GDPR
A practical introduction to the EU General Data Protection Regulation for organizations that handle personal data of people in Europe, including who it reaches outside the EU, who enforces it, what it requires, what compliance costs when there is no audit to buy, and how to start.
privacy · eu
Quick decision helper
Not sure whether GDPR's international transfer rules apply to your data flow? Answer one question about how the data moves.
How does personal data from people in the EU, UK, or Switzerland reach your organization?
What is GDPR
The General Data Protection Regulation, Regulation (EU) 2016/679, is the European Union’s law on how organizations may collect and use information about people. It was adopted in April 2016, has applied since May 25, 2018, and is directly binding in all 27 EU member states plus Norway, Iceland, and Liechtenstein. The United Kingdom kept a near-identical copy after Brexit (the UK GDPR), so in practice one set of rules covers most of Europe.
GDPR is a law about personal data, not a security standard. “Personal data” means any information relating to an identified or identifiable person: names, email addresses, IP addresses, device identifiers, location, purchase history, employee records, and anything that can be linked back to someone. The regulation governs the whole life of that data: whether you may collect it, what you must tell people, what rights they have over it, how you secure it, who you may share it with, where it may go, and what happens when it leaks.
Two roles organize everything. A controller decides why and how personal data is processed (the retailer, the employer, the app publisher). A processor handles data on a controller’s instructions (the hosting provider, the payroll service, the analytics vendor). Both have direct obligations, and their relationship must be written into a contract.
The most common misconception outside Europe is that GDPR is about cookie banners and consent. Consent is one of six lawful bases and often the worst one to rely on; most business processing rests on contract, legal obligation, or legitimate interests. The second misconception is that there is something to pass. There is no GDPR audit, certificate, or seal that a law requires. Compliance is a state you maintain and can prove, mostly through your own records, when a regulator, customer, or plaintiff asks.
Who GDPR applies to
Article 3 sets the reach, and it is wider than most non-EU companies expect. GDPR applies if:
- you have an establishment in the EU or EEA (a subsidiary, branch, office, or even a stable arrangement such as a single employee or agent) and the processing happens in the context of its activities, regardless of where the data or the people are; or
- you are outside the EU but process personal data of people who are in the EU while offering them goods or services (paid or free) or monitoring their behavior (analytics, tracking, profiling).
“Offering goods or services” turns on intent: an EU-language version of your site, euro pricing, shipping to EU countries, or marketing aimed at EU customers all count; a U.S. site that an EU visitor happens to reach generally does not. “Monitoring behavior” catches almost every website that runs behavioral analytics or advertising trackers on EU visitors. Citizenship is irrelevant; GDPR protects people physically in the EU, and an American in Paris is covered while a French citizen in New York is not.
Practical cases that surprise people:
- A U.S. SaaS company with a handful of EU customers is a controller for those customers’ account data and, usually, a processor for the personal data its customers load into the product. Its customers will send it a data processing agreement and ask about transfers.
- An employer with staff in the EU is subject to GDPR for their HR data even if it sells nothing there.
- A vendor that never sees an EU person but processes EU personal data for a controller (hosting, support, payroll) is a processor with its own obligations, and the controller is required to put a contract on it.
- A non-EU organization with no EU establishment that falls under Article 3 must appoint an EU representative (Article 27) unless its processing is occasional, low-risk, and excludes special-category data at scale.
GDPR does not apply to purely personal or household activity, to law enforcement processing (a separate directive), or to anonymized data that can no longer be linked to a person. Whether “pseudonymized” data is personal data for a given holder is the live question the Digital Omnibus proposal is trying to settle.
Applicability is the first thing to decide and write down, because it determines whether you need a representative, which supervisory authority you answer to, and whether your data flows are restricted transfers. The Is data entered on our site by an EU visitor a transfer? guide covers the most common confusion.
Who manages and enforces GDPR
GDPR is EU law with national enforcement, and several bodies share the work:
- The European Parliament and Council adopt and amend the regulation. The European Commission proposes changes (the Digital Omnibus, November 2025), adopts adequacy decisions that allow free data flows to approved countries (the EU-US Data Privacy Framework, July 2023), and publishes the standard contractual clauses used for transfers to everywhere else.
- National supervisory authorities, at least one per member state (Ireland’s Data Protection Commission, France’s CNIL, Germany’s federal and 16 state authorities, and so on), investigate complaints and breaches, audit, order changes, ban processing, and fine. For cross-border processing, the authority where your main establishment sits acts as lead supervisory authority under the one-stop-shop, coordinating with the others. Non-EU organizations without an establishment have no lead authority and can be pursued by any of them.
