The General Data Protection Regulation is the EU law that governs how organizations collect, use, store, and share personal data. It took effect on May 25, 2018, replaced the 1995 Data Protection Directive, and applies extraterritorially: an organization anywhere in the world is in scope if it offers goods or services to people in the EU or monitors their behavior (Article 3). This guide walks through a 10-step roadmap that compliance teams can execute in order.
| Regulation | Regulation (EU) 2016/679 (GDPR) |
|---|---|
| In force since | May 25, 2018 |
| Max penalty | EUR 20M or 4% of global annual turnover |
| Enforcing authority | National supervisory authorities, coordinated by the EDPB |
| Official text | EUR-Lex CELEX 32016R0679 |
What GDPR requires
The regulation rests on seven Article 5 principles: lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. Every obligation in the rest of the text traces back to one of these. Article 6 then requires a documented lawful basis for each processing purpose, and Articles 15 to 22 give individuals rights to access, rectify, erase, restrict, port, and object to processing of their data.
The 10-step roadmap
- Build a data inventory. List every system, form, and vendor that touches personal data. You cannot assign lawful bases or answer deletion requests for data you have not mapped.
- Assign a lawful basis per purpose. Consent, contract, legal obligation, vital interests, public task, or legitimate interests (Article 6(1)). Document the choice; switching bases later is what regulators penalize.
- Create your Article 30 records of processing. Controllers and processors both need them. See our ROPA template guide.
- Rewrite privacy notices. Articles 13 and 14 list the mandatory content: purposes, bases, recipients, retention periods, rights, and transfer safeguards.
- Fix website consent. Non-essential cookies and trackers need prior opt-in consent that is as easy to refuse as to give. This is the most frequently enforced violation.
- Operationalize data subject rights. Set up intake, identity verification, and a workflow that meets the one-month deadline.
- Paper your vendors. Every processor needs an Article 28 contract with the eight mandatory clauses.
- Prepare breach response. Article 33 gives you 72 hours to notify the supervisory authority after becoming aware of a reportable breach.
- Assess transfers. Data leaving the EEA needs an adequacy decision, standard contractual clauses with a transfer impact assessment, or another Chapter V mechanism.
- Decide whether you need a DPO and DPIAs. Article 37 makes a DPO mandatory for public bodies and for large-scale monitoring or special category processing; Article 35 requires DPIAs for high-risk processing.
Penalties and enforcement
Enforcement is real and growing. The Irish DPC fined Meta EUR 1.2 billion in May 2023 over EU-US transfers, the largest GDPR fine issued to date. Amazon received EUR 746 million from Luxembourg in 2021, LinkedIn EUR 310 million in 2024 over advertising lawful basis, and TikTok EUR 345 million in 2023 over children’s defaults. Smaller organizations are not ignored: national authorities issue hundreds of five-figure and six-figure fines each year, frequently triggered by a single complaint about a website.
Where to start
Your public website is the fastest thing to check and the first thing a complainant or regulator sees. Run a free scan to see which trackers fire before consent, what your privacy policy discloses, and where your site diverges from what GDPR expects, then work the roadmap above from the top.