AI Summarize

Share

The General Data Protection Regulation (GDPR) is the primary data protection law in the EU. It sets out rules for how organizations collect, use, store, and share the personal data of people in the EU.

You're in the right place, if you're looking for information about how to understand and comply with the GDPR. The GDPR affects any organization that processes the data of people in the EU/EEA. This includes if your business is based outside of the EU/EEA.

The GDPR gives individuals control over their data and privacy rights. It carries heavy fines for businesses who don't comply: up to 20 million Euros or 4% of global turnover.

This article covers what the GDPR is and the key terms, privacy principles, and who the GDPR applies to. It goes into detail on the lawful bases available for processing data under the GDPR, individual rights and business obligations, and how to get started with GDPR compliance.

At the end of this article you'll find information on what kind of Privacy Policy is required, including a template, and advice on how to handle DSAR requests. Finally you'll learn about potential fines, GDPR myths, interactions with other laws, and GDPR frequently asked questions.

GDPR compliance requires a number of documents, such as a Privacy Policy in particular. TermsFeed helps businesses with this compliance, using the TermsFeed Privacy Policy generator.

Our Privacy Policy Generator makes it easy to create a Privacy Policy for your business. Just follow these steps:

  1. At Step 1, select the Website option or App option or both.

    TermsFeed Privacy Policy Generator: Create Privacy Policy - Step 1

  2. Answer some questions about your website or app.

    TermsFeed Privacy Policy Generator: Answer questions about website - Step 2

  3. Answer some questions about your business.

    TermsFeed Privacy Policy Generator: Answer questions about business practices  - Step 3

  4. Enter the email address where you'd like the Privacy Policy delivered and click "Generate."

    TermsFeed Privacy Policy Generator: Enter your email address - Step 4

    You'll be able to instantly access and download your new Privacy Policy.



What Is the GDPR?

The GDPR is the General Data Protection Regulation, an EU law that sets rules for handling personal data. The GDPR is intended to give people control over their data, and respects people's privacy rights.

The GDPR was passed in April 2016, and came into full effect on 25 May 2018. It replaced the 1995 Data Protection Directive. The law harmonized privacy and data protection laws for all EU member states, so that laws across the region were consistent.

The GDPR was created because existing laws were not capable of handling modern data-theft risks or data misuse. Personal data had become a trillion dollar industry (big data), but individuals had minimal control. The GDPR then gave individuals the ability to control who had access to their data, and how their data is used, shared, or retained.

The GDPR introduced the idea of "Privacy by Design", which means that privacy principles are incorporated from the start into the design of websites and products that use personal data.

The Privacy by Design principle is important to understand, as you will need to follow Privacy by Design principles when you are creating software or hardware products, websites or apps, that process personal data. Trying to integrate Privacy by Design principles after the fact is harder than incorporating them from the beginning, so start as early as possible in your design process.

The introduction of the GDPR set a new global benchmark for privacy rights, and influenced many other laws. It led to the development of the California Consumer Privacy Act (CCPA), the Lei Geral de Proteção de Dados in Brazil (LGPD), and other privacy laws around the world such as the Personal Information Protection Law in China (PIPL). You will find the influence of the GDPR in other laws you are subject to, even if you are not in the EU.

Overall, the GDPR set the standard for individual privacy rights and the types of data protection obligations that businesses around the world must follow.

Key GDPR Terms Explained (A Beginner's Glossary)

Before going further, here are the words you will keep hearing throughout this guide and in any conversation about the GDPR.

Term Explanation
Personal data Personal data is any information that potentially identifies a living person, whether directly or indirectly. This includes information such as name, email, IP address, cookie ID, location, or opinions.
Special category (sensitive) data Special category data is health, biometric, genetic, racial/ethnic, political, religious, trade-union, or sexual-orientation data. This data is covered by Article 9 of the GDPR and is subject to stricter rules.
Data subject The data subject is the individual whose data is being processed.
Processing Data processing is almost anything you do with data, such as collecting, storing, using, sharing, deleting.
Data controller The data controller is the entity that decides why and how data is processed.
Data processor

The data processor is the third party that processes data on behalf of the data controller.

For example, your business is the data controller, and MailChimp/Aweber (or similar programs) is the data processor, when conducting email marketing.

The 7 Principles of the GDPR

The GDPR is built on seven principles that underpin every right and obligation in the regulation. Take these principles into account when you are dealing with personal data or designing products that will process personal data.

The seven principles are the following.

  1. Lawfulness, fairness, and transparency means that you need to process data only in lawful ways, use data in ways that normal people expect, and be open about what you are doing.

    For example, if you are conducting online marketing, you need to let customers know this is happening, tell them what data you will collect and how you will use it for marketing purposes.