- The European Data Protection Board (EDPB) brings the authorities together, issues guidelines that in practice define what compliance looks like, and resolves disputes between authorities with binding decisions. Its news page is the closest thing GDPR has to a change feed.
- The Court of Justice of the European Union (CJEU) interprets the regulation; its rulings (Schrems II on transfers, the 2025 SRB v EDPS ruling on pseudonymized data) can rewrite practice overnight.
- Individuals enforce too: they can complain to any authority, sue for material and non-material damages, and be represented by non-profit organizations in collective actions.
Fines come in two tiers: up to €10 million or 2 percent of worldwide annual turnover for failures of controller and processor duties (records, security, breach notification, DPOs), and up to €20 million or 4 percent for violating the principles, lawful basis, individual rights, or transfer rules, whichever is higher. Regulators issued roughly €1.2 billion in fines in 2025 and about €7.1 billion since 2018, the largest being €1.2 billion against Meta in 2023 for transfers. Nine of the ten largest fines hit large technology companies, but authorities fine small businesses, hospitals, landlords, and municipalities constantly at smaller amounts, and orders to stop processing can hurt more than a fine.
Enforcement is changing. The GDPR Procedural Regulation (Regulation (EU) 2025/2518) entered into force on January 1, 2026 and applies to new cross-border cases from April 2, 2027, harmonizing how complaints are handled, giving investigated organizations rights to be heard and to see the file, and setting deadlines (most investigations to conclude within 15 months). Expect cross-border cases to move faster and demand documentation earlier.
What is in scope
Scope in GDPR is every processing activity involving personal data within your reach under Article 3, not a system boundary you draw. “Processing” means anything done to personal data: collecting, storing, viewing, analyzing, sharing, and deleting. The unit of analysis is the purpose: why you process a given set of data about a given set of people.
That framing pulls in more than most security programs track:
- Every category of person you hold data about: customers, prospects, website visitors, employees and applicants, vendor contacts, end users of your customers’ products.
- Every system that holds the data, including email, spreadsheets, backups, logs, CRM, HR, support desks, and the analytics and advertising tags on your website.
- Every vendor that touches it, each of which needs an Article 28 data processing agreement and, if outside the EU, a transfer tool. The Vendors and processors: DPA, transfer tool, or both? guide walks through the paperwork.
- Every border crossing. Personal data leaving the EU or EEA to a country without an adequacy decision is a restricted transfer under Chapter V that needs a mechanism: the Data Privacy Framework for certified U.S. companies, standard contractual clauses with a transfer impact assessment, or binding corporate rules within a group. See Choosing a GDPR transfer tool.
- Special categories (health, genetic and biometric data, racial or ethnic origin, political opinions, religion, union membership, sex life or orientation) and criminal data, which are prohibited to process unless a specific Article 9 or 10 condition applies, and children’s data, which triggers parental consent rules and heightened care.
A scope exercise you can run this week:
- List every group of people you hold data about.
- For each, list what data you hold, why, on which lawful basis, in which systems, for how long, and who it is shared with.
- Mark which vendors are outside the EU or EEA and what transfer tool covers each.
- Flag any special-category or children’s data and any automated decision-making or large-scale monitoring, which point to a DPIA.
- Write it up as your record of processing activities (Article 30). That document is the spine of the whole program.
GDPR has no concept of a narrow scope you can certify: if a processing activity is within your reach, the law applies to it. What you can do is minimize the data you collect and the vendors you use, which shrinks the work more reliably than any boundary argument.
What GDPR requires
The regulation’s official text runs 99 articles in 11 chapters, with 173 recitals explaining intent. The operative core:
Principles (Article 5). Personal data must be processed lawfully, fairly, and transparently; collected for specified purposes and not reused incompatibly; limited to what is necessary; accurate; kept no longer than needed; and secured. The controller must be able to demonstrate all of this (accountability). Every enforcement action ultimately cites one of these.
Lawful basis (Article 6). Each purpose needs one of six bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests. Consent must be freely given, specific, informed, and as easy to withdraw as to give. Legitimate interests requires a documented balancing test. Special-category data needs an additional Article 9 condition.
Individual rights (Chapter III, Articles 12 to 23). To be informed (privacy notices), to access their data, to rectify it, to erase it (“right to be forgotten”), to restrict processing, to portability, to object (including to direct marketing, absolutely), and not to be subject to solely automated decisions with significant effects. Requests must generally be answered within one month.
