The General Data Protection Regulation (GDPR) is the EU’s comprehensive data privacy law, effective since 25 May 2018. It applies to any organization worldwide that offers goods or services to people in the EU or tracks their behavior. Organizations that break these rules can face fines up to €20 million or 4% of their global annual turnover, whichever is higher.
Between January 2025 and January 2026, GDPR fines totaled €1.2 billion, matching the previous year. Over eight years, fines have reached about €7.1 billion, according to DLA Piper’s annual GDPR enforcement survey. No other privacy law is enforced at this scale, and many fined companies are outside Europe. With GDPR, what matters is whose data you handle, not where your company is located.
Key takeaways
- Geography follows the data subject, not your company. Offer EU users goods or services, or monitor their browsing, and GDPR applies, US headquarters and all.
- Assume you are a controller. If you decide why and how data is collected on your properties, the full duty set and the primary liability are yours.
- Nothing non-essential fires before consent. Opt-in is the operating default, and withdrawal must be as easy as giving. A banner that promises this while tags fire anyway is evidence, not compliance.
- The 72-hour breach clock is real. Know your notification path before you need it.
- Fines come in two tiers: €10 million or 2% and €20 million or 4% of global turnover, whichever is higher. The biggest checks have been written for transfer and consent failures, not exotic violations.
- Compliance is observable. What your site actually sends, to whom, and when, can be measured, and regulators, researchers, and plaintiffs already do.
If you run a website, buy or build software, handle customer data, or want to know what the law behind every consent banner says, this guide covers what GDPR is, who it applies to, what it demands, and where compliance becomes visible.
What is GDPR?
The General Data Protection Regulation is a directly binding EU regulation, formally Regulation (EU) 2016/679, setting one set of data protection rules across the European Union and the wider European Economic Area. A regulation needs no national transposition. The same text has applied identically in every member state since 25 May 2018.
Quick facts:
- Replaces: the 1995 Data Protection Directive and its patchwork of 28 national implementations. One rulebook for the single market.
- Protects: “personal data,” meaning any information relating to an identified or identifiable person, from names and email addresses to IP addresses and cookie IDs.
Does GDPR apply to you?
GDPR protects people in the EU. Citizenship is irrelevant. The law follows their data to whoever handles it, wherever they sit.
The two triggers that pull a US company in
You do not need to have an office or presence in Europe. A company without one still falls under GDPR as soon as either of the following applies:
- You offer goods or services to people in the EU. Payment is irrelevant: a free app, newsletter, or SaaS trial aimed at EU users counts. Regulators look for indicators like EU languages or currencies, EU domains, EU shipping.
- You monitor the behavior of people in the EU. Tracking EU visitors as they browse (analytics, ad pixels, behavioral profiling, session replay) counts as “monitoring” under the law. This happens in the browser, not in your server room.

If either trigger applies and you have no EU establishment, you must appoint an EU-based representative (Article 27) to act as your contact point for regulators and data subjects. The exception is very limited and only applies to occasional, low-risk processing with no large-scale sensitive or criminal-conviction data. A website that regularly tracks EU visitors does not qualify.
The law also governs where EU data goes. Serving EU customers from US servers raises transfer questions with rules of their own.
Who GDPR does not apply to
- Purely personal or household activity: your address book, family photos, your own home camera.
- No EU targeting or monitoring: a US-only business serving US customers falls outside the triggers above.
- Deceased persons: GDPR protects the living. Member states may legislate for the dead.
- Anonymous data: information that cannot be linked back to an identifiable person falls outside the regulation entirely.
Key terms: personal data, data subject, processing
Three Article 4 definitions unlock the whole regulation. If you can classify your data using these terms, the rest of the law becomes much clearer.
| Term | Plain meaning | Where defined | On your website |
| Personal data | Any information relating to an identified or identifiable person, including indirect identifiers | Art. 4(1) | Email addresses, names, IP addresses, cookie IDs, device fingerprints, location data |
| Data subject | The living person the data is about: GDPR’s word for “user,” “customer,” or “visitor” | Art. 4(1) | Every person who fills in your form or lands on your page |
| Processing | Virtually anything done with personal data: collecting, storing, reading, combining, sharing, deleting | Art. 4(2) | An analytics tag firing, a CRM sync, a support ticket export |
| Special categories | Sensitive data (health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, union membership, sex life or orientation). Processing banned unless a narrow exception applies | Art. 9 | Health intake forms, inferred-interest ad segments, accessibility settings that reveal disability |
Two consequences follow. “We don’t collect personal data” is almost never true of a website: IP addresses and cookie IDs are personal data, full stop. And if special-category data flows through your forms or tools, the default rule is do not process it.
