The GDPR (General Data Protection Regulation) is the European Union's legal framework that fundamentally changed the rules for processing personal data.
What is the GDPR?
The GDPR is EU Regulation 2016/679, which came into force on 25 May 2018. Unlike a directive, it is directly applicable in all EU member states without the need for transposition into national law.
Key principles of the GDPR
- Lawfulness, fairness and transparency – Personal data must be processed in a lawful and transparent manner.
- Purpose limitation – Data may only be collected for specified, legitimate purposes.
- Data minimisation – Only data necessary for the given purpose may be processed.
- Accuracy – Data must be accurate and kept up to date.
- Storage limitation – Data must not be kept longer than necessary.
- Integrity and confidentiality – Appropriate security of the data must be ensured.
Who does the GDPR apply to?
The GDPR applies to all organisations that process personal data of EU citizens, regardless of where they are based. If you have a website with visitors from the EU, the GDPR applies to you.
Penalties for breaching the GDPR
The GDPR introduces two tiers of sanctions:
- Up to EUR 10 million or 2% of global annual turnover for less serious infringements
- Up to EUR 20 million or 4% of global annual turnover for serious infringements
GDPR and cookies
For cookies, the GDPR applies in conjunction with the ePrivacy Directive. If cookies contain personal data (e.g. user identifiers), you must ensure a legal basis for their processing – most commonly user consent.