Glossary/Compliance/General Data Protection Regulation
Compliance

General Data Protection Regulation

GDPR

General Data Protection Regulation is the EU regulation governing personal data processing, in force since 25 May 2018, with extraterritorial reach over any controller or processor handling EU residents' data.

What GDPR is

The General Data Protection Regulation (GDPR) is Regulation (EU) 2016/679, applicable from 25 May 2018. It replaced the 1995 Data Protection Directive and harmonised data-protection law across the European Economic Area.

Its territorial scope under Article 3 is famously broad: GDPR applies to any controller or processor established in the EU, and to any non-EU controller or processor that offers goods or services to EU data subjects or monitors their behaviour in the EU.

The regulation rests on six lawful bases for processing under Article 6 plus stricter conditions for special-category data under Article 9, and on six core principles in Article 5: lawfulness, fairness, and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality.

Accountability is the seventh, overarching principle: controllers must be able to demonstrate compliance, not just claim it.

Enforcement is delegated to national supervisory authorities (the ICO in the UK, the CNIL in France, the BfDI in Germany, the Garante in Italy), coordinated through the European Data Protection Board (EDPB). Maximum administrative fines reach 20 million EUR or 4 percent of total worldwide annual turnover, whichever is higher.

When you will meet GDPR

You will encounter GDPR as soon as you process the personal data of anyone in the EU or EEA, regardless of where your company is incorporated. Typical touchpoints are the website privacy notice, cookie consent banner, processor agreements with vendors, Records of Processing Activities, Data Protection Impact Assessments for high-risk processing, and breach notifications to the supervisory authority within 72 hours.

Where this comes up in our guides

General Data Protection Regulation FAQ

Yes, when the company offers goods or services to people in the EU or monitors their behaviour in the EU. The test is the location of the data subject, not the company. A US SaaS with EU customers is in scope and typically must designate an Article 27 EU Representative.
At a glance
Category
Compliance
Also written
GDPR
Confirm current figures with the official registry or a qualified adviser before relying on them.
Related terms
← All 120 glossary terms
Sources
  1. 1Regulation (EU) 2016/679 (GDPR), Official Journal of the European Union
  2. 2European Data Protection Board (EDPB) Guidelines
  3. 3UK Information Commissioner's Office GDPR Guide
Definition reviewed March 2026.
Put it to use

Eight jurisdictions, costed out in full.

See what a company actually costs in year one, and how the jurisdictions compare on tax, capital and timeline.

Tax calculatorEffective rates on your revenue and margin.Country comparisonEleven criteria, side by side.Cost estimatorWhat the first year actually costs.Document checklistWhat each registry will ask for.

New terms as the rules change

Thresholds move, regimes close, new ones open. One email, no pitches.