Global Privacy Law European Union / EEA

EU GDPR Overview: Scope, Duties, Rights, and Enforcement

The GDPR in one page: who it reaches, lawful bases, data subject rights, controller and processor duties, transfers, breach rules, and the fines regulators actually impose.

Regulation

Regulation (EU) 2016/679 (General Data Protection Regulation), applicable since May 25, 2018

Max Penalty

Up to 20 million EUR or 4% of total worldwide annual turnover, whichever is higher (Article 83(5)); a lower tier of 10 million EUR or 2% applies to duties like security and records

Enforcing Authority

National supervisory authorities in each EU/EEA state, coordinated by the European Data Protection Board; one-stop-shop via a lead authority for cross-border processing

Official Source

eur-lex.europa.eu

Executive Summary

  • The GDPR governs processing of personal data of people in the EU/EEA, reaching non-EU organizations that offer them goods or services or monitor their behavior (Article 3).
  • Every processing operation needs one of six lawful bases (Article 6); special-category data needs an additional Article 9 condition; consent must be freely given, specific, informed, and unambiguous.
  • Data subjects hold rights of access, rectification, erasure, restriction, portability, objection, and protections against solely automated decisions, generally answerable within one month.
  • Controllers owe accountability: records of processing, DPIAs for high-risk processing, breach notification to authorities within 72 hours, processor contracts under Article 28, and DPOs where triggered.
  • Fines reach 20 million EUR or 4% of worldwide turnover; the largest to date is Meta's 1.2 billion EUR transfer penalty (2023), and cumulative GDPR fines pass 5 billion EUR.

Seven years in, the GDPR has settled into what its drafters intended: not a compliance checklist but an operating constraint on how organizations handle people’s data, enforced with fines that reach revenue-percentage scale and doctrines that keep tightening through CJEU judgments and EDPB decisions. The pattern in the enforcement record is unmistakable. The headline penalties punish business models built on shaky lawful bases; the everyday penalties punish missing paperwork, silent breach handling, and rights requests that vanish into inboxes. Both are avoidable with the same machinery, a real data map, a basis register, working rights and breach workflows, and papered processor relationships, which is why GDPR maturity has become the de facto foundation on which every other privacy regime’s compliance gets built.

Applicable sinceMay 25, 2018
ReachEU establishments + anyone targeting or monitoring people in the EU
Fine tiers20M EUR / 4% (basis, rights, transfers); 10M EUR / 2% (security, records)
Breach clock72 hours to the authority; high-risk breaches also to individuals
Largest fineMeta, 1.2 billion EUR (2023, transfers)
Full textRegulation (EU) 2016/679

Going deeper

Start with basis and map. The lawful basis guide and RoPA template are the load-bearing artifacts.

Wire the workflows. Data subject rights, breach notification, and DPIAs each have dedicated guides.

Paper the relationships. Controller-processor contracts and cross-border transfers are where enforcement concentrates.

Watch the record. The enforcement tracker follows where authorities actually aim.

Your cookie banner and trackers are the most-inspected GDPR surface: check yours with a free scan.

Frequently Asked Questions

Who does the GDPR apply to, including outside Europe?

Article 3 draws two circles. Establishment: processing in the context of the activities of an EU/EEA establishment, an office, subsidiary, or stable arrangement, regardless of where the processing physically happens; a US company with a Dublin sales office is inside for processing connected to that establishment's activities. Targeting: organizations with no EU presence are covered where they offer goods or services (paid or free) to people in the EU, evidenced by factors like EU-currency pricing, EU languages beyond incidental use, EU shipping, or country-targeted marketing, or where they monitor behavior of people in the EU, which captures tracking cookies, analytics profiling, and behavioral advertising aimed at EU visitors; such organizations must generally appoint an EU representative (Article 27). What it covers: personal data means any information relating to an identified or identifiable natural person, names, emails, IP addresses, device identifiers, location traces, and pseudonymized data remains personal data (only true anonymization exits the regulation). What it does not: purely personal or household activity, and data about legal entities as such. Two role definitions organize every duty: controllers determine purposes and means; processors act on controllers' documented instructions, and the same company is usually both, controller for its marketing and HR, processor for its customers' data, with distinct obligation sets per role that contracts must reflect.

What makes processing lawful, and how strict is consent really?

Article 6 offers six bases and demands one per purpose: consent; contract necessity (processing objectively needed to perform a contract with the data subject, not merely mentioned in one, a line the EDPB and the Meta behavioral-advertising decisions enforced sharply); legal obligation; vital interests; public task; and legitimate interests, the flexible basis requiring a documented three-part test (genuine interest, necessity, balancing against the data subject's rights) that fails where the person would not reasonably expect the processing. Consent, when chosen, is demanding: freely given (no bundling with service access where alternatives exist, no imbalance exploitation), specific and granular per purpose, informed, unambiguous (pre-ticked boxes are invalid, per the CJEU's Planet49 judgment), and withdrawable as easily as given, with the withdrawal not degrading service. Special-category data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data for identification, health, sex life and orientation) is prohibited to process unless an Article 9(2) condition adds to the Article 6 basis, explicit consent, employment law, vital interests, substantial public interest, health care, and a few others. Criminal-offense data has its own Article 10 regime. The operational discipline: a lawful-basis register mapping every purpose to its basis, because switching bases retroactively when one fails is exactly the move regulators penalize, and the basis chosen dictates which rights apply (portability rides on consent and contract; objection rides on legitimate interests).