Data controller vs data processor
Every GDPR obligation lands on one of two roles. Most organizations wear both hats.
| Data controller | Data processor | |
| Decides | Why and how personal data is processed | Nothing. It acts on the controller’s documented instructions |
| Typical examples | The website owner, the employer with HR records, the SaaS vendor for its own account data | Your email platform, cloud host, payroll provider |
| Key duties | Lawful basis, notices, honoring data subject rights, security, breach notification, records | Contractual processing only, security, supporting the controller, breach alerts to the controller |
| Liability | Primary: answers for the whole processing chain, including its processors | Direct liability for its own security and instruction-breaking |
Why the split matters in practice:
- You are the controller for your own website’s data. Your analytics vendor, tag manager, and email platform are your processors, and their mistakes can still be your problem.
- Every processor relationship needs a contract. Article 28 requires a data processing agreement (DPA) covering instructions, security, and sub-processors. More details are in our third-party risk guide.
- Controllers answer the regulator’s questions. When something goes wrong, the regulator calls the controller first.
When you must appoint a DPO
Not everyone needs one. Article 37 makes a Data Protection Officer mandatory when:
- you are a public authority
- your core activities require large-scale, regular and systematic monitoring of people, or
- your core activities involve large-scale processing of special-category or criminal-conviction data
Everyone else may appoint one voluntarily. Either way, the DPO monitors compliance internally, acts as the regulator’s contact point, and must have their contact details published.
The 7 principles of GDPR
Article 5 sets out seven key principles. These principles are the foundation of the law, and every other requirement in the regulation is based on them.
- Lawfulness, fairness, transparency: A valid legal basis, no deception, and people told it is happening.
- Purpose limitation: Collect data for a stated, specific purpose. Don’t quietly repurpose it later.
- Data minimization: Only collect the data you actually need for your purpose. Any extra form field you do not need can become a risk.
- Accuracy: Keep personal data correct and current. Fix or erase what is wrong.
- Storage limitation: Keep data identifiable only as long as needed, then delete or anonymize it (data retention rules).
- Integrity and confidentiality: Data security through appropriate technical and organizational measures.
- Accountability: The provable principle. The controller must be able to demonstrate all of the above, with documentation, not intentions.
Accountability is the one regulators lean on hardest. In an investigation, “we take privacy seriously” is not evidence: records, assessments, contracts, and logs are.
What makes processing legal, and what counts as consent
Processing personal data is illegal by default. One of six lawful bases in Article 6 must apply:
- Consent: the person said yes to the standard below. For optional processing: marketing emails, non-essential cookies, optional profiling.
- Contract: necessary to deliver what the person signed up for: shipping the order, running the account.
- Legal obligation: the law requires it: tax records, employment reporting.
- Vital interests: necessary to protect someone’s life. Rare and narrow.
- Public task: public authorities’ official functions. Rarely relevant to private companies.
- Legitimate interests: a genuine business need, documented through a balancing test, that doesn’t override the person’s rights. The most used and most abused basis. Regulators demand the paperwork.
Pick the basis before collecting. It constrains everything that follows. Do not default to consent: where another basis genuinely fits, it outlasts consent, which can be withdrawn.
The consent standard most cookie banners fail
GDPR consent must be freely given, specific, informed, and unambiguous, signaled by a clear affirmative action. Direct consequences:
- Pre-ticked boxes, silence, and inactivity are not consent.
- Consent bundled into terms of service is not valid.
- People must be able to withdraw their consent at any time, and it should be just as easy as giving (Article 7(3)). If accepting takes one click but refusing takes four, the consent is not valid.
This is the standard your cookie banner is measured against. And the gap between banner and behavior is where enforcement keeps landing. Watch for it on your own site.
What rights do people have under GDPR?
GDPR gives every data subject eight enforceable rights. Any controller holding their data must honor them:
- Right to be informed (Arts. 13–14): to know who is processing their data, why, and for how long.
