Skip to content
— CH. 1 · INTRODUCTION —

General Data Protection Regulation

12 min listen · Ch. 1 of 7
7 sections
  • The General Data Protection Regulation, known almost universally as GDPR, landed on the 25th of May 2018 with a question that no one had quite answered before: who really owns your personal data? Academic experts who helped shape the regulation described it as "the most consequential regulatory development in information policy in a generation." On the day it took effect, Facebook, WhatsApp, Instagram, and Google were all sued within hours of midnight. Websites for the Chicago Tribune and Los Angeles Times went dark for European visitors rather than face liability. The volume of online behavioural advertising in Europe dropped by 25 to 40 percent in a single day. What had the European Union built that caused such immediate and dramatic reaction? And why did countries as far away as Brazil, Japan, South Korea, and Thailand look to it as a model? The answers reach back to 2012, run through treaty negotiations, whistleblowers, and the architecture of consent, and stretch forward to billion-euro fines still being handed down years after the law took effect.

  • On the 25th of January 2012, the European Commission published its proposal for a new data regulation. The road from that proposal to an enforceable law took more than six years. In October 2013, the European Parliament's Committee on Civil Liberties, Justice and Home Affairs cast its orientation vote. By December 2015, a formal trilogue meeting between the Parliament, the Council, and the Commission produced a joint proposal. Austria cast the only dissenting vote when the Council of the European Union adopted the text on the 8th of April 2016, arguing that the regulation fell short of protections in the 1995 directive it was replacing. The European Parliament adopted the final text on the 14th of April 2016. The regulation entered into force 20 days later, on the 24th of May 2016, but member states were given two full years before its provisions became directly applicable. Supporters of the law later attributed part of its passage to the influence of whistleblower Edward Snowden. Mark Zuckerberg called it "a very positive step for the Internet" and urged the United States to adopt similar rules at home. Free software advocate Richard Stallman praised some aspects but pressed for additional safeguards against technology companies "manufacturing consent." The regulation superseded the Data Protection Directive 95/46/EC, which it replaced with a single unified set of rules carrying direct legal force across all member states, with no need for transposition into national law.

  • Article 12 of the GDPR requires every data controller to communicate with individuals in language that is "concise, transparent, intelligible and easily accessible", with particular care for children. That principle runs through the entire structure of individual rights the regulation creates. Under Article 15, any person can request an overview of what categories of data a controller holds about them, a copy of the actual data, and details about who it is shared with and how it was obtained. Article 17 created a right of erasure, though it replaced an earlier proposal for a broader "right to be forgotten" that the European Parliament had debated in March 2014. Article 20 established data portability, meaning a person can demand that their data be transferred from one electronic system to another. Article 21 lets individuals object to the processing of their data for marketing or non-service purposes, and controllers must inform people of this right from their very first communication. Under Article 82, any person who has suffered material or non-material damage from a GDPR breach has the right to compensation. The Court of Justice of the European Union clarified in the Osterreichische Post case (C-300/21) that a breach, actual damage, and a causal link between the two are required, but the damage does not need to reach any minimum threshold of seriousness. There is one misconception that the regulation has consistently had to correct: consent is not the only lawful basis for processing data. Five other legal grounds exist, including contractual obligation, legal compliance, vital interests, public interest, and legitimate interest.

  • Pseudonymisation sits at the heart of how the GDPR asks organisations to protect data they cannot yet delete. The regulation defines it as transforming personal data so that it cannot be attributed to a specific individual without additional information kept separately. Encryption is one example: it renders data unintelligible unless the correct decryption key is available, and that key must be stored separately from the encrypted data. Tokenisation is another approach, replacing sensitive data with non-sensitive substitutes called tokens. Tokens carry no intrinsic meaning but allow processing and analysis to continue on data while the sensitive core remains hidden. Unlike encrypted data, tokenised data does not change in type or length, which means it can pass through legacy database systems that are sensitive to such variations, and it requires fewer computational resources. Recital 78 specifies that pseudonymisation should be applied to personal data as early as possible. Article 35 requires data protection impact assessments whenever specific risks arise to the rights and freedoms of individuals, and prior approval from a data protection authority is required for high-risk processing. A report by the European Union Agency for Network and Information Security added a practical point: encryption and decryption must be performed locally rather than by a remote service, because both the data and the keys must remain under the data owner's control. The report concluded that outsourced cloud storage can be relatively safe, but only if the cloud service itself never holds the decryption keys. Approximately 25% of software vulnerabilities have been found to carry GDPR implications, according to research cited in relation to Article 33.

