GDPR Compliance Guide

What is the GDPR? Learn who it applies to, the 7 principles, consent and cookie rules, data subject rights, fines and a step-by-step GDPR compliance checklist.

GDPR Compliance Guide: Requirements, Rights, Consent and Fines

The General Data Protection Regulation (GDPR) is the European Union's data protection law. It gives people control over their personal data and sets rules for every organization that collects, uses or shares it, including companies outside the EU.

What Is the GDPR?

The GDPR (Regulation (EU) 2016/679) is a regulation that harmonizes data protection law across all EU member states. It was adopted on 27 April 2016 and has applied since 25 May 2018, replacing the 1995 Data Protection Directive (95/46/EC). The text contains 99 articles in 11 chapters, supported by 173 recitals that explain how the articles should be interpreted.

Because it is a regulation rather than a directive, the GDPR applies directly in every member state without needing national laws to implement it. Member states can still add rules in specific areas, such as the age of digital consent or employee data.

GDPR, DSGVO and RGPD: the same law

The GDPR is known by different names across Europe:

  • GDPR: General Data Protection Regulation (English)
  • DSGVO: Datenschutz-Grundverordnung (German)
  • RGPD: Règlement général sur la protection des données (French), Reglamento General de Protección de Datos (Spanish), and the equivalent names in Italian and Portuguese
  • AVG: Algemene verordening gegevensbescherming (Dutch)

When did the GDPR go into effect?

The GDPR entered into force on 24 May 2016 and became enforceable on 25 May 2018, after a two-year transition period that gave organizations time to prepare. Supervisory authorities have been issuing fines under it ever since.

Who Does the GDPR Apply To?

The GDPR has extraterritorial reach (Article 3). It applies to:

  1. Organizations established in the EU/EEA that process personal data, wherever the processing takes place.
  2. Organizations outside the EU/EEA that offer goods or services to people in the EU/EEA, whether paid or free.
  3. Organizations outside the EU/EEA that monitor the behaviour of people in the EU/EEA, for example through tracking cookies, analytics, profiling or targeted advertising.

If your website gets visitors from Europe and runs analytics, advertising or marketing tags, the GDPR applies to you. There is no exemption for small companies.

Key GDPR Terms and Definitions

TermMeaning (Article 4)
Personal dataAny information relating to an identified or identifiable person, including names, emails, IP addresses, cookie IDs, device IDs and location data.
Special category dataSensitive data such as health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade union membership and sexual orientation (Article 9).
Data subjectThe individual the personal data relates to.
ProcessingAny operation on personal data: collecting, recording, storing, using, sharing, erasing and so on.
ControllerThe organization that decides why and how personal data is processed.
ProcessorAn organization that processes personal data on behalf of a controller, such as a hosting or email provider.
ConsentA freely given, specific, informed and unambiguous indication of the data subject's wishes by a clear affirmative action.
PseudonymisationProcessing data so it can no longer be linked to a person without additional information kept separately.
Personal data breachA security incident leading to the accidental or unlawful loss, destruction, alteration or disclosure of personal data.
Supervisory authorityThe independent national data protection authority (DPA) that enforces the GDPR.

The 7 Principles of the GDPR

Article 5 sets out seven principles that underpin every GDPR requirement:

  1. Lawfulness, fairness and transparency: Process data lawfully, fairly and in a way people can understand.
  2. Purpose limitation: Collect data for specified, explicit and legitimate purposes, and do not reuse it for incompatible purposes.
  3. Data minimisation: Collect only the data that is adequate, relevant and necessary for the purpose.
  4. Accuracy: Keep personal data accurate and up to date, and correct or delete inaccurate data.
  5. Storage limitation: Keep data in identifiable form no longer than necessary.
  6. Integrity and confidentiality: Protect data with appropriate security against unauthorised access, loss or damage.
  7. Accountability: The controller is responsible for compliance and must be able to demonstrate it.

