General Data Protection Regulation
The General Data Protection Regulation, known almost universally as GDPR, landed on the 25th of May 2018 with a question that no one had quite answered before: who really owns your personal data? Academic experts who helped shape the regulation described it as "the most consequential regulatory development in information policy in a generation." On the day it took effect, Facebook, WhatsApp, Instagram, and Google were all sued within hours of midnight. Websites for the Chicago Tribune and Los Angeles Times went dark for European visitors rather than face liability. The volume of online behavioural advertising in Europe dropped by 25 to 40 percent in a single day. What had the European Union built that caused such immediate and dramatic reaction? And why did countries as far away as Brazil, Japan, South Korea, and Thailand look to it as a model? The answers reach back to 2012, run through treaty negotiations, whistleblowers, and the architecture of consent, and stretch forward to billion-euro fines still being handed down years after the law took effect.
On the 25th of January 2012, the European Commission published its proposal for a new data regulation. The road from that proposal to an enforceable law took more than six years. In October 2013, the European Parliament's Committee on Civil Liberties, Justice and Home Affairs cast its orientation vote. By December 2015, a formal trilogue meeting between the Parliament, the Council, and the Commission produced a joint proposal. Austria cast the only dissenting vote when the Council of the European Union adopted the text on the 8th of April 2016, arguing that the regulation fell short of protections in the 1995 directive it was replacing. The European Parliament adopted the final text on the 14th of April 2016. The regulation entered into force 20 days later, on the 24th of May 2016, but member states were given two full years before its provisions became directly applicable. Supporters of the law later attributed part of its passage to the influence of whistleblower Edward Snowden. Mark Zuckerberg called it "a very positive step for the Internet" and urged the United States to adopt similar rules at home. Free software advocate Richard Stallman praised some aspects but pressed for additional safeguards against technology companies "manufacturing consent." The regulation superseded the Data Protection Directive 95/46/EC, which it replaced with a single unified set of rules carrying direct legal force across all member states, with no need for transposition into national law.
Article 12 of the GDPR requires every data controller to communicate with individuals in language that is "concise, transparent, intelligible and easily accessible", with particular care for children. That principle runs through the entire structure of individual rights the regulation creates. Under Article 15, any person can request an overview of what categories of data a controller holds about them, a copy of the actual data, and details about who it is shared with and how it was obtained. Article 17 created a right of erasure, though it replaced an earlier proposal for a broader "right to be forgotten" that the European Parliament had debated in March 2014. Article 20 established data portability, meaning a person can demand that their data be transferred from one electronic system to another. Article 21 lets individuals object to the processing of their data for marketing or non-service purposes, and controllers must inform people of this right from their very first communication. Under Article 82, any person who has suffered material or non-material damage from a GDPR breach has the right to compensation. The Court of Justice of the European Union clarified in the Osterreichische Post case (C-300/21) that a breach, actual damage, and a causal link between the two are required, but the damage does not need to reach any minimum threshold of seriousness. There is one misconception that the regulation has consistently had to correct: consent is not the only lawful basis for processing data. Five other legal grounds exist, including contractual obligation, legal compliance, vital interests, public interest, and legitimate interest.
Consent under GDPR is not a casual checkbox. Recital 32 specifies that it must be freely given, specific, plainly worded, and unambiguous. An opt-out pre-selected by default is a direct violation. Multiple types of data processing cannot be bundled into a single prompt; each use of data requires its own separate affirmation. Withdrawing consent must be no harder than giving it, and a controller cannot refuse service to users who decline consent for processing that is not strictly necessary. For children, defined in the regulation as anyone under 16 years old (with member states allowed to lower this to 13), consent must come from a parent or custodian and must be verifiable. Consent obtained under the old 1995 directive does not need to be re-obtained, provided it was collected in compliance with what the GDPR now requires, as Recital 171 confirms. When calls are recorded for business purposes, a typical disclaimer at the start of the call is not sufficient. If a caller withdraws consent mid-recording, the agent must be able to stop the recording immediately and ensure it is not stored. The regulation is equally clear about automated decision-making: individuals have the right to contest any decision reached on a solely algorithmic basis. A 2020 study found that major technology companies including Google, Amazon, Facebook, Apple, and Microsoft used dark patterns in their consent interfaces, raising serious questions about whether the consents obtained through those mechanisms were lawful under the regulation.