  2. Purpose limitation is the idea that personal data is only collected for legitimate, explicit, specified purposes, and nothing more.

    For instance, data used to fulfill orders for a clothing store is not automatically repurposable for marketing.

  3. Data minimization is the concept that you collect as little data as possible, and nothing extra.

    For example, for an online clothing store, you need a customer address and credit card information, but not their birthdate, political beliefs, or even gender.

  4. Accuracy means that data must be kept up-to-date and accurate. If data becomes incorrect or out-of-date, you need to delete it or update it.
  5. Storage limitation means that you must only keep data as long as necessary to fulfill the purposes that you collected it for.
  6. Integrity and confidentiality (security) means that data must be kept secure and confidential. You must protect it against unauthorized access (e.g. through hacks or leaks). This includes taking technical steps like using encryption, anonymization, and pseudonymization, as well as physical measures to protect data like locking server rooms.
  7. Accountability means that you are responsible for complying with the GDPR, and accountable for following these principles. You have to be able to demonstrate, or show, your compliance through detailed records.

These principles are the foundation that everything else in the GDPR builds on.

Does the GDPR Apply to You?

One of the biggest misconceptions about the GDPR is that it only applies to EU companies. Rather, it applies to any company or organization processing the data of people in the EU.

The GDPR has what is called "extraterritorial reach". This means that even though it is an EU law, it applies to companies or organizations outside of the EU in some circumstances.

Article 3 of the GDPR says that the GDPR applies to controllers or data processors that are processing personal data "regardless of whether the processing takes place in the Union or not".

Your processing will be covered by the GDPR, if you are a data controller or processor outside of the EU, and if you are:

  • Offering goods or services to data subjects in the EU (regardless of whether or not payment is required)
  • Monitoring the behavior of data subjects in the EU, as their behavior takes place within the EU

The application of the GDPR depends on the physical location of the individual data subject, not their nationality. Small businesses, sole traders, charities or clubs are not exempt from these rules.

You will be covered by the GDPR and need to comply, if you are an EU company or organization, processing the data of people in the EU.

Does the GDPR Apply to US and Non-EU Businesses?

Yes, in many cases it does. A US or other non-EU business must comply with the GDPR if it offers goods or services to people in the EU/EEA or monitors their behavior.

For example, a California company collecting the data of EU users, or a company in Australia tracking visitors to its website, will both have to comply with the GDPR.

This means that in many cases, you will need to consider the GDPR in your legal and privacy planning, particularly if your business is international. Many GDPR beginners assume that geographic distance from the EU means you are exempt. This is incorrect.

The GDPR likely doesn't apply to you, if your business has no EU customers and does not track or monitor people in the EU.

Who Is Exempt from the GDPR?

Exemptions from the GDPR are rare.

For example, collecting personal data for purely personal or household activities is exempt from the GDPR. This includes activities like taking photos for your family photo album.

Processing for the purposes of law enforcement and criminal justice data processing is excluded. These activities are considered out of the scope of the GDPR. Data processing done by EU member states in pursuit of the common EU foreign and security policy is excluded.

You will be subject to lighter documentation duties, if your company or organization has less than 250 employees. However, these lighter documentation duties disappear, if your organization processes sensitive data or processes frequently.

The GDPR will not apply to you if you are not processing any personal data during your business activities. This is still the case even if you are based in the EU, as long as you are not collecting the data of or tracking people in the EU.

The 6 Lawful Bases for Processing Personal Data

You cannot just process personal data because you want to. Instead, you need a lawful basis (or a lawful reason) for doing so.

The GDPR gives you six lawful bases that are relevant to your data processing activities. You only need to meet one of these lawful bases to process data.

The following list explains all 6 lawful bases.

  1. Consent means you have clear, affirmative agreement from an individual saying that you are allowed to process their personal data for a specific purpose.

    One example of this is a customer checking a checkbox on your website.

  2. Contract means you are permitted to process the data necessary to fulfill a contract with someone.

    For example, if a customer orders a product from you, you need their address to send it to them.

  3. Legal obligation means you need to carry out the processing to comply with a legal obligation you have.

    One example of this is retaining invoices or customer information for long periods of time to comply with auditing requirements or an ongoing legal dispute.

  4. Vital interests means the processing is necessary to protect the life of someone.
  5. Performing a task in the public interest means processing data for public interest tasks or for your official functions is permitted.
  6. Legitimate interest means processing data necessary for your legitimate interests is permitted, unless there is a good reason not to (i.e. something in favor of protecting the privacy or data of the other person).

    In those cases, the interests of the individual override your legitimate interest. One example of this is data collection for fraud prevention.