The 6 Lawful Bases for Processing Personal Data

Under Article 6, every processing activity needs at least one lawful basis:

  1. Consent: The person has given valid consent for a specific purpose.
  2. Contract: Processing is necessary to perform a contract with the person, or to take steps before entering one.
  3. Legal obligation: Processing is necessary to comply with the law.
  4. Vital interests: Processing is necessary to protect someone's life.
  5. Public task: Processing is necessary for a task in the public interest or official authority.
  6. Legitimate interests: Processing is necessary for your legitimate interests, unless those interests are overridden by the person's rights and freedoms.

For non-essential cookies, tracking pixels and personalised advertising, consent is the lawful basis in practice. Regulators and the Court of Justice of the EU have repeatedly rejected legitimate interest and contract as a basis for behavioural advertising.

Understanding Consent Under the GDPR

What is valid consent?

Under Article 4(11), consent is a "freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her." Valid consent must be:

  • Freely given: A real choice, with no detriment for refusing. Rejecting must be as easy as accepting.
  • Specific: Separate consent for separate purposes, such as analytics and advertising.
  • Informed: People must know who you are, what data you collect, why, and who you share it with.
  • Unambiguous: A clear affirmative action, such as clicking "Accept" or ticking an unchecked box.
  • Withdrawable: It must be as easy to withdraw consent as to give it (Article 7(3)).
  • Documented: You must be able to prove consent was given (Article 7(1)).

Acceptable forms of consent

  • Ticking an unchecked checkbox on a web form
  • Clicking a clearly labelled "Accept" or "I agree" button in a consent banner
  • Choosing technical settings, such as toggling purposes in a preference centre
  • A written or recorded oral statement

Unacceptable consent practices

  • Pre-ticked boxes or pre-enabled toggles (confirmed invalid by the CJEU in Planet49, 2019)
  • Silence or inactivity
  • "Scroll to accept" or "continuing to browse means you agree"
  • Bundled consent covering several unrelated purposes with one click
  • Cookie walls that block access unless the user accepts, without a genuine alternative
  • Hiding the reject option behind extra clicks while "Accept all" is one click away

Key GDPR articles on consent

GDPR ReferenceSummary
Art. 4(11)Defines consent as freely given, specific, informed and unambiguous.
Art. 6(1)(a)Consent as a lawful basis for processing.
Art. 7(1-4)Conditions for consent: proof, clear request, right to withdraw, no unnecessary conditioning.
Art. 8Conditions for children's consent to online services.
Art. 9(2)(a)Explicit consent for special category data.
Recital 32Consent requires a clear affirmative act; silence, pre-ticked boxes and inactivity are not consent.
Recital 42-43Consent is not free if there is no genuine choice or if separate purposes cannot be consented to separately.

The Article 29 Working Party (now the EDPB) confirmed that "scrolling down or swiping through terms and conditions which include declarations of consent will not satisfy the requirement of a clear and affirmative action." The EDPB Guidelines 05/2020 on consent remain the main reference for valid consent.

Cookies and the GDPR

Cookies and similar technologies are regulated by two laws that work together:

  • The ePrivacy Directive (Article 5(3)) requires prior consent before storing or reading information on a user's device, unless it is strictly necessary for a service the user requested.
  • The GDPR defines the standard of that consent and governs the personal data collected. Recital 30 confirms that online identifiers such as cookie IDs and IP addresses can be personal data.

What this means for websites:

  • Strictly necessary cookies (session, security, load balancing, shopping cart, storing the consent choice) do not require consent.
  • Analytics, advertising, personalisation and social media cookies require opt-in consent before they are set.
  • Tags such as Google Analytics, Google Ads, Meta Pixel, LinkedIn Insight and TikTok Pixel must be blocked or run in a consent-aware mode until the user agrees.
  • The banner must offer Accept and Reject with equal prominence, plus granular choices. See what a compliant cookie banner needs.
  • Users must be able to change their choice at any time, for example through a persistent settings link.

Cookie consent is the most actively enforced area of the GDPR and ePrivacy rules. The French CNIL alone has issued fines of hundreds of millions of euros to large websites for making cookies hard to refuse.