Pseudonymisation sits at the heart of how the GDPR asks organisations to protect data they cannot yet delete. The regulation defines it as transforming personal data so that it cannot be attributed to a specific individual without additional information kept separately. Encryption is one example: it renders data unintelligible unless the correct decryption key is available, and that key must be stored separately from the encrypted data. Tokenisation is another approach, replacing sensitive data with non-sensitive substitutes called tokens. Tokens carry no intrinsic meaning but allow processing and analysis to continue on data while the sensitive core remains hidden. Unlike encrypted data, tokenised data does not change in type or length, which means it can pass through legacy database systems that are sensitive to such variations, and it requires fewer computational resources. Recital 78 specifies that pseudonymisation should be applied to personal data as early as possible. Article 35 requires data protection impact assessments whenever specific risks arise to the rights and freedoms of individuals, and prior approval from a data protection authority is required for high-risk processing. A report by the European Union Agency for Network and Information Security added a practical point: encryption and decryption must be performed locally rather than by a remote service, because both the data and the keys must remain under the data owner's control. The report concluded that outsourced cloud storage can be relatively safe, but only if the cloud service itself never holds the decryption keys. Approximately 25% of software vulnerabilities have been found to carry GDPR implications, according to research cited in relation to Article 33.
On the 21st of January 2019, less than eight months after GDPR took effect, the French data protection authority fined Google €50 million for insufficient transparency and control over personal data used in behavioural advertising. That fine was striking, but it was only the beginning. In July 2019, the British Information Commissioner's Office announced an intention to fine British Airways £183 million for a 2018 web skimming attack affecting around 380,000 transactions. The final penalty was reduced to £20 million after the ICO considered British Airways' representations and the economic impact of COVID-19. Around €160 million in GDPR fines were issued across all of 2020. By 2021 the total for that year alone had exceeded one billion euros. In 2024 and early 2025, enforcement continued to intensify. The Irish Data Protection Commission fined TikTok €345 million for violations related to children's data privacy. In January 2025, Meta received a fine of €1.2 billion for unlawfully transferring data between the EU and the United States. Enforcement has not been uniform, however. A Politico investigation in December 2019 found that Ireland and Luxembourg were facing significant backlogs in investigations of major technology companies, with Ireland citing the complexity of the regulation as a factor. Critics pointed to varying interpretations between member states, a tendency to prioritise guidance over enforcement, and insufficient cooperation across borders. The Irish Council for Civil Liberties filed a formal complaint with the Commission in November 2021, and by January 2023 the Commission had issued a new commitment in response. A 2024 study found that the regulation reduced EU user website page views and website revenue each by 12%.
The GDPR does not stop at the borders of the European Economic Area. Article 3(2) extends the regulation to any organisation outside the EEA that offers goods or services to individuals located within the EEA, or that monitors their behaviour, regardless of where the actual processing takes place. Non-EU organisations subject to the regulation must designate an EU Representative under Article 27 to serve as the contact point for European supervisory authorities and data subjects. Failing to make that designation is itself a violation, subject to fines of up to €10 million or 2% of annual worldwide turnover. Chapter V prohibits transferring personal data to countries outside the EEA unless the European Commission has formally declared that country's data protection adequate, or appropriate safeguards such as binding corporate rules or standard contractual clauses are in place. The United Kingdom's relationship with this regime shifted sharply after Brexit. The UK formally left the EU on the 31st of January 2020 and remained subject to EU law until the transition period ended on the 31st of December 2020. The UK enacted the Data Protection Act 2018 on the 23rd of May 2018, which augmented the GDPR, and subsequently retained a version called the UK GDPR. The European Commission issued an adequacy decision for the UK GDPR on the 28th of June 2021, valid for four years. That decision was set to expire on the 27th of June 2025 but was extended for six months while the Commission assessed the Data (Use and Access) Act 2025. On the 19th of December 2025, the Commission renewed the adequacy decision until the 27th of December 2031. The California Consumer Privacy Act, adopted on the 28th of June 2018 and in effect from the 1st of January 2020, drew explicit comparisons to the GDPR, as did Virginia's Consumer Data Privacy Act passed on the 2nd of March 2021 and Colorado's Privacy Act enacted on the 8th of July 2021. Turkey adopted a national data protection law on the 24th of March 2016, and China modelled its 2021 Personal Information Protection Law on the GDPR framework. That pattern of influence has a name: scholars call it the Brussels effect, the phenomenon by which European standards become de facto global baselines because multinational companies find it more practical to adopt a single high standard than to maintain separate processes for each jurisdiction.
