GDPR (General Data Protection Regulation)

The GDPR is the EU regulation that governs how organizations process personal data of people in the EU, with fines up to 4% of worldwide turnover.

The General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, is the EU law that governs the processing of personal data. It was adopted on 27 April 2016 and has applied since 25 May 2018. Its reach extends beyond the EU: under Article 3 it also applies to organizations outside the Union that offer goods or services to people in the EU or monitor their behavior there.

The core duties that compliance teams put into practice:

  • A lawful basis for every processing purpose, and processing in line with the Article 5 principles, including purpose limitation, data minimization and storage limitation.
  • Transparency to individuals and their rights of access, rectification, erasure, restriction, portability and objection, plus safeguards around decisions based solely on automated processing (Article 22).
  • Accountability: records of processing activities, data protection impact assessments for high-risk processing, and a data protection officer where the regulation requires one.
  • Notification of a personal data breach to the supervisory authority within 72 hours of becoming aware of it, where feasible (Article 33).

The highest tier of fines reaches EUR 20 million or 4% of total worldwide annual turnover, whichever is higher (Article 83(5)). National data protection authorities enforce the regulation, with a lead authority for cross-border processing and the European Data Protection Board issuing guidelines, so enforcement actions and board guidance are as important to track as the text itself.

The text is under review. On 19 November 2025 the Commission proposed a Digital Omnibus, COM(2025) 837, that would amend the GDPR along with other digital laws. As of 30 September 2026, the Legislative Observatory shows it still at committee stage in Parliament, so the GDPR as adopted remains the text to comply with. Where AI systems process personal data, the GDPR applies alongside the EU AI Act.

This entry is general information, not legal advice.

Sources

  1. Regulation (EU) 2016/679 (General Data Protection Regulation), EUR-Lex accessed 30 Sep 2026
  2. European Parliament Legislative Observatory, Simplification of the digital legislative framework (Digital Omnibus), 2025/0360(COD) accessed 30 Sep 2026

Know which changes apply to your business.

RegWatch reads the regulators you choose and explains every change it surfaces.

Book a demo