The most important lawful bases for most businesses are consent, contract, and legitimate interest. This is because they are the ones most likely to be used for typical commercial processing. Consider the "legal obligation" lawful basis, if you work in certain fields or are faced with a lawsuit (you must retain documents during the dispute).

Here's an example from Cloudflare in which the lawful bases are outlined in its Privacy Policy, along with an invitation to contact the company if more information is needed.

Cloudflare Privacy Policy - Notice To EU, UK, And Swiss Residents clasue excerpt

Whichever lawful basis applies to the processing you want to undertake, you need to make sure the lawful basis is valid before you begin processing. You must tell data subjects which lawful bases you rely on. This is outlined in your Privacy Policy.

Individual Rights Under the GDPR

The GDPR gives people control over their data through a set of rights.

There are eight rights under the GDPR. These rights are the following.

  1. The right to be informed means that individuals have a right to know what data you are collecting, for what purpose, and what you will do with it (e.g. sharing, transferring or storing). You must provide this information in your Privacy Policy and make sure your customers or users have an opportunity to read it and agree to it validly.
  2. The right of access means that individuals have a right to request a copy of their data that you are processing. They have a right to ask who you share it with and what purposes you use it for.
  3. The right to rectification means that individuals have a right for you to correct inaccurate data. This includes completing incomplete data.
  4. The right to erasure means individuals have the right to have their data deleted. This right is often called "the right to be forgotten".
  5. The right to restrict processing means that individuals have a right to ask you to restrict or limit processing of their data to certain purposes.
  6. The right to data portability means individuals have the right to receive a machine-readable format of their data, and transfer it elsewhere.
  7. The right to object means individuals have the right to object to the processing you are doing. This right mostly applies to activities like direct marketing or processing under the legitimate interests lawful basis.
  8. The right not to be subject to automated decision-making means that individuals have the right not to have decisions made about them on a solely automated basis, if those decisions have legal or similarly significant effects. For example, bank loan decisions made solely by machine learning or AI processes.

Here's how Clubhouse adapts its Privacy Policy to satisfy the GDPR's individual rights requirements.

Clubhouse Privacy Policy: GDPR Rights clause excerpt

The individual rights set out in the GDPR are not absolute. There are some exceptions. For example, the right to erasure is not enforceable if your company needs to retain the data because of other legal rules, or if a lawsuit is ongoing.

How People Exercise Their Rights (DSARs)

The main way individuals exercise their GDPR rights is through a Data Subject Access Request (DSAR). All organizations and businesses are potentially subject to a DSAR at any time.

Through the DSAR a data subject asks what data you hold on them, request a copy of that data, or ask you to correct, delete, transfer, or stop processing that data.

Here's an example of how Amazon provides users with a DSAR request process for accessing copies of customer data.

Amazon Privacy Central - Data requests example

DSARs are made in several different ways. This includes verbally or in writing, through your website, email, or letter. Once you receive a DSAR you have to respond within one month.

A useful approach is to proactively set up a process through which people send you DSAR requests. An inbox e.g. [email protected] is one possibility, or a DSAR web form on your website. It's important that you don't make people jump through hoops to submit a request.

What the GDPR Requires of Businesses

Here is what you actually have to do in terms of business steps to take, if the GDPR applies to you.

  1. Have a lawful basis for processing and be transparent. Before you start processing personal data, determine which lawful basis applies. Then, draft a Privacy Policy that is clear and transparent about what data you are collecting and why.
  2. Keep data secure. Any data you collect needs to be kept secure. This means physical, organizational and technical security measures, including keeping paper files in locked cabinets, or using encryption and anonymization for digital data. You must regularly test and assess your measures.
  3. Notify breaches within 72 hours. You need to notify the Supervisory Authority within 72 hours if any data breaches occur. As soon as you notice a breach, start this timer, as the clock starts from when you discover the breach, not when it actually happened.
  4. Appoint a DPO where required. A Data Protection Officer (DPO) is a person who is tasked with making sure your business or organization protects personal data in line with the GDPR.
  5. Carry out DPIAs for high-risk processing. A Data Protection Impact Assessment (DPIA) is a process that helps you to identify and mitigate potential risks to individual data subjects. Carry out a DPIA if data processing is potentially high risk to the individual.
  6. Safeguard international data transfers. You need to check whether the transfer country has equivalent protections for data, when you transfer data internationally. You need to protect any data transferred, using mechanisms like encryption and pseudonymization.
  7. Build in privacy by design and default. This means making design choices that consider privacy considerations by default, and incorporating them into your processes and products.
  8. Keep records of processing activities. Keeping records helps you meet your GDPR obligations. This is because you have to demonstrate, for example, how and when consent was collected, among other things. This protects you against fines.

The following sections go through these business obligations in more detail.

