GDPR

The General Data Protection Regulation – EU Regulation 2016/679, in force since May 2018.

The GDPR (General Data Protection Regulation) is the European Union's legal framework that fundamentally changed the rules for processing personal data.

What is the GDPR?

The GDPR is EU Regulation 2016/679, which came into force on 25 May 2018. Unlike a directive, it is directly applicable in all EU member states without the need for transposition into national law.

Key principles of the GDPR

  • Lawfulness, fairness and transparency – Personal data must be processed in a lawful and transparent manner.
  • Purpose limitation – Data may only be collected for specified, legitimate purposes.
  • Data minimisation – Only data necessary for the given purpose may be processed.
  • Accuracy – Data must be accurate and kept up to date.
  • Storage limitation – Data must not be kept longer than necessary.
  • Integrity and confidentiality – Appropriate security of the data must be ensured.

Who does the GDPR apply to?

The GDPR applies to all organisations that process personal data of EU citizens, regardless of where they are based. If you have a website with visitors from the EU, the GDPR applies to you.

Penalties for breaching the GDPR

The GDPR introduces two tiers of sanctions:

  • Up to EUR 10 million or 2% of global annual turnover for less serious infringements
  • Up to EUR 20 million or 4% of global annual turnover for serious infringements

GDPR and cookies

For cookies, the GDPR applies in conjunction with the ePrivacy Directive. If cookies contain personal data (e.g. user identifiers), you must ensure a legal basis for their processing – most commonly user consent.

Need to sort out cookies on your website?

Consentio provides a GDPR-compliant cookie banner with Google Consent Mode v2 support. Implementation in 5 minutes.

Get started for free