General Data Protection Regulation
The General Data Protection Regulation (GDPR) is a comprehensive privacy and data protection law that governs how personal data is collected, processed, stored, and shared across the European Union and the European Economic Area. Since taking effect in 2018, it has become one of the world’s most influential privacy frameworks, shaping regulatory approaches and business practices far beyond Europe.
Purpose and Scope
GDPR was designed to strengthen individual control over personal information while creating a more consistent set of data protection rules across EU member states. It applies not only to organizations established in the EU, but also to organizations elsewhere that offer goods or services to people in the EU or monitor their behavior.
The regulation covers personal data, meaning information that can identify a person directly or indirectly, including names, email addresses, identification numbers, location data, and online identifiers. Organizations that process such information must have a lawful basis for doing so and must handle it transparently and securely.
Key Rights for Individuals
A central feature of GDPR is the set of rights granted to individuals regarding their personal data. These rights include access to personal information, correction of inaccurate data, deletion in certain circumstances (the “right to be forgotten”), restriction of processing, data portability, and the ability to object to certain forms of processing.
Organizations must also provide clear privacy notices explaining how data is used and, in many situations, obtain valid consent before processing information. Consent must be freely given, specific, informed, and unambiguous.
Organizational Responsibilities
Organizations subject to GDPR must implement privacy-by-design and privacy-by-default principles, meaning data protection considerations should be built into systems and processes from the start. They are expected to collect only the data necessary for a specific purpose and retain it only as long as needed.
Additional obligations may include conducting data protection impact assessments, appointing a Data Protection Officer (DPO) in certain situations, maintaining records of processing activities, and reporting qualifying personal data breaches to regulators within prescribed timeframes.
Impact and Enforcement
GDPR is widely regarded as a landmark privacy regulation because of its broad territorial reach and significant enforcement powers. Supervisory authorities in EU member states can investigate violations and impose substantial penalties, with the most serious infringements potentially leading to fines of up to €20 million or 4% of an organization’s worldwide annual turnover, whichever is higher.
Beyond enforcement, GDPR has influenced privacy legislation around the world and encouraged organizations to adopt stronger data governance, transparency, and security practices as part of everyday operations.