulatory statuses for organisations that handle personal data:
- Controller (Article 4(7)) — the natural or legal person who determines the purposes and means of the processing. The bank that decides what data to collect from customers and why is the controller. The hospital that runs medical records for its patients is the controller. Generally, the controller is the entity in the customer-facing position.
- Processor (Article 4(8)) — the natural or legal person who processes personal data on behalf of the controller. The cloud provider that hosts the bank’s customer database is a processor. The payroll company that runs the hospital’s employee records is a processor. The processor acts on documented instructions from the controller.
Two or more controllers can be joint controllers (Article 26) when they jointly determine the purposes and means of processing — frequent in advertising ecosystems and in employer/works-council relationships. The CJEU in Fashion ID (C-40/17, 29 July 2019) held that a website operator who embeds a Facebook “Like” button is a joint controller with Facebook for the data collection that happens through that button.
The split matters because:
- The controller carries most of the substantive obligations (lawful basis, transparency, data subject rights, breach notification to the DPA, DPIAs).
- The processor is bound by Article 28 contracts with the controller, must process only on documented instructions, must implement security measures, must assist the controller, and must notify the controller of breaches without undue delay. A processor who oversteps and starts deciding the purposes of processing becomes a controller for that processing and inherits the controller’s obligations.
Data subject rights (Articles 12–22)
People in the EU/EEA have a set of enforceable rights against any organisation processing their personal data. The full list:
| Right | Article | What it does |
|---|---|---|
| To information | 13–14 | Be told, at the time data is collected, who is processing it, why, on what legal basis, for how long, and what rights you have |
| To access | 15 | Get confirmation that your data is being processed, plus a copy of it and the essential metadata about the processing |
| To rectification | 16 | Have inaccurate data corrected and incomplete data completed |
| To erasure (“to be forgotten”) | 17 | Have your data deleted in defined circumstances (no longer needed, consent withdrawn, unlawful processing, etc.) |
| To restriction of processing | 18 | Block further processing while a dispute is resolved |
| To data portability | 20 | Receive the data you provided to a controller in a structured, commonly used, machine-readable format and transmit it to another controller |
| To object | 21 | Object to processing based on legitimate interests or public task; absolute right to object to direct marketing |
| Not to be subject to automated decision-making | 22 | Avoid being subject to a fully automated decision (including profiling) that produces legal or similarly significant effects, unless one of three exceptions applies |
The controller must respond to a request without undue delay and at the latest within one month (Article 12(3)), extendable by two further months for complex cases. Responses are free of charge unless the request is manifestly unfounded or excessive.
A right that is often overlooked: under Article 22, a fully automated decision with legal or similarly significant effects (refusing a loan, declining an insurance claim, denying access to a service) is in principle prohibited unless it is necessary for a contract, authorised by law, or based on explicit consent — and even then, the data subject has the right to obtain human intervention, express their point of view and contest the decision. This provision overlaps materially with the EU AI Act’s rules on high-risk AI systems used for the same kinds of decisions.
Data Protection Officer (DPO) — Articles 37–39
Three categories of organisation are required to designate a DPO:
- Public authorities and bodies (other than courts in their judicial capacity).
- Controllers or processors whose core activities consist of processing operations that, by their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale — typical examples: ad-tech, large platforms, telecoms, customer-facing surveillance systems.
- Controllers or processors whose core activities consist of processing special categories of data on a large scale — typical examples: hospitals, health-tech, biometric services.
The DPO must have expert knowledge of data-protection law and practice, must be involved in all data-protection issues, must report to the highest level of management, must be granted adequate resources, and cannot be dismissed or penalised for performing the role. The DPO is not personally liable for the organisation’s compliance — that liability sits on the controller — but the DPO’s independence is a structural protection that EU law treats seriously.
A DPO can be an employee or an external contractor. Many groups appoint a single DPO for multiple legal entities, provided the DPO is “easily accessible from each establishment” (Article 37(2)).