Data Breach Notification (72 Hours)

A personal data breach is any accidental or unlawful loss, destruction, alteration, or unauthorized disclosure of or access to personal data.

You must notify the supervisory authority within 72 hours of becoming aware of the breach if or when a data breach occurs. The 72 hour timer does not begin when the breach actually happened. Notify individuals without delay if the data breach is a high risk to them.

Document every breach with a report including a description of the nature of the breach, the categories of data, number of people or accounts affected, the consequences, and measures you have taken. Include the contact details of the DPO.

Valid consent under the GDPR must be freely given, specific, informed, and unambiguous. It must be expressed by the individual through a clear affirmative action.

This means that you are not allowed to use pre-ticked boxes or bundling approaches. Silence or inactivity are not valid consent.

Here's an example of how Diptyque gets explicit consent from users before they sign up for marketing on its website.

Diptyque Paris - Subscribe form with unchecked checkbox to agree to Privacy Policy and Cookie PolicyDiptyque Paris - Subscribe form with unchecked checkbox to agree to Privacy Policy and Cookie Policy

Note that the subscribe button is unclickable until the checkbox has been checked. This is another way to ensure that clear consent has been received.

Freely given consent means that the user or customer must have a real choice. Don't make your service contingent on processing data if it isn't necessary for your service. Specific and informed means the individual needs to know what they are agreeing to. Your data privacy practices must be disclosed in your Privacy Policy.

The age of consent for data processing is 16, when online services are offered directly to children (when consent is the lawful basis). Member states have the power to lower it to 13 through their own national laws implementing the GDPR. Individuals younger than this need parental approval for data sharing.

Seek user consent before using non-essential website cookies in order to fully comply with the regulation.

Here's how EY explicitly obtains consent from its users to provide cookies in compliance with the GDPR.

Example of the Cookie notice banner as consent wall

Consent must be as easy to withdraw as it is for the individual to give it. Make it a simple process for users, if they decide they don't want you to process their data anymore.

Consent must be explicit if you process special category (sensitive) data on the basis of consent.

Keep records of consent, known as consent logs. Record who consented, when, how, and through what service or website. You must be able to demonstrate that you obtained valid consent from data subjects whose data you processed.

Data Protection Officer (DPO)

A Data Protection Officer (DPO) is the person responsible for overseeing the data protection strategy and GDPR compliance of your organization or business.

DPOs are mandatory for public administrations, as well as if your business is processing sensitive data on a large scale, or is carrying out large scale, regular, and systematic monitoring of individuals. For many businesses a DPO is not mandatory. One example of a business that needs a mandatory DPO, is a security company responsible for mapping shopping malls and large public spaces for security monitoring.

Having a DPO is still best practice, even if it's not mandatory. It helps your business stay compliant with the GDPR. Provide your customers with the details of how to contact your DPO.

Spotify complies with this requirement in its Privacy Policy as shown below.

Spotify - Legal - Privacy Policy - How to contact us clause highlighted

A DPO must inform you of your obligations under the GDPR. Another task of a DPO is to monitor compliance, including compliance when it comes to training staff, conducting audits, and carrying out privacy planning.

Hire a DPO externally or appoint an internal staff member to be your DPO. Whoever the DPO is, you need to tell the Supervisory Authority or Data Protection Authority (DPA).

The DPO provides advice on, and monitors, the process if you carry out a DPIA. The DPO is the contact person for the Supervisory Authority, if they are involved with your business for any reason.

Data Protection Impact Assessments (DPIA)

A Data Protection Impact Assessment (DPIA) is a risk assessment for personal data. The GDPR requires a DPIA whenever processing is likely to pose a high risk to the rights and freedoms of an individual.

A DPIA is necessary when you are, for example, profiling an individual, processing sensitive data on a large scale, or systematically monitoring public spaces on a large scale. For example, a bus company wants to install cameras inside buses to monitor behavior.

High-risk processing includes:

  • The use of innovative technology, or existing technologies used in a novel way, including AI
  • Decisions that potentially result in denial of service to an individual
  • Large-scale profiling
  • Biometric data processing
  • Genetic data processing
  • Data matching (combining or comparing data from multiple sources)
  • Invisible data processing (processing data that has not been obtained directly from the individual)
  • Tracking, such as geolocation or behavior
  • Targeting of children or vulnerable individuals
  • Processing that has a risk of physical harm or a risk to safety

Before you begin processing, the DPIA must determine the processing and its purposes, identify the risks to individuals, and decide whether the processing is necessary and proportionate. This means that the benefits must outweigh the risks to individuals' privacy and other rights.

Don't proceed, and consult the Supervisory Authority, if you conclude through a DPIA that the processing is too high risk.