GDPR and Digital Marketing

The GDPR does not ban marketing, but it changes how marketing data is collected and used:

  • Tracking and profiling for personalised ads requires consent. Show a consent banner at the first interaction and do not fire marketing tags before consent.
  • Email marketing generally requires opt-in consent under the ePrivacy rules, with a limited "soft opt-in" for existing customers in many member states. Every email needs an easy unsubscribe.
  • Data from third parties: When you obtain personal data from another source, you must inform the person within a reasonable period and at the latest within one month (Article 14).
  • Right to object: People can object to direct marketing at any time, and you must stop.
  • Ad tech signals: Publishers and advertisers use the IAB Transparency and Consent Framework (TCF) and Google Consent Mode v2 to pass consent choices to vendors. Since March 2024, Google requires a Google-certified CMP and Consent Mode signals for ads personalisation and measurement in the EEA and UK.

Data discovery and mapping

You cannot protect or delete data you cannot find. Map where personal data enters your organization (websites, apps, forms, CRM, ad platforms, support tools), where it is stored, who has access, which vendors receive it and how long it is kept. A data map is the foundation for your records of processing, your privacy policy and responding to data subject requests.

Children's Data Under the GDPR

Article 8 says that when information society services (apps, websites, games, social media) rely on consent from a child, the child must be at least 16 to consent on their own. Below that age, consent must be given or authorised by a parent or guardian. Member states may lower the age to no less than 13, so the threshold varies:

Age of digital consentExample countries
13Belgium, Denmark, Sweden, Finland, Estonia, Latvia, Malta, Portugal
14Spain, Italy, Austria, Bulgaria, Cyprus, Lithuania
15France, Czech Republic, Greece, Slovenia
16Germany, Ireland, Netherlands, Poland, Hungary, Luxembourg, Romania, Slovakia, Croatia

You must make reasonable efforts to verify parental consent, use language children can understand (Recital 58), and take extra care with profiling and advertising aimed at children.

Data Subject Rights Under the GDPR

The GDPR gives individuals eight rights (Articles 12-22). You must respond to requests without undue delay and within one month, extendable by two further months for complex or numerous requests. Requests are free of charge in most cases.

  1. Right to be informed (Art. 13-14): To be told what data is collected, why, by whom, for how long and who it is shared with, usually through a privacy notice.
  2. Right of access (Art. 15): To obtain a copy of their personal data and information about how it is used. This is known as a Data Subject Access Request (DSAR).
  3. Right to rectification (Art. 16): To have inaccurate data corrected and incomplete data completed.
  4. Right to erasure / "right to be forgotten" (Art. 17): To have data deleted in certain circumstances.
  5. Right to restrict processing (Art. 18): To limit how data is used, for example while accuracy is disputed.
  6. Right to data portability (Art. 20): To receive data they provided in a structured, machine-readable format and transfer it to another controller.
  7. Right to object (Art. 21): To object to processing based on legitimate interests or public task, and an absolute right to object to direct marketing.
  8. Rights related to automated decision-making and profiling (Art. 22): Not to be subject to decisions based solely on automated processing that have legal or similarly significant effects, without safeguards.

When must data be deleted?

Under Article 17, a person can have their data erased when:

  • The data is no longer necessary for the purpose it was collected for
  • They withdraw consent and there is no other lawful basis
  • They object to processing and there are no overriding legitimate grounds, or they object to direct marketing
  • The data was processed unlawfully
  • Erasure is required by a legal obligation
  • The data was collected from a child for online services

Erasure can be refused when processing is necessary for freedom of expression, a legal obligation, public health, archiving or research purposes, or legal claims. If you made the data public or shared it, you must take reasonable steps to inform other controllers of the erasure request.

Accountability: What the GDPR Requires You to Document

Records of Processing Activities (RoPA)

Article 30 requires controllers and processors to keep a written record of processing activities, including purposes, categories of data and data subjects, recipients, international transfers, retention periods and security measures. The limited exemption for organizations with fewer than 250 employees does not apply when processing is regular, risky or involves special category data, so most businesses need a RoPA.

Data Protection Impact Assessment (DPIA)

Article 35 requires a DPIA before processing that is likely to result in a high risk to individuals, such as large-scale profiling, systematic monitoring, processing special category data at scale, or new technologies. A DPIA describes the processing, assesses necessity and risks, and sets out measures to address them. Read more in our guide to the DPIA (Data Protection Impact Assessment).