- Right of access (Art. 15): a copy of their data and how it is processed.
- Right to rectification (Art. 16): to have inaccurate data corrected.
- Right to erasure (Art. 17): the “right to be forgotten.” Deletion when data is no longer needed, consent is withdrawn, or processing was unlawful.
- Right to restrict processing (Art. 18): to freeze use of data while a dispute is resolved.
- Right to data portability (Art. 20): their data in a machine-readable format, transmissible elsewhere.
- Right to object (Art. 21): to stop processing based on legitimate interests or for direct marketing, where objection is absolute.
- Rights around automated decisions (Art. 22): not to be subject to solely automated decisions with legal or similarly significant effects, save narrow exceptions.
Requests are free, bar manifestly unfounded or excessive ones. They must be answered within one month.
What GDPR requires of organizations
These are the core duties. Each has its deep guide one click away.
| Duty | What it means in practice | Deep guide |
| Privacy notices (Arts. 13–14) | Disclose at collection: who you are, what and why you collect, recipients, retention | Your consent-and-notice layer |
| Records of Processing Activities (ROPA) (Art. 30) | Living inventory: what you process, why, where it goes, recipients | The artifact regulators ask for first |
| Security / TOMs (Art. 32) | Technical and organizational measures: encryption, access control, resilience, all tested | Our security-measures coverage |
| Data protection by design and by default (Art. 25) | Privacy built in from the first sketch. Defaults set to most protective | Design-stage, not retrofit |
| Breach notification (Art. 33) | Notify the supervisory authority within 72 hours of awareness if rights are at risk. Notify affected people without undue delay when the risk is high | Breach notification and privacy incidents |
| DPIA (Art. 35) | A Data Protection Impact Assessment before high-risk processing: systematic monitoring, large-scale sensitive data, new technologies | Privacy impact assessments |
| DPO (Art. 37–39) | Appoint a Data Protection Officer when the triggers apply | Triggers covered above |
None of these duties requires an EU office, an EU lawyer, or certification. They are operational artifacts. And the 72-hour breach clock is the one with a literal deadline.
GDPR fines and enforcement
Enforcement runs through national Data Protection Authorities, one per member state, with the European Data Protection Board (EDPB) coordinating cross-border consistency. Two tiers of administrative fines cap the exposure. Article 83 sets both:
| Tier | Cap | What lands here |
| Lower | €10 million or 2% of total worldwide annual turnover, whichever is higher | Records, security-by-design, DPIA and breach-notification failures, certification and monitoring bodies |
| Upper | €20 million or 4% of total worldwide annual turnover, whichever is higher | Core violations: the principles, lawful basis, data subject rights, unlawful transfers, DPA orders ignored |
“Whichever is higher” is the operative phrase: for large companies the percentage applies to global group turnover, which is how a single decision reaches ten figures. Fines are not the only remedy. DPAs can order processing stopped, and Article 82 lets individuals claim compensation for material and non-material damage, fueling private actions.
What the biggest fines were actually for:
The record has a pattern. Headline fines punish the ordinary duties covered above: lawful basis, consent, transfers, security.
- Meta: €1.2 billion (May 2023). The largest GDPR fine ever: Ireland’s DPC, acting on an EDPB binding decision that compelled the fine, found Meta’s transfers of European Facebook data to US servers breached the transfer rules. EDPB Chair Andrea Jelinek: “The unprecedented fine is a strong signal to organizations that serious infringements have far-reaching consequences.” Meta was also ordered to suspend the transfers and fix its US-stored data. The corrective orders outlast the headline number.
- TikTok: €530 million (2025). The largest fine of 2025, again Ireland’s DPC: European user data flowing to China, plus transparency failures. The transfer rules are where the biggest checks keep getting written.
- Google: €100 million (December 2020). France’s CNIL fined Google for advertising cookies placed on google.fr before consent, with a defective opt-out: a website-layer violation, enforced against banner mechanics.
- The background rate: beyond the headlines, 443 breach notifications per day in the year to January 2026, up 22%. That is enforcement’s ordinary machinery running at record volume, per DLA Piper’s January 2026 survey.