Data Transfers Outside the EU

Personal data moves freely within the EU/EEA, but sending it to a "third country" requires an approved safeguard.

Some countries have what is called an "adequacy decision". This means that the law of that country has been determined to be adequate (when compared to the GDPR), in the eyes of the European Commission. The countries with an adequacy decision include: Andorra, Argentina, Canada, Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, South Korea, Switzerland, the UK and Uruguay. The United States is a partial case: only US companies that self-certify under the EU-US Data Privacy Framework are covered.

If no adequacy decision has been made, transfers of data outside of the EU are only allowed using "appropriate safeguards". There are two main types: Standard Contractual Clauses (SCCs), and Binding Corporate Rules (BCRs).

SCCs are pre-approved contractual clauses that establish what the data protection rules are when data is transferred between the party in the EU, and the one outside of it. These SCCs have been approved by the European Commission.

BCRs are agreements between different companies within the same group, such as a Spanish branch and a Brazilian branch of the same company. They are rules that establish how data will be protected within the company, even outside the EU.

For example, TikTok adopts some GDPR-prescribed safeguards for data transfers as shown below.

TikTok - Legal - Privacy Policy - Our global operations and data transfers - excerpt

Between the EU and the US there is the EU-US Data Privacy Framework. This framework is a "partial" adequacy decision. This means that only US companies that agree to follow the rules of the Privacy Framework, are treated as being covered by it.

You (the data controller) will ultimately be responsible for the compliance of overseas suppliers under the GDPR.

Privacy by Design and by Default

Privacy by design means building data protection into your products and processes from the very start.

This means when you create a product, website, app, or service, you think about privacy at the beginning, instead of as an afterthought. This includes considering what data you need, how you will collect, store, transfer and share it.

The requirements for privacy by design and default are set out in GDPR Article 25.

By default, you must apply the most privacy-protective approach possible. This includes using technical and organizational measures, as well as following seven privacy-by-design principles.

These principles for privacy-by-design were established before the GDPR, and include taking a proactive not reactive approach; setting privacy as the default; embedding privacy into design; giving users full functionality; establishing end-to-end security; creating visibility and transparency around privacy; and having general respect for user privacy.

Article 25 requires you to follow data minimization and purpose limitation principles.

You must consider from the beginning how data subjects will be able to exercise their privacy rights.

Keep Data Secure Under the GDPR

Article 32 of the GDPR requires you to put appropriate technical and organizational measures in place to protect the personal data you hold.

This means you must consider the risks of the data you have, including what kind of data it is, how much of it you have, and whether or not it is sensitive. Then you need to decide on appropriate measures to protect that specific data. For example, health or financial data needs stronger protection than data on clothing preferences for a fashion company.

Technical measures are things like using firewalls and access controls, as well as encryption, pseudonymization, and anonymization. Organizational measures include things like clear privacy practices within your business, staff training, and carefully checking vendors you work with.

Spotify explains its security practices in its Privacy Policy below, including steps that the user can take themselves to protect their privacy.

Spotify Privacy Policy - Keeping your personal data safe clause

Physical protection is necessary, such as keeping physical copies of data in locked rooms. Make sure to regularly check these measures and assess their effectiveness.

Records of Processing Activities (ROPA)

Article 30 of the GDPR requires controllers and processors to maintain a record of their processing activities (ROPA).

This ROPA must contain all information about the processing you are carrying out, including what types of data you collect and for what purposes, the type of data subjects you collect from, how you process data, share, transfer and store it, and how you keep it secure.

The UK Information Commissioner's Office (ICO) provides two ROPA templates for data controllers and processors to use. Here's an example of some of the information they suggest it should contain.

ICO UK GDPR guidance documentation - ROPA example

The ROPA must include your contact details, and it must be in writing (including electronic form). You must provide your ROPA if the Supervisory Authority asks for it.

You don't need to maintain a ROPA if your business or organization has fewer than 250 employees. However, this doesn't apply if you carry out regular processing, processing that involves high risks to individuals, or processing of sensitive data. Most businesses, even small ones, carry out payroll, HR, marketing, or analytics. As a result, usually you'll need to maintain a ROPA.

How to Get Started with GDPR Compliance

Here is a practical path to get compliant with the GDPR. This includes the main steps you need to take before you start processing personal data, as well as what to do if something goes wrong, and how to stay compliant.

