What is the GDPR?

Close
Read time
9 mins
Published
Aug 20, 2026
Share
Magnifying glass analysing the CMP banners from a GDPR point of view on mobile and desktop
  • GDPR has applied since May 25, 2018, to any organization processing EU residents' personal data, regardless of where the organization is based.
  • Fines can reach 20 million or 4% of global annual turnover; enforcement has issued over 7.1 billion in penalties since 2018.
  • Valid consent must be freely given, specific, informed, and unambiguous, so pre-ticked boxes, cookie walls, and scroll-to-accept all fail that test.
  • Special rules apply to children's data ("GDPR-K"), and the EU AI Act now layers extra obligations on top of GDPR for AI systems.
  • The proposed EU Digital Omnibus would fold cookie consent into the GDPR, but it remains contested in trilogue and is not law yet.
  • Cookiebot CMP automates GDPR-compliant consent collection, logging, and documentation.

The General Data Protection Regulation (GDPR) is the EU's core data protection law. It governs how organizations collect, use, store, and share the personal data of people in the EU, regardless of where the organization itself is based. It sets clear rules on legal grounds for processing, transparency, documentation, and consent, backed by enforcement powers European authorities have used with increasing frequency since 2018.

Who Does the GDPR Apply To?

The GDPR applies to organizations established in the EU, and to organizations outside the EU that offer goods or services to people in the EU or monitor their behavior. This includes use of analytics, ad trackers, and profiling. In addition to companies based in Europe, a retailer in Ohio with EU customers, or a Singapore SaaS company running ads targeted at Berlin, is in scope. No EU servers or office required, only EU visitors whose data is processed.

Controllers and Processors

A data controller decides why and how personal data is processed. A data processor, e.g., a SaaS vendor, an analytics tool, an ad network, acts on the controller's instructions. Both carry legal obligations, and a controller can't outsource responsibility by pointing at a contract. It must actively vet and monitor every processor and third party on its site.

What Counts as Personal Data?

Personal data is any information tied to an identifiable individual, either directly (a name, an ID number) or indirectly (location data, an online identifier, or a combination of factors). This covers IP addresses and device identifiers unless properly anonymized, and pseudonymized data if it can plausibly be re-identified.

Consent is the legal ground governing most cookie and tracking scenarios. To be valid, it must be freely given, specific, informed, and unambiguous. Website visitors, app users, e-commerce customers, and others, must provide a clear affirmative action, not an assumption drawn from behavior.

The consent guidelines from the European Data Protection Board (EDPB) rule out the usual shortcuts: pre-ticked boxes, and continued browsing or scrolling. Cookie walls, which block site access unless the visitor accepts tracking, also fail, since there's no genuine choice. A 2024 EDPB opinion extended this to "consent or pay" models on large platforms. These offer only tracking-consent or a paid alternative, which usually fails the freely-given test unless a genuinely free, non-tracking option also exists.

"Explicit consent" is a distinct, higher Art. 9 GDPR standard for special category data (health, biometric, religious belief). Standard cookie consent uses the ordinary standard above, and the terms aren't interchangeable.

The Six Lawful Bases for Processing Personal Data

Consent is not the only route to lawful processing under the GDPR. Article 6 GDPR sets out six lawful bases, and an organization only needs one to process personal data legitimately. Choosing the wrong basis, or defaulting to consent when another basis fits better, is itself a compliance risk.

The Six Bases

Article 6(1) GDPR lists these on equal legal footing; none takes precedence over the others, and the right one depends on the purpose of the processing, not the type of data involved.

GDPR Lawful Bases

GDPR Lawful Bases
Consent

The individual has given clear, affirmative permission for a specific purpose. This is the basis most cookie and tracking scenarios rely on, and it's covered in detail below.

Contract

Processing is necessary to fulfill a contract with the individual, or to take steps at their request before entering one, e.g., processing a shipping address to deliver an order.

Legal obligation

The organization must process the data to comply with EU or Member State law, e.g., retaining financial records for tax authorities.

Vital interests

Processing is necessary to protect someone's life, used rarely and typically only where no other basis applies.

Public task

Processing is necessary to perform a task in the public interest or exercise official authority, and applies mainly to public bodies rather than private companies.

Legitimate interests

The organization has a genuine business reason to process the data that isn't overridden by the individual's rights and interests, e.g., basic fraud prevention or network security.

Why This Matters for Cookies and Tracking

Not every cookie needs consent. Strictly necessary cookies, e.g., those required for a shopping cart or login session to function, can often rely on legitimate interests, since ePrivacy rules already carve out an exemption for them. Analytics, advertising, and profiling cookies, by contrast, almost always require consent, since there's no other basis available for that kind of non-essential tracking.