Records, DPIAs, breach notification
Three procedural obligations that produce most of the day-to-day documentation in a compliance programme:
Records of processing activities (Article 30)
Every controller (and every processor on the controller’s side) must maintain a written record of the processing activities under its responsibility. The record lists what data is processed, for what purpose, on what legal basis, who it’s shared with, retention periods, and security measures. The exemption for organisations under 250 employees is narrower than it looks — it does not apply if the processing is likely to result in a risk, is not occasional, or includes special categories.
Data Protection Impact Assessment (DPIA) — Article 35
A DPIA is required where processing is likely to result in a high risk to the rights and freedoms of natural persons — in particular for systematic and extensive automated decision-making, large-scale processing of special categories, or large-scale systematic monitoring of public areas. National DPAs publish their own lists of processing operations that always trigger a DPIA. If the DPIA shows residual high risk that the controller cannot mitigate, the controller must consult the DPA before starting (Article 36).
Personal data breach notification — Articles 33–34
Where a personal data breach occurs, the controller must notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it (Article 33), unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the breach is likely to result in a high risk, the controller must also notify the affected data subjects “without undue delay” (Article 34). Processors must notify their controller without undue delay.
The 72-hour clock is the most operationally pressured deadline in the Regulation. Most major DPAs publish online breach-notification forms; what they expect from the first notification is a description of the breach, the categories and approximate number of data subjects, the likely consequences, and the measures taken or proposed.
International transfers — Chapter V
Personal data may be transferred from the EEA to a third country only on one of the routes set out in Articles 44–49:
1. Adequacy decision (Article 45)
The European Commission has, by formal decision, recognised the third country as providing a level of data protection essentially equivalent to that in the EU. Once an adequacy decision is in force, transfers to that country can flow freely without further authorisation. As of 2026, the Commission has issued adequacy decisions covering:
- United Kingdom (28 June 2021; renewed December 2025) — covers both GDPR and the Law Enforcement Directive
- United States — under the EU–US Data Privacy Framework (10 July 2023), for commercial entities self-certified to the framework
- Republic of Korea (17 December 2021)
- Japan (2019), Canada (2002, commercial organisations only), Israel (2011), New Zealand (2013), Argentina (2003), Uruguay (2012), Switzerland (2000), Andorra (2010), Faroe Islands (2010), Guernsey (2003), Isle of Man (2004), Jersey (2008)
- Brazil (26 January 2026 — most recent addition)
- European Patent Organisation (15 July 2025) — for the international organisation rather than a country
2. Appropriate safeguards (Article 46)
Where there is no adequacy decision, the transfer is permitted if the exporter has put appropriate safeguards in place. The two most-used safeguards in practice:
- Standard Contractual Clauses (SCCs) — model contractual terms approved by the Commission. The current SCCs are set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, entered into force on 27 June 2021 and used by the vast majority of EEA-to-third-country transfers today. They are modular, covering controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller transfers.
- Binding Corporate Rules (BCRs) — internal codes of conduct for intra-group transfers within multinational organisations, approved by a lead DPA after a long, detailed approval process. Used by groups like Airbus, IBM, Salesforce.
3. Derogations (Article 49)
A short, narrowly-drafted list of exceptions for non-routine transfers: explicit consent of the data subject, contract performance with the data subject, important reasons of public interest, legal claims, vital interests. These cannot be used as a workaround for routine business transfers — they are reserved for genuinely occasional, non-systematic situations.
Schrems II and what changed
The Court of Justice of the European Union in Data Protection Commissioner v. Facebook Ireland Ltd and Maximilian Schrems (C-311/18), judgment of 16 July 2020 invalidated the prior EU–US Privacy Shield because US surveillance law (FISA Section 702, EO 12333) provided neither the substantive limitations nor the actionable redress mechanisms required by EU fundamental-rights standards. The same judgment upheld the validity of SCCs in principle but ruled that the data exporter and the data importer must, before transferring, assess on a case-by-case basis whether the law of the third country provides the level of protection required by EU law, and if not, put supplementary measures in place (encryption, pseudonymisation, contractual additions) — or stop the transfer.