Controller and processor duties (Chapter IV, Articles 24 to 43):
- Data protection by design and by default (Article 25).
- Processor contracts (Article 28) with mandatory terms, and processors may not engage sub-processors without authorization.
- Records of processing activities (Article 30) for organizations with 250 or more employees, and for smaller ones whose processing is more than occasional, risky, or involves special categories, which is nearly all of them.
- Security of processing (Article 32): measures appropriate to the risk, with encryption, pseudonymization, resilience, and regular testing named as examples. GDPR does not prescribe controls, which is why organizations map to ISO/IEC 27001 or SOC 2 to show this article is met.
- Breach notification (Articles 33 and 34): to the supervisory authority within 72 hours of becoming aware unless the breach is unlikely to result in risk, and to affected individuals without undue delay when the risk is high.
- Data protection impact assessments (Article 35) before high-risk processing (large-scale monitoring, special-category data at scale, new technologies, profiling with legal effects), with prior consultation of the authority when residual risk stays high.
- Data protection officer (Articles 37 to 39), mandatory for public bodies, for organizations whose core activities involve regular and systematic large-scale monitoring, and for large-scale special-category processing. The DPO must be independent and report to the top.
- EU representative (Article 27) for non-EU organizations within reach.
International transfers (Chapter V, Articles 44 to 50). Personal data may leave the EU only to a country with an adequacy decision, under appropriate safeguards (standard contractual clauses, binding corporate rules, an approved code or certification), or under narrow derogations. Transfers are the most-fined area after lawful basis.
Remedies and fines (Chapter VIII, Articles 77 to 84). Complaints, judicial remedies, compensation, and the two fine tiers described above.
The documents that matter, and how much weight each carries:
- The regulation itself is binding. Read the articles you are relying on; they are shorter than commentary about them.
- EDPB guidelines are not formally binding but define what authorities expect on consent, legitimate interests, transfers, breach notification, DPIAs, and more.
- The Commission’s standard contractual clauses (2021) are the transfer contract most organizations sign; the Data Privacy Framework list is where U.S. companies self-certify.
- National law fills gaps GDPR left to member states (the age of digital consent, employee data, DPO rules, and fine publication, as the Netherlands’ 2026 amendments show), so a company with EU establishments has a second layer to check.
- The GDPR Procedural Regulation governs how cross-border investigations run from April 2027.
How compliance is validated
GDPR is validated by regulatory oversight and self-demonstration, not by audit. There is no certification a law requires, and no assessor whose sign-off ends the question.
What “demonstrating compliance” means in practice:
- Your own records are the primary evidence: the record of processing activities, the legitimate-interest assessments, the DPIAs, the processor agreements, the transfer impact assessments, the breach register, and the training log. An authority’s first request in an investigation is for these.
- A supervisory authority can audit you on complaint, after a breach notification, on its own initiative, or as part of a sector sweep. It can order production of documents and access to premises.
- Customers validate through due diligence: questionnaires, contractual audit rights in the DPA, and increasingly requests for a SOC 2 report or ISO/IEC 27001 certificate as evidence for Article 32.
- Courts validate after the fact, in damages claims or challenges to authority decisions.
Optional third-party validation exists and has weight with customers but not as a legal shield:
- Article 42 certifications. Europrivacy, approved by the EDPB in 2022, is the only EU-wide GDPR certification; a handful of national schemes also exist. Certification is a factor authorities consider and a way to show processors’ compliance, but it does not reduce liability.
- Codes of conduct (Article 40), such as the EU Cloud Code of Conduct for processors, with monitoring bodies that check adherence.
- ISO/IEC 27701, a privacy management extension of ISO/IEC 27001, is a certifiable standard that maps closely to GDPR duties but is not a GDPR certification.
- SOC 2 and ISO/IEC 27001 demonstrate the security half (Article 32) and are what most enterprise customers actually ask for.
Who may perform the work
No license is required to help an organization comply with GDPR. Data protection officers must have expert knowledge but need no specific credential; lawyers are needed for national-law questions and for representing you before an authority; privacy consultants and security firms perform gap assessments, build records of processing, and run DPIAs. Aeris Secure performs readiness assessments and remediation work; it does not certify GDPR compliance, because nothing can.
Two independence rules matter: a DPO may not hold a role that decides the purposes and means of processing (so the head of marketing or IT cannot be the DPO), and an EU representative is a separate role from the DPO. Verify a Europrivacy or code-of-conduct claim through the scheme’s public register, and verify a vendor’s transfer position through the Data Privacy Framework list or the signed clauses, not through a badge on a website.