  1. Map and inventory your data. This includes what you collect, where it comes from, where it is stored, who accesses it. This inventory of data helps you with other processes, such as your ROPA.
  2. Identify your lawful basis for each processing activity. Make sure you identify your lawful basis before you begin processing. Each individual processing activity must have its own lawful basis. Make sure you have a good reason, and consult a lawyer if necessary before you begin, if you rely on a lawful basis like legitimate interest.
  3. Write or update your Privacy Policy and Privacy Notice. If you don't have a Privacy Policy, you need one that is GDPR-compliant. It must be written in plain language and updated regularly.
  4. Set up consent mechanisms (banners, checkboxes) and DSAR handling. Your consent mechanisms must ensure that users give specific, informed, and unambiguous consent. This includes using cookie consent banners, non- pre-checked checkboxes, and separate consents for separate purposes. Establish a DSAR handling approach before you begin processing.
  5. Secure the data (encryption, access controls). Make sure security plans and measures are in place before you collect any data. Test these systems well before you start.
  6. Sign Data Processing Agreements (DPAs) with vendors/processors. A DPA helps to establish expectations with your vendors and processors about how they will process data on your behalf. Check beforehand whether any of your vendors or processors transfer data outside of the EU.
  7. Appoint a DPO or an internal owner. Choose a suitable person for a DPO before you begin. Make sure someone at your organization is responsible for privacy practices and monitoring, if you don't need a DPO.
  8. Train your staff. Establish training plans and educational steps to ensure that your staff know what to do when it comes to handling personal data. Make sure this includes breach monitoring and response.
  9. Prepare a breach-response plan. Establish a specific plan for breach response, including who is responsible, who investigates, who notifies the Supervisory Authority, and who notifies customers if necessary.
  10. Set reminders to review regularly. Compliance is ongoing. Review your privacy practices regularly to ensure you are still compliant. You need to incorporate any new laws into your business practices.

GDPR Privacy Policy: What to Include + Free Template

A GDPR-compliant privacy policy is required to include a number of things, including a clear disclosure of data types collected, the purpose and lawful basis, and how the data will be shared, transferred, and stored. You must inform data subjects of their rights in the Privacy Policy.

The following template is an example of what to include in your Privacy Policy.

Generate a Privacy Policy in just a few minutes

You can download the Sample GDPR Privacy Policy Template as HTML code below. Copy it from the box field below (right-click > Select All and then Copy-paste) and then paste it on your website pages.

Screenshot of the Sample GDPR Privacy Policy Template


Does the GDPR Apply to You? - Decision Guide

Use the decision guide below, if you are still unsure whether the GDPR applies to your business:

  1. Do you have an establishment (such as a business, company, or organization) based in the EU/EEA that processes personal data? Yes = in scope
  2. Do you offer goods and/or services to people in the EU/EEA (even if those goods and services are free, or offered via a website)? Yes = in scope. This applies even if your establishment itself is outside of the EU/EEA.
  3. Do you monitor EU/EEA residents' behavior (such as placing cookies through your website, using analytics or advertising tracking, or profiling)? Yes = in scope. This applies even if your establishment itself is outside of the EU/EEA.
  4. Is the use of personal data purely a personal or household activity, such as taking photographs for a private album? Exempt, because the GDPR does not apply.

How to Handle a Data Subject Access Request (DSAR) - Step by Step

You need to respond promptly when you receive a DSAR. The steps include the following.

  1. Verify the identity of the requester. This means confirming the person is actually the data subject.
  2. Log the request and start the one-month clock. Once you receive the request, the one-month timer begins for you to respond. Record the DSAR request with the time you received it.
  3. Locate the personal data of the requester. You then need to search for the data of the requester across your systems, including the databases and systems of third parties.
  4. Check for exemptions/refusals. Then, check whether any exemptions apply, such as whether it includes data that identifies other people. You are not permitted to refuse requests unless they are unfounded or excessive.
  5. Prepare the response. This means you need to put together what the GDPR requires, including a copy of data, purposes, recipients, retention, and data subject rights information.
  6. Deliver securely within one month. Make sure to use a secure delivery method like an encrypted file, and deliver the information within one month. This is extendable by a further two months for complex cases, but you must tell the requester within the first month that it will take this long.
  7. Document everything. Take good notes on what you searched, found, withheld, and when you responded. These documents are important if a Supervisory Authority ever audits DSARs you have received.

GDPR Penalties and Fines

GDPR fines are among the largest in the world. There are two tiers of fines, depending on what the breach is.

  • The lower tier is for breaches of smaller controller/processor obligations, security, and certification. This carries fines of up to €10 million or 2% of global turnover, whichever is higher.
  • The higher tier is for breaches of the principles of the GDPR, including the principles of lawful, fair, and transparent processing, purpose limitation, data minimization, accuracy, and storage limitation. This includes breaches such as not having a lawful basis for processing. A breach in this higher tier results in potential fines of up to €20 million, or 4% of global turnover, whichever is higher.

Some real life GDPR fines are displayed in the table below.

