What is the GDPR? Learn who it applies to, the 7 principles, consent and cookie rules, data subject rights, fines and a step-by-step GDPR compliance checklist.
The General Data Protection Regulation (GDPR) is the European Union's data protection law. It gives people control over their personal data and sets rules for every organization that collects, uses or shares it, including companies outside the EU.
The GDPR (Regulation (EU) 2016/679) is a regulation that harmonizes data protection law across all EU member states. It was adopted on 27 April 2016 and has applied since 25 May 2018, replacing the 1995 Data Protection Directive (95/46/EC). The text contains 99 articles in 11 chapters, supported by 173 recitals that explain how the articles should be interpreted.
Because it is a regulation rather than a directive, the GDPR applies directly in every member state without needing national laws to implement it. Member states can still add rules in specific areas, such as the age of digital consent or employee data.
The GDPR is known by different names across Europe:
The GDPR entered into force on 24 May 2016 and became enforceable on 25 May 2018, after a two-year transition period that gave organizations time to prepare. Supervisory authorities have been issuing fines under it ever since.
The GDPR has extraterritorial reach (Article 3). It applies to:
If your website gets visitors from Europe and runs analytics, advertising or marketing tags, the GDPR applies to you. There is no exemption for small companies.
| Term | Meaning (Article 4) |
|---|---|
| Personal data | Any information relating to an identified or identifiable person, including names, emails, IP addresses, cookie IDs, device IDs and location data. |
| Special category data | Sensitive data such as health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership and sexual orientation (Article 9). |
| Data subject | The individual the personal data relates to. |
| Processing | Any operation on personal data: collecting, recording, storing, using, sharing, erasing and so on. |
| Controller | The organization that decides why and how personal data is processed. |
| Processor | An organization that processes personal data on behalf of a controller, such as a hosting or email provider. |
| Consent | A freely given, specific, informed and unambiguous indication of the data subject's wishes by a clear affirmative action. |
| Pseudonymisation | Processing data so it can no longer be linked to a person without additional information kept separately. |
| Personal data breach | A security incident leading to the accidental or unlawful loss, destruction, alteration or disclosure of personal data. |
| Supervisory authority | The independent national data protection authority (DPA) that enforces the GDPR. |
Article 5 sets out seven principles that underpin every GDPR requirement:
Under Article 6, every processing activity needs at least one lawful basis:
For non-essential cookies, tracking pixels and personalised advertising, consent is the lawful basis in practice. Regulators and the Court of Justice of the EU have repeatedly rejected legitimate interest and contract as a basis for behavioural advertising.
Under Article 4(11), consent is a "freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her." Valid consent must be:
| GDPR Reference | Summary |
|---|---|
| Art. 4(11) | Defines consent as freely given, specific, informed and unambiguous. |
| Art. 6(1)(a) | Consent as a lawful basis for processing. |
| Art. 7(1-4) | Conditions for consent: proof, clear request, right to withdraw, no unnecessary conditioning. |
| Art. 8 | Conditions for children's consent to online services. |
| Art. 9(2)(a) | Explicit consent for special category data. |
| Recital 32 | Consent requires a clear affirmative act; silence, pre-ticked boxes and inactivity are not consent. |
| Recital 42-43 | Consent is not free if there is no genuine choice or if separate purposes cannot be consented to separately. |
The Article 29 Working Party (now the EDPB) confirmed that "scrolling down or swiping through terms and conditions which include declarations of consent will not satisfy the requirement of a clear and affirmative action." The EDPB Guidelines 05/2020 on consent remain the main reference for valid consent.
Cookies and similar technologies are regulated by two laws that work together:
What this means for websites:
Cookie consent is the most actively enforced area of the GDPR and ePrivacy rules. The French CNIL alone has issued fines of hundreds of millions of euros to large websites for making cookies hard to refuse.