Getting this distinction right shapes what a cookie banner needs to ask for, and what it can quietly allow. A Cookiebot™ scan can help identify which cookies on a site are firing before consent, and which basis genuinely applies to each.

GDPR-K: How the GDPR Treats Children's Data

"GDPR-K" is informal shorthand for Art. 8 GDPR covering children's consent when a service ("information society service") is offered directly to a child. It applies narrowly: only when consent is the legal basis and the service targets children directly, and is not a separate law from the GDPR.

The default digital age of consent is 16, but Member States can lower it to 13, so the threshold varies by country. Below that age, the organization needs verifiable parental or guardian consent, though the GDPR doesn't mandate a specific verification method.

The rationale, per Recital 38, is that children are less aware of processing risks and merit extra protection against profiling and marketing. It's also why higher-risk processing involving children may call for an Art. 35 GDPR data protection impact assessment (DPIA).

GDPR-K is distinct from the UK's Children's Code and COPPA in the U.S. They have common purposes, but separate regimes with their own thresholds, and compliance with one doesn't cover the others.

European Union stars inside a black shield shape surrounded by icons related to GDPR compliance

Individual Rights Under the GDPR

The GDPR gives people rights to access, correct, and erase ("right to be forgotten") their data, and to receive it in a portable format. Consent can be withdrawn at any time, and it must be as easy to do so as it was to give. As a best practice, it should also be easy to change consent at a granular level at any time. Organizations must act on valid requests within a set timeframe, stopping processing or deleting data without unreasonable delay.

Qualifying data breaches must be reported to the relevant authority within 72 hours, and to affected individuals directly if the breach poses a high risk to their rights and freedoms.

GDPR and the EU AI Act: Where They Overlap

The EU AI Act sits alongside the GDPR, not in place of it. Both apply to any AI system processing personal data, enforced by different authorities on different logic. The GDPR covers ongoing accountability while the AI Act covers pre-market risk classification for high-risk systems. A few overlaps matter if your site uses AI for personalization, chatbots, or automated decisions.

GDPR and AI Act Overlap

GDPR and AI Act Overlap
Automated decisions and profiling
  • Art. 22 GDPR gives people the right not to be subject to solely automated decisions with legal or similarly significant effects (e.g., automated credit or hiring decisions)
  • The AI Act's human-oversight requirements for high-risk systems address the same concern from the system side. Existing Article 22 compliance is a head start, but the AI Act's requirements are more specific.
Impact assessments
  • Art. 35 GDPR DPIAs and the AI Act's Article 27 Fundamental Rights Impact Assessment (FRIA) overlap for high-risk AI systems handling personal data.
  • The AI Act allows a FRIA to build on an existing DPIA rather than duplicating it.
AI transparency and disclosure
  • AI Act Article 50 requires disclosing AI interaction and labeling AI-generated or manipulated content, a separate requirement from the GDPR, but one that reinforces its transparency principle.
  • Treat both as one coordinated disclosure exercise.
What's still unsettled
  • Proposed Article 88c, which would treat AI-training use of personal data as a GDPR legitimate interest, is part of the same contested Digital Omnibus proposal and hasn't been enacted.
  • There's no GDPR-specific legal basis carve-out for AI training yet.

GDPR Fines and Enforcement in 2026

The maximum penalty under the GDPR for the most serious violations is EUR 20 million or four percent of global annual turnover, whichever is higher. For lower tier violations it's up to EUR 10 million or two percent of global annual turnover, whichever is higher. These haven't changed since 2018, however, the frequency of enforcement has ramped up. Aggregate fines have passed EUR 7.1 billion, with more than 60 percent issued since 2023 as enforcement capacity and cross-border coordination have grown.

The largest GDPR fine to date is Meta Platforms Ireland's EUR 1.2 billion penalty from the Irish DPC in 2023 for unlawful EU-U.S. transfers, followed by TikTok's 530 million fine from the same authority in May 2025 for transfers to China. A widely reported EUR 746 million Amazon fine was annulled on procedural grounds in March 2026, though the underlying violations were upheld.

Cookie consent remains a target in its own right: French, Spanish, and Italian authorities continue to fine non-compliant banners, defaulted-on trackers, and consent flows that make refusing harder than accepting.

Do you know what your website is collecting?

Scan your site for free and see all the cookies and trackers in use. Get your customized report and privacy compliance risk level in minutes.

 

International Data Transfers and the EU-U.S. Data Privacy Framework

Transfers outside the EU require an adequacy finding or safeguards like Standard Contractual Clauses (SCCs). The EU-U.S. Data Privacy Framework covers transfers to self-certified U.S. organizations and remains in force and usable.