  • On the 21st of January 2019, less than eight months after GDPR took effect, the French data protection authority fined Google €50 million for insufficient transparency and control over personal data used in behavioural advertising. That fine was striking, but it was only the beginning. In July 2019, the British Information Commissioner's Office announced an intention to fine British Airways £183 million for a 2018 web skimming attack affecting around 380,000 transactions. The final penalty was reduced to £20 million after the ICO considered British Airways' representations and the economic impact of COVID-19. Around €160 million in GDPR fines were issued across all of 2020. By 2021 the total for that year alone had exceeded one billion euros. In 2024 and early 2025, enforcement continued to intensify. The Irish Data Protection Commission fined TikTok €345 million for violations related to children's data privacy. In January 2025, Meta received a fine of €1.2 billion for unlawfully transferring data between the EU and the United States. Enforcement has not been uniform, however. A Politico investigation in December 2019 found that Ireland and Luxembourg were facing significant backlogs in investigations of major technology companies, with Ireland citing the complexity of the regulation as a factor. Critics pointed to varying interpretations between member states, a tendency to prioritise guidance over enforcement, and insufficient cooperation across borders. The Irish Council for Civil Liberties filed a formal complaint with the Commission in November 2021, and by January 2023 the Commission had issued a new commitment in response. A 2024 study found that the regulation reduced EU user website page views and website revenue each by 12%.

  • The GDPR does not stop at the borders of the European Economic Area. Article 3(2) extends the regulation to any organisation outside the EEA that offers goods or services to individuals located within the EEA, or that monitors their behaviour, regardless of where the actual processing takes place. Non-EU organisations subject to the regulation must designate an EU Representative under Article 27 to serve as the contact point for European supervisory authorities and data subjects. Failing to make that designation is itself a violation, subject to fines of up to €10 million or 2% of annual worldwide turnover. Chapter V prohibits transferring personal data to countries outside the EEA unless the European Commission has formally declared that country's data protection adequate, or appropriate safeguards such as binding corporate rules or standard contractual clauses are in place. The United Kingdom's relationship with this regime shifted sharply after Brexit. The UK formally left the EU on the 31st of January 2020 and remained subject to EU law until the transition period ended on the 31st of December 2020. The UK enacted the Data Protection Act 2018 on the 23rd of May 2018, which augmented the GDPR, and subsequently retained a version called the UK GDPR. The European Commission issued an adequacy decision for the UK GDPR on the 28th of June 2021, valid for four years. That decision was set to expire on the 27th of June 2025 but was extended for six months while the Commission assessed the Data (Use and Access) Act 2025. On the 19th of December 2025, the Commission renewed the adequacy decision until the 27th of December 2031. The California Consumer Privacy Act, adopted on the 28th of June 2018 and in effect from the 1st of January 2020, drew explicit comparisons to the GDPR, as did Virginia's Consumer Data Privacy Act passed on the 2nd of March 2021 and Colorado's Privacy Act enacted on the 8th of July 2021. Turkey adopted a national data protection law on the 24th of March 2016, and China modelled its 2021 Personal Information Protection Law on the GDPR framework. That pattern of influence has a name: scholars call it the Brussels effect, the phenomenon by which European standards become de facto global baselines because multinational companies find it more practical to adopt a single high standard than to maintain separate processes for each jurisdiction.

Common questions

When did the GDPR come into effect?

The GDPR became directly applicable in all EU member states on the 25th of May 2018, two years after it entered into force on the 24th of May 2016. It was adopted by the European Parliament on the 14th of April 2016 and extended to EEA countries Iceland, Liechtenstein, and Norway on the 20th of July 2018.

What is the maximum fine under GDPR?

The most serious GDPR violations can result in fines of up to €20 million or up to 4% of annual worldwide turnover of the preceding financial year, whichever is greater. Less severe breaches carry fines of up to €10 million or 2% of annual worldwide turnover.

What rights does GDPR give individuals over their personal data?

The GDPR gives individuals the right to access their personal data (Article 15), the right to have inaccurate data corrected, the right to erasure under certain conditions (Article 17), the right to data portability between electronic systems (Article 20), and the right to object to processing for marketing purposes (Article 21). Individuals also have the right to compensation for material or non-material damage caused by a GDPR breach, under Article 82.

Does GDPR apply to companies outside the European Union?

Yes. Article 3(2) extends the GDPR to any organisation outside the EEA that offers goods or services to individuals located within the EEA, or that monitors their behaviour, regardless of where processing takes place. Such organisations must also designate an EU Representative under Article 27, and failure to do so is itself a violation subject to fines.

How has GDPR influenced privacy laws in other countries?

The GDPR has been cited as a model for laws in Brazil, Japan, Singapore, South Africa, South Korea, Sri Lanka, Thailand, and Turkey. In the United States, California's Consumer Privacy Act (adopted the 28th of June 2018), Virginia's Consumer Data Privacy Act (the 2nd of March 2021), and Colorado's Privacy Act (the 8th of July 2021) all draw on similar principles. China's 2021 Personal Information Protection Law was also modelled on the GDPR framework.

What is a GDPR data protection officer and who is required to appoint one?

A data protection officer (DPO) is a person with expert knowledge of data protection law and practices, responsible for monitoring an organisation's internal compliance with the GDPR. Under Article 37, a DPO must be appointed by public authorities, organisations that carry out large-scale regular or systematic monitoring of individuals, and organisations that process large volumes of special categories of data. The DPO's contact details must be published and registered with the supervisory authority.

