[Atomic Glue](atomicglue.co)
PRIVACY
Home › Glossary › Privacy· 181 ·

GDPR

jee-dee-pee-arnoun
Filed underPrivacyLegal
In brief · quick answer

The General Data Protection Regulation (GDPR) is a European Union regulation that governs how organizations collect, process, and store personal data of EU residents. It applies to any organization worldwide that handles EU resident data.

§ 1 Definition

GDPR (Regulation (EU) 2016/679) is the European Union's comprehensive data protection law, effective May 25, 2018. It grants EU residents significant rights over their personal data and imposes strict obligations on organizations that process that data. Key rights include the right to access, right to rectification, right to erasure (right to be forgotten), right to data portability, and right to object to processing. GDPR applies to any organization, regardless of location, that offers goods/services to EU residents or monitors their behavior. Fines can reach 4% of global annual revenue or 20 million euros, whichever is higher.

§ 2 Key Principles

Lawfulness, fairness, and transparency: Processing must have a legal basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests). Purpose limitation: Data can only be collected for specified, explicit, and legitimate purposes. Data minimization: Only collect data that is necessary for the stated purpose. Accuracy: Personal data must be accurate and kept up to date. Storage limitation: Data must not be kept longer than necessary. Integrity and confidentiality: Appropriate security measures must protect personal data. Accountability: The controller must demonstrate compliance.

§ 3 Rights of Data Subjects

Right to be informed: Individuals must be told how their data is used (privacy notice). Right of access: Individuals can request a copy of their data (subject access request). Right to rectification: Inaccurate data must be corrected. Right to erasure (Right to be forgotten): Individuals can request data deletion under certain conditions. Right to restrict processing: Individuals can limit how their data is used. Right to data portability: Individuals can receive their data in a machine-readable format. Right to object: Individuals can object to processing for direct marketing or legitimate interests. Rights related to automated decision-making: Individuals can challenge automated decisions.

§ 4 Global Applicability

GDPR applies to US companies and any non-EU organization if they offer goods or services to EU residents or monitor their behavior (e.g., website tracking, analytics). This is the extraterritorial scope of Article 3. Many misconceptions persist about GDPR not applying to US businesses. If you have EU visitors on your website and use cookies, analytics, or marketing automation, GDPR likely applies to you. Compliance requires a Data Protection Officer (DPO) in some cases, Data Protection Impact Assessments (DPIAs) for high-risk processing, and maintaining Records of Processing Activities (ROPA).

§ 5 Note

Common misconception: 'GDPR doesn't apply to US companies.' This is wrong. If you serve EU users, track EU users, or have EU employees, GDPR applies. The regulation explicitly has extraterritorial scope.

§ 6 Common questions

Q. Does GDPR apply to small businesses?
A. Yes, but with some exemptions. Organizations with fewer than 250 employees are exempt from some record-keeping requirements, but all the core data protection principles and individual rights still apply.
Q. What are the maximum GDPR fines?
A. The higher of 20 million euros or 4% of global annual turnover. Lower tier: 10 million euros or 2% of turnover. Fines depend on the nature, gravity, and duration of the infringement.
Q. What is the difference between a data controller and a data processor?
A. A controller determines the purposes and means of processing personal data. A processor processes data on behalf of the controller. Both have obligations under GDPR, but the controller bears primary responsibility.
Key takeaways
  • GDPR protects EU residents' personal data, with extraterritorial reach.
  • Key rights: access, rectification, erasure, portability, objection.
  • Fines up to 4% of global revenue or 20 million euros.
  • GDPR applies to any organization handling EU resident data, regardless of location.
How Atomic Glue helps

Atomic Glue helps clients achieve GDPR compliance through cookie consent implementation, privacy policy drafting, data processing agreements, and secure data handling architecture. See Trust & Security.

Get in touch
# GDPR

The General Data Protection Regulation (GDPR) is a European Union regulation that governs how organizations collect, process, and store personal data of EU residents. It applies to any organization worldwide that handles EU resident data.

Category: Privacy (also: Legal)

Author: Atomic Glue Security Team

## Definition

GDPR (Regulation (EU) 2016/679) is the European Union's comprehensive data protection law, effective May 25, 2018. It grants EU residents significant rights over their personal data and imposes strict obligations on organizations that process that data. Key rights include the right to access, right to rectification, right to erasure (right to be forgotten), right to data portability, and right to object to processing. GDPR applies to any organization, regardless of location, that offers goods/services to EU residents or monitors their behavior. Fines can reach 4% of global annual revenue or 20 million euros, whichever is higher.

## Key Principles

**Lawfulness, fairness, and transparency**: Processing must have a legal basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests). **Purpose limitation**: Data can only be collected for specified, explicit, and legitimate purposes. **Data minimization**: Only collect data that is necessary for the stated purpose. **Accuracy**: Personal data must be accurate and kept up to date. **Storage limitation**: Data must not be kept longer than necessary. **Integrity and confidentiality**: Appropriate security measures must protect personal data. **Accountability**: The controller must demonstrate compliance.

## Rights of Data Subjects

**Right to be informed**: Individuals must be told how their data is used (privacy notice). **Right of access**: Individuals can request a copy of their data (subject access request). **Right to rectification**: Inaccurate data must be corrected. **Right to erasure** (Right to be forgotten): Individuals can request data deletion under certain conditions. **Right to restrict processing**: Individuals can limit how their data is used. **Right to data portability**: Individuals can receive their data in a machine-readable format. **Right to object**: Individuals can object to processing for direct marketing or legitimate interests. **Rights related to automated decision-making**: Individuals can challenge automated decisions.

## Global Applicability

**GDPR applies to US companies and any non-EU organization** if they offer goods or services to EU residents or monitor their behavior (e.g., website tracking, analytics). This is the extraterritorial scope of Article 3. Many misconceptions persist about GDPR not applying to US businesses. If you have EU visitors on your website and use cookies, analytics, or marketing automation, GDPR likely applies to you. Compliance requires a Data Protection Officer (DPO) in some cases, Data Protection Impact Assessments (DPIAs) for high-risk processing, and maintaining Records of Processing Activities (ROPA).

## Note

Common misconception: 'GDPR doesn't apply to US companies.' This is wrong. If you serve EU users, track EU users, or have EU employees, GDPR applies. The regulation explicitly has extraterritorial scope.

## Common questions

Q: Does GDPR apply to small businesses?

A: Yes, but with some exemptions. Organizations with fewer than 250 employees are exempt from some record-keeping requirements, but all the core data protection principles and individual rights still apply.

Q: What are the maximum GDPR fines?

A: The higher of 20 million euros or 4% of global annual turnover. Lower tier: 10 million euros or 2% of turnover. Fines depend on the nature, gravity, and duration of the infringement.

Q: What is the difference between a data controller and a data processor?

A: A controller determines the purposes and means of processing personal data. A processor processes data on behalf of the controller. Both have obligations under GDPR, but the controller bears primary responsibility.

## Key takeaways

## Related entries


Last updated December 2024. Permalink: atomicglue.co/glossary/gdpr

Schedule a call

30 min · Video call

1
Date
2
Time
3
Details