What rights do data subjects have, and what does answering them cost?

Eight core rights, each with machinery behind it. Access (Article 15): a copy of their personal data plus purposes, categories, recipients, retention, sources, and the existence of automated decision-making, the highest-volume right, answered within one month (extendable by two for complex requests), free in the ordinary case. Rectification: correcting inaccurate data and completing incomplete data. Erasure (Article 17, 'right to be forgotten'): deletion where data is no longer necessary, consent is withdrawn, processing was unlawful, or an objection succeeds, subject to exceptions (legal obligations, freedom of expression, legal claims), and it obligates informing downstream recipients. Restriction: freezing processing during disputes. Portability (Article 20): receiving consent- or contract-based data in a structured, commonly used, machine-readable format, or direct transmission where feasible. Objection (Article 21): stopping legitimate-interests processing unless compelling grounds override, and an absolute stop for direct marketing. Article 22 protections against solely automated significant decisions, with human-intervention safeguards. Withdrawal of consent at any time. Cost drivers in practice: identity verification proportionate to risk; locating data across systems (the data-map dependency); redacting third-party data from access copies; propagating erasure through backups and processors; and the one-month clock running from receipt, not from when the request reaches the right team. Refusals must be reasoned and notified with complaint rights; manifestly unfounded or excessive requests can be refused or charged, narrowly.

What do controllers and processors owe operationally: records, DPIAs, breaches, DPOs, transfers?

Accountability (Article 5(2)) is the master duty: being able to demonstrate compliance, which decomposes into artifacts. Records of processing (Article 30): a maintained register of processing activities, purposes, categories, recipients, transfers, retention, and security measures, for controllers and processors (small-enterprise exemptions are narrow). Data protection by design and default (Article 25): privacy engineered into systems, minimization as the default setting. Security (Article 32): risk-appropriate technical and organizational measures, encryption, resilience, testing. Processor contracts (Article 28): mandatory clauses, instructions-only processing, confidentiality, security, subprocessor consent and flow-down, assistance duties, deletion or return, audit rights. DPIAs (Article 35): mandatory before high-risk processing (systematic extensive profiling, large-scale special-category processing, systematic public monitoring), with prior consultation of the authority where residual risk stays high. DPOs (Article 37): mandatory for public authorities and where core activities involve regular, systematic large-scale monitoring or large-scale special-category processing, independent, resourced, reporting to top management. Breach notification: to the supervisory authority within 72 hours of awareness unless risk to individuals is unlikely, and to affected individuals without undue delay where risk is high (Articles 33-34), with an internal breach register regardless. Transfers (Chapter V): personal data leaves the EEA only under adequacy decisions (the EU-US Data Privacy Framework among them), appropriate safeguards (SCCs with transfer impact assessments post-Schrems II, BCRs), or narrow derogations. Miss the artifacts and the fine tiers stack: records and security failures draw the 2% tier; basis, rights, and transfer failures the 4% tier.

How is the GDPR enforced, and what do the fines actually look like?

Enforcement runs through national supervisory authorities (CNIL in France, the Irish DPC, Germany's federal and state authorities, and so on), with cross-border cases coordinated through the one-stop-shop: the authority of the main establishment leads, other concerned authorities weigh in, and the EDPB resolves disputes through binding Article 65 decisions, a mechanism that repeatedly hardened outcomes against Big Tech (several Meta fines rose after EDPB intervention). Powers exceed fines: investigation, processing bans (the Irish DPC's suspension threat preceded Meta's transfer fine), erasure orders, and certification withdrawals. The fine record: Meta 1.2 billion EUR (2023, unlawful US transfers, plus an order to suspend); Amazon 746 million EUR (2021, advertising consent); Meta/Instagram/WhatsApp fines cumulatively past 2.5 billion EUR across consent, transparency, and children's-data cases; TikTok 530 million EUR (2025, China transfers and transparency) and 345 million EUR (2023, children's defaults); Uber 290 million EUR (2024, transfers); LinkedIn 310 million EUR (2024, advertising bases); Google 90 and 60 million EUR CNIL cookie penalties (under ePrivacy, enforced alongside). Cumulative fines passed 5 billion EUR across roughly 2,300 published penalties by 2025. Patterns worth internalizing: lawful-basis failures for advertising, international transfers, children's data, and dark-pattern consent flows draw the headline numbers; but the median enforcement action is far smaller and hits ordinary companies for missing records, unanswered DSARs, late breach notifications, and absent processor contracts, the artifacts, again. Private enforcement grows in parallel: Article 82 damages claims and collective actions are normalizing non-material damage awards across member states.

Regulatory Crosswalk

UK GDPRISO/IEC 27701EU AI ActePrivacy Directive

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.