GDPR: The Complete Guide to EU Data Protection Compliance
Executive Summary
The General Data Protection Regulation (GDPR) is the European Union's comprehensive data protection law, in force since May 2018. It governs how organizations collect, process, and store personal data of individuals in the EU, and applies extraterritorially to any organization — regardless of where it's based — that offers goods or services to, or monitors, individuals in the EU. This guide covers the core roles, lawful bases for processing, data subject rights, breach notification requirements, and how getTRAC automates the evidence collection an ongoing GDPR program depends on.
Key Takeaways
- GDPR applies extraterritorially — an organization outside the EU is still in scope if it offers goods/services to, or monitors, individuals in the EU.
- Two core roles: the controller determines the purpose and means of processing; the processor processes data on the controller's behalf.
- Processing requires a lawful basis — consent is only one of six; contract necessity, legal obligation, vital interests, public task, and legitimate interests are the others.
- Data breaches likely to result in risk to individuals must be reported to the relevant supervisory authority within 72 hours of becoming aware of them.
- Maximum fines run up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious violations.
- Organizations may need to appoint a Data Protection Officer (DPO) depending on the scale and nature of their processing.
Who GDPR applies to {#who-it-applies-to}
GDPR applies to any organization that processes personal data of individuals located in the EU, whether the organization itself is based in the EU or not. It applies extraterritorially to non-EU organizations that offer goods or services to EU individuals (even for free) or monitor their behavior, such as through analytics or profiling. This means a SaaS company based outside the EU with EU customers, or a site that tracks EU visitors, is very often in scope.
Controller vs processor {#controller-vs-processor}
- Data controller — the organization that determines the purposes and means of processing personal data. The controller carries the primary compliance obligations under GDPR.
- Data processor — an organization that processes personal data on behalf of, and under instruction from, a controller. Processors have direct obligations under GDPR too (a change from the previous regime), and controller–processor relationships must be governed by a data processing agreement.
An organization can be a controller for some data and a processor for other data at the same time, depending on the relationship.
Lawful basis for processing {#lawful-basis}
Every instance of personal data processing needs a lawful basis under GDPR Article 6. Consent is the most commonly referenced, but it's only one of six:
- Consent — freely given, specific, informed, and unambiguous.
- Contract — processing necessary to perform a contract with the individual.
- Legal obligation — processing required to comply with a legal obligation.
- Vital interests — processing necessary to protect someone's life.
- Public task — processing necessary for a task carried out in the public interest.
- Legitimate interests — processing necessary for a legitimate interest, balanced against the individual's rights and freedoms.
Choosing the right basis matters — it shapes which rights apply and how they must be honored (for example, data processed under consent can be withdrawn; data processed under legitimate interests can be objected to).
Data subject rights {#rights}
- Right to be informed — clear notice about how personal data is processed.
- Right of access — a copy of personal data being processed, and information about that processing.
- Right to rectification — correcting inaccurate personal data.
- Right to erasure ("right to be forgotten") — deletion of personal data under certain conditions.
- Right to restrict processing — limiting how data is processed in certain circumstances.
- Right to data portability — receiving personal data in a structured, machine-readable format.
- Right to object — objecting to processing based on legitimate interests or for direct marketing.
- Rights related to automated decision-making — including profiling that produces legal or similarly significant effects.
Breach notification {#breach-notification}
A personal data breach likely to result in a risk to individuals' rights and freedoms must be reported to the relevant supervisory authority within 72 hours of the organization becoming aware of it. Where the breach is likely to result in a high risk to individuals, those individuals must also be notified directly, without undue delay. Processors must notify the controller of a breach without undue delay after becoming aware of it, so the controller can meet its own notification obligations.
Penalties and enforcement {#penalties}
GDPR fines are tiered by severity. The lower tier — covering violations like inadequate record-keeping or failure to notify a breach — runs up to €10 million or 2% of global annual turnover, whichever is higher. The upper tier — covering violations of core data-processing principles, lawful basis, or data subject rights — runs up to €20 million or 4% of global annual turnover, whichever is higher.
These figures should be independently verified against the current in-force text of the Regulation before being cited in any external-facing material, consistent with this guide's "never invent facts" standard.
How getTRAC helps with GDPR {#how-gettrac-helps}
getTRAC maps ongoing platform activity to GDPR requirements alongside seven other frameworks (ISO 27001, SOC 2, DPDP, HIPAA, RBI, NIST, PCI DSS), so evidence for data processing records, consent logs, and access controls accumulates continuously rather than being reconstructed ahead of an audit or regulator inquiry. For organizations building a GDPR program for the first time — particularly the data subject rights and breach-notification workflows — Compliance Consulting pairs a human consultant with the platform.
FAQ {#faq}
Does GDPR apply to companies outside the EU? Yes — GDPR applies extraterritorially to any organization that offers goods or services to, or monitors, individuals located in the EU, regardless of where the organization itself is based.
What's the difference between a controller and a processor? A controller determines the purpose and means of processing personal data and carries the primary compliance obligations; a processor processes data on the controller's behalf and has its own direct obligations too, governed by a data processing agreement between the two.
How is GDPR different from India's DPDP Act? GDPR is generally more structurally complex, with six distinct lawful bases, a broader set of data subject rights, and a more detailed accountability framework. India's DPDP Act takes a comparatively simplified approach with a digital-data-specific focus. Organizations already compliant with GDPR will find significant conceptual overlap with DPDP, but should not assume line-for-line equivalence.
How quickly must a data breach be reported under GDPR? Within 72 hours of the organization becoming aware of a breach likely to result in risk to individuals, reported to the relevant supervisory authority — with direct notification to affected individuals required as well when the risk is high.
Frequently asked questions
Does GDPR apply to companies outside the EU?
Yes — GDPR applies extraterritorially to any organization that offers goods or services to, or monitors, individuals located in the EU, regardless of where the organization itself is based.
What's the difference between a controller and a processor?
A controller determines the purpose and means of processing personal data and carries the primary compliance obligations; a processor processes data on the controller's behalf and has its own direct obligations too, governed by a data processing agreement between the two.
How is GDPR different from India's DPDP Act?
GDPR is generally more structurally complex, with six distinct lawful bases, a broader set of data subject rights, and a more detailed accountability framework. India's DPDP Act takes a comparatively simplified approach with a digital-data-specific focus. Organizations already compliant with GDPR will find significant conceptual overlap with DPDP, but should not assume line-for-line equivalence.
Ask TIARA about this article
Get a grounded answer on GDPR compliance, or ask your own question.