This case-by-case assessment is now embedded in the SCCs themselves and in the EDPB Recommendations 01/2020 on supplementary measures. Three years later, the Commission’s EU–US Data Privacy Framework (10 July 2023) re-established a no-questions-asked transfer route to certified US companies — but the framework relies on the President’s Executive Order 14086 of 7 October 2022 and remains exposed to a Schrems III challenge that is widely expected.
Governance: who supervises and who enforces
GDPR uses a three-level governance model.
EU level
- European Data Protection Board (EDPB) — independent body composed of the heads of every national supervisory authority (one per Member State) plus the EDPS. The EDPB issues guidelines that harmonise the interpretation of GDPR across the EU, resolves cross-border disputes between national DPAs through binding decisions under Article 65, and approves codes of conduct, certification schemes and BCR applications. Chair: Anu Talus (Finland, Office of the Data Protection Ombudsman). Deputy Chairs: Jelena Virant Burnik (Slovenia, Information Commissioner — elected at the December 2025 plenary, replacing Irene Loizidou Nikolaidou) and Zdravko Vukić (Croatia).
- European Data Protection Supervisor (EDPS) — independent EU institution that supervises the processing of personal data by EU institutions, bodies, offices and agencies under Regulation (EU) 2018/1725. The EDPS sits as an additional member of the EDPB. Current Supervisor: Wojciech Wiewiórowski (took office 6 December 2019 for the 2019–2024 term; remains in post on an interim basis as of June 2026, pending appointment of a successor).
National level
Each Member State has at least one independent supervisory authority (DPA) that handles complaints, conducts investigations, issues fines, and authorises certain processing operations. The most-cited DPAs in cross-border cases:
- 🇮🇪 Ireland — Data Protection Commission (DPC) — lead supervisor for most US tech companies established in Ireland (Meta, Google, TikTok, Microsoft, X). Has issued the largest GDPR fines on record.
- 🇫🇷 France — CNIL — one of the oldest data protection authorities in the world (created by the Loi Informatique et Libertés of 6 January 1978) and among the most active EU enforcers, especially on ad-tech, cookies and consent-banner compliance.
- 🇩🇪 Germany — federal-level BfDI plus 17 Länder DPAs (one per federal state, plus separate ones for the public and private sectors in some Länder). Most cross-border cases are split between Hamburg, Berlin, Bavaria and Rhineland-Palatinate.
- 🇮🇹 Italy — Garante per la protezione dei dati personali — most active in AI-related enforcement (OpenAI, Replika).
- 🇪🇸 Spain — AEPD — issues by far the highest number of fines per year, but typically smaller individual amounts.
- 🇪🇪 Estonia — Andmekaitse Inspektsioon (AKI) — see our profile of AKI.
- 🇫🇮 Finland — Office of the Data Protection Ombudsman (Tietosuojavaltuutettu) — currently led by Anu Talus, who is also EDPB Chair.
One-stop-shop and the lead supervisory authority
For cross-border processing — processing that takes place in more than one Member State, or that substantially affects data subjects in more than one Member State — Article 56 designates a lead supervisory authority (the DPA of the controller’s main EU establishment) to take primary responsibility for the case. Other concerned DPAs participate, can object, and can trigger an EDPB Article 65 decision if they cannot agree.
The mechanism has two consequences in practice:
- Cross-border tech investigations channel through Ireland (where most US tech HQs sit) and Luxembourg (Amazon), even when most affected data subjects live elsewhere. This has caused recurrent friction between the DPC and other national DPAs.
- EDPB Article 65 binding decisions have become the actual decisive event in several of the largest cases — the Meta €1.2 billion transfer fine and the 2023 TikTok €345 million children’s-data fine were both shaped by binding EDPB decisions after the DPC’s draft decision was disputed by other DPAs. By contrast, the later TikTok €530 million transfer fine (May 2025) was a clean DPC one-stop-shop decision: no objections were raised by other DPAs and it did not go to Article 65 dispute resolution — a reminder that the lead-authority model still produces most outcomes without an EDPB override.
