What Is GDPR (General Data Protection Regulation)?

Related problems: We have customers or staff in Europe and don't know what applies to us; A European customer sent us a data processing agreement to sign; Not sure whether our cloud and SaaS vendors handle personal data lawfully; Moving personal data between the US and Europe

The General Data Protection Regulation (GDPR) is the European Union’s main law on personal data. It sets out when an organization may collect and use information about people, what it must tell them, what rights they have over that information, how the data must be protected, and when it may be sent to other countries. It applies across EU member states and the wider European Economic Area, and its reach extends to many organizations based elsewhere that deal with people there. This entry is an overview for buyers, not legal advice.

At a glance

  • GDPR covers personal data, meaning information about an identified or identifiable person, which is broader than many US definitions of PII.
  • It can apply to organizations outside the EU that offer goods or services to, or monitor, people in the EU.
  • Organizations need a lawful basis for each use of personal data and must respect rights such as access, correction and erasure.
  • Vendors that process personal data on your behalf need a contract with set terms, commonly called a data processing agreement.
  • Transfers outside the European Economic Area are allowed only with a recognized mechanism and supporting safeguards.

What problem it solves

Personal data is collected everywhere: customer records, marketing lists, employee files, support tickets, call recordings, website analytics. Before GDPR, rules varied across Europe and individuals had little visibility or control. GDPR gives one framework with common principles, strong individual rights and regulators with real enforcement powers.

For a mid-market buyer, the problem shows up in practical ways. A European customer sends a data processing agreement and a security questionnaire. A marketing team wants a new tool that tracks website visitors. HR moves to a global payroll platform. Each one raises the same questions: what personal data is involved, who processes it, where it goes and how it is protected.

How it works

Roles. Obligations depend on whether an organization decides how personal data is used or handles it for someone else; the roles are set out in the next section.

Principles and lawful basis. Data must be used fairly and transparently, for specified purposes, limited to what is needed, kept accurate, retained no longer than necessary and secured. Each use needs a lawful basis, such as contract, legal obligation, legitimate interests or consent.

Rights. Individuals can ask to access their data, correct it, have it erased in some cases, restrict or object to processing and move it to another provider. Organizations need a process to answer these requests on time.

Security and breaches. Organizations must apply security appropriate to the risk and, for many breaches, notify the regulator and sometimes the people affected within set deadlines.

Transfers. Sending personal data outside the European Economic Area requires a recognized transfer mechanism, covered in the next section. This is where questions of data residency often come up.

Accountability. Organizations must be able to show compliance: records of processing, policies, impact assessments for higher-risk processing and, in some cases, a data protection officer. Strong data governance makes this far easier.

Roles, fine tiers and transfer mechanisms

GDPR has no compliance levels; voluntary certification schemes exist, but none is required. Its closest structures are the roles an organization plays, which decide its duties, and two tiers of maximum fines. Which role a party plays is decided by the facts of the processing, not by what a contract calls it.

Role Who it is Main obligations What a buyer typically sees
Controller The organization that decides why and how personal data is used, such as a business using a CRM for its customers Lawful basis, transparency, individuals’ rights, security, breach notification, choosing processors that give sufficient guarantees Privacy notice, records of processing, impact assessments
Joint controllers Two or more organizations that decide purposes and means together A transparent arrangement setting out who handles which duties, such as answering individuals A joint controller agreement or summary of it
Processor A vendor that handles personal data on a controller’s documented instructions, as most SaaS, cloud, contact center and managed service providers do Act only on instructions, keep data secure and confidential, assist the controller, notify it of breaches Data processing agreement, security evidence, subprocessor list
Subprocessor A processor’s own vendor, such as the cloud host behind a SaaS product Bound by terms similar to the processor’s, with the controller informed of changes Published subprocessor list and change notices

Fine tiers. The regulation sets two maximums. Breaches of many organizational duties, such as security, records and processor terms, can bring fines of up to 10 million euros or 2% of worldwide annual turnover, whichever is higher. Breaches of the core principles, lawful basis, individuals’ rights and transfer rules can bring up to 20 million euros or 4%. These are ceilings; regulators decide actual amounts case by case and can also issue orders, such as to stop processing.

