Skip to content

Glossary GDPR

What Is the GDPR?

  • Analytics
Definition

The GDPR (General Data Protection Regulation) is the European Union regulation that governs how companies collect, process, and store the personal data of individuals, directly applicable since 25 May 2018 across all 27 member states.

A closed padlock on stacked folders with blank spines — beside the title GDPR
The padlock is not yours; it belongs to whoever is in the files
On this page 6
  1. What does GDPR mean?
  2. The rights GDPR gives users
  3. How it works
  4. Why it matters
  5. Best practices
  6. Common mistakes
In brief

What principles the GDPR imposes on any website with European visitors, how it differs from consent as a legal basis, and what fines the EU has issued in 2025 and 2026.

A closed padlock on stacked folders with blank spines — beside the title GDPR
The padlock is not yours; it belongs to whoever is in the files

What does GDPR mean?

GDPR, the General Data Protection Regulation, is Regulation (EU) 2016/679. It governs how companies collect, process, and store the personal data of individuals. Adopted on 27 April 2016, it has been directly applicable law since 25 May 2018 across all 27 member states.

As a regulation rather than a directive, it needed no national law to bring it into force: the same text applies in Germany, Spain, or Poland, in effect on the same day everywhere. It replaced the older Directive 95/46/EC, which had left each country room to adapt its own rules.

Its reach extends beyond companies based in the EU. Article 3 of the regulation gives it extraterritorial effect: any company that processes data belonging to people who live in the EU must comply, wherever its own headquarters sit, in Madrid, London, or Singapore. A US online store with German customers is bound by the GDPR just as much as a Berlin-based company.

The rights GDPR gives users

RightWhat it allows
AccessFind out what data a company holds about you and why it uses it.
RectificationCorrect inaccurate or incomplete personal data.
Erasure ("right to be forgotten")Request deletion of your data once there's no legitimate reason left to keep it.
PortabilityReceive your data in a reusable format and move it to another provider.
ObjectionRefuse to have your data used for specific purposes, such as direct marketing.

These rights, set out in Articles 15 to 21 of the regulation, must be exercisable free of charge, and a company has a maximum of one month to respond. An online store with no way to request account deletion breaks the regulation, even if no one ever files a complaint.

How it works

The GDPR rests on seven principles laid out in Article 5: lawfulness and transparency (a company needs a legal basis and must explain it clearly), purpose limitation (data gets used only for the purpose stated when it was collected), data minimization (a company asks only for the demographic data or other information it strictly needs, not everything it could get), accuracy, storage limitation, integrity and confidentiality, and accountability: a company must be able to document and prove compliance at any time.

Article 6 lists six legal bases for processing personal data, and consent is only one of them, not the only one. Alongside it sit contract performance (processing a shipping address to complete an order), legitimate interest, a legal obligation, protection of vital interests, and the exercise of a public task. An online store can process billing data under a contract without asking for separate consent, but it needs explicit consent to install an advertising cookie or a tracking pixel on social media.

The distinction matters because each legal basis follows its own rules: consent can be withdrawn at any time as easily as it was given, while a contractual obligation can't be undone without cancelling the contract itself. Treating one as a substitute for the other creates unnecessary friction for users and needless legal risk for the company.

Why it matters

For any website with visitors in the EU, the GDPR turns into concrete obligations. The cookie banner has to ask for consent before any analytics or targeting script loads, not after. A newsletter form needs its own consent checkbox, separate from the one for accepting terms, and unsubscribing has to be as easy as subscribing; double opt-in is the standard way to keep that consent documented and provable.

The right to erasure lands directly on user accounts: if someone asks to delete theirs, the company also has to remove the matching data from any buyer persona tool or CRM that stores it. Tracking someone across an entire customer journey needs a valid legal basis at every touchpoint.

Any outside tool that processes personal data on the company's behalf, from an analytics provider to an email marketing platform, requires a data processing agreement. And any site with a contact form or user registration needs a privacy policy written for that site, not a generic text copied from somewhere else. A badly configured consent manager also tends to block rendering and slow load time, which drags the issue straight into technical SEO.

Best practices

  • Ask for consent with a checkbox unchecked by default, never pre-ticked, and explain what the data will be used for before the user agrees.
  • Sign a data processing agreement with every outside vendor that handles personal data, analytics and email marketing tools included.
  • Offer a clear channel to request access, rectification, or erasure, without forcing users to call or write a letter.
  • Keep a record of processing activities, even if the company has fewer than 250 employees.
  • Review regularly what personal data each tool on the site is storing, and delete whatever no longer serves an active purpose.
  • If you segment a target audience using personal data, document the legal basis behind it.

Common mistakes

  • Loading analytics or advertising scripts before the user has agreed to them in the cookie banner.
  • Pre-checking the consent box on registration or newsletter forms.
  • Treating consent as the only possible legal basis and asking for it even when a contract already justifies the processing.
  • Having no defined process to answer an erasure request within the one-month deadline.
  • Sharing data with an outside vendor before signing a data processing agreement.
Manuel Riveiro Rodriguez CEO & Digital Strategist

A technical audit covers this and everything else in one pass.

Request an audit

Frequently asked

What's the difference between GDPR and consent?

GDPR is the entire legal framework governing any processing of personal data in the EU. Consent is just one of six legal bases that allow that processing, alongside contract performance or legitimate interest. A company can comply with GDPR without ever asking for consent, as long as another valid legal basis applies.

Who does GDPR apply to?

Any company that processes data belonging to people who live in the EU, regardless of where that company is based. A US online store with German customers is bound by the regulation just as much as a company headquartered in Munich. What matters is the user's location, not the company's.

What happens if a company breaks GDPR?

Data protection authorities can impose fines of up to 20 million euros or 4% of annual global turnover, whichever is higher. In May 2025, Ireland's authority fined TikTok 530 million euros over data transfers to China without adequate safeguards, the largest penalty of the year.

Is GDPR still the same in 2026?

The original text still stands, but in November 2025 the European Commission put forward a simplification package, the "Digital Omnibus," proposing changes to concepts like the definition of personal data and the obligations placed on small businesses. Final adoption isn't expected before late 2026.

Do I need a cookie notice if my site doesn't sell anything?

Yes. As soon as a site uses any cookie that isn't strictly necessary for it to function, analytics or advertising cookies included, it needs consent before activating it. The obligation doesn't depend on whether the site sells anything, only on whether it collects personal data from visitors.

Sources

  1. EUR-Lex, Regulation (EU) 2016/679: the full legal text of the GDPR, confirming it's a directly applicable regulation in force since 25 May 2018, with no national transposition needed. Published 4 May 2016.
  2. European Commission, "Legal framework of EU data protection": the official summary of the legal framework, confirming the date it took effect and its extension across the European Economic Area.
  3. EDPB, "Irish Supervisory Authority fines TikTok €530 million": the official announcement of the largest GDPR fine of 2025, the basis for the penalty figure used in this article. Published 4 July 2025.