GDPR
GDPR
Definition: The General Data Protection Regulation, the European Union’s comprehensive data privacy law governing how companies collect, store, and process personal data of EU residents.
How It Works
- Territorial scope (Article 3): applies to any organization processing personal data of people in the EU, regardless of where the organization is based. A US company with no EU office is still covered if it sells to or tracks EU residents.
- Lawful basis required (Article 6): every processing activity needs one of six legal grounds: consent, contract necessity, legal obligation, vital interests, public task, or legitimate interests. No basis means no lawful processing.
- Data subject rights: access (know what’s held), rectification (fix errors), erasure (“right to be forgotten”), portability (export in a usable format), restriction of processing, and objection to processing, including automated profiling.
- Business obligations: appoint a Data Protection Officer above certain processing thresholds, maintain records of processing activity, run Data Protection Impact Assessments for high-risk processing, sign Data Processing Agreements with vendors, and report breaches to the supervisory authority within 72 hours.
- Consent standard: must be freely given, specific, informed, and unambiguous. Pre-checked boxes and bundled consent do not count as valid consent.
- Cross-border transfers: moving EU personal data outside the EU requires a safeguard: an adequacy decision for the destination country, Standard Contractual Clauses, or Binding Corporate Rules for intra-group transfers.
- Privacy by design and by default (Article 25): systems must be built to minimize data collection and protect privacy from the start, not bolted on after launch.
- Enforced by national Data Protection Authorities (DPAs) in each EU member state, coordinated through the European Data Protection Board for cross-border cases.
Key Articles at a Glance
| Article | Covers |
|---|---|
| Art 3 | Territorial scope, including non-EU companies |
| Art 5 | Core principles: minimization, purpose limitation, accuracy, storage limits |
| Art 6 | Lawful bases for processing |
| Art 7 | Conditions for valid consent |
| Art 12-23 | Data subject rights (access, erasure, portability, objection) |
| Art 33-34 | Breach notification to authorities and affected individuals |
| Art 35 | Data Protection Impact Assessments |
| Art 83 | Administrative fines and their tiers |
Data Subject Rights in Detail
| Right | Article | What it means in practice |
|---|---|---|
| Access | Art 15 | User can request a copy of all personal data held about them |
| Rectification | Art 16 | User can correct inaccurate or incomplete data |
| Erasure | Art 17 | User can request deletion, subject to legal-retention exceptions |
| Portability | Art 20 | User can receive their data in a structured, machine-readable format |
| Restriction | Art 18 | User can pause processing while a dispute is resolved |
| Objection | Art 21 | User can stop processing based on legitimate interests or direct marketing |
Under the Hood
Choosing a lawful basis under Article 6 is the first engineering decision behind any data collection form, not an afterthought:
Given: A user submits a GDPR erasure request on day 0. Step: The business has 1 month to respond, deadline day 30. If the request is complex, for example the data is spread across many systems and third-party processors, the business may extend the deadline by up to 2 further months, but must notify the user of the extension and the reason for it within the original 1-month window. Answer: Final legal deadline is day 90. The required interim notice of the extension is due by day 30, not day 90.
Given: An e-commerce company wants to email past customers a marketing newsletter. Step: Contract necessity covers the order confirmation email but not marketing. Legitimate interest could apply, but requires a documented balancing test and an easy opt-out. Consent is the safer, unambiguous ground for marketing specifically. Answer: The company relies on consent (Art 6(1)(a)) for the newsletter, and contract necessity (Art 6(1)(b)) for the transactional order email, tracked as two separate lawful bases in its records of processing.
Given: A user requests erasure, but the company also needs some of that data to comply with a 7-year financial record-keeping law. Step: Article 17(3) lists exceptions to the right to erasure, including compliance with a legal obligation. The company must still delete everything not covered by the exception. Answer: The company deletes marketing and profile data immediately, but retains only the specific financial records required by law, and documents the legal basis for that retention.
Given: A ransomware attack exposes a customer database at 9:00 AM on a Monday. Step: Article 33 requires notification to the supervisory authority within 72 hours of the company becoming aware of the breach. If the breach poses a high risk to individuals, Article 34 also requires notifying those individuals directly, without undue delay. Answer: The authority notification is due by 9:00 AM Thursday. Affected users must also be told directly, since a stolen customer database is a high-risk breach, not just a low-risk internal log leak.