Data Protection Officer (DPO)

Under Article 37, you must appoint a DPO if you are a public authority, or if your core activities involve large-scale regular and systematic monitoring of individuals, or large-scale processing of special category or criminal data. Organizations outside the EU that fall under the GDPR must usually also appoint an EU representative (Article 27). Read more in our guide to the DPO (Data Protection Officer).

Data protection by design and by default

Article 25 requires privacy to be built into systems from the start and the most privacy-friendly settings to be applied by default. For websites, this means non-essential tags stay off until the user consents.

Processors and Data Processing Agreements

Under Article 28, controllers may only use processors that provide sufficient guarantees, and must sign a Data Processing Agreement (DPA) covering subject matter, duration, purposes, security, sub-processors, audits and deletion of data. Learn more about Data Processing Agreements (DPA).

Data breach notification

  • Notify your supervisory authority within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to individuals (Article 33).
  • Notify affected individuals without undue delay when the breach is likely to result in a high risk (Article 34).
  • Document every breach, including those not reported.

International Data Transfers

Chapter V restricts transfers of personal data outside the EEA. Transfers are allowed when:

  • The European Commission has issued an adequacy decision for the destination (such as the UK, Switzerland, Japan, South Korea, Canada for commercial organizations, and the United States for companies certified under the EU-US Data Privacy Framework since July 2023)
  • Appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs), supported by a transfer impact assessment
  • A specific derogation applies, such as explicit consent for an occasional transfer

Transfers are one of the most heavily fined areas of the GDPR, as shown by the record fine against Meta below.

Who Enforces the GDPR?

  • National supervisory authorities (DPAs): Each EU/EEA country has an independent data protection authority, such as the CNIL (France), the Irish Data Protection Commission, the German federal and state authorities, the Spanish AEPD, the Italian Garante and the Dutch Autoriteit Persoonsgegevens. They investigate complaints, carry out audits and issue fines and orders.
  • One-stop-shop: Companies with a main establishment in the EU deal mainly with a lead supervisory authority in that country for cross-border processing (Article 56).
  • European Data Protection Board (EDPB): Brings together all national authorities, issues guidelines and resolves disputes between them to ensure consistent enforcement.
  • Courts and individuals: Individuals can complain to a DPA, go to court and claim compensation for material or non-material damage (Article 82). Consumer groups can bring representative actions.

GDPR Fines and Penalties

Article 83 sets two tiers of administrative fines. The maximum is based on the higher of a fixed amount or a percentage of the company group's total worldwide annual turnover.

Lower tier: up to €10 million or 2% of global annual turnover

Applies to infringements such as:

  • Failing to keep records of processing activities
  • Failing to notify a data breach to the authority or to individuals
  • Not implementing data protection by design and by default
  • Missing Data Processing Agreements or using unsuitable processors
  • Not appointing a DPO or EU representative when required
  • Breaching the conditions for children's consent

Higher tier: up to €20 million or 4% of global annual turnover

Applies to more serious infringements, including:

  • Breaching the basic principles of processing, including lawfulness, fairness and transparency
  • Processing without a valid lawful basis or without valid consent
  • Infringing data subject rights, such as access, erasure and objection
  • Unlawful international data transfers
  • Failing to comply with an order from a supervisory authority

Fines must be effective, proportionate and dissuasive. Authorities consider the nature, gravity and duration of the infringement, intent or negligence, steps taken to reduce damage, previous infringements and cooperation. Beyond fines, authorities can order processing to stop, require data to be deleted or suspend data transfers.

Notable GDPR fines

CompanyFineYearAuthorityReason
Meta Platforms Ireland€1.2 billion2023Irish DPCUnlawful transfers of personal data to the United States
Amazon Europe€746 million2021Luxembourg CNPDProcessing for targeted advertising without valid consent
TikTok€530 million2025Irish DPCTransfers of EEA user data to China and lack of transparency
Instagram (Meta)€405 million2022Irish DPCProcessing of children's personal data
Meta (Facebook and Instagram)€390 million2023Irish DPCInvalid legal basis for personalised advertising
LinkedIn€310 million2024Irish DPCBehavioural analysis and targeted advertising without a valid legal basis
Uber€290 million2024Dutch APTransfers of driver data to the United States
WhatsApp€225 million2021Irish DPCLack of transparency about data processing

Cookie consent is also heavily enforced. The CNIL has fined Google, Meta, Amazon, Microsoft, TikTok and Shein for cookie banners that made refusing harder than accepting or that set advertising cookies before consent.

