What is the GDPR?

Close
Read time
7 mins
Published
Aug 20, 2026
Share
Magnifying glass analysing the CMP banners from a GDPR point of view on mobile and desktop
  • GDPR has applied since May 25, 2018, to any organization processing EU residents' personal data, regardless of where the organization is based.
  • Fines can reach 20 million or 4% of global annual turnover; enforcement has issued over 7.1 billion in penalties since 2018.
  • Valid consent must be freely given, specific, informed, and unambiguous, so pre-ticked boxes, cookie walls, and scroll-to-accept all fail that test.
  • Special rules apply to children's data ("GDPR-K"), and the EU AI Act now layers extra obligations on top of GDPR for AI systems.
  • The proposed EU Digital Omnibus would fold cookie consent into the GDPR, but it remains contested in trilogue and is not law yet.
  • Cookiebot CMP automates GDPR-compliant consent collection, logging, and documentation.

The General Data Protection Regulation (GDPR) is the EU's core data protection law. It governs how organizations collect, use, store, and share the personal data of people in the EU, regardless of where the organization itself is based. It sets clear rules on legal grounds for processing, transparency, documentation, and consent, backed by enforcement powers European authorities have used with increasing frequency since 2018.

Who Does the GDPR Apply To?

The GDPR applies to organizations established in the EU, and to organizations outside the EU that offer goods or services to people in the EU or monitor their behavior. This includes use of analytics, ad trackers, and profiling. In addition to companies based in Europe, a retailer in Ohio with EU customers, or a Singapore SaaS company running ads targeted at Berlin, is in scope. No EU servers or office required, only EU visitors whose data is processed.

Controllers and Processors

A data controller decides why and how personal data is processed. A data processor, e.g., a SaaS vendor, an analytics tool, an ad network, acts on the controller's instructions. Both carry legal obligations, and a controller can't outsource responsibility by pointing at a contract. It must actively vet and monitor every processor and third party on its site.

What Counts as Personal Data?

Personal data is any information tied to an identifiable individual, either directly (a name, an ID number) or indirectly (location data, an online identifier, or a combination of factors). This covers IP addresses and device identifiers unless properly anonymized, and pseudonymized data if it can plausibly be re-identified.

Consent is the legal ground governing most cookie and tracking scenarios. To be valid, it must be freely given, specific, informed, and unambiguous. Website visitors, app users, e-commerce customers, and others, must provide a clear affirmative action, not an assumption drawn from behavior.

The consent guidelines from the European Data Protection Board (EDPB) rule out the usual shortcuts: pre-ticked boxes, and continued browsing or scrolling. Cookie walls, which block site access unless the visitor accepts tracking, also fail, since there's no genuine choice. A 2024 EDPB opinion extended this to "consent or pay" models on large platforms. These offer only tracking-consent or a paid alternative, which usually fails the freely-given test unless a genuinely free, non-tracking option also exists.

"Explicit consent" is a distinct, higher Art. 9 GDPR standard for special category data (health, biometric, religious belief). Standard cookie consent uses the ordinary standard above, and the terms aren't interchangeable.

GDPR-K: How the GDPR Treats Children's Data

"GDPR-K" is informal shorthand for Art. 8 GDPR covering children's consent when a service ("information society service") is offered directly to a child. It applies narrowly: only when consent is the legal basis and the service targets children directly, and is not a separate law from the GDPR.

The default digital age of consent is 16, but Member States can lower it to 13, so the threshold varies by country. Below that age, the organization needs verifiable parental or guardian consent, though the GDPR doesn't mandate a specific verification method.

The rationale, per Recital 38, is that children are less aware of processing risks and merit extra protection against profiling and marketing. It's also why higher-risk processing involving children may call for an Art. 35 GDPR data protection impact assessment (DPIA).

GDPR-K is distinct from the UK's Children's Code and COPPA in the U.S. They have common purposes, but separate regimes with their own thresholds, and compliance with one doesn't cover the others.

European Union stars inside a black shield shape surrounded by icons related to GDPR compliance

Individual Rights Under the GDPR

The GDPR gives people rights to access, correct, and erase ("right to be forgotten") their data, and to receive it in a portable format. Consent can be withdrawn at any time, and it must be as easy to do so as it was to give. As a best practice, it should also be easy to change consent at a granular level at any time. Organizations must act on valid requests within a set timeframe, stopping processing or deleting data without unreasonable delay.

Qualifying data breaches must be reported to the relevant authority within 72 hours, and to affected individuals directly if the breach poses a high risk to their rights and freedoms.

GDPR and the EU AI Act: Where They Overlap

The EU AI Act sits alongside the GDPR, not in place of it. Both apply to any AI system processing personal data, enforced by different authorities on different logic. The GDPR covers ongoing accountability while the AI Act covers pre-market risk classification for high-risk systems. A few overlaps matter if your site uses AI for personalization, chatbots, or automated decisions.

