What is GDPR?
The General Data Protection Regulation (GDPR) is the European Union's comprehensive data privacy law enacted in 2018.
The General Data Protection Regulation (GDPR) is the European Union's comprehensive data privacy law enacted in 2018. It governs how organizations collect, store, process, and delete personal data of EU residents.
Key requirements: lawful basis for processing, explicit consent, data minimization, right to access, right to deletion (right to be forgotten), data portability, breach notification (72 hours), Data Protection Officer (DPO) requirement, and Privacy Impact Assessments.
Penalties: Up to €20M or 4% of global annual revenue, whichever is higher. Major fines have been issued to Meta ($1.3B), Amazon ($887M), and Google ($57M).
Why It Matters
GDPR compliance is mandatory for any organization processing EU residents' data — regardless of where the organization is located. Non-compliance carries severe financial penalties and reputational damage.
Frequently Asked Questions
Does GDPR apply outside the EU?
Yes — GDPR applies to any organization processing data of EU residents, regardless of where the company is headquartered. A US company with EU customers must comply.
Related Terms
Need Expert Help?
Richard Ewing is a Product Economist and AI Capital Auditor. He helps companies translate technical complexity into financial clarity.
Book Advisory Call →