Transfer mechanisms. Personal data can leave the European Economic Area under an adequacy decision for the destination country (the EU-US Data Privacy Framework is one, covering certified US companies, though it faces a pending court challenge), standard contractual clauses, binding corporate rules within a corporate group, or approved codes of conduct or certifications. Narrow exceptions exist for occasional transfers. Contractual mechanisms usually need a transfer risk assessment as well.

Amendments to GDPR have been proposed at EU level and were still being negotiated at the time of writing, so confirm the current text. This is an overview, not legal advice; counsel or your data protection officer should confirm roles and transfer choices for your situation.

When it matters for buyers

  • When expanding into Europe or selling to European customers. Contracts will expect GDPR terms and evidence of security.
  • When choosing SaaS, cloud or contact center vendors. Each one that touches personal data needs a data processing agreement, and its subprocessors and data locations matter.
  • When adopting analytics, marketing or AI tools. These often collect more personal data than teams realize.
  • When a deadline or audit appears. A customer review or regulator inquiry is easier with records already in place.

Our governance, risk and compliance overview covers advisors and tools that help map obligations to controls.

Questions to ask vendors

  • Do you act as a processor or a controller for each kind of our data, and will you sign a data processing agreement that meets GDPR requirements?
  • Where is our data stored and processed, including backups, support access and subprocessors?
  • Which transfer mechanism do you rely on for data leaving the European Economic Area?
  • How do you help us answer access and erasure requests?
  • How quickly will you notify us of a personal data breach, and what will you tell us?
  • What security certifications or audit reports can you share?
  • How and when is our data deleted at the end of the contract?

How it differs from data residency

GDPR is a law about how personal data is handled wherever it goes, including rules for transferring it out of Europe. Data residency is about where data is physically stored and processed. Keeping data in an EU region can simplify transfer questions, but it does not by itself make processing lawful or secure, and GDPR does not require all personal data to stay in Europe. Likewise, GDPR’s personal data is broader than personally identifiable information (PII) as many US organizations define it. Within a governance, risk and compliance (GRC) program, GDPR sits alongside other privacy and data security compliance obligations, which vary by country and sector.

Frequently Asked Questions

Does GDPR apply to companies outside Europe?
It can. GDPR applies to organizations established in the EU, and also to organizations elsewhere that offer goods or services to people in the EU or monitor their behavior. Whether it applies to you depends on the facts, so check with counsel; this is not legal advice.
Does GDPR require our data to stay in Europe?
Not as such. It allows personal data to be transferred outside the European Economic Area when a recognized transfer mechanism is in place, such as an adequacy decision or standard contractual clauses with supporting safeguards. Some customers or sector rules ask for data to stay in a region anyway, which is a data residency question.
What is a data processing agreement?
It is the contract GDPR requires between an organization that decides how personal data is used (the controller) and a vendor that processes it on its behalf (the processor). It covers instructions, confidentiality, security, subprocessors, assistance with individuals' rights, breach notification and deletion or return of data at the end.
How large can GDPR fines be?
The regulation sets two ceilings: up to 10 million euros or 2% of worldwide annual turnover for many organizational failings, and up to 20 million euros or 4% for breaches of core principles, individuals' rights or transfer rules, whichever is higher in each case. Regulators set actual amounts case by case and can also issue orders, such as to stop processing.
Is GDPR the same as UK GDPR?
They are closely related but separate. After leaving the EU, the UK kept a version of GDPR in its own law, alongside its own data protection act and regulator. Requirements are similar, but transfer rules and enforcement differ, so treat them as two regimes.
Is personal data under GDPR the same as PII?
Not exactly. GDPR's personal data is any information relating to an identified or identifiable person, which is generally broader than how PII is used in many US contexts. Identifiers such as device IDs or IP addresses can be personal data under GDPR.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.