---------------------------
Title: What is the GDPR?
URL: https://www.cookiebot.com/en/gdpr/
---------------------------

# What is the GDPR?

## At a Glance

- GDPR has applied since May 25, 2018, to any organization processing EU residents' personal data, regardless of where the organization is based.
- Fines can reach €20 million or 4% of global annual turnover; enforcement has issued over €7.1 billion in penalties since 2018.
- Valid consent must be freely given, specific, informed, and unambiguous, so pre-ticked boxes, cookie walls, and scroll-to-accept all fail that test.
- Special rules apply to children's data ("GDPR-K"), and the EU AI Act now layers extra obligations on top of GDPR for AI systems.
- The proposed EU Digital Omnibus would fold cookie consent into the GDPR, but it remains contested in trilogue and is not law yet.
- Cookiebot CMP automates GDPR-compliant consent collection, logging, and documentation.

The General Data Protection Regulation (GDPR) is the EU's core data protection law. It governs how organizations collect, use, store, and share the personal data of people in the EU, regardless of where the organization itself is based. It sets clear rules on legal grounds for processing, transparency, documentation, and consent, backed by enforcement powers European authorities have used with increasing frequency since 2018.

## Who Does the GDPR Apply To?

The GDPR applies to organizations established in the EU, and to organizations outside the EU that offer goods or services to people in the EU or monitor their behavior. This includes use of analytics, ad trackers, and profiling. In addition to companies based in Europe, a retailer in Ohio with EU customers, or a Singapore SaaS company running ads targeted at Berlin, is in scope. No EU servers or office required, only EU visitors whose data is processed.

### Controllers and Processors

A **data controller** decides why and how personal data is processed. A **data processor**, e.g., a SaaS vendor, an analytics tool, an ad network, acts on the controller's instructions. Both carry legal obligations, and a controller can't outsource responsibility by pointing at a contract. It must actively vet and monitor every processor and third party on its site.

### What Counts as Personal Data?

[Personal data](https://www.cookiebot.com/en/common-pii-questions-faq-cookiebot/) is any information tied to an identifiable individual, either directly (a name, an ID number) or indirectly (location data, an online identifier, or a combination of factors). This covers IP addresses and device identifiers unless properly anonymized, and pseudonymized data if it can plausibly be re-identified.

### Valid Consent Under the GDPR

[Consent](https://www.cookiebot.com/en/consent-management/) is the legal ground governing most cookie and tracking scenarios. To be valid, it must be freely given, specific, informed, and unambiguous. Website visitors, app users, e-commerce customers, and others, must provide a clear affirmative action, not an assumption drawn from behavior.

The consent guidelines from the [European Data Protection Board (EDPB)](https://www.edpb.europa.eu/home_en) rule out the usual shortcuts: pre-ticked boxes, and continued browsing or scrolling. Cookie walls, which block site access unless the visitor accepts tracking, also fail, since there's no genuine choice. A 2024 EDPB opinion extended this to "consent or pay" models on large platforms. These offer only tracking-consent or a paid alternative, which usually fails the freely-given test unless a genuinely free, non-tracking option also exists.

"Explicit consent" is a distinct, higher Art. 9 GDPR standard for special category data (health, biometric, religious belief). Standard cookie consent uses the ordinary standard above, and the terms aren't interchangeable.

## The Six Lawful Bases for Processing Personal Data

Consent is not the only route to lawful processing under the GDPR. [Article 6 GDPR](https://gdpr.eu/article-6-how-to-process-personal-data-legally/) sets out six lawful bases, and an organization only needs one to process personal data legitimately. Choosing the wrong basis, or defaulting to consent when another basis fits better, is itself a compliance risk.

### The Six Bases

Article 6(1) GDPR lists these on equal legal footing; none takes precedence over the others, and the right one depends on the purpose of the processing, not the type of data involved.

## GDPR Lawful Bases

- **Consent** — The individual has given clear, affirmative permission for a specific purpose. This is the basis most cookie and tracking scenarios rely on, and it's covered in detail below.
- **Contract** — Processing is necessary to fulfill a contract with the individual, or to take steps at their request before entering one, e.g., processing a shipping address to deliver an order.
- **Legal obligation** — The organization must process the data to comply with EU or Member State law, e.g., retaining financial records for tax authorities.
- **Vital interests** — Processing is necessary to protect someone's life, used rarely and typically only where no other basis applies.
- **Public task** — Processing is necessary to perform a task in the public interest or exercise official authority, and applies mainly to public bodies rather than private companies.
- **Legitimate interests** — The organization has a genuine business reason to process the data that isn't overridden by the individual's rights and interests, e.g., basic fraud prevention or network security.

#### Why This Matters for Cookies and Tracking

Not every cookie needs consent. Strictly necessary cookies, e.g., those required for a shopping cart or login session to function, can often rely on legitimate interests, since [ePrivacy rules](https://www.cookiebot.com/en/eprivacy-regulation/) already carve out an exemption for them. Analytics, advertising, and profiling cookies, by contrast, almost always require consent, since there's no other basis available for that kind of non-essential tracking.

