Skip to content
Home

General Data Protection Regulation (GDPR): EU personal data law

Comprehensive overview of the GDPR: its purpose, scope, key principles and rights, enforcement, compliance measures, history and practical impact on organisations handling personal data.

Overview

The General Data Protection Regulation (GDPR) is a European Union legal framework adopted on 27 April 2016 and enforceable since 25 May 2018. It establishes uniform rules across EU Member States for the protection of personal data and replaces the earlier 1995 Data Protection Directive. As a regulation, it is directly applicable without needing national transposition. The GDPR was approved by the European Parliament, the Council of the European Union and the European Commission, and it governs processing of personal information within the EU and certain processing activities outside the EU that relate to EU residents (EU data subjects).

Image gallery

2 Images

Key principles and individual rights

The GDPR codifies several foundational principles that organisations must follow when processing personal data. These include lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. The regulation also grants specific rights to individuals, for example:

  • Right of access to personal data and information about processing.
  • Right to rectification and to erase data ("right to be forgotten").
  • Right to restriction of processing and to object to certain kinds of processing, including direct marketing.
  • Right to data portability to receive and transfer personal data in a structured, commonly used format.
  • Rights concerning automated decision-making and profiling.

Scope, roles and enforcement

The GDPR applies to controllers and processors established in the EU and, in many cases, to organisations outside the EU that offer goods or services to, or monitor the behaviour of, EU residents. Roles defined by the text include data controllers (who determine processing purposes) and data processors (who process on behalf of controllers). Supervisory authorities in each Member State oversee enforcement and cooperate through the European Data Protection Board. Non-compliance can lead to administrative fines of up to €20,000,000 or up to 4% of annual global turnover, whichever is higher, together with other corrective measures.

Practical compliance measures

Organisations subject to the GDPR commonly implement measures such as appointing a Data Protection Officer when required, keeping processing records, carrying out Data Protection Impact Assessments for high-risk activities, and notifying supervisory authorities of personal data breaches within 72 hours when feasible. Cross-border transfers of personal data outside the EU require appropriate safeguards (for example, adequacy decisions, standard contractual clauses or binding corporate rules) and have been influenced by subsequent court rulings and guidance on international data flows.

History, purpose and development

The GDPR was developed to modernise and harmonise data protection rules across the EU in response to technological change and the growth of cross-border digital services. By replacing the 1995 Directive it sought to give individuals stronger control over their personal data while simplifying obligations for businesses operating across multiple Member States. Since its entry into force the GDPR has influenced data protection laws worldwide and prompted updates to corporate practices, software design and public policy.

Impact, examples and notable facts

Practical examples of GDPR application include online platforms updating consent mechanisms, employers limiting access to personnel records, healthcare providers strengthening security for sensitive health data, and marketing teams adapting data collection and profiling practices. The regulation's extraterritorial reach, significant fines, and emphasis on accountability have made it a key reference point for privacy law globally. Its implementation has also prompted legal and policy debates about balancing privacy, innovation and law enforcement needs.

Further reading: See the EU institutions involved in the GDPR's adoption at Parliament, Council and Commission, and overview material on data protection in the EU.

Questions and answers

Q: What is the General Data Protection Regulation (GDPR)?

A: The GDPR is a regulation adopted by the European Parliament, the Council of the European Union and the European Commission that protects people's personal data throughout the EU.

Q: When did it take effect?

A: It took effect on 25 May 2018.

Q: What does GDPR aim to do?

A: The GDPR is aimed at giving citizens control over their personal data and simplifying regulations for economic relations with other countries by making EU procedures standardised.

Q: Does it replace any existing laws?

A: Yes, it replaces the Data Protection Directive of 1995.

Q: Do local laws need to be changed in order to comply with GDPR?

A: No, no changes are needed in local laws within the EU as this regulation is binding.

Q: What happens if someone or a company doesn't comply with GDPR law? A: They may face a fine of up to 20,000,000 euros, or up to 4% of their company's profits from the previous year, whichever number is higher.

Related articles

Author

AlegsaOnline.com General Data Protection Regulation (GDPR): EU personal data law

URL: https://en.alegsaonline.com/art/37940

Share

Sources