Who does the GDPR apply to, including outside Europe?
Article 3 draws two circles. Establishment: processing in the context of the activities of an EU/EEA establishment, an office, subsidiary, or stable arrangement, regardless of where the processing physically happens; a US company with a Dublin sales office is inside for processing connected to that establishment's activities. Targeting: organizations with no EU presence are covered where they offer goods or services (paid or free) to people in the EU, evidenced by factors like EU-currency pricing, EU languages beyond incidental use, EU shipping, or country-targeted marketing, or where they monitor behavior of people in the EU, which captures tracking cookies, analytics profiling, and behavioral advertising aimed at EU visitors; such organizations must generally appoint an EU representative (Article 27). What it covers: personal data means any information relating to an identified or identifiable natural person, names, emails, IP addresses, device identifiers, location traces, and pseudonymized data remains personal data (only true anonymization exits the regulation). What it does not: purely personal or household activity, and data about legal entities as such. Two role definitions organize every duty: controllers determine purposes and means; processors act on controllers' documented instructions, and the same company is usually both, controller for its marketing and HR, processor for its customers' data, with distinct obligation sets per role that contracts must reflect.
What makes processing lawful, and how strict is consent really?
Article 6 offers six bases and demands one per purpose: consent; contract necessity (processing objectively needed to perform a contract with the data subject, not merely mentioned in one, a line the EDPB and the Meta behavioral-advertising decisions enforced sharply); legal obligation; vital interests; public task; and legitimate interests, the flexible basis requiring a documented three-part test (genuine interest, necessity, balancing against the data subject's rights) that fails where the person would not reasonably expect the processing. Consent, when chosen, is demanding: freely given (no bundling with service access where alternatives exist, no imbalance exploitation), specific and granular per purpose, informed, unambiguous (pre-ticked boxes are invalid, per the CJEU's Planet49 judgment), and withdrawable as easily as given, with the withdrawal not degrading service. Special-category data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data for identification, health, sex life and orientation) is prohibited to process unless an Article 9(2) condition adds to the Article 6 basis, explicit consent, employment law, vital interests, substantial public interest, health care, and a few others. Criminal-offense data has its own Article 10 regime. The operational discipline: a lawful-basis register mapping every purpose to its basis, because switching bases retroactively when one fails is exactly the move regulators penalize, and the basis chosen dictates which rights apply (portability rides on consent and contract; objection rides on legitimate interests).
What rights do data subjects have, and what does answering them cost?
Eight core rights, each with machinery behind it. Access (Article 15): a copy of their personal data plus purposes, categories, recipients, retention, sources, and the existence of automated decision-making, the highest-volume right, answered within one month (extendable by two for complex requests), free in the ordinary case. Rectification: correcting inaccurate data and completing incomplete data. Erasure (Article 17, 'right to be forgotten'): deletion where data is no longer necessary, consent is withdrawn, processing was unlawful, or an objection succeeds, subject to exceptions (legal obligations, freedom of expression, legal claims), and it obligates informing downstream recipients. Restriction: freezing processing during disputes. Portability (Article 20): receiving consent- or contract-based data in a structured, commonly used, machine-readable format, or direct transmission where feasible. Objection (Article 21): stopping legitimate-interests processing unless compelling grounds override, and an absolute stop for direct marketing. Article 22 protections against solely automated significant decisions, with human-intervention safeguards. Withdrawal of consent at any time. Cost drivers in practice: identity verification proportionate to risk; locating data across systems (the data-map dependency); redacting third-party data from access copies; propagating erasure through backups and processors; and the one-month clock running from receipt, not from when the request reaches the right team. Refusals must be reasoned and notified with complaint rights; manifestly unfounded or excessive requests can be refused or charged, narrowly.
What do controllers and processors owe operationally: records, DPIAs, breaches, DPOs, transfers?
Accountability (Article 5(2)) is the master duty: being able to demonstrate compliance, which decomposes into artifacts. Records of processing (Article 30): a maintained register of processing activities, purposes, categories, recipients, transfers, retention, and security measures, for controllers and processors (small-enterprise exemptions are narrow). Data protection by design and default (Article 25): privacy engineered into systems, minimization as the default setting. Security (Article 32): risk-appropriate technical and organizational measures, encryption, resilience, testing. Processor contracts (Article 28): mandatory clauses, instructions-only processing, confidentiality, security, subprocessor consent and flow-down, assistance duties, deletion or return, audit rights. DPIAs (Article 35): mandatory before high-risk processing (systematic extensive profiling, large-scale special-category processing, systematic public monitoring), with prior consultation of the authority where residual risk stays high. DPOs (Article 37): mandatory for public authorities and where core activities involve regular, systematic large-scale monitoring or large-scale special-category processing, independent, resourced, reporting to top management. Breach notification: to the supervisory authority within 72 hours of awareness unless risk to individuals is unlikely, and to affected individuals without undue delay where risk is high (Articles 33-34), with an internal breach register regardless. Transfers (Chapter V): personal data leaves the EEA only under adequacy decisions (the EU-US Data Privacy Framework among them), appropriate safeguards (SCCs with transfer impact assessments post-Schrems II, BCRs), or narrow derogations. Miss the artifacts and the fine tiers stack: records and security failures draw the 2% tier; basis, rights, and transfer failures the 4% tier.
How is the GDPR enforced, and what do the fines actually look like?
Enforcement runs through national supervisory authorities (CNIL in France, the Irish DPC, Germany's federal and state authorities, and so on), with cross-border cases coordinated through the one-stop-shop: the authority of the main establishment leads, other concerned authorities weigh in, and the EDPB resolves disputes through binding Article 65 decisions, a mechanism that repeatedly hardened outcomes against Big Tech (several Meta fines rose after EDPB intervention). Powers exceed fines: investigation, processing bans (the Irish DPC's suspension threat preceded Meta's transfer fine), erasure orders, and certification withdrawals. The fine record: Meta 1.2 billion EUR (2023, unlawful US transfers, plus an order to suspend); Amazon 746 million EUR (2021, advertising consent); Meta/Instagram/WhatsApp fines cumulatively past 2.5 billion EUR across consent, transparency, and children's-data cases; TikTok 530 million EUR (2025, China transfers and transparency) and 345 million EUR (2023, children's defaults); Uber 290 million EUR (2024, transfers); LinkedIn 310 million EUR (2024, advertising bases); Google 90 and 60 million EUR CNIL cookie penalties (under ePrivacy, enforced alongside). Cumulative fines passed 5 billion EUR across roughly 2,300 published penalties by 2025. Patterns worth internalizing: lawful-basis failures for advertising, international transfers, children's data, and dark-pattern consent flows draw the headline numbers; but the median enforcement action is far smaller and hits ordinary companies for missing records, unanswered DSARs, late breach notifications, and absent processor contracts, the artifacts, again. Private enforcement grows in parallel: Article 82 damages claims and collective actions are normalizing non-material damage awards across member states.