Getting this distinction right shapes what a cookie banner needs to ask for, and what it can quietly allow. A [Cookiebot™ scan](https://www.cookiebot.com/en/cookie-checker/) can help identify which cookies on a site are firing before consent, and which basis genuinely applies to each.

## GDPR-K: How the GDPR Treats Children's Data

"GDPR-K" is informal shorthand for [Art. 8 GDPR](https://gdpr.eu/article-8-childs-consent/) covering children's consent when a service ("information society service") is offered directly to a child. It applies narrowly: only when consent is the legal basis and the service targets children directly, and is not a separate law from the GDPR.

The default digital age of consent is 16, but Member States can lower it to 13, so the threshold varies by country. Below that age, the organization needs verifiable parental or guardian consent, though the GDPR doesn't mandate a specific verification method.

The rationale, per [Recital 38](https://gdpr.eu/recital-38-special-protection-of-childrens-personal-data/), is that children are less aware of processing risks and merit extra protection against profiling and marketing. It's also why higher-risk processing involving children may call for an [Art. 35 GDPR](https://gdpr.eu/article-35-impact-assessment/) [data protection impact assessment (DPIA)](https://usercentrics.com/knowledge-hub/data-protection-impact-assessment-dpia/).

GDPR-K is distinct from the [UK's Children's Code](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/introduction-to-the-childrens-code/) and [COPPA](https://www.cookiebot.com/en/coppa-compliance-requirements-checklist/) in the U.S. They have common purposes, but separate regimes with their own thresholds, and compliance with one doesn't cover the others.

## Individual Rights Under the GDPR

[The GDPR gives people rights](https://www.cookiebot.com/en/gdpr-data-subject-rights/) to access, correct, and erase ("right to be forgotten") their data, and to receive it in a portable format. Consent can be withdrawn at any time, and it must be as easy to do so as it was to give. As a best practice, it should also be easy to change consent at a granular level at any time. Organizations must act on valid requests within a set timeframe, stopping processing or deleting data without unreasonable delay.

Qualifying [data breaches](https://www.cookiebot.com/en/personal-data-breach/) must be reported to the relevant authority within 72 hours, and to affected individuals directly if the breach poses a high risk to their rights and freedoms.

## GDPR and the EU AI Act: Where They Overlap

The [EU AI Act](https://www.cookiebot.com/en/eu-ai-act/) sits alongside the GDPR, not in place of it. Both apply to any AI system processing personal data, enforced by different authorities on different logic. The GDPR covers ongoing accountability while the AI Act covers pre-market risk classification for high-risk systems. A few overlaps matter if your site uses AI for personalization, chatbots, or automated decisions.

## GDPR and AI Act Overlap

- **Automated decisions and profiling** — Art. 22 GDPR gives people the right not to be subject to solely automated decisions with legal or similarly significant effects (e.g., automated credit or hiring decisions)
The AI Act's human-oversight requirements for high-risk systems address the same concern from the system side. Existing Article 22 compliance is a head start, but the AI Act's requirements are more specific.
- **Impact assessments** — Art. 35 GDPR DPIAs and the AI Act's Article 27 Fundamental Rights Impact Assessment (FRIA) overlap for high-risk AI systems handling personal data.
The AI Act allows a FRIA to build on an existing DPIA rather than duplicating it.
- **AI transparency and disclosure** — AI Act Article 50 requires disclosing AI interaction and labeling AI-generated or manipulated content, a separate requirement from the GDPR, but one that reinforces its transparency principle.
Treat both as one coordinated disclosure exercise.
- **What's still unsettled** — Proposed Article 88c, which would treat AI-training use of personal data as a GDPR legitimate interest, is part of the same contested Digital Omnibus proposal and hasn't been enacted.
There's no GDPR-specific legal basis carve-out for AI training yet.

## GDPR Fines and Enforcement in 2026

The maximum penalty under the GDPR for the most serious violations is EUR 20 million or four percent of global annual turnover, whichever is higher. For lower tier violations it's up to EUR 10 million or two percent of global annual turnover, whichever is higher. These haven't changed since 2018, however, the frequency of enforcement has ramped up. Aggregate fines have passed EUR 7.1 billion, with more than 60 percent issued since 2023 as enforcement capacity and cross-border coordination have grown.

The [largest GDPR fine](https://usercentrics.com/knowledge-hub/gdpr-fines/) to date is Meta Platforms Ireland's EUR 1.2 billion penalty from the Irish DPC in 2023 for unlawful EU-U.S. transfers, followed by TikTok's €530 million fine from the same authority in May 2025 for transfers to China. A widely reported EUR 746 million Amazon fine was annulled on procedural grounds in March 2026, though the underlying violations were upheld.

Cookie consent remains a target in its own right: French, Spanish, and Italian authorities continue to fine non-compliant banners, defaulted-on trackers, and consent flows that make refusing harder than accepting.

