GDPR

GDPR

Definition: The General Data Protection Regulation, the European Union’s comprehensive data privacy law governing how companies collect, store, and process personal data of EU residents.

How It Works

  • Territorial scope (Article 3): applies to any organization processing personal data of people in the EU, regardless of where the organization is based. A US company with no EU office is still covered if it sells to or tracks EU residents.
  • Lawful basis required (Article 6): every processing activity needs one of six legal grounds: consent, contract necessity, legal obligation, vital interests, public task, or legitimate interests. No basis means no lawful processing.
  • Data subject rights: access (know what’s held), rectification (fix errors), erasure (“right to be forgotten”), portability (export in a usable format), restriction of processing, and objection to processing, including automated profiling.
  • Business obligations: appoint a Data Protection Officer above certain processing thresholds, maintain records of processing activity, run Data Protection Impact Assessments for high-risk processing, sign Data Processing Agreements with vendors, and report breaches to the supervisory authority within 72 hours.
  • Consent standard: must be freely given, specific, informed, and unambiguous. Pre-checked boxes and bundled consent do not count as valid consent.
  • Cross-border transfers: moving EU personal data outside the EU requires a safeguard: an adequacy decision for the destination country, Standard Contractual Clauses, or Binding Corporate Rules for intra-group transfers.
  • Privacy by design and by default (Article 25): systems must be built to minimize data collection and protect privacy from the start, not bolted on after launch.
  • Enforced by national Data Protection Authorities (DPAs) in each EU member state, coordinated through the European Data Protection Board for cross-border cases.

Key Articles at a Glance

ArticleCovers
Art 3Territorial scope, including non-EU companies
Art 5Core principles: minimization, purpose limitation, accuracy, storage limits
Art 6Lawful bases for processing
Art 7Conditions for valid consent
Art 12-23Data subject rights (access, erasure, portability, objection)
Art 33-34Breach notification to authorities and affected individuals
Art 35Data Protection Impact Assessments
Art 83Administrative fines and their tiers

Data Subject Rights in Detail

RightArticleWhat it means in practice
AccessArt 15User can request a copy of all personal data held about them
RectificationArt 16User can correct inaccurate or incomplete data
ErasureArt 17User can request deletion, subject to legal-retention exceptions
PortabilityArt 20User can receive their data in a structured, machine-readable format
RestrictionArt 18User can pause processing while a dispute is resolved
ObjectionArt 21User can stop processing based on legitimate interests or direct marketing

Under the Hood

Choosing a lawful basis under Article 6 is the first engineering decision behind any data collection form, not an afterthought:

Given: A user submits a GDPR erasure request on day 0. Step: The business has 1 month to respond, deadline day 30. If the request is complex, for example the data is spread across many systems and third-party processors, the business may extend the deadline by up to 2 further months, but must notify the user of the extension and the reason for it within the original 1-month window. Answer: Final legal deadline is day 90. The required interim notice of the extension is due by day 30, not day 90.

Given: An e-commerce company wants to email past customers a marketing newsletter. Step: Contract necessity covers the order confirmation email but not marketing. Legitimate interest could apply, but requires a documented balancing test and an easy opt-out. Consent is the safer, unambiguous ground for marketing specifically. Answer: The company relies on consent (Art 6(1)(a)) for the newsletter, and contract necessity (Art 6(1)(b)) for the transactional order email, tracked as two separate lawful bases in its records of processing.

Given: A user requests erasure, but the company also needs some of that data to comply with a 7-year financial record-keeping law. Step: Article 17(3) lists exceptions to the right to erasure, including compliance with a legal obligation. The company must still delete everything not covered by the exception. Answer: The company deletes marketing and profile data immediately, but retains only the specific financial records required by law, and documents the legal basis for that retention.

Given: A ransomware attack exposes a customer database at 9:00 AM on a Monday. Step: Article 33 requires notification to the supervisory authority within 72 hours of the company becoming aware of the breach. If the breach poses a high risk to individuals, Article 34 also requires notifying those individuals directly, without undue delay. Answer: The authority notification is due by 9:00 AM Thursday. Affected users must also be told directly, since a stolen customer database is a high-risk breach, not just a low-risk internal log leak.

