The GDPR is a regulation that applies directly across the European Union and, through the EEA Agreement, in Iceland, Liechtenstein and Norway. It governs the processing of personal data — any information relating to an identified or identifiable living person — whether that processing is automated or forms part of a structured filing system.
Its structure is scope-based rather than threshold-based. There is no employee count or revenue figure that switches the GDPR on. If you are established in the EU/EEA and process personal data in the context of that establishment, or you are outside it but offer goods or services to people in the EU/EEA or monitor their behaviour there, the regulation applies. Size affects some documentation duties, not applicability.
The regulation distinguishes controllers, who decide the purposes and means of processing, from processors, who process on a controller's documented instructions. The distinction determines who owes which duty, what a contract must contain, and who an individual can approach.
Accountability is the organising idea. It is not enough to comply; a controller must be able to demonstrate compliance through records, assessments, policies, contracts and technical measures that a regulator can inspect.
Who and what it applies to
- Material scope
- Processing of personal data wholly or partly by automated means, and non-automated processing of personal data that forms part of a filing system. Purely personal or household activity is out of scope, as are certain law-enforcement and national-security activities covered by other instruments.
- Territorial scope
- Processing in the context of an EU/EEA establishment, regardless of where the processing physically happens; and processing by organisations outside the EU/EEA where they offer goods or services to individuals in the EU/EEA or monitor their behaviour there.
- Special categories
- Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, plus genetic data, biometric data used for identification, health data, and data concerning sex life or sexual orientation. Processing is prohibited unless a specific additional condition applies.
Core principles
- Lawfulness, fairness and transparency — every processing operation needs a valid lawful basis and an honest explanation to the individual.
- Purpose limitation — collect for specified, explicit and legitimate purposes, and do not reuse in incompatible ways.
- Data minimisation — adequate, relevant and limited to what is necessary.
- Accuracy — keep personal data correct and up to date, and correct or erase inaccurate data without delay.
- Storage limitation — keep identifiable data no longer than necessary for the purpose.
- Integrity and confidentiality — apply appropriate technical and organisational security measures.
- Accountability — be responsible for, and able to demonstrate, compliance with the above.
Individual rights
Information
Clear, accessible privacy information at the point of collection, or within a reasonable period where data is obtained indirectly.
Access
A copy of their personal data plus supporting information about purposes, recipients, retention and rights.
Rectification
Correction of inaccurate data and completion of incomplete data.
Erasure
Deletion where one of the specified grounds applies, subject to exemptions such as legal obligations.
Restriction
Processing paused while accuracy or a lawful basis is contested.
Portability
Data provided by the individual, in a structured, commonly used, machine-readable format, where processing is based on consent or contract and is automated.
Objection
Objection to processing based on legitimate interests or public task, and an absolute right to object to direct marketing.
Automated decisions
Protection against decisions based solely on automated processing that produce legal or similarly significant effects, with limited exceptions and safeguards.
Organisational obligations
Records of processing
Maintain records of processing activities. The limited exemption for organisations under 250 employees rarely applies in practice because it falls away for regular processing, risky processing or special-category data.
Lawful basis and transparency
Identify a lawful basis before processing, document it, and describe it in a privacy notice written for the reader rather than for the file.
Data protection by design and default
Build safeguards into systems and default settings, not around them afterwards.
DPIAs
Assess high-risk processing before it starts, and consult the supervisory authority where residual high risk remains.
Processor contracts
Put in place written terms covering instructions, confidentiality, security, sub-processors, assistance, deletion and audit.
Security
Appropriate technical and organisational measures taking account of state of the art, cost, and the risk to individuals.
Breach handling
Notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk. Notify affected individuals where the risk is high.
DPO
Appoint a data protection officer where processing is by a public authority, or where core activities involve large-scale regular and systematic monitoring or large-scale special-category processing.
Cross-border considerations
- Transfers of personal data outside the EU/EEA need a transfer mechanism: an adequacy decision, appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or a narrow derogation.
- Where safeguards are relied on, a transfer impact assessment considers the destination country's law and practice and whether supplementary technical, contractual or organisational measures are needed.
- Remote access from outside the EU/EEA — including support teams and cloud administration — is a transfer, even when the data stays on European infrastructure.
Enforcement overview
- Supervisory authorities investigate complaints, conduct audits, issue warnings and reprimands, order changes to processing, and impose bans on processing.
- Two tiers of administrative fine exist, with the higher tier reaching the greater of EUR 20 million or 4% of total worldwide annual turnover for the preceding financial year.
- Individuals may also seek judicial remedy and compensation for material or non-material damage, and representative actions are possible in several member states.
- The one-stop-shop mechanism gives cross-border cases a lead authority, with cooperation and consistency procedures through the EDPB.
Implementation checklist
- 1Maintain a current record of processing activities with named owners for each activity.
- 2Document the lawful basis for each purpose, and where legitimate interests are used, keep the balancing assessment.
- 3Publish layered privacy information that matches actual practice.
- 4Operate a documented rights workflow with identity verification and a one-month response clock.
- 5Run and record DPIAs before high-risk processing begins.
- 6Hold Article 28 terms with every processor, and track sub-processors.
- 7Map transfers, choose a mechanism, and keep transfer assessments with the contract.
- 8Set retention periods you can actually enforce, and test that deletion happens.
- 9Rehearse the 72-hour breach clock, including out-of-hours detection and escalation.
Frequently asked questions
Does the GDPR only apply to large companies?
No. The GDPR is scope-based, not threshold-based. A two-person company that processes personal data in the EU/EEA context is in scope; size affects some documentation duties, not applicability.
Is consent always required?
No. Consent is one of six lawful bases. Contract, legal obligation, vital interests, public task and legitimate interests are equally valid where they genuinely fit the purpose.
Does hosting data in Europe remove transfer obligations?
Not by itself. If people outside the EU/EEA can access the data — including administrators and support staff — that access is a transfer and needs a mechanism.
Official sources
Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation. This page was last reviewed on August 2026.