The General Data Protection Regulation, or GDPR, is a set of rules that controls how personal information is handled in Europe. It went into effect on May 25, 2018, and applies to any organization that collects or processes data from people living in the European Union, regardless of where the company is located. If you live in the EU or your data is collected by a company doing business there, GDPR rules likely affect your information.
Learn About Luxury Apartment Costs in Calumet City →
GDPR was created because technology companies were collecting massive amounts of personal data without always telling people what they were doing with it. Before GDPR existed, people had little control over their own information. A person might not know which companies had their email address, phone number, or browsing history. GDPR changed this by giving individuals more power over their personal data and requiring companies to be transparent about their practices.
The regulation covers a wide range of organizations—not just large tech companies. Small businesses, nonprofits, schools, hospitals, and government agencies all must follow GDPR rules if they process personal data from EU residents. The rules apply whether data is collected online, on paper forms, or through other methods. This means a French bakery selling to customers online must follow the same core principles as a multinational corporation.
Personal data under GDPR includes anything that can identify a person: names, email addresses, phone numbers, ID numbers, physical location, online activity, medical information, and financial details. Even information that seems harmless—like a cookie that tracks which websites someone visits—falls under GDPR protection.
Organizations that break GDPR rules face serious consequences. Fines can reach up to 20 million euros or 4% of a company's yearly revenue, whichever is higher. For major violations, fines can go up to 30 million euros or 6% of revenue. These are not small penalties, which is why thousands of companies spent significant resources preparing for GDPR before it took effect.
Practical takeaway: Understanding what GDPR covers helps you know which of your rights apply and what protections companies must provide. The regulation protects information you share with any organization in Europe, whether you realize it or not.
GDPR gives individuals eight main rights regarding their personal data. These rights shift power away from large organizations and toward the people whose information is being collected. Knowing these rights helps you understand what companies must do when you ask questions about your data.
Get Your Free Python Beginner Information Guide →
The right to be informed means companies must tell you when they collect your data and explain how they will use it. This disclosure must happen before or when data is collected, and it should be clear and honest. A website should explain in plain language what information they gather and why—not hide this information in confusing legal documents buried in a terms-of-service page.
The right of access allows you to request a copy of all personal information a company holds about you. This is sometimes called a "Subject Access Request" or SAR. When you submit this request, the company must provide the information within 30 days. You can see everything they collected: your activity history, preferences they recorded, communications with customer service, and more. Many people are surprised at how much data companies store about them.
The right to rectification lets you correct information that is wrong or incomplete. If a company has your address spelled incorrectly or listed the wrong phone number, you can request that they fix it. This matters because incorrect data can cause problems—you might miss important communications or be denied services based on false information.
The right to erasure is sometimes called the "right to be forgotten." You can request that a company delete your personal data under certain circumstances. This does not mean they must delete everything forever—there are exceptions for legal obligations and legitimate business reasons. But if a company no longer needs your data, or if you withdraw permission, they should remove it.
The right to restrict processing means you can ask a company to stop using your data in certain ways, even if they do not delete it. For example, you might ask them to stop using your information for marketing emails while they investigate whether the data they have about you is correct.
The right to data portability allows you to get a copy of your information in a common format that you can move to another company. This matters because it prevents companies from locking you in. If you want to switch email providers, you should be able to get your data from the old company and move it to the new one.
The right to object lets you say no to certain types of data processing. You can object to marketing communications, profiling, and automated decision-making. If a company uses artificial intelligence or algorithms to make decisions about you—like whether you get a loan or a job—you can object and ask for human review.
The right related to automated decision-making protects you from decisions made entirely by computer algorithms. If a system automatically denies your request for something important without human involvement, you can challenge it and ask for a human to review the decision.
Practical takeaway: These eight rights give you concrete tools to control your information. You can contact companies directly to exercise these rights—you do not need special permission or a lawyer to make a request.
GDPR requires organizations to follow specific practices when handling personal data. These requirements apply whether a company is a small startup or a multinational corporation. Understanding what companies must do gives you insight into what protections are actually in place for your information.
Free Guide to Hemorrhoid Treatment Options →
Companies must have a lawful reason to collect data. The regulation lists six possible lawful bases: the person gave permission, it is necessary for a contract, it follows a legal obligation, it protects someone's vital interests, it serves a public task, or the company has a legitimate interest. Companies cannot simply collect data because they want to. If asked, they must explain which lawful basis applies to your information.
Permission, or "consent," is one lawful basis. But consent under GDPR must be real and voluntary. A company cannot require you to accept data collection as the price of service unless that collection is actually necessary. Hiding consent requests in confusing language or using pre-checked boxes does not work under GDPR. Companies must ask clearly and receive a clear yes from you.
Companies must practice data minimization—collecting only the information they actually need. If a store wants to mail you a receipt, they should not collect your medical history or financial records. They should collect the smallest amount of data that serves their purpose. This principle stops companies from gathering massive profiles on everyone they meet.
Information must be kept accurate and up to date. Companies should correct wrong information and delete information that is no longer correct. They cannot knowingly keep false data about you.
Data must be stored securely and protected from theft, hacking, or loss. Companies should use encryption, strong passwords, and access controls. If there is a security breach, they must notify affected people and sometimes notify regulators. A company that suffers a data breach cannot simply hide it—transparency is required.
Organizations must be transparent about what they do with data. Privacy policies should explain data collection, use, storage, and sharing in clear language that regular people can understand. The policy cannot be written in legal jargon that only lawyers understand.
Companies must practice accountability. They should document what data they collect, why they collect it, how long they keep it, and what safeguards protect it. If a regulator asks questions, the company must be able to show that they are following the rules.
For high-risk processing, companies must conduct a Data Protection Impact Assessment. This is an evaluation of whether the data collection could cause harm and what steps protect against that harm. Examples of high-risk processing include monitoring workers, tracking children, or using artificial intelligence to make important decisions.
Companies must appoint a Data Protection Officer in certain situations—particularly in government agencies and companies that do large-scale monitoring of people. The DPO is responsible for making sure the organization follows GDPR.
Practical takeaway: When a company tells you about its privacy practices, you can use these requirements to evaluate whether they are actually following GDPR or just making vague promises.
GDPR rules apply differently depending on what kind of organization collects data and what they do with it. Understanding how GDPR affects different sectors helps you know what protections exist in the specific areas of your life.
Free Guide to Online Cash Advance Options →
Small businesses face
This guide is for general information only and is not medical, financial, legal, or other professional advice. For decisions specific to your situation, consult a qualified professional. See our Editorial Policy.