All sources

161 references cited across the entry

  1. 3The UK GDPR28 June 2021
  2. 11JournalYour Data Is My Data: A Framework for Addressing Interdependent Privacy InfringementsBernadette Kamleitner et al. — 2019-10-01
  3. 13JournalWhen data protection by design and data subject rights clashMichael Veale et al. — 2018
  4. 14JournalSingling out people without knowing their names – Behavioural targeting, pseudonymous data, and the new Data Protection RegulationFrederik J. Zuiderveen Borgesius — April 2016
  5. 15The Right to Be ForgottenTony Baldry et al. — 1 Essex Court — 15 May 2014
  6. 17Right to object2019-08-30
  7. 29reach of the GDPR: What is at stake?Piper-Meredith Jankowski — 21 June 2017
  8. 35Exemptions2020-07-20
  9. 36BookServices of General Economic Interest as a Constitutional Concept of EU LawCaroline Wehlander — TMC Asser Press — 2016
  10. 42Digital Rights post-BrexitOpen Rights Group — 2 November 2022
  11. 44NewsNew UK Data Protection Act not welcomed by allWarwick Ashford — 24 May 2018
  12. 46NewsUK data protection 'adequacy' gets EU governments' sign-offKathryn Wynn — Pinsent Masons — 18 June 2021
  13. 47NewsEU–UK adequacy decisions approved by the EDPB: EDPB calls for effective monitoringSheilah Mackie et al. — Womble Bond Dickinson — November 18, 2025
  14. 50NewsFacebook urged to disable 'like' feature for child usersPatrick Greenfield — 15 April 2019
  15. 51UK seeks divergence from GDPR to 'fuel growth'Keumars Afifi-Sabet — 12 March 2021
  16. 57The High Costs of GDPR ComplianceChris Babel — UBM Technology Group — 11 July 2017
  17. 63NewsNo one's ready for GDPRSarah Jeong — 22 May 2018
  18. 64NewsNew rules on data protection pose compliance issues for firmsElaine Edwards — 22 February 2018
  19. 66JournalThe impact of the EU general data protection regulation on scientific researchGauthier Chassang — 2017
  20. 71JournalWhy a Right to Explanation of Automated Decision-Making Does Not Exist in the General Data Protection RegulationSandra Wachter et al. — 28 December 2016
  21. 75What the GDPR means for Facebook, the EU and youJustin Jaffe et al. — 25 May 2018
  22. 77MagazineEurope's new privacy law will change the web, and moreNitasha Tiku — 19 March 2018
  23. 79NewsA radical proposal to keep your personal data safeRichard Stallman — 3 April 2018
  24. 80JournalThe European Union general data protection regulation: what it is and what it meansChris Jay Hoofnagle et al. — 10 February 2019
  25. 84NewsEU citizens being tracked on sensitive government websitesMadhumita Murgia — 18 March 2019
  26. 86NewsHow Europe's GDPR Regulations Became a MemeAngela Watercutter — 25 May 2018
  27. 91The Data Protection Officer (DPO): Everything You Need to KnowDebra J. Farber — Cranium and HackerOne — 20 March 2018
  28. 92What might bug bounty programs look like under the GDPR?Jennifer Baker — The International Association of Privacy Professionals (IAPP) — 27 March 2018
  29. 93JournalDid App Privacy Improve After the GDPR?N. Momen et al. — November 2019
  30. 94Privacy Technologies and PolicyMajid Hatamian et al. — Springer International Publishing — 2019
  31. 103NewsWhy Your Inbox Is Crammed Full of Privacy PoliciesNitasha Tiku — 24 May 2018
  32. 107BookThe impact of the GDPR on the online advertising marketBernd Skiera et al. — Bernd Skiera — 5 July 2022
  33. 115NewsGoogle hit with £44m GDPR fineChris Fox — 21 January 2019
  34. 118NewsEnglish Translation of the Letter from the Romanian Data Protection Authority to RISE ProjectGeorge Bălăiți — Organized Crime and Corruption Reporting Project — 9 November 2018
  35. 122NewsBA faces £183m fine over passenger data breachMark Sweney — 8 July 2019
  36. 127BookProceedings of Mensch und Computer 2019Fatemeh Alizadeh et al. — ACM Press — 2019
  37. 131BookHuman Centred Intelligent SystemsSoheil Human et al. — Springer — 2021
  38. 139NewsCalifornia Unanimously Passes Historic Privacy BillIssie Lapowsky — 2018-06-28
  39. 142Colorado Privacy Act becomes lawSarah Rippy — 8 July 2021
  40. 144BookHigh Wire: How China Regulates Big Tech and Governs Its EconomyAngela Huyue Zhang — Oxford University Press — 2024
  41. 146Martinique's CARICOM AccessionGabriel Perkins — 2 June 2026
  42. 148EDPB-EDPS Joint Response on the US Cloud ActEuropean Data Protection Supervisor — 10 July 2019
  43. 150Don't Get Spooked by the CLOUD ActMartin Whitworth — International Data Corporation — 2018
  44. 151JournalRegulating Privacy Online: An Economic Evaluation of the GDPRSamuel G. Goldberg et al. — 2024
  45. 159GDPR – 20. juli er datoen!Kjetil Kolsrud — 10 July 2018