Penalties (Article 83)
Administrative fines under GDPR are graduated between two tiers. The structure:
| Tier | Article | Typical breaches | Maximum fine |
|---|---|---|---|
| Lower | 83(4) | Articles 8, 11, 25–39, 42, 43 — controller/processor obligations, DPO, records, security, certification body obligations | €10,000,000 or 2% of total worldwide annual turnover, whichever is higher |
| Higher | 83(5) | Articles 5, 6, 7, 9 (basic principles, lawful bases, conditions for consent, special categories), 12–22 (data subject rights), 44–49 (international transfers) | €20,000,000 or 4% of total worldwide annual turnover, whichever is higher |
| Higher | 83(6) | Non-compliance with an order from a supervisory authority (e.g., refusing to halt processing as ordered) | €20,000,000 or 4% of total worldwide annual turnover, whichever is higher |
Article 83(2) lists the factors the supervisory authority must weigh in setting the actual fine: nature, gravity and duration of the infringement; intentional vs negligent character; previous infringements; cooperation with the authority; categories of personal data affected; the manner the breach was discovered; etc. Member States may set additional national rules on the criminal sanctions for certain infringements (Article 84) on top of the administrative fines.
In practice the supervisory authority will calculate the fine using the EDPB Guidelines 04/2022 on the calculation of administrative fines, which provides a structured methodology adopted by every DPA.
Notable enforcement
The biggest GDPR fines on record (verified via enforcementtracker.com, CMS Law’s editorially-curated registry):
| Year | Company | Fine | DPA | Cause |
|---|---|---|---|---|
| 2023 | Meta Platforms Ireland | €1.2 billion (12 May 2023) | DPC Ireland | Continuing US transfers of EU user data after Schrems II without an adequate basis |
| 2025 | TikTok Technology | €530 million (2 May 2025) | DPC Ireland | Transfers of EEA user data to China without an adequate basis |
| 2022 | Meta Platforms (Instagram) | €405 million (2 September 2022) | DPC Ireland | Children’s data — public exposure of teenage users’ contact details by default |
| 2023 | Meta Platforms | €390 million (4 January 2023) | DPC Ireland | Reliance on “contract” as the legal basis for behavioural advertising on Facebook and Instagram |
| 2023 | TikTok | €345 million (1 September 2023) | DPC Ireland | Children’s data — default settings, profile visibility, parental controls |
A separate, very visible case — the €746 million fine issued by Luxembourg’s CNPD against Amazon Europe Core on 15 July 2021 over targeted advertising consent — has had a remarkable appellate history. The Luxembourg Administrative Tribunal upheld it on 18 March 2025; the Luxembourg Administrative Court (the higher court) annulled the decision on 12 March 2026 and sent the case back to the CNPD for fresh analysis on the criteria of fault and intentional violation. As of May 2026 the case is pending reconsideration.
Below the headline figures sit thousands of smaller enforcement actions: Spain’s AEPD has led the EU on the number of fines for six consecutive years (per CMS GDPR Enforcement Tracker, 2024/2025 report), followed by Italy and Romania. Most are in the four- to six-figure range, often for cookie-banner non-compliance, weak security or breach-notification failures.
How GDPR overlaps with other EU regimes
- ePrivacy Directive (2002/58/EC, as amended) — the “cookie law”. Governs the storage of and access to information on a user’s device (cookies, local storage, fingerprinting) and the confidentiality of electronic communications. Applies on top of GDPR; consent for non-essential cookies is governed by ePrivacy first, GDPR second. The long-promised ePrivacy Regulation has not been adopted.
- EU AI Act (Regulation 2024/1689) — applies in parallel. The AI Act regulates the AI system itself (risk classification, technical documentation, conformity assessment, market surveillance); GDPR continues to apply to the personal data flowing through the system. See our AI Act pillar.
- MiCA (Regulation 2023/1114) — CASPs hold KYC and transaction data. GDPR applies to that data on top of MiCA. See our MiCA pillar.
- DORA (Regulation 2022/2554) — operational resilience for financial entities, including incident notification regimes that overlap operationally with GDPR’s Article 33 breach-notification regime. See our DORA pillar.
- NIS 2 Directive (Directive (EU) 2022/2555) — cybersecurity obligations for “essential” and “important” entities. Article 33 GDPR breach notification and NIS 2 incident notification are separate but commonly trigger together.