GDPR and AI Act Overlap

GDPR and AI Act Overlap
Automated decisions and profiling
  • Art. 22 GDPR gives people the right not to be subject to solely automated decisions with legal or similarly significant effects (e.g., automated credit or hiring decisions)
  • The AI Act's human-oversight requirements for high-risk systems address the same concern from the system side. Existing Article 22 compliance is a head start, but the AI Act's requirements are more specific.
Impact assessments
  • Art. 35 GDPR DPIAs and the AI Act's Article 27 Fundamental Rights Impact Assessment (FRIA) overlap for high-risk AI systems handling personal data.
  • The AI Act allows a FRIA to build on an existing DPIA rather than duplicating it.
AI transparency and disclosure
  • AI Act Article 50 requires disclosing AI interaction and labeling AI-generated or manipulated content, a separate requirement from the GDPR, but one that reinforces its transparency principle.
  • Treat both as one coordinated disclosure exercise.
What's still unsettled
  • Proposed Article 88c, which would treat AI-training use of personal data as a GDPR legitimate interest, is part of the same contested Digital Omnibus proposal and hasn't been enacted.
  • There's no GDPR-specific legal basis carve-out for AI training yet.

GDPR Fines and Enforcement in 2026

The maximum penalty under the GDPR for the most serious violations is EUR 20 million or four percent of global annual turnover, whichever is higher. For lower tier violations it's up to EUR 10 million or two percent of global annual turnover, whichever is higher. These haven't changed since 2018, however, the frequency of enforcement has ramped up. Aggregate fines have passed EUR 7.1 billion, with more than 60 percent issued since 2023 as enforcement capacity and cross-border coordination have grown.

The largest GDPR fine to date is Meta Platforms Ireland's EUR 1.2 billion penalty from the Irish DPC in 2023 for unlawful EU-U.S. transfers, followed by TikTok's 530 million fine from the same authority in May 2025 for transfers to China. A widely reported EUR 746 million Amazon fine was annulled on procedural grounds in March 2026, though the underlying violations were upheld.

Cookie consent remains a target in its own right: French, Spanish, and Italian authorities continue to fine non-compliant banners, defaulted-on trackers, and consent flows that make refusing harder than accepting.

Do you know what your website is collecting?

Scan your site for free and see all the cookies and trackers in use. Get your customized report and privacy compliance risk level in minutes.

 

International Data Transfers and the EU-U.S. Data Privacy Framework

Transfers outside the EU require an adequacy finding or safeguards like Standard Contractual Clauses (SCCs). The EU-U.S. Data Privacy Framework covers transfers to self-certified U.S. organizations and remains in force and usable.

It's under active scrutiny, though. Following the U.S. Supreme Court's Trump v. Slaughter ruling on FTC independence, the EDPB asked the Commission on July 31, 2026 to examine whether it undermines a safeguard behind the adequacy decision. A CJEU challenge (Case C-703/25 P) is pending. Neither has invalidated the Framework, but given its two predecessors (Safe Harbor, Privacy Shield) were both struck down, this remains something to monitor.

Lady sitting at the desk, surrounded by icons related to

The EU Digital Omnibus: What's Changing (and What Isn't, Yet)

In November 2025, the Commission proposed folding cookie consent into the GDPR via new Articles 88a and 88b (making browser-level privacy signals legally binding) and Article 88c (treating AI-training data use as a legitimate interest). It's a significant package, but still only a contested proposal.

By mid-2026, the Council had dropped three of the Commission's four core reforms from its negotiating position, and in June 2026 removed Article 88b entirely after media/advertising lobbying. As of early August 2026, trilogue negotiations are still deciding Article 88b's fate, with no agreed text.

In practical terms, browser-based signals like Global Privacy Control (GPC) aren't currently required under EU law, and the version on the table is narrower than the Commission's original proposal. This is separate from the Omnibus's AI Act track, which has been adopted and took effect in July 2026.

GDPR Compliance Checklist

GDPR Compliance Checklist

GDPR Compliance Checklist
1
Prepare your organization

Train staff on data protection principles and assign a data protection officer if required, generally public authorities, large-scale monitoring operations, or those processing special category data at scale.

2
Audit your data

Map where personal data lives, who can access it, and which third parties process it, including embedded website tools.

3
Audit your service partners

Confirm vendors and embedded tools are compliant or operating from an adequate jurisdiction, and document their data flows.

4
Get consent right

Implement a consent mechanism meeting the freely-given, specific, informed, unambiguous standard, and log every decision, including changes over time.

5
Handle data subject rights requests

Build a repeatable process for access, correction, deletion, and portability requests, with clear ownership and turnaround times.

6
Prepare for breaches

Have detection, investigation, and 72-hour notification procedures ready before you need them.

Where This Leaves You

GDPR compliance isn't a one-time project. It's an ongoing practice of getting consent right, respecting the rights this regulation gives people, and keeping pace with a regulatory landscape that's still very much in motion, from the Digital Omnibus negotiations to the AI Act's growing overlap with data protection law. Get the fundamentals in this checklist right, and you'll be well placed to adapt as the details shift.

See your website's GDPR compliance gaps in minutes

Cookiebot™ CMP scans your site for every cookie and tracker in use, then handles consent collection, logging, and documentation automatically. Try it free for 14 days.