Why It Matters
- Fines are large and revenue-based: up to €20 million or 4% of a company’s total worldwide annual revenue, whichever is higher, not just EU revenue.
- Extraterritorial reach: any company with EU users is in scope, so “we’re not a European company” is not a defense.
- Engineering consequences are concrete: teams need a data map (what personal data exists, where it lives, who processes it), a deletion pipeline that reaches production databases, backups, logs, caches, and analytics tools, and a 72-hour breach notification process that works under pressure, not just on paper.
- Vendor risk flows downstream: every subprocessor a company uses needs its own Data Processing Agreement, so GDPR compliance work rarely stays contained to one team.
- Audits ask for evidence, not intent: a SOC 2 or enterprise security review will often ask for the actual data map and deletion process, not just a policy document describing them.
- Shaped privacy law well beyond the EU: California’s CCPA, Brazil’s LGPD, and other regional laws borrowed heavily from its structure and vocabulary.
Common Pitfalls
- Assuming GDPR only applies to European companies, when Article 3’s extraterritorial scope covers any company handling EU residents’ data.
- Writing a privacy policy that promises deletion or export rights without a technical mechanism that can actually reach every system, including backups and third-party processors, that holds a copy of the data.
- Using dark patterns in cookie consent banners: pre-ticked boxes, a prominent “Accept All” button next to a buried or multi-click “Reject” option, which regulators have specifically targeted in enforcement actions.
- Treating one Data Processing Agreement as covering all vendors, instead of confirming each subprocessor’s own compliance and data transfer mechanism.
- Missing the 72-hour breach notification clock because no single team owns the process end to end.
- Logging or caching personal data in places the deletion pipeline doesn’t know about, like debug logs, error trackers, or analytics warehouses.
- Relying on a single blanket consent checkbox for multiple unrelated purposes (analytics, marketing, third-party sharing), instead of granular, purpose-specific consent as Article 7 requires.
- Forgetting that consent must be as easy to withdraw as it was to give, so a “subscribe” button with no matching one-click “unsubscribe” path is itself a compliance gap.
- Storing the DPA/DPIA paperwork but never actually running the impact assessment before shipping a high-risk feature like biometric login or large-scale profiling.
- This section is informational only and is not legal advice; consult qualified counsel for compliance decisions.
Comparison
| GDPR | CCPA | |
|---|---|---|
| Jurisdiction | EU residents, worldwide reach (Art 3) | California residents, threshold-based business scope |
| Default | Opt-in: consent or another lawful basis required before processing | Opt-out: processing allowed by default, consumer can opt out of sale/sharing |
| Private right of action | Limited; mainly via DPA complaints and collective redress (Art 80) | Limited to data breaches, with statutory damages |
| Response deadline | 1 month, extendable by 2 more months | 45 days, extendable by another 45 days |
| Breach notification | Within 72 hours to the supervisory authority | “Without unreasonable delay” to affected consumers |
| Maximum penalties | Up to €20M or 4% of global annual revenue | Up to $7,500 per intentional violation |
| Enforcement | National DPAs plus the European Data Protection Board | California Privacy Protection Agency (CPPA) |
| Consent standard | Explicit opt-in, granular by purpose | Implied consent unless the consumer opts out |
| Minors’ data | Parental consent generally required under 16 | Opt-in (not opt-out) required for consumers under 16 |
Example
Two widely reported enforcement actions show what GDPR risk actually looks like in practice:
- Meta, 2023 (Irish DPC): fined €1.2 billion, the largest GDPR fine to date, for transferring EU users’ data to the United States without adequate safeguards after the EU-US Privacy Shield framework was invalidated.
- Google, 2019 (France’s CNIL): fined €50 million for failing to give clear, easily accessible information about its data processing and for not obtaining valid, specific consent for personalized ads.
Together the cases show both the scale of GDPR penalties and how consent flows and cross-border data transfer mechanics, not just having a privacy policy on file, are squarely within its scope.
Related Terms
Referenced by