The General Data Protection Regulation (GDPR) is the European Union’s main law on personal data. It sets out when an organization may collect and use information about people, what it must tell them, what rights they have over that information, how the data must be protected, and when it may be sent to other countries. It applies across EU member states and the wider European Economic Area, and its reach extends to many organizations based elsewhere that deal with people there. This entry is an overview for buyers, not legal advice.
At a glance
- GDPR covers personal data, meaning information about an identified or identifiable person, which is broader than many US definitions of PII.
- It can apply to organizations outside the EU that offer goods or services to, or monitor, people in the EU.
- Organizations need a lawful basis for each use of personal data and must respect rights such as access, correction and erasure.
- Vendors that process personal data on your behalf need a contract with set terms, commonly called a data processing agreement.
- Transfers outside the European Economic Area are allowed only with a recognized mechanism and supporting safeguards.
What problem it solves
Personal data is collected everywhere: customer records, marketing lists, employee files, support tickets, call recordings, website analytics. Before GDPR, rules varied across Europe and individuals had little visibility or control. GDPR gives one framework with common principles, strong individual rights and regulators with real enforcement powers.
For a mid-market buyer, the problem shows up in practical ways. A European customer sends a data processing agreement and a security questionnaire. A marketing team wants a new tool that tracks website visitors. HR moves to a global payroll platform. Each one raises the same questions: what personal data is involved, who processes it, where it goes and how it is protected.
How it works
Roles. Obligations depend on whether an organization decides how personal data is used or handles it for someone else; the roles are set out in the next section.
Principles and lawful basis. Data must be used fairly and transparently, for specified purposes, limited to what is needed, kept accurate, retained no longer than necessary and secured. Each use needs a lawful basis, such as contract, legal obligation, legitimate interests or consent.
Rights. Individuals can ask to access their data, correct it, have it erased in some cases, restrict or object to processing and move it to another provider. Organizations need a process to answer these requests on time.
Security and breaches. Organizations must apply security appropriate to the risk and, for many breaches, notify the regulator and sometimes the people affected within set deadlines.
Transfers. Sending personal data outside the European Economic Area requires a recognized transfer mechanism, covered in the next section. This is where questions of data residency often come up.
Accountability. Organizations must be able to show compliance: records of processing, policies, impact assessments for higher-risk processing and, in some cases, a data protection officer. Strong data governance makes this far easier.
Roles, fine tiers and transfer mechanisms
GDPR has no compliance levels; voluntary certification schemes exist, but none is required. Its closest structures are the roles an organization plays, which decide its duties, and two tiers of maximum fines. Which role a party plays is decided by the facts of the processing, not by what a contract calls it.
| Role | Who it is | Main obligations | What a buyer typically sees |
|---|---|---|---|
| Controller | The organization that decides why and how personal data is used, such as a business using a CRM for its customers | Lawful basis, transparency, individuals’ rights, security, breach notification, choosing processors that give sufficient guarantees | Privacy notice, records of processing, impact assessments |
| Joint controllers | Two or more organizations that decide purposes and means together | A transparent arrangement setting out who handles which duties, such as answering individuals | A joint controller agreement or summary of it |
| Processor | A vendor that handles personal data on a controller’s documented instructions, as most SaaS, cloud, contact center and managed service providers do | Act only on instructions, keep data secure and confidential, assist the controller, notify it of breaches | Data processing agreement, security evidence, subprocessor list |
| Subprocessor | A processor’s own vendor, such as the cloud host behind a SaaS product | Bound by terms similar to the processor’s, with the controller informed of changes | Published subprocessor list and change notices |
Fine tiers. The regulation sets two maximums. Breaches of many organizational duties, such as security, records and processor terms, can bring fines of up to 10 million euros or 2% of worldwide annual turnover, whichever is higher. Breaches of the core principles, lawful basis, individuals’ rights and transfer rules can bring up to 20 million euros or 4%. These are ceilings; regulators decide actual amounts case by case and can also issue orders, such as to stop processing.
Transfer mechanisms. Personal data can leave the European Economic Area under an adequacy decision for the destination country (the EU-US Data Privacy Framework is one, covering certified US companies, though it faces a pending court challenge), standard contractual clauses, binding corporate rules within a corporate group, or approved codes of conduct or certifications. Narrow exceptions exist for occasional transfers. Contractual mechanisms usually need a transfer risk assessment as well.
Amendments to GDPR have been proposed at EU level and were still being negotiated at the time of writing, so confirm the current text. This is an overview, not legal advice; counsel or your data protection officer should confirm roles and transfer choices for your situation.
When it matters for buyers
- When expanding into Europe or selling to European customers. Contracts will expect GDPR terms and evidence of security.
- When choosing SaaS, cloud or contact center vendors. Each one that touches personal data needs a data processing agreement, and its subprocessors and data locations matter.
- When adopting analytics, marketing or AI tools. These often collect more personal data than teams realize.
- When a deadline or audit appears. A customer review or regulator inquiry is easier with records already in place.
Our governance, risk and compliance overview covers advisors and tools that help map obligations to controls.
Questions to ask vendors
- Do you act as a processor or a controller for each kind of our data, and will you sign a data processing agreement that meets GDPR requirements?
- Where is our data stored and processed, including backups, support access and subprocessors?
- Which transfer mechanism do you rely on for data leaving the European Economic Area?
- How do you help us answer access and erasure requests?
- How quickly will you notify us of a personal data breach, and what will you tell us?
- What security certifications or audit reports can you share?
- How and when is our data deleted at the end of the contract?
How it differs from data residency
GDPR is a law about how personal data is handled wherever it goes, including rules for transferring it out of Europe. Data residency is about where data is physically stored and processed. Keeping data in an EU region can simplify transfer questions, but it does not by itself make processing lawful or secure, and GDPR does not require all personal data to stay in Europe. Likewise, GDPR’s personal data is broader than personally identifiable information (PII) as many US organizations define it. Within a governance, risk and compliance (GRC) program, GDPR sits alongside other privacy and data security compliance obligations, which vary by country and sector.