The GDPR does not ban marketing, but it changes how marketing data is collected and used:
You cannot protect or delete data you cannot find. Map where personal data enters your organization (websites, apps, forms, CRM, ad platforms, support tools), where it is stored, who has access, which vendors receive it and how long it is kept. A data map is the foundation for your records of processing, your privacy policy and responding to data subject requests.
Article 8 says that when information society services (apps, websites, games, social media) rely on consent from a child, the child must be at least 16 to consent on their own. Below that age, consent must be given or authorised by a parent or guardian. Member states may lower the age to no less than 13, so the threshold varies:
| Age of digital consent | Example countries |
|---|---|
| 13 | Belgium, Denmark, Sweden, Finland, Estonia, Latvia, Malta, Portugal |
| 14 | Spain, Italy, Austria, Bulgaria, Cyprus, Lithuania |
| 15 | France, Czech Republic, Greece, Slovenia |
| 16 | Germany, Ireland, Netherlands, Poland, Hungary, Luxembourg, Romania, Slovakia, Croatia |
You must make reasonable efforts to verify parental consent, use language children can understand (Recital 58), and take extra care with profiling and advertising aimed at children.
The GDPR gives individuals eight rights (Articles 12-22). You must respond to requests without undue delay and within one month, extendable by two further months for complex or numerous requests. Requests are free of charge in most cases.
Under Article 17, a person can have their data erased when:
Erasure can be refused when processing is necessary for freedom of expression, a legal obligation, public health, archiving or research purposes, or legal claims. If you made the data public or shared it, you must take reasonable steps to inform other controllers of the erasure request.
Article 30 requires controllers and processors to keep a written record of processing activities, including purposes, categories of data and data subjects, recipients, international transfers, retention periods and security measures. The limited exemption for organizations with fewer than 250 employees does not apply when processing is regular, risky or involves special category data, so most businesses need a RoPA.
Article 35 requires a DPIA before processing that is likely to result in a high risk to individuals, such as large-scale profiling, systematic monitoring, processing special category data at scale, or new technologies. A DPIA describes the processing, assesses necessity and risks, and sets out measures to address them. Read more in our guide to the DPIA (Data Protection Impact Assessment).
Under Article 37, you must appoint a DPO if you are a public authority, or if your core activities involve large-scale regular and systematic monitoring of individuals, or large-scale processing of special category or criminal data. Organizations outside the EU that fall under the GDPR must usually also appoint an EU representative (Article 27). Read more in our guide to the DPO (Data Protection Officer).
Article 25 requires privacy to be built into systems from the start and the most privacy-friendly settings to be applied by default. For websites, this means non-essential tags stay off until the user consents.
Under Article 28, controllers may only use processors that provide sufficient guarantees, and must sign a Data Processing Agreement (DPA) covering subject matter, duration, purposes, security, sub-processors, audits and deletion of data. Learn more about Data Processing Agreements (DPA).
Chapter V restricts transfers of personal data outside the EEA. Transfers are allowed when:
Transfers are one of the most heavily fined areas of the GDPR, as shown by the record fine against Meta below.
Article 83 sets two tiers of administrative fines. The maximum is based on the higher of a fixed amount or a percentage of the company group's total worldwide annual turnover.
Applies to infringements such as:
Applies to more serious infringements, including:
Fines must be effective, proportionate and dissuasive. Authorities consider the nature, gravity and duration of the infringement, intent or negligence, steps taken to reduce damage, previous infringements and cooperation. Beyond fines, authorities can order processing to stop, require data to be deleted or suspend data transfers.
| Company | Fine | Year | Authority | Reason |
|---|---|---|---|---|
| Meta Platforms Ireland | €1.2 billion | 2023 | Irish DPC | Unlawful transfers of personal data to the United States |
| Amazon Europe | €746 million | 2021 | Luxembourg CNPD | Processing for targeted advertising without valid consent |
| TikTok | €530 million | 2025 | Irish DPC | Transfers of EEA user data to China and lack of transparency |
| Instagram (Meta) | €405 million | 2022 | Irish DPC | Processing of children's personal data |
| Meta (Facebook and Instagram) | €390 million | 2023 | Irish DPC | Invalid legal basis for personalised advertising |
| €310 million | 2024 | Irish DPC | Behavioural analysis and targeted advertising without a valid legal basis | |
| Uber | €290 million | 2024 | Dutch AP | Transfers of driver data to the United States |
| €225 million | 2021 | Irish DPC | Lack of transparency about data processing |
Cookie consent is also heavily enforced. The CNIL has fined Google, Meta, Amazon, Microsoft, TikTok and Shein for cookie banners that made refusing harder than accepting or that set advertising cookies before consent.