Up Next
Common questions
When did the GDPR come into effect?
The GDPR became directly applicable in all EU member states on the 25th of May 2018, two years after it entered into force on the 24th of May 2016. It was adopted by the European Parliament on the 14th of April 2016 and extended to EEA countries Iceland, Liechtenstein, and Norway on the 20th of July 2018.
What is the maximum fine under GDPR?
The most serious GDPR violations can result in fines of up to €20 million or up to 4% of annual worldwide turnover of the preceding financial year, whichever is greater. Less severe breaches carry fines of up to €10 million or 2% of annual worldwide turnover.
What rights does GDPR give individuals over their personal data?
The GDPR gives individuals the right to access their personal data (Article 15), the right to have inaccurate data corrected, the right to erasure under certain conditions (Article 17), the right to data portability between electronic systems (Article 20), and the right to object to processing for marketing purposes (Article 21). Individuals also have the right to compensation for material or non-material damage caused by a GDPR breach, under Article 82.
Does GDPR apply to companies outside the European Union?
Yes. Article 3(2) extends the GDPR to any organisation outside the EEA that offers goods or services to individuals located within the EEA, or that monitors their behaviour, regardless of where processing takes place. Such organisations must also designate an EU Representative under Article 27, and failure to do so is itself a violation subject to fines.
How has GDPR influenced privacy laws in other countries?
The GDPR has been cited as a model for laws in Brazil, Japan, Singapore, South Africa, South Korea, Sri Lanka, Thailand, and Turkey. In the United States, California's Consumer Privacy Act (adopted the 28th of June 2018), Virginia's Consumer Data Privacy Act (the 2nd of March 2021), and Colorado's Privacy Act (the 8th of July 2021) all draw on similar principles. China's 2021 Personal Information Protection Law was also modelled on the GDPR framework.
What is a GDPR data protection officer and who is required to appoint one?
A data protection officer (DPO) is a person with expert knowledge of data protection law and practices, responsible for monitoring an organisation's internal compliance with the GDPR. Under Article 37, a DPO must be appointed by public authorities, organisations that carry out large-scale regular or systematic monitoring of individuals, and organisations that process large volumes of special categories of data. The DPO's contact details must be published and registered with the supervisory authority.
