Privacy Laws
What is GDPR (General Data Protection Regulation)?
The General Data Protection Regulation (GDPR) is the European Union's comprehensive data protection law, in force since May 25, 2018, which governs how organizations anywhere in the world process the personal data of people in the EU, with fines up to €20 million or 4% of global annual turnover.
The GDPR applies extraterritorially: any organization that offers goods or services to people in the EU, or monitors their behavior, is covered regardless of where it is established. A US eCommerce store shipping to Berlin or tracking EU visitors on its website is in scope. The law protects 'personal data' — any information relating to an identified or identifiable person, expressly including online identifiers like IP addresses and cookie IDs.
Its architecture rests on principles (Article 5): lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. Every processing operation needs one of six legal bases under Article 6 — consent, contract, legal obligation, vital interests, public task, or legitimate interests — chosen and documented before processing begins.
Individuals ('data subjects') hold enforceable rights: access, rectification, erasure, restriction, portability, and objection, generally answerable within one month. Organizations carry matching duties: privacy notices (Articles 13-14), data protection by design and by default (Article 25), processor contracts (Article 28), records of processing (Article 30), breach notification to regulators within 72 hours (Article 33), impact assessments for high-risk processing (Article 35), and, for some, a Data Protection Officer.
Enforcement runs through national supervisory authorities with two fine tiers — up to €10 million or 2% of global turnover for operational failures, and up to €20 million or 4% for violations of principles, legal bases, or rights. Cumulative fines have run into the billions of euros, with the largest actions targeting unlawful advertising processing and data transfers.
Why it matters for eCommerce
For an online store, GDPR shows up concretely: opt-in consent before marketing cookies fire for EU visitors, a lawful basis mapped for every use of customer data, DSAR handling that reaches your email and analytics vendors, processor agreements with every SaaS tool touching customer data, and breach response rehearsed against a 72-hour clock. Selling to Europe means all of it applies, even with no EU office.
Frequently asked questions
- Does GDPR apply to US companies?
- Yes, if they offer goods or services to people in the EU or monitor their behavior — shipping to EU addresses, accepting euros, or running tracking on EU visitors all count. Physical presence in Europe is not required.
- What are the maximum GDPR fines?
- Two tiers: up to €10 million or 2% of worldwide annual turnover (whichever is higher) for infringements like inadequate security or missing records, and up to €20 million or 4% for violating processing principles, legal bases, consent rules, or data subject rights.
- What is the deadline to answer a GDPR data subject request?
- One month from receipt, extendable by two further months for complex or numerous requests — with the individual informed of the extension and its reasons within the first month.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
Run a free GDPR scan of your site