Company GDPR Fine Reason
Amazon €746M Processed personal data without a lawful basis.
WhatsApp €225M Didn't transparently explain to users how data was processed and shared with other Meta companies.
Google €50M Consent wasn't specific or unambiguous. Ad personalisation information for users was unclear.
Instagram €405M Data from accounts of children was public, including email addresses and phone numbers.
Marriott £18.4M Insufficient security protections for data. Data was breached and undetected for four years.
British Airways £20M Insufficient security protections for data resulted in the breach of 400,000 customer accounts.

The authorities weigh the gravity of the breach, the intent of the data processor / controller, and any mitigation steps taken, when considering the size of the fine. They consider how well the company cooperated and whether they have a history of breaches.

These fines are unlikely to affect you, if you keep GDPR compliance a top priority. However, mistakes happen, so make sure you are diligent with auditing processes.

Common GDPR Myths Debunked

The GDPR has generated a number of common misconceptions. Below are some of the most common misconceptions alongside their corrections.

Myth Fact
"GDPR only applies to EU companies" False. The GDPR has an extraterritorial effect, which means that it applies to companies outside of the EU, who process the data of people in the EU.
"Small businesses are exempt" False. Small businesses are not exempt from the GDPR due to their size. However, they only need to keep limited documentation.
"It is all about consent" False. Consent is only one of the six lawful bases. There are many other lawful grounds for processing.
"GDPR means no marketing emails" False. Marketing practices, including sending marketing emails, are still allowed, as long as you have a lawful basis. For marketing this will in most cases be consent or legitimate interest.
"Complying with another law = GDPR-compliant" False. It doesn't mean you will be compliant with the GDPR, just because you comply with the requirements of another privacy law.
"Compliance is a one-time project" False. GDPR compliance is ongoing. You need to continually check what data you are collecting, what purposes you use it for, update your Privacy Policy, respond to DSAR requests, and more.
"GDPR means I must delete all my data" False. You only need to delete the data of data subjects when it is no longer necessary. In some cases this will be after a short time. In other cases you must keep data for many years.

GDPR vs Other Privacy Laws

The GDPR inspired a wave of copycat laws.

A comparison between the GDPR and other privacy laws is in the table below.

Law Scope Key rights Maximum penalties
GDPR Anyone processing the data of people in the EU/EEA Right of access, to be informed, to correction, to erasure, to restrict processing, to data portability, to object, and not to be subjected to automated decision-making Up to €20M or 4% of global turnover, whichever is higher
CCPA/CPRA For-profit businesses with more than $26.6M annual revenue; those buying, selling, or sharing personal data of 100,000+ California consumers or households; or those that get more than 50% of their annual revenue from selling or sharing the data of California residents Right to know, deletion of data, correction of data, opt out of the sale of data, sharing of data, limit use of sensitive information, and non-discrimination $7,988 per intentional violation or violation involving the data of children, or $2,663 per unintentional violation
Brazil LGPD Anyone processing data of people in Brazil, or data processing that takes place in Brazil Right to data access, correction, anonymization, erasure, data portability, and revoke consent Up to 2% of Brazil revenue (capped at R$50M) per violation
Canada PIPEDA Applies to businesses in Canada, and any business with a "real and substantial" connection to Canada, such as processing data of many Canadian residents Right to access and correction, plus privacy principles similar to GDPR $100,000 CAD per violation (for certain violations)
Australia Privacy Act Applies to businesses with a turnover higher than $3 million (AUD), as well as health service providers or businesses trading personal information Right to access and correction $50M (AUD) or three times the benefit obtained, or 30% of the turnover for the breach period, whichever is greater

The UK GDPR and Brexit

Since Brexit, the UK has its own version of the GDPR, called the UK GDPR.

The rules of the UK GDPR are more-or-less the same as the GDPR. The UK GDPR carries fines up to £17.5 million or 4% of global turnover if you breach it.

The UK GDPR works alongside another law, called the Data Protection Act 2018 (DPA 2018). The DPA 2018 establishes exemptions for the UK intelligence agency and national defense, sets out UK-specific rules like the age of consent (13), and creates the UK Supervisory Authority, the ICO.

The UK has recently updated its framework through the Data (Use and Access) Act 2025. UK and the EU approaches to privacy law may diverge over time. UK businesses that process personal data must in some cases register with the ICO and pay an annual data protection fee (from £52 per year).

You need to comply with both laws if you have customers both in the EU and UK, even though they are so similar. There is an adequacy decision between the EU and UK.

Benefits of GDPR Compliance (Beyond Avoiding Fines)

Compliance is not just a burden. Rather, it has benefits for your business, too.