All sources
161 references cited across the entry
- 2What is the LGPD? Brazil's version of the GDPRRichie Koch — 2019-07-31
- 3The UK GDPR28 June 2021
- 4NewsGDPR vs CCPA: What are the main differences?Lucarini Francesca
- 6GDPR Recitals – Full listGDPR-info.eu
- 8What is personal data?2019-04-24
- 11JournalYour Data Is My Data: A Framework for Addressing Interdependent Privacy InfringementsBernadette Kamleitner et al. — 2019-10-01
- 13JournalWhen data protection by design and data subject rights clashMichael Veale et al. — 2018
- 14JournalSingling out people without knowing their names – Behavioural targeting, pseudonymous data, and the new Data Protection RegulationFrederik J. Zuiderveen Borgesius — April 2016
- 15The Right to Be ForgottenTony Baldry et al. — 1 Essex Court — 15 May 2014
- 16Practical Data Privacy Books by ThoughtworkersKatharine Jarmul
- 17Right to object2019-08-30
- 18Using privacy laws to regulate automated decision makingBarry Sookman — 30 April 2021
- 23Data science under GDPR with pseudonymization in the data pipelineJan Lindquist — 17 April 2018
- 25Data protection by design and default2023-07-01
- 29reach of the GDPR: What is at stake?Piper-Meredith Jankowski — 21 June 2017
- 35Exemptions2020-07-20
- 36BookServices of General Economic Interest as a Constitutional Concept of EU LawCaroline Wehlander — TMC Asser Press — 2016
- 38Extraterritorial Scope of GDPR: Do Businesses Outside the EU Need to Comply?American Bar Association
- 39UK: Understanding the full impact of Brexit on UK: EU data flowsDLA Piper — 23 September 2019
- 41How to transfer data to a 'third country' under the GDPRConor Donnelly — 18 January 2018
- 42Digital Rights post-BrexitOpen Rights Group — 2 November 2022
- 44NewsNew UK Data Protection Act not welcomed by allWarwick Ashford — 24 May 2018
- 45Google shifts authority over UK user data to the US in wake of BrexitJon Porter — 20 February 2020
- 46NewsUK data protection 'adequacy' gets EU governments' sign-offKathryn Wynn — Pinsent Masons — 18 June 2021
- 47NewsEU–UK adequacy decisions approved by the EDPB: EDPB calls for effective monitoringSheilah Mackie et al. — Womble Bond Dickinson — November 18, 2025
- 49NewsUnder-18s face 'like' and 'streaks' limits2019-04-19
- 50NewsFacebook urged to disable 'like' feature for child usersPatrick Greenfield — 15 April 2019
- 51UK seeks divergence from GDPR to 'fuel growth'Keumars Afifi-Sabet — 12 March 2021
- 52Data sharing myths busted19 May 2023
- 53Top nine GDPR myths busted22 January 2019
- 54Five GDPR myth-busters11 May 2023
- 55A new era for privacy – GDPR six months onPeter Gooch — 2018
- 57The High Costs of GDPR ComplianceChris Babel — UBM Technology Group — 11 July 2017
- 58Preparing for New Privacy Regimes: Privacy Professionals' Views on the General Data Protection Regulation and Privacy ShieldBaker & McKenzie — 4 May 2016
- 59GDPR Compliance Cost CalculatorGeorgi Georgiev
- 60How Europe's 'breakthrough' privacy law takes on Facebook and GoogleOlivia Solon — 19 April 2018
- 61NewsEurope's new privacy rules are no silver bulletMark Scott — 2018-04-22
- 63NewsNo one's ready for GDPRSarah Jeong — 22 May 2018
- 64NewsNew rules on data protection pose compliance issues for firmsElaine Edwards — 22 February 2018
- 65Looking to comply with GDPR? Here's a primer on anonymization and pseudonymizationMatt Wes — IAPP — 25 April 2017
- 66JournalThe impact of the EU general data protection regulation on scientific researchGauthier Chassang — 2017
- 67Pseudonymisation of Personal Data According to the General Data Protection RegulationLaura Tarhonen — 2017
- 69NewsAI watchdog needed to regulate automated decision-making, say expertsIan Sample — 27 January 2017