Is there a GDPR in the US? (GDPR vs CCPA and state laws)
No. The US has no comprehensive federal privacy law. What exists is sectoral federal statutes (HIPAA for health, GLBA for finance, COPPA for children) plus a state patchwork: around twenty comprehensive state laws in effect, led by the California Consumer Privacy Act (CCPA/CPRA). The last serious federal attempt, the American Privacy Rights Act, died in Congress in 2024.
The biggest difference is not the checklist of rights. It is the consent model. For US operators, that is a mental flip:

| GDPR (EU/EEA) | CCPA/CPRA (California) | Other US state laws | |
| Scope | Any organization worldwide targeting or monitoring people in the EU | For-profits over revenue/volume thresholds handling California residents’ data | Similar thresholds, varying by state |
| Key rights | The eight rights listed above | Know, delete, correct, opt-out of sale/share, limit sensitive-PI use | California-like, with variations |
| Enforcer | National DPAs + EDPB | California Privacy Protection Agency + Attorney General | State attorneys general |
| Private lawsuits | Yes, compensation for material and non-material damage (Art. 82) | Limited, mainly data breaches | Mostly none |
Complying with your home-state law barely moves you toward GDPR compliance, because the defaults are inverted. US state laws let tags fire until visitors opt out. GDPR lets nothing non-essential fire until they opt in. (More: What is CCPA and the CCPA compliance guide.)
Can EU personal data leave the EU?
Yes. Chapter V of the regulation makes transfers a privilege, not a default. EU personal data may move to a third country only under an approved mechanism:
- Adequacy decisions: the European Commission declares a country’s protections “essentially equivalent.” For US companies, the relevant one is the EU–US Data Privacy Framework (DPF), adopted in July 2023: data flows freely to DPF-self-certified US companies; no further mechanism needed.
- Standard Contractual Clauses (SCCs): Commission contract terms binding the importer to GDPR-level protection, plus a transfer impact assessment of destination law. The workhorse for non-certified vendors.
- Binding Corporate Rules (BCRs): regulator-approved internal codes for transfers within a corporate group. Expensive and slow, so mostly an enterprise option.
The largest fine in GDPR history was a transfer violation. Meta’s €1.2 billion, SCCs and all. Max Schrems, whose litigation forced the issue, puts the structural problem bluntly: unless US surveillance law changes, companies built on EU-to-US data flows operate on borrowed time. The DPF papers over that problem for certified companies. For now. Treat transfer architecture as a living risk, not a signed-and-filed contract.
What GDPR means for your website
All of GDPR’s duties converge at one physical place: the pages your visitors load. GDPR’s most-enforced rules (consent, transparency, minimization) are decided in the browser, in the milliseconds around a consent banner.
The legal plumbing, once: cookies and similar trackers fall under the older ePrivacy Directive, whose Article 5(3) requires consent before storing or accessing anything on a visitor’s device. The consent standard itself is GDPR’s. And ePrivacy says when a tag needs consent. GDPR defines a valid “yes” and governs everything the tag does afterward.
What fires before consent on a typical site
Open a typical marketing site and watch the network panel before touching the banner. The tag manager loads first because it loads everything else: the analytics tag, ad pixels, session replay, chat widget, and A/B tool. Each can call its partners, fourth parties you never contracted with. Every request can carry personal data: IP address, cookie ID, page URL, referrer. None of this shows on the page.

Under the two laws, none of that may fire before the visitor says yes, except what is strictly necessary to deliver the page. Enforcement interprets it the same way. The CNIL’s cookie fines against Google turned on exactly this sequence: advertising cookies placed before consent, and rejection is harder than acceptance.
The cookie banner is the symptom, not the system
A banner is a claim about behavior. It is not the behavior. The stated layer (banner, privacy notice, consent-tool settings) says non-essential tags wait for a yes. The observed layer, what the browser actually sends and to whom, often disagrees:
| Stated (what the site claims) | Observed (what the browser does) |
| “No tracking before consent” | Analytics and ad requests leave on first paint |
| “Reject all works” | The same vendors load after reject as after accept |
| “We share data with 12 partners” | 40+ third- and fourth-party endpoints receive requests |
| “Global Privacy Control honored” | GPC signal present, behavior unchanged |
Measurement says the gap is the norm: in a widely cited 2020 study, researchers scraped the consent banners on the UK’s 10,000 most-visited sites and, of the 680 they captured, only 11.8% met the law’s minimum consent requirements. Half had no reject-all button. The study is several years old, but the enforcement record since, including the CNIL actions, measures the same gap.