Why It Matters

  • Fines are large and revenue-based: up to €20 million or 4% of a company’s total worldwide annual revenue, whichever is higher, not just EU revenue.
  • Extraterritorial reach: any company with EU users is in scope, so “we’re not a European company” is not a defense.
  • Engineering consequences are concrete: teams need a data map (what personal data exists, where it lives, who processes it), a deletion pipeline that reaches production databases, backups, logs, caches, and analytics tools, and a 72-hour breach notification process that works under pressure, not just on paper.
  • Vendor risk flows downstream: every subprocessor a company uses needs its own Data Processing Agreement, so GDPR compliance work rarely stays contained to one team.
  • Audits ask for evidence, not intent: a SOC 2 or enterprise security review will often ask for the actual data map and deletion process, not just a policy document describing them.
  • Shaped privacy law well beyond the EU: California’s CCPA, Brazil’s LGPD, and other regional laws borrowed heavily from its structure and vocabulary.

Common Pitfalls

  • Assuming GDPR only applies to European companies, when Article 3’s extraterritorial scope covers any company handling EU residents’ data.
  • Writing a privacy policy that promises deletion or export rights without a technical mechanism that can actually reach every system, including backups and third-party processors, that holds a copy of the data.
  • Using dark patterns in cookie consent banners: pre-ticked boxes, a prominent “Accept All” button next to a buried or multi-click “Reject” option, which regulators have specifically targeted in enforcement actions.
  • Treating one Data Processing Agreement as covering all vendors, instead of confirming each subprocessor’s own compliance and data transfer mechanism.
  • Missing the 72-hour breach notification clock because no single team owns the process end to end.
  • Logging or caching personal data in places the deletion pipeline doesn’t know about, like debug logs, error trackers, or analytics warehouses.
  • Relying on a single blanket consent checkbox for multiple unrelated purposes (analytics, marketing, third-party sharing), instead of granular, purpose-specific consent as Article 7 requires.
  • Forgetting that consent must be as easy to withdraw as it was to give, so a “subscribe” button with no matching one-click “unsubscribe” path is itself a compliance gap.
  • Storing the DPA/DPIA paperwork but never actually running the impact assessment before shipping a high-risk feature like biometric login or large-scale profiling.
  • This section is informational only and is not legal advice; consult qualified counsel for compliance decisions.

Comparison

GDPRCCPA
JurisdictionEU residents, worldwide reach (Art 3)California residents, threshold-based business scope
DefaultOpt-in: consent or another lawful basis required before processingOpt-out: processing allowed by default, consumer can opt out of sale/sharing
Private right of actionLimited; mainly via DPA complaints and collective redress (Art 80)Limited to data breaches, with statutory damages
Response deadline1 month, extendable by 2 more months45 days, extendable by another 45 days
Breach notificationWithin 72 hours to the supervisory authority“Without unreasonable delay” to affected consumers
Maximum penaltiesUp to €20M or 4% of global annual revenueUp to $7,500 per intentional violation
EnforcementNational DPAs plus the European Data Protection BoardCalifornia Privacy Protection Agency (CPPA)
Consent standardExplicit opt-in, granular by purposeImplied consent unless the consumer opts out
Minors’ dataParental consent generally required under 16Opt-in (not opt-out) required for consumers under 16

Example

Two widely reported enforcement actions show what GDPR risk actually looks like in practice:

  • Meta, 2023 (Irish DPC): fined €1.2 billion, the largest GDPR fine to date, for transferring EU users’ data to the United States without adequate safeguards after the EU-US Privacy Shield framework was invalidated.
  • Google, 2019 (France’s CNIL): fined €50 million for failing to give clear, easily accessible information about its data processing and for not obtaining valid, specific consent for personalized ads.

Together the cases show both the scale of GDPR penalties and how consent flows and cross-border data transfer mechanics, not just having a privacy policy on file, are squarely within its scope.

Dig deeper