- 70EU's Right to Explanation: A Harmful Restriction on Artificial IntelligenceNick Wallace — 25 January 2017
- 71JournalWhy a Right to Explanation of Automated Decision-Making Does Not Exist in the General Data Protection RegulationSandra Wachter et al. — 28 December 2016
- 72JournalSlave to the algorithm? Why a "right to an explanation" is probably not the remedy you are looking forLilian Edwards et al. — 2017
- 73Five benefits GDPR compliance will bring to your businessMichael Frimin — 29 March 2018
- 74Europe's tough new digital privacy law should be a model for US policymakersTrevor Butterworth — Vox — 23 May 2018
- 75What the GDPR means for Facebook, the EU and youJustin Jaffe et al. — 25 May 2018
- 76NewsZuckerberg says he wants strict European-style privacy laws — but some experts question his motivesElizabeth Schulze — 2019-04-01
- 77MagazineEurope's new privacy law will change the web, and moreNitasha Tiku — 19 March 2018
- 78NewsToday, a new E.U. law transforms privacy rights for everyone. Without Edward Snowden, it might never have happened.Nikhil Kalyanpur et al. — 25 May 2018
- 79NewsA radical proposal to keep your personal data safeRichard Stallman — 3 April 2018
- 80JournalThe European Union general data protection regulation: what it is and what it meansChris Jay Hoofnagle et al. — 10 February 2019
- 81NewsScammers are using GDPR email alerts to conduct phishing attacksKeumars Afifi-Sabet — 3 May 2018
- 82Most GDPR emails unnecessary and some illegal, say expertsAlex Hern — 21 May 2018
- 83EU gov't and public health sites are lousy with adtech, study findsNatasha Lomas — 18 March 2019
- 84NewsEU citizens being tracked on sensitive government websitesMadhumita Murgia — 18 March 2019
- 85NewsFall asleep in seconds by listening to a soothing voice read the EU's new GDPR legislationJames Vincent — 3 June 2018
- 86NewsHow Europe's GDPR Regulations Became a MemeAngela Watercutter — 25 May 2018
- 87NewsThe Internet Created a GDPR-Inspired Meme Using Privacy PoliciesAnn-Marie Alcántara — 31 May 2018
- 88NewsHelp, my lightbulbs are dead! How GDPR became bigger than BeyonceMatt Burgess
- 89NewsHere Are Some of the Worst Attempts At Complying with GDPRKaleigh Rogers — 25 May 2018
- 90What Percentage of Your Software Vulnerabilities Have GDPR Implications?HackerOne — 16 January 2018
- 91The Data Protection Officer (DPO): Everything You Need to KnowDebra J. Farber — Cranium and HackerOne — 20 March 2018
- 92What might bug bounty programs look like under the GDPR?Jennifer Baker — The International Association of Privacy Professionals (IAPP) — 27 March 2018
- 93JournalDid App Privacy Improve After the GDPR?N. Momen et al. — November 2019
- 94Privacy Technologies and PolicyMajid Hatamian et al. — Springer International Publishing — 2019
- 96NewsInstapaper is temporarily shutting off access for European users due to GDPRNick Statt — 23 May 2018
- 97Unroll.me to close to EU users saying it can't comply with GDPRNatasha Lomas — 5 May 2018
- 98NewsHow GDPR, ad fatigue and content costs are complicating the now-global streaming warsAndrew Blustein — September 4, 2019
- 99NewsSites block users, shut down activities and flood inboxes as GDPR rules loomAlex Hern et al. — 24 May 2018
- 100NewsBlocking 500 Million Users Is Easier Than Complying With Europe's New RulesBloomberg L.P. — 25 May 2018
- 101NewsU.S. News Outlets Block European Readers Over New Privacy RulesAdam Satariano — 25 May 2018
- 103NewsWhy Your Inbox Is Crammed Full of Privacy PoliciesNitasha Tiku — 24 May 2018
- 104NewsGetting a Flood of G.D.P.R.-Related Privacy Policy Updates? Read ThemBrian X. Chen — 23 May 2018
- 106NewsGDPR mayhem: Programmatic ad buying plummets in Europe25 May 2018
- 107BookThe impact of the GDPR on the online advertising marketBernd Skiera et al. — Bernd Skiera — 5 July 2022
