General Data Protection Regulation is the EU regulation governing personal data processing, in force since 25 May 2018, with extraterritorial reach over any controller or processor handling EU residents' data.
The General Data Protection Regulation (GDPR) is Regulation (EU) 2016/679, applicable from 25 May 2018. It replaced the 1995 Data Protection Directive and harmonised data-protection law across the European Economic Area.
Its territorial scope under Article 3 is famously broad: GDPR applies to any controller or processor established in the EU, and to any non-EU controller or processor that offers goods or services to EU data subjects or monitors their behaviour in the EU.
The regulation rests on six lawful bases for processing under Article 6 plus stricter conditions for special-category data under Article 9, and on six core principles in Article 5: lawfulness, fairness, and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality.
Accountability is the seventh, overarching principle: controllers must be able to demonstrate compliance, not just claim it.
Enforcement is delegated to national supervisory authorities (the ICO in the UK, the CNIL in France, the BfDI in Germany, the Garante in Italy), coordinated through the European Data Protection Board (EDPB). Maximum administrative fines reach 20 million EUR or 4 percent of total worldwide annual turnover, whichever is higher.
You will encounter GDPR as soon as you process the personal data of anyone in the EU or EEA, regardless of where your company is incorporated. Typical touchpoints are the website privacy notice, cookie consent banner, processor agreements with vendors, Records of Processing Activities, Data Protection Impact Assessments for high-risk processing, and breach notifications to the supervisory authority within 72 hours.
See what a company actually costs in year one, and how the jurisdictions compare on tax, capital and timeline.