  • A clear Privacy Policy and transparent data practices help you build trust with your customers, and a good reputation on the market.
  • A clean data-processing register gives you more insight into what data you hold, which helps to keep your systems more organized and running smoothly.
  • Good compliance approaches encourage you to establish a stronger security system for your business, leading to fewer breaches. This again contributes to your business reputation and helps you to build customer loyalty.
  • Compliance with the GDPR helps you comply with laws in other countries, since so many laws are modeled on the GDPR.

GDPR Compliance Checklist (Downloadable)

The steps for GDPR compliance are sometimes confusing, and it's easy to lose track of tasks when you're managing other things for your business. A checklist helps to keep your compliance process simple, and helps you see which steps you've taken along with those you still need to take.

The below checklist includes the main steps at a high level that you need to go through to be compliant with the GDPR. Many of these have sub-tasks and smaller steps that you need to complete as well. Go through the items in the below checklist in order, and return to the checklist regularly when you are auditing your GDPR compliance and privacy practices. This checklist is downloadable, so you can store it and print it out if desired.

A high-quality Privacy Policy Generator is provided by TermsFeed, if you need a Privacy Policy to help you comply with the GDPR.

☐ Map your data

☐ Identify the lawful bases you will rely on

☐ Publish a GDPR-compliant Privacy Policy

☐ Set up valid consent mechanisms

☐ Appoint a DPO (or an owner)

☐ Sign DPAs with all data processors

☐ Carry out DPIAs for high-risk processing

☐ Implement data security measures

☐ Create a 72-hour breach-response plan

☐ Set up DSAR handling (one-month response)

☐ Train your staff to understand privacy issues and respond accordingly

☐ Schedule regular reviews of your privacy practices

Download the GDPR Compliance Checklist as a PDF file.

☐ Map your data

☐ Identify the lawful bases you will rely on

☐ Publish a GDPR-compliant Privacy Policy

☐ Set up valid consent mechanisms

☐ Appoint a DPO (or an owner)

☐ Sign DPAs with all data processors

☐ Carry out DPIAs for high-risk processing

☐ Implement data security measures

☐ Create a 72-hour breach-response plan

☐ Set up DSAR handling (one-month response)

☐ Train your staff to understand privacy issues and respond accordingly

☐ Schedule regular reviews of your privacy practices


GDPR for Beginners: Frequently Asked Questions

Here are quick answers to the questions beginners ask most about the GDPR.

GDPR stands for the General Data Protection Regulation. This is an EU privacy law that came into force in 2018, and made privacy laws consistent across the entire EU. Many laws around the world are modelled on the GDPR.
In simple words, the GDPR is a European privacy law that creates rules for anyone processing the data of people in the EU. It has obligations for businesses and privacy rights for individuals, as well as penalties for non-compliance.
The GDPR applies to any business or organization processing the data of people in the EU, regardless of whether the business or organization is in the EU or not.
Yes, in some circumstances. If a US business is processing the data of an EU resident, the GDPR will apply.
The seven principles of the GDPR are lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality (security); and accountability.
Under the GDPR, personal data is any information that potentially identifies a living person, whether directly or indirectly. This includes information such as name, email, physical address, birthdate, financial information, or cookie ID.
GDPR fines range from €10 million or 2% of global turnover for smaller breaches, up to €20 million, or 4% of global turnover for more serious breaches of the GDPR.
Yes. If your business has fewer than 250 employees you potentially have reduced documentation obligations. But otherwise, even small businesses need to comply with the GDPR if they are processing the personal data of people in the EU.
A DSAR is when a data subject (individual) asks about what data you hold on them. They are permitted to request a copy of that data, or ask you to correct, delete, transfer, or stop processing that data.

Summary and Key Takeaways

The key takeaways to remember include:

  • The GDPR establishes rules to protect individual privacy and personal data. It applies far beyond EU borders, which means you potentially need to comply with it even if your business is based in another country.
  • Know the seven GDPR privacy principles, and the six lawful bases. Make sure you have a lawful basis for processing before you begin.
  • Honor the eight data privacy rights of individuals and handle DSARs promptly, within one month.
  • Meet the core obligations: transparency, security, giving 72-hours notice when a breach occurs, and carrying out DPIAs when required. Appoint a DPO if necessary, or simply as best practice.
  • Fines for breaches under the GDPR are as high as EUR20M or 4% of global turnover
  • Compliance with the GDPR is an ongoing process, not a one-time act. Continually practicing GDPR compliance builds trust with customers
  • Start with a solid Privacy Policy and make sure to provide it to your customers in a clear and understandable way, before you start collecting or processing data. TermsFeed helps you with your GDPR approach and provides a high-quality Privacy Policy generator so you stay compliant.

Privacy Policy Generator
The first step to compliance: A Privacy Policy.

Stay compliant with our agreements, policies, and consent banners — everything you need, all in one place.

Generate Privacy Policy