- Digital Services Act (Regulation (EU) 2022/2065) and Digital Markets Act (Regulation (EU) 2022/1925) — content moderation and platform-competition obligations on very large online platforms; both refer back to GDPR for personal-data aspects.
What this means for you
If you’re a controller (you decide what to do with personal data — most companies are controllers for their customer and employee data):
- Build a record of processing activities (Article 30) before you do anything else. Without it, you cannot answer a DPA’s first question.
- For each processing operation: identify the lawful basis (Article 6), check whether special categories (Article 9) are involved, document the retention period, and write a privacy notice that gives the Article 13/14 information to data subjects in a clear, concise form.
- Set up a process for handling data subject requests (Articles 15–22) within one month, with internal escalation and a tracker that survives staff turnover.
- For high-risk processing, run a DPIA (Article 35) before the processing starts. Don’t retro-fit it after a complaint.
- Set up breach detection and notification infrastructure — the 72-hour clock starts from awareness of the breach, not from internal escalation.
- For transfers outside the EEA, check the adequacy decision map; otherwise put SCCs (or BCRs) in place and run the Schrems II transfer impact assessment.
If you’re a processor (you handle personal data on a controller’s instructions — typical for SaaS, cloud hosts, payroll providers, marketing-automation tools):
- Every relationship with a controller needs an Article 28 contract (sometimes called a “DPA” — data-processing agreement). The contract must include Article 28(3) mandatory clauses — purposes, duration, types of data, data-subject categories, controller’s instructions, processor obligations, sub-processor rules, security measures.
- You may only act on documented instructions from the controller. Going beyond instructions makes you a controller for that processing.
- You must assist the controller in responding to data subject requests, breach notification, DPIAs, prior consultation. Build the operational playbooks.
- Sub-processors require either specific or general written authorisation; either way, your contract with the sub-processor must impose the same data-protection obligations.
If you’re a data subject (everyone is):
- Your rights are listed in Articles 15–22; you exercise them by writing to the controller (most have a privacy email or web form).
- If you don’t get a response within one month, or you’re not satisfied with the response, you can complain to your national DPA — the EDPB list of DPA contacts is the authoritative directory.
- For cross-border issues, you can complain to the DPA of your habitual residence, your place of work, or the place of the alleged infringement; the lead supervisory authority is then identified and the case is routed to it.
TL;DR
GDPR is the EU’s general law on the processing of personal data, applied since 25 May 2018 across all 27 Member States plus the three EEA states. It is extraterritorial: any non-EU organisation that offers goods or services to people in the EU, or that monitors their behaviour, is in scope. Seven principles, six lawful bases (with stricter rules for special categories under Article 9), eight enforceable rights for data subjects (Articles 15–22), and procedural plumbing — records of processing, DPIAs, breach notification within 72 hours — make up the day-to-day compliance work. Cross-border data transfers go through adequacy decisions (UK, US-DPF, Korea, Japan, Canada commercial, Switzerland and others), Standard Contractual Clauses (Commission Decision 2021/914), or Binding Corporate Rules; Schrems II invalidated the prior US Privacy Shield in 2020 and forced exporters to do a transfer-impact assessment. Enforcement is by national DPAs coordinated by the EDPB (Chair: Anu Talus, Finland) and, for EU institutions, by the EDPS (Wojciech Wiewiórowski). Penalties tier at €10M or 2% worldwide turnover for procedural failures and €20M or 4% worldwide turnover for the most serious breaches; the largest fine on record is €1.2 billion against Meta in 2023 over EU–US transfers.
Sources
- Regulation (EU) 2016/679 — full text on EUR-Lex — official source of GDPR
- European Data Protection Board (EDPB) — guidelines, opinions, Article 65 decisions, EDPB membership
- European Data Protection Supervisor (EDPS) — supervisor of EU institutions
- European Commission — adequacy decisions overview
- Commission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
- Schrems II — CJEU C-311/18 judgment of 16 July 2020
- enforcementtracker.com — CMS Law’s editorially-curated registry of GDPR fines
- EDPB Guidelines 04/2022 on the calculation of administrative fines