GDPR Compliance Checklist

Use this checklist to identify gaps and maintain compliance:

1. Map your personal data

  • Identify what personal data you collect, from where, why, where it is stored and who receives it.
  • Create and maintain your Records of Processing Activities.

2. Establish a lawful basis for each purpose

  • Document the lawful basis for every processing activity.
  • Use consent for non-essential cookies, tracking and personalised advertising.

3. Implement a GDPR-compliant consent banner

  • Block non-essential cookies and tags until consent.
  • Offer Accept, Reject and granular choices with equal prominence.
  • Store proof of consent and let users change their choice at any time.
  • Pass consent signals to Google (Consent Mode v2) and ad tech vendors (IAB TCF).

4. Publish a transparent privacy policy and cookie policy

  • Explain what you collect, why, how long you keep it, who you share it with and how people can exercise their rights.
  • List the cookies and trackers used on your website.

5. Enable data subject rights

  • Provide a simple way to submit access, deletion, correction, portability and objection requests.
  • Verify identity and respond within one month.

6. Manage vendors and processors

  • Audit third-party tools and sign Data Processing Agreements.
  • Put transfer safeguards in place for vendors outside the EEA.

7. Build in privacy and security

  • Apply data protection by design and by default.
  • Minimise data, set retention periods and delete data you no longer need.
  • Use encryption, access controls and regular security testing.

8. Assess high-risk processing

  • Carry out DPIAs for high-risk processing.
  • Appoint a DPO and an EU representative where required.

9. Prepare for data breaches

  • Set up a procedure to detect, assess, record and report breaches within 72 hours.

10. Train staff and review regularly

  • Train employees on data protection.
  • Review policies, cookies and vendors regularly, and after new laws or guidance.

How to Create a GDPR Privacy Policy

A GDPR privacy policy is a public document that explains how your organization collects, uses, stores, shares and protects personal data, and how people can exercise their rights. Under Article 12 it must be concise, transparent, intelligible and easily accessible, using clear and plain language.

Key elements of a GDPR privacy policy (Articles 13-14)

  1. Identity and contact details of the controller, and of the DPO or EU representative if applicable
  2. What personal data you collect
  3. Purposes of processing and the lawful basis for each
  4. Legitimate interests pursued, where relevant
  5. Recipients and third parties
  6. International transfers and the safeguards used
  7. Retention periods
  8. Data subject rights and how to exercise them
  9. The right to withdraw consent at any time
  10. The right to complain to a supervisory authority
  11. Use of cookies and tracking technologies
  12. Any automated decision-making or profiling

Creating a privacy policy from scratch takes time. Use UniConsent's free Privacy Policy Generator to create a GDPR-ready privacy policy for your business.

GDPR Countries: Where Does the GDPR Apply?

The GDPR applies across the European Economic Area (EEA): the 27 EU member states plus Iceland, Liechtenstein and Norway. It also applies to organizations anywhere in the world that offer goods or services to, or monitor, people in the EEA.

EU member states (27 countries)

Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain and Sweden.

EEA countries outside the EU

Iceland, Liechtenstein and Norway.

UK GDPR and Switzerland

The UK left the EU but kept its own version of the law, the UK GDPR, alongside the Data Protection Act 2018 and PECR for cookies. Switzerland has its own revised Federal Act on Data Protection (nFADP). Both have similar consent expectations for cookies and tracking.

GDPR vs CCPA/CPRA

GDPRCCPA / CPRA
JurisdictionEU/EEA, with global reachCalifornia, United States
Who it applies toAny organization processing EU/EEA personal data, regardless of sizeFor-profit businesses meeting revenue or data-volume thresholds
Consent modelOpt-in before non-essential processing and cookiesOpt-out of sale and sharing of personal information
Lawful basisRequired for all processing (6 bases)Not required
Key user signalConsent banner choices"Do Not Sell or Share" link and Global Privacy Control
Maximum penalties€20 million or 4% of global turnoverPer-violation administrative fines, plus private right of action for data breaches

Websites with visitors from both regions need a CMP that shows opt-in consent in Europe and opt-out choices in the US. Learn more about the CCPA and CPRA.