The GDPR compliance process
A first program at a small or mid-sized organization takes three to six months of part-time work; large or data-heavy organizations take a year or more. The steps:
- Decide applicability and write it down. Establishment in the EU or Article 3(2) reach; which authority is your lead, or whether you need an EU representative.
- Inventory processing into a record of processing activities: people, data, purposes, lawful bases, systems, retention, recipients, transfers.
- Fix the legal layer. Assign and document a lawful basis for each purpose, run legitimate-interest assessments, rewrite privacy notices to Article 13 and 14 standards, and set retention schedules.
- Paper the vendors. Sign Article 28 agreements with every processor and put a transfer tool on every non-EU one.
- Build the operational procedures: rights requests within one month, breach detection and 72-hour notification, DPIAs before new high-risk processing, consent management where consent is the basis.
- Assess security against Article 32, and align it to a recognized framework if customers will ask for proof.
- Appoint roles: a DPO where required (or a named privacy lead where not), an EU representative if applicable.
- Train staff and run the risk assessment, then keep the records current as processing changes.
Who decides, and what to ask them
There is rarely a single external party who tells you what GDPR requires of you; the decisions are yours to make and document, and the parties who later judge them are the supervisory authority and your customers. The people to consult:
- Your EU customers’ privacy or procurement teams, who will send you their DPA and ask for your transfer tool, your sub-processor list, your security evidence, and your breach notification commitments. Ask what their DPA requires beyond the Article 28 minimum, and which transfer tool they accept.
- Your lead supervisory authority (or the authorities in the countries where your customers are, if you have no EU establishment), through its published guidance and, for DPIAs with high residual risk, prior consultation. Ask which national rules layer on top of GDPR in that country.
- Counsel in the relevant member state for employee data, the age of consent, and anything that could reach a court.
- Your DPO or privacy lead, who owns the record of processing and the DPIA decisions.
Questions to settle early: which lawful basis carries each core purpose; whether you need a DPO or a representative; which vendors are outside the EU and what covers them; how you will find and delete one person’s data across every system within a month; and who calls the authority at hour 60 of a breach.
Reality check: the program stalls on the data inventory and on vendor paperwork, not on legal theory. Both are grinding, cross-functional work that no consultant can finish for you.
Cost, time, and internal effort
GDPR has no required audit or certification fee, so this page shows no headline cost range. What compliance costs is internal time plus whatever help you buy, and both scale with how much personal data you process and how many people and vendors touch it.
The recurring external costs, when incurred:
- Outsourced data protection officer: roughly $4,000 to $60,000 per year, from light retained advisory to a full DPO function for a data-heavy SaaS company. A full-time in-house DPO costs $90,000 to $170,000 in salary.
- EU representative: roughly $250 to $2,500 per year for non-EU organizations that need one.
- Gap assessment: roughly $3,500 to $12,000 for a consultant’s initial assessment and data inventory at a small or mid-sized organization; each consultant-led DPIA adds roughly $1,500 to $15,000.
- Privacy management software (consent, rights requests, data mapping): from a few hundred dollars a month for small businesses to enterprise licenses in the tens of thousands.
Published all-in figures put a small business’s first year at roughly $3,500 to $35,000, a mid-market organization’s ongoing spend at $30,000 to $90,000 per year, and enterprise implementations at $250,000 to more than $1 million. Euro figures in the sources are rounded to dollars.
Internal effort is the larger cost for most organizations. A first program at a small or mid-sized company takes roughly 100 to 600 staff hours across privacy, legal, IT, marketing, and HR before remediation; the data inventory and vendor paperwork consume most of it. Ongoing operation (rights requests, vendor reviews, DPIAs for new projects, breach readiness) is a permanent part-time job.
The page’s ranges are directional, not a quote. The best predictors are whether you reach the EU from outside (representative plus transfer tools), whether special-category or children’s data is involved (DPIAs, stricter bases), how many vendors you use, and how far your security practice is from Article 32.
Time follows effort. A U.S. SaaS company with a few EU customers and clean vendor management can be defensibly compliant in a quarter. A company that has never inventoried its data, runs behavioral advertising, and has 80 vendors is looking at a year.
Maintaining compliance
GDPR compliance decays as processing changes, and the law’s accountability principle means the records must keep pace. A typical operating rhythm:
- Keep the record of processing current. New products, features, vendors, analytics tags, and HR tools all change it. Tie updates to change management and procurement.