It's under active scrutiny, though. Following the U.S. Supreme Court's Trump v. Slaughter ruling on FTC independence, the EDPB asked the Commission on July 31, 2026 to examine whether it undermines a safeguard behind the adequacy decision. A CJEU challenge (Case C-703/25 P) is pending. Neither has invalidated the Framework, but given its two predecessors (Safe Harbor, Privacy Shield) were both struck down, this remains something to monitor.

Lady sitting at the desk, surrounded by icons related to

The EU Digital Omnibus: What's Changing (and What Isn't, Yet)

In November 2025, the Commission proposed folding cookie consent into the GDPR via new Articles 88a and 88b (making browser-level privacy signals legally binding) and Article 88c (treating AI-training data use as a legitimate interest). It's a significant package, but still only a contested proposal.

By mid-2026, the Council had dropped three of the Commission's four core reforms from its negotiating position, and in June 2026 removed Article 88b entirely after media/advertising lobbying. As of early August 2026, trilogue negotiations are still deciding Article 88b's fate, with no agreed text.

In practical terms, browser-based signals like Global Privacy Control (GPC) aren't currently required under EU law, and the version on the table is narrower than the Commission's original proposal. This is separate from the Omnibus's AI Act track, which has been adopted and took effect in July 2026.

GDPR Compliance Checklist

GDPR Compliance Checklist

GDPR Compliance Checklist
1
Prepare your organization

Train staff on data protection principles and assign a data protection officer if required, generally public authorities, large-scale monitoring operations, or those processing special category data at scale.

2
Audit your data

Map where personal data lives, who can access it, and which third parties process it, including embedded website tools.

3
Audit your service partners

Confirm vendors and embedded tools are compliant or operating from an adequate jurisdiction, and document their data flows.

4
Get consent right

Implement a consent mechanism meeting the freely-given, specific, informed, unambiguous standard, and log every decision, including changes over time.

5
Handle data subject rights requests

Build a repeatable process for access, correction, deletion, and portability requests, with clear ownership and turnaround times.

6
Prepare for breaches

Have detection, investigation, and 72-hour notification procedures ready before you need them.

Where This Leaves You

GDPR compliance isn't a one-time project. It's an ongoing practice of getting consent right, respecting the rights this regulation gives people, and keeping pace with a regulatory landscape that's still very much in motion, from the Digital Omnibus negotiations to the AI Act's growing overlap with data protection law. Get the fundamentals in this checklist right, and you'll be well placed to adapt as the details shift.

See your website's GDPR compliance gaps in minutes

Cookiebot™ CMP scans your site for every cookie and tracker in use, then handles consent collection, logging, and documentation automatically. Try it free for 14 days.

Frequently asked questions

Yes, EU-US data transfers are allowed under the GDPR but must be conducted using approved mechanisms such as Standard Contractual Clauses or the new EU-U.S. Data Privacy Framework, ensuring compliance with EU data protection standards. These mechanisms must be rigorously assessed to ensure they provide sufficient data protection as per EU standards. The Data Privacy Framework is only applicable to companies that are self-certified and appear on the Data Privacy Framework List.

Yes, cookies and trackers that process personal data from users inside the EU are allowed upon obtaining the explicit consent from end-users. However, cookies are not allowed to be activated and used without such consent from the end-user (except cookies that are strictly necessary for the most basic functions of your website).

Scan your website for free to see all cookies in use

Yes, most of the data that cookies collect are classified as personal data under the GDPR. This includes IP addresses, search and browser history, and device information. If you’re unsure whether your website collects personal data, try the free compliance test by Cookiebot CMP.

Try the free GDPR cookie checker with Cookiebot CMP

Yes, data processing agreements (DPAs) are legally required under data protection laws like the GDPR and CCPA/CPRA when a data controller engages a third-party data processor to handle personal data on its behalf.

There are very few substantial differences between the UK-GDPR and its EU equivalent. Essentially, the UK has lifted the entire structure of the EU GDPR and put it in place into UK law. However, the UK-GDPR changes key areas of the law concerning national security, intelligence services and immigration.

Learn more about GDPR in the UK

If your website has users from inside the EU, you are required to comply with the EU’s General Data Protection Regulation (GDPR) – regardless of where in the world you and your website is located. You are required to ask for and obtain the explicit consent from end-users before tracking any of their personal data for the use of website analytics.

Scan your website to see where in the world your website sends data to

If you have users from inside the EU, you need to be in compliance with the EU’s GDPR – no matter where in the world you and your website is located. Any processing of personal data from individuals inside the European Union requires their explicit consent to do so. This includes the use of Google Analytics, cookies and other tracking technologies on your website.

Scan your website for free to see all cookies in use

Yes, if your website collects or processes personal data from individuals residing in the European Union, you need a GDPR compliance solution to meet the requirements of the regulation and avoid potential fines and penalties.