How UniConsent Helps You Comply With the GDPR

UniConsent is an IAB Europe-registered and Google-certified Consent Management Platform (CMP). It covers the website side of GDPR compliance:

  • GDPR-compliant consent banner with Accept, Reject and granular purpose choices, fully customisable to your brand
  • Automatic blocking of non-essential cookies and scripts until consent
  • Cookie scanning that detects and categorises cookies and generates your cookie declaration
  • Consent records that store proof of consent to support your accountability obligations
  • Google Consent Mode v2 and IAB TCF v2.3 support for Google Ads, Google Analytics and ad tech vendors
  • Geo-targeting to show GDPR opt-in consent in Europe and opt-out choices in the US
  • Multi-language banners covering all EU languages
  • One-tag installation directly or with Google Tag Manager, WordPress and Shopify

Frequently Asked Questions About the GDPR

Where can I find the full GDPR text?

The official text of Regulation (EU) 2016/679 is published on EUR-Lex in all EU languages. It has 99 articles in 11 chapters and 173 recitals.

Does the GDPR apply to companies outside the EU?

Yes. It applies to any organization that offers goods or services to people in the EU/EEA or monitors their behaviour, for example with analytics or advertising cookies, wherever the organization is based.

Do I need a cookie banner for GDPR compliance?

Yes, if your website uses any cookies or trackers that are not strictly necessary, such as analytics, advertising or social media tags. You must get opt-in consent before setting them and let users reject them as easily as accepting.

What is a Data Subject Access Request (DSAR)?

A DSAR is a request from an individual to access the personal data an organization holds about them. You must provide a copy of the data and information about how it is used within one month, free of charge in most cases.

What does data minimisation mean?

Data minimisation means collecting and keeping only the personal data that is adequate, relevant and limited to what is necessary for your stated purpose.

What is a DPIA?

A Data Protection Impact Assessment is a process to identify and reduce the risks of processing that is likely to be high risk, such as large-scale profiling or monitoring. It is mandatory under Article 35 for such processing.

What is a Record of Processing Activities (RoPA)?

A RoPA is an internal record required by Article 30 that documents what personal data you process, why, who receives it, where it is transferred, how long it is kept and how it is secured.

Is legitimate interest enough for analytics and advertising cookies?

No. Under the ePrivacy rules, non-essential cookies require prior consent, and European regulators and courts have rejected legitimate interest as a basis for behavioural advertising.

What happens if I am not GDPR compliant?

Supervisory authorities can issue fines of up to €20 million or 4% of global annual turnover, order you to stop processing or delete data, and suspend data transfers. Individuals can also claim compensation.

Further Reading

If your site runs analytics or advertising tags, start a free UniConsent trial to add a GDPR consent banner, block tags until consent and keep a record of every choice.

UniConsent Consent Manager for GDPR Compliance

  • Certified IAB CMP
  • Google Consent Mode v2 support
  • Fully customisable multiple stages
  • One-tag Implementation
  • Google Tag Manager support
  • Tracking and insight
  • Multiple languages support
  • IAB TCF and Google DFP support
  • Prebid GDPR CMP API support
  • JavaScript tags blocking and cookies blocking
  • Cookies scan and disclosing
  • Certified by IAB Europe
  • Easy self-serve solution
  • Learn more from GDPR Summary

Microsoft certified CMP - UniConsent CMPIAB certified CMP - UniConsent CMPIAB TCF V2 certified CMP - UniConsent CMPIAB TCF Canada certified consent manager - UniConsent CMPGoogle-certified CMP Gold tire - UniConsent CMPGoogle-certified CMP partner

Comply With Global Privacy Regulations

Trusted by 5000+ of global publishers and marketers
  • sej
  • football365
  • sharethrough
  • districtm
  • pf1
  • tower cast

Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc

Sign up