Privacy & legal
Also known as: General Data Protection Regulation

GDPR

The European Union's General Data Protection Regulation, effective since 25 May 2018, which governs how organizations collect, store, and process personal data belonging to EU residents — with extraterritorial reach and fines of up to 4% of global annual revenue.

GDPR sets rules for processing personal data, including lawful bases, special-category data, individual rights, security, and breach notification. An organization should identify whether it acts as a controller or processor, document why each data field is necessary, set retention limits, and honor access, correction, deletion, and objection requests where they apply. Processor relationships can require a Data Processing Agreement, while higher-risk processing may need a Data Protection Impact Assessment. Web analytics can also fall under national ePrivacy rules governing storage or access on a user's device. Avoiding analytics cookies reduces one technical category of storage, but it does not automatically establish legitimate interests or remove every consent obligation. IP-derived hashes and other pseudonymised values can remain personal data. A privacy notice should describe the actual data flow rather than repeat a generic compliance claim. The correct assessment depends on purpose, implementation, other technology, contractual roles, data transfers, and jurisdiction. Technical minimization helps, but legal conclusions should be reviewed against the live deployment and current regulator guidance.

Examples

  • A US SaaS company offering a free EU-hosted option so it has a legal path to serve European customers.
  • An analytics operator documenting its purpose, data flow, retention, lawful-basis assessment, and jurisdiction-specific consent analysis.

Related terms

Reference

EUR-Lex — Regulation (EU) 2016/679 (GDPR)