Website GDPR compliance is not a banner configuration but an observed behavior property (which scripts fire, when, carrying what, to whom). It can be checked only by watching the browser, not by reading your notices. Signals count too. Honoring Global Privacy Control and other browser-level opt-outs is part of the observed layer. Vendor chains reach into third- and fourth-party risk that contracts alone cannot reveal.
How MELURNA helps comply with GDPR
MELURNA operates at exactly that observed layer, so we can say what banner vendors skip: enforcement punishes contradiction, not absence. The sites in the record above were fined for what their banners did, not for missing one. Worked through one site:
A US SaaS company serves EU visitors. Its banner says analytics waits for consent. MELURNA monitors the site’s sensitive-data flows (across pages and customer journeys, with no integrations to deploy) and reports what actually happens: which scripts fire before consent, what each request carries, which third parties and downstream recipients receive it, and what changed since the last scan. Consent comparison shows observed data movement after accept, reject, no action, and GPC, so the team can check, per vendor, whether “reject” behaves like the banner promises. The observed behavior is mapped against GDPR and related privacy obligations, turning “we believe we’re compliant” into a stated-versus-observed gap list: disclosure mismatches, consent-control failures, undocumented cross-border flows.
This is what accountability looks like in practice. Seeing the issues won’t fix them, but it gives you an evidence-based starting point.
Next steps
Did the self-test pull you in? Work in this order, from orientation to a defensible program:
- Map your data. What you collect, where it flows, who receives it. This is the ROPA regulators ask for first. The website’s observed flows are the part you cannot write from memory.
- Fix the lawful basis per purpose. Decide and document which of the six covers each purpose, before adding anything new.
- Bring notices in line. Your privacy notice must match the map from step 1, not the template it started from.
- Make consent mechanics real. Verify that accept, reject, no-action, and GPC states change script behavior. Observe it, don’t assume it.
- Close the vendor contracts. A DPA with every processor. DPF certification or SCCs for every US-bound flow.
- Build the evidence habit. DPIAs before high-risk launches, breach rehearsal against the 72-hour clock, periodic observation of the website layer as vendors and tags change.
Start by looking at your own site, the way a regulator’s technical audit would.
FAQs
Does GDPR apply in the UK?
Not directly. Since Brexit, the UK runs its own near-identical regime: the UK GDPR plus the Data Protection Act 2018, enforced by the ICO, with fines up to £17.5 million or 4% of global turnover (ICO guidance hub). Serving both markets means running both regimes.
Is there an official GDPR certification?
No government body issues a “GDPR certified” stamp, and vendors selling one are overselling. Articles 42–43 create voluntary certification mechanisms (the EDPB approved the first European Data Protection Seal, Europrivacy, in 2022), and certification never reduces a controller’s or processor’s responsibility.
What is the difference between pseudonymized and anonymized data?
Pseudonymized data, where identifiers are replaced by keys with the key held separately, is still personal data under GDPR, because re-identification is possible. Truly anonymized data, where re-identification is not reasonably possible, falls outside the regulation. The distinction matters because datasets marketed as “anonymous” that still key records to a device, cookie, or hashed ID are, legally, pseudonymized at best.
Are small businesses exempt from GDPR?
No. GDPR applies to organizations of any size. The only size relief is Article 30(5): under 250 employees, formal processing records may be skipped if processing is occasional, low-risk, and free of special-category and criminal-conviction data. A business that routinely tracks website visitors rarely meets even that bar.
Who enforces GDPR?
National Data Protection Authorities, one per EU/EEA member state, such as Ireland’s DPC and France’s CNIL. For cross-border processing, a “one-stop-shop” makes the DPA of your main EU establishment your lead regulator, with the EDPB coordinating consistency and, as the Meta decision showed, imposing binding resolutions when authorities disagree.
DISCLAIMER: This guide is for general informational purposes only and does not constitute legal advice. While we strive for accuracy, we make no warranties about the completeness or reliability of this information, and are not liable for any errors, omissions, or actions taken based on its contents. Consult a licensed attorney for guidance specific to your business.