Do you know what your website is collecting?
Scan your site for free and see all the cookies and trackers in use. Get your customized report and privacy compliance risk level in minutes.

[Start Scan](https://www.cookiebot.com/en/cookie-checker/)

## International Data Transfers and the EU-U.S. Data Privacy Framework

Transfers outside the EU require an adequacy finding or safeguards like [Standard Contractual Clauses (SCCs)](https://usercentrics.com/knowledge-hub/scc-gdpr/). The [EU-U.S. Data Privacy Framework](https://usercentrics.com/knowledge-hub/eu-us-data-privacy-framework/) covers transfers to self-certified U.S. organizations and remains in force and usable.

It's under active scrutiny, though. Following the U.S. Supreme Court's *[Trump v. Slaughter](https://www.supremecourt.gov/opinions/25pdf/25-332_qn12.pdf)* ruling on FTC independence, the EDPB asked the Commission on July 31, 2026 to examine whether it undermines a safeguard behind the adequacy decision. A CJEU challenge ([Case C-703/25 P](https://infocuria.curia.europa.eu/tabs/affair?lang=EN&searchTerm=%22C-703%2F25+P%22&publishedId=C-703%2F25+P)) is pending. Neither has invalidated the Framework, but given its two predecessors (Safe Harbor, Privacy Shield) were both struck down, this remains something to monitor.

## The EU Digital Omnibus: What's Changing (and What Isn't, Yet)

In November 2025, the Commission proposed folding cookie consent into the GDPR via new Articles 88a and 88b (making browser-level privacy signals legally binding) and Article 88c (treating AI-training data use as a legitimate interest). It's a significant package, but still only a contested proposal.

By mid-2026, the Council had dropped three of the Commission's four core reforms from its negotiating position, and in June 2026 removed Article 88b entirely after media/advertising lobbying. As of early August 2026, trilogue negotiations are still deciding Article 88b's fate, with no agreed text.

In practical terms, browser-based signals like [Global Privacy Control (GPC) ](https://www.cookiebot.com/en/global-privacy-control/)aren't currently required under EU law, and the version on the table is narrower than the Commission's original proposal. This is separate from the Omnibus's AI Act track, which has been adopted and took effect in July 2026.

# GDPR Compliance Checklist

## GDPR Compliance Checklist

- **Prepare your organization** — Train staff on data protection principles and assign a data protection officer if required, generally public authorities, large-scale monitoring operations, or those processing special category data at scale.
- **Audit your data** — Map where personal data lives, who can access it, and which third parties process it, including embedded website tools.
- **Audit your service partners** — Confirm vendors and embedded tools are compliant or operating from an adequate jurisdiction, and document their data flows.
- **Get consent right** — Implement a consent mechanism meeting the freely-given, specific, informed, unambiguous standard, and log every decision, including changes over time.
- **Handle data subject rights requests** — Build a repeatable process for access, correction, deletion, and portability requests, with clear ownership and turnaround times.
- **Prepare for breaches** — Have detection, investigation, and 72-hour notification procedures ready before you need them.

## Where This Leaves You

GDPR compliance isn't a one-time project. It's an ongoing practice of getting consent right, respecting the rights this regulation gives people, and keeping pace with a regulatory landscape that's still very much in motion, from the Digital Omnibus negotiations to the AI Act's growing overlap with data protection law. Get the fundamentals in this checklist right, and you'll be well placed to adapt as the details shift.

See your website's GDPR compliance gaps in minutes
Cookiebot™ CMP scans your site for every cookie and tracker in use, then handles consent collection, logging, and documentation automatically. Try it free for 14 days.

[Start Free Trial](https://admin.cookiebot.com/signup)

## Summary

This guide explains what the GDPR is, who it applies to, and what it requires from any organization processing EU residents' personal data. It covers valid consent, data subject rights, fines and 2026 enforcement trends, and the EU's proposed Digital Omnibus changes to cookie consent rules. Get a current picture of GDPR compliance, plus how Cookiebot CMP supports it.

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/en/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/en/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/en/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/en/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/en/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/en/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/)
- [Pricing](https://www.cookiebot.com/en/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/en/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/en/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/en/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/en/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/en/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/en/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/en/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/en/microsoft-consent-mode-cmp/)
- [View all regulations](https://www.cookiebot.com/en/regulations-and-frameworks/)

### Partners
- [Become an affiliate](https://www.cookiebot.com/en/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/en/resellers/)
- [Find a partner](https://www.cookiebot.com/en/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/en/blog/)
- [Customer stories](https://www.cookiebot.com/en/customer-stories/)
- [Customer directory](https://www.cookiebot.com/en/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/en/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/en/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/en/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/en/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/en/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/en/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/en/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/en/cookie-declaration/) · [Data Processing Agreement](https://www.cookiebot.com/en/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/en/legal-notice/) · [Accessibility Statement](https://www.cookiebot.com/en/accessibility-statement-wcag-compliance/)