Use this checklist to identify gaps and maintain compliance:
A GDPR privacy policy is a public document that explains how your organization collects, uses, stores, shares and protects personal data, and how people can exercise their rights. Under Article 12 it must be concise, transparent, intelligible and easily accessible, using clear and plain language.
Creating a privacy policy from scratch takes time. Use UniConsent's free Privacy Policy Generator to create a GDPR-ready privacy policy for your business.
The GDPR applies across the European Economic Area (EEA): the 27 EU member states plus Iceland, Liechtenstein and Norway. It also applies to organizations anywhere in the world that offer goods or services to, or monitor, people in the EEA.
Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain and Sweden.
Iceland, Liechtenstein and Norway.
The UK left the EU but kept its own version of the law, the UK GDPR, alongside the Data Protection Act 2018 and PECR for cookies. Switzerland has its own revised Federal Act on Data Protection (nFADP). Both have similar consent expectations for cookies and tracking.
| GDPR | CCPA / CPRA | |
|---|---|---|
| Jurisdiction | EU/EEA, with global reach | California, United States |
| Who it applies to | Any organization processing EU/EEA personal data, regardless of size | For-profit businesses meeting revenue or data-volume thresholds |
| Consent model | Opt-in before non-essential processing and cookies | Opt-out of sale and sharing of personal information |
| Lawful basis | Required for all processing (6 bases) | Not required |
| Key user signal | Consent banner choices | "Do Not Sell or Share" link and Global Privacy Control |
| Maximum penalties | €20 million or 4% of global turnover | Per-violation administrative fines, plus private right of action for data breaches |
Websites with visitors from both regions need a CMP that shows opt-in consent in Europe and opt-out choices in the US. Learn more about the CCPA and CPRA.
UniConsent is an IAB Europe-registered and Google-certified Consent Management Platform (CMP). It covers the website side of GDPR compliance:
The official text of Regulation (EU) 2016/679 is published on EUR-Lex in all EU languages. It has 99 articles in 11 chapters and 173 recitals.
Yes. It applies to any organization that offers goods or services to people in the EU/EEA or monitors their behaviour, for example with analytics or advertising cookies, wherever the organization is based.
Yes, if your website uses any cookies or trackers that are not strictly necessary, such as analytics, advertising or social media tags. You must get opt-in consent before setting them and let users reject them as easily as accepting.
A DSAR is a request from an individual to access the personal data an organization holds about them. You must provide a copy of the data and information about how it is used within one month, free of charge in most cases.
Data minimisation means collecting and keeping only the personal data that is adequate, relevant and limited to what is necessary for your stated purpose.
A Data Protection Impact Assessment is a process to identify and reduce the risks of processing that is likely to be high risk, such as large-scale profiling or monitoring. It is mandatory under Article 35 for such processing.
A RoPA is an internal record required by Article 30 that documents what personal data you process, why, who receives it, where it is transferred, how long it is kept and how it is secured.
No. Under the ePrivacy rules, non-essential cookies require prior consent, and European regulators and courts have rejected legitimate interest as a basis for behavioural advertising.
Supervisory authorities can issue fines of up to €20 million or 4% of global annual turnover, order you to stop processing or delete data, and suspend data transfers. Individuals can also claim compensation.
If your site runs analytics or advertising tags, start a free UniConsent trial to add a GDPR consent banner, block tags until consent and keep a record of every choice.
Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up