What does GDPR mean?
GDPR, the General Data Protection Regulation, is Regulation (EU) 2016/679. It governs how companies collect, process, and store the personal data of individuals. Adopted on 27 April 2016, it has been directly applicable law since 25 May 2018 across all 27 member states.
As a regulation rather than a directive, it needed no national law to bring it into force: the same text applies in Germany, Spain, or Poland, in effect on the same day everywhere. It replaced the older Directive 95/46/EC, which had left each country room to adapt its own rules.
Its reach extends beyond companies based in the EU. Article 3 of the regulation gives it extraterritorial effect: any company that processes data belonging to people who live in the EU must comply, wherever its own headquarters sit, in Madrid, London, or Singapore. A US online store with German customers is bound by the GDPR just as much as a Berlin-based company.