- 108Press corner
- 114NewsGoogle, Facebook hit with serious GDPR complaints: Others will be soonDavid Meyer
- 115NewsGoogle hit with £44m GDPR fineChris Fox — 21 January 2019
- 116Google fined €50 million for GDPR violation in FranceJon Porter — 21 January 2019
- 117NewsYet Another GDPR Disaster: Journalists Ordered To Hand Over Secret Sources Under 'Data Protection' LawMike Masnick — 19 November 2018
- 118NewsEnglish Translation of the Letter from the Romanian Data Protection Authority to RISE ProjectGeorge Bălăiți — Organized Crime and Corruption Reporting Project — 9 November 2018
- 120NewsBritish Airways breach caused by credit card skimming malware, researchers sayZack Whittaker — 11 September 2018
- 121NewsBritish Airways boss apologises for 'malicious' data breach7 September 2018
- 122NewsBA faces £183m fine over passenger data breachMark Sweney — 8 July 2019
- 123NewsBritish Airways faces record £183m fine for data breach8 July 2019
- 125'We have a huge problem': European regulator despairs over lack of enforcementNicholas Vinocur — 27 December 2019
- 126NewsEurope-wide overhaul of GDPR monitoring triggered by ICCLJohnny Ryan — 2023-01-31
- 127BookProceedings of Mensch und Computer 2019Fatemeh Alizadeh et al. — ACM Press — 2019
- 128JournalGDPR Reality Check–Claiming and Investigating Personally Identifiable Data from CompaniesFatemeh Alizadeh et al. — 2020
- 129JournalUnderstanding challenges of GDPR implementation in business enterprises: a systematic literature reviewYelena Smirnova et al. — 2024-04-04
- 130DPO.VN – Chuyên gia bảo vệ dữ liệu cá nhân2025-04-21
- 131BookHuman Centred Intelligent SystemsSoheil Human et al. — Springer — 2021
- 132NewsHow Europe's Intelligence Services Aim to Avoid the EU's Highest Court—and What It Means for the United StatesTheodore and Kenneth Christakis and Propp — March 8, 2021
- 133NewsFines for breaches of EU privacy law spike sevenfold to $1.2 billion, as Big Tech bears the bruntRyan Browne — 2022-01-18
- 134TikTok fined €345 million for GDPR violations on children's privacy15 September 2024
- 135Meta hit with record €1.2 billion GDPR fine over US data transfers10 January 2025
- 136NewsEU ditches plans to regulate tech patents, AI liability, online privacyFoo Yun Chee — 12 February 2025
- 137The GDPR Is in Effect: Should U.S. Companies Be Afraid?Jeff John Roberts — 25 May 2018
- 138NewsCommentary: California's New Data Privacy Law Could Begin a Regulatory DisasterDanny Allan — 2018-10-23
- 139NewsCalifornia Unanimously Passes Historic Privacy BillIssie Lapowsky — 2018-06-28
- 140NewsMarketers and tech companies confront California's version of GDPRGeorge P. Slefo — 2018-06-29
- 141Virginia passes the Consumer Data Protection ActSarah Rippy — 3 March 2021
- 142Colorado Privacy Act becomes lawSarah Rippy — 8 July 2021
- 144BookHigh Wire: How China Regulates Big Tech and Governs Its EconomyAngela Huyue Zhang — Oxford University Press — 2024
- 145New Federal Act on Data Protection (nFADP)S. M. E. Portal
- 146Martinique's CARICOM AccessionGabriel Perkins — 2 June 2026
- 147The European Union (EU) General Data Protection Regulation (GDPR) in the Caribbean ContextStaff writer — 23 January 2020
- 148EDPB-EDPS Joint Response on the US Cloud ActEuropean Data Protection Supervisor — 10 July 2019
- 14921 Thoughts and Questions about the UK-US CLOUD Act Agreement: (and an Explanation of How it Works – with Charts)Theodore Christakis — October 17, 2019
- 150Don't Get Spooked by the CLOUD ActMartin Whitworth — International Data Corporation — 2018
- 151JournalRegulating Privacy Online: An Economic Evaluation of the GDPRSamuel G. Goldberg et al. — 2024
- 159GDPR – 20. juli er datoen!Kjetil Kolsrud — 10 July 2018