Glossary | GDPR & Data Privacy

General Data Protection Regulation (GDPR)

What is the General Data Protection Regulation (GDPR)?

The General Data Protection Regulation (GDPR), formally known as Regulation (EU) 2016/679, is the European Union’s primary legal framework governing the collection, processing, and storage of personal data. It came into full effect on 25 May 2018 and applies to any organisation that processes the personal data of individuals located in the EU, regardless of where the organisation itself is based.

Why It Matters

The GDPR fundamentally changed how businesses must handle personal data. It introduced strict obligations around consent, data security, and individuals’ rights — and backed these with significant enforcement powers, including fines of up to €20 million or 4% of global annual turnover, whichever is higher.

Critically, the GDPR applies beyond EU borders. If your business collects or processes data from EU residents — whether through a website, app, or ecommerce platform — you are likely subject to its requirements regardless of where your company is established.

For businesses of all sizes, understanding and complying with the GDPR is essential for lawful operations and for maintaining the trust of customers and partners.

What is the General Data Protection Regulation (GDPR)?

Key Requirements

Who Does the GDPR Apply To?

The GDPR applies to organisations that:

  • Are established in the EU and process personal data, or
  • Are established outside the EU but offer goods or services to, or monitor the behaviour of, individuals in the EU.

This regulation applies under:

Obligations differ depending on whether your organisation acts as a Data Controller, a Data Processor, or both.

Responsibilities Under the GDPR

While specific obligations depend on your role, responsibilities commonly include:

  • Processing personal data lawfully, fairly, and transparently
  • Collecting data only for specified, explicit, and legitimate purposes
  • Appointing a Data Protection Officer (DPO) where required
  • Appointing an EU Representative if established outside the EU
  • Implementing appropriate technical and organisational security measures
  • Reporting personal data breaches to the relevant supervisory authority within 72 hours
  • Honouring individuals’ rights, including the right to access, rectification, and erasure of their data

GDPR and the EU Representative

Non-EU organisations subject to the GDPR are required under Article 27 to appoint an EU Representative — a natural or legal person established within the EU who acts as a point of contact for supervisory authorities and data subjects.

This is a separate requirement from other EU regulatory roles such as the Authorised Representative under the GPSR or EU MDR. Businesses operating across multiple regulatory frameworks should confirm their obligations under each separately.

Frequently Asked Questions

Yes, if you offer goods or services to individuals in the EU, or monitor their behaviour — for example through website cookies or analytics — the GDPR is likely to apply to your organisation regardless of where you are based.

Fines can reach up to €20 million or 4% of total global annual turnover for the preceding financial year, whichever is higher. Supervisory authorities can also issue warnings, reprimands, and temporary or permanent bans on data processing.

A Data Controller determines the purposes and means of processing personal data. A Data Processor processes data on behalf of a controller. Both have obligations under the GDPR, though controllers carry the primary responsibility for compliance.

gdpr logo

Need GDPR Representative Services?

Euverify provides EU Representative services for organisations outside the European Union that are subject to the GDPR. Our team supports regulatory communication, documentation, and ongoing compliance management.