- Run DPIAs before, not after, new high-risk processing, and revisit them when the processing changes.
- Handle rights requests within one month, log them, and test the deletion path across every system at least annually.
- Rehearse breach notification. Seventy-two hours passes quickly; know who decides, who drafts, and which authority’s form you file.
- Review vendors and transfers annually: sub-processor lists, DPA currency, Data Privacy Framework certifications (which renew yearly and are under review after the 2026 U.S. Supreme Court ruling in Trump v. Slaughter), and transfer impact assessments.
- Refresh notices and consent when purposes change, and retire data at the end of its retention period.
- Train staff on request handling and breach reporting annually.
- Run the risk assessment that Articles 24, 32, and 35 assume, at least annually and after major changes. The free risk assessment tool on this site produces a risk register and report in the browser without sending data anywhere.
- Watch the change feed: EDPB guidelines, CJEU rulings, adequacy decisions, national amendments, and the Digital Omnibus negotiations, which could change the definition of personal data and the rules for AI training and cookies. Follow this page for major items.
How to get started
If GDPR has just landed on your desk, begin with five concrete actions:
- Decide applicability in writing. Do you have an EU establishment? Do you offer goods or services to, or monitor, people in the EU? If yes without an establishment, you need an EU representative. Write the conclusion and its reasoning in a one-page memo.
- Read the articles you will live by. Articles 5, 6, 12 to 22, 28, 30, 32 to 35, and 44 to 46 of the official text take about an hour and replace a great deal of secondhand advice.
- Start the record of processing. A spreadsheet is fine: people, data, purpose, lawful basis, systems, retention, recipients, transfers. Every later step depends on it.
- Run a first risk assessment and a gap review. Use a simple method (the risk assessment tool works) and walk the requirements against your inventory, paying special attention to vendor agreements, transfers, breach notification readiness, and any special-category data.
- Paper the vendors and pick your transfer tools. List every processor, check which are outside the EU, and decide between the Data Privacy Framework and standard contractual clauses for each; the transfer tool guide and the DPA vs transfer tool guide cover the decision. If you need help, a gap assessment from a privacy consultant or an outsourced DPO is the usual first purchase.
For official starting points, use the regulation for the text, the EDPB for guidelines and news, and the European Commission’s data protection pages for adequacy decisions and standard contractual clauses.
The first goal is not 99 articles. It is knowing whether GDPR reaches you, what personal data you hold and why, and which vendors carry it across the border. Once those three answers are written down, GDPR is a set of procedures and contracts you can build, and minimizing the data you keep will save more than any clever legal argument.
Guides
- Vendors and processors: do we need a DPA, a transfer tool, or both?
What GDPR expects for each vendor that touches EU personal data: an Article 28 processing agreement, a Chapter V transfer tool, or both, and how that paperwork actually gets signed in practice.
- Is data entered on our site by an EU visitor a transfer?
Why a person in the EU submitting data directly to your site usually is not a restricted transfer, and where GDPR's transfer rules actually apply.
- Choosing a GDPR transfer tool: DPF, SCCs, or both
When a restricted transfer actually happens, which mechanism covers it, and when self-certifying to the Data Privacy Framework is worth it.
Version history
| Version | Status | Released | Effective | Retired | Summary | Guides |
|---|---|---|---|---|---|---|
| Regulation (EU) 2016/679 | current | Apr 27, 2016 | May 25, 2018 | n/a | Adopted April 27, 2016 and applied from May 25, 2018, replacing the 1995 Data Protection Directive with one directly applicable law across the EU and EEA. The text has not been amended since; what changes is the interpretation (EDPB guidelines, CJEU rulings, adequacy decisions such as the 2023 EU-US Data Privacy Framework) and now the procedural layer. Regulation (EU) 2025/2518, the GDPR Procedural Regulation, entered into force January 1, 2026 and applies to new cross-border cases from April 2, 2027. The Commission's Digital Omnibus proposal (November 2025) would amend GDPR itself and is still being negotiated. | |
| Directive 95/46/EC | retired → Regulation (EU) 2016/679 | Oct 24, 1995 | Oct 24, 1998 | May 25, 2018 | The Data Protection Directive, implemented differently by each member state's national law. GDPR kept its core concepts (controller, processor, lawful basis, data subject rights) and added direct applicability, extraterritorial reach, accountability duties, breach notification, and fines with teeth. | None yet |
New versions are announced in news. Follow this standard to get notified.