Skip to content
Thursday 2026-07-30 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

Definition

General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) is a European Union regulation that governs how organizations collect, process, store, and share personal data of individuals within the EU, establishing seven core principles, eight data subject rights, and significant penalties for non-compliance.

Updated

What is the GDPR?

The GDPR is the world’s most comprehensive data protection regulation. Drafted and passed by the European Union, it replaced the earlier Data Protection Directive (95/46/EC) and created a single, harmonized data privacy law across all EU and EEA member states [1].

Though an EU regulation, the GDPR has extraterritorial reach: it applies to any organization—regardless of where it is based—that processes the personal data of individuals located in the EU while offering them goods or services, or monitoring their behavior [1]. This means a US-based company with European customers must comply with the GDPR just as a company headquartered in Berlin would.

The regulation came into effect on May 25, 2018, and remains the governing framework for data protection in the EU in 2026. It has influenced data protection legislation worldwide, including Brazil’s LGPD, California’s CCPA/CPRA, and Japan’s APPI amendments.

Seven core principles

The GDPR is built on seven foundational principles that govern all personal data processing [1]:

1. Lawfulness, fairness, and transparency — Personal data must be processed lawfully, fairly, and in a transparent manner. Organizations must have a valid legal basis for processing and must tell individuals what they are doing with their data.

2. Purpose limitation — Data must be collected for specified, explicit, and legitimate purposes. You cannot collect data for one reason and then use it for another without additional consent or legal basis.

3. Data minimization — Organizations must collect only the data that is adequate, relevant, and necessary for the stated purpose. Collecting ‘just in case’ data violates this principle.

4. Accuracy — Personal data must be accurate and kept up to date. Inaccurate data must be erased or rectified without delay.

5. Storage limitation — Data must be kept in a form that permits identification of individuals for no longer than is necessary for the stated purpose.

6. Integrity and confidentiality — Data must be processed in a manner that ensures appropriate security, including protection against unauthorized processing, accidental loss, destruction, or damage.

7. Accountability — The data controller is responsible for demonstrating compliance with all of the above principles. It is not enough to comply; you must be able to prove it.

Data subject rights

The GDPR grants individuals eight fundamental rights over their personal data [1]:

  • Right to be informed — Individuals must be told how their data is being used, by whom, and for what purpose.
  • Right of access — Individuals can request a copy of all personal data an organization holds about them.
  • Right to rectification — Individuals can correct inaccurate or incomplete personal data.
  • Right to erasure (right to be forgotten) — Individuals can request deletion of their data in certain circumstances, such as when the data is no longer necessary for its original purpose.
  • Right to restrict processing — Individuals can request that their data be used only for limited purposes.
  • Right to data portability — Individuals can move, copy, or transfer their personal data easily between service providers.
  • Right to object — Individuals can object to processing for direct marketing, research, or other purposes.
  • Rights related to automated decision-making — Individuals can request human intervention in decisions made solely by automated processes, including profiling, that significantly affect them.

This last right—Article 22—is particularly relevant for AI systems. Individuals have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects.

Enforcement and penalties

GDPR enforcement is carried out by national Data Protection Authorities (DPAs) in each EU/EEA member state, coordinated by the European Data Protection Board (EDPB) [2].

Penalties are severe and structured in two tiers:

  • Less severe violations (Article 83(4)): Up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Applies to violations of obligations for controllers, processors, and certification bodies.
  • Severe violations (Article 83(5)): Up to €20 million or 4% of total worldwide annual turnover, whichever is higher. Applies to violations of core principles, lawful basis, consent, data subject rights, and cross-border transfer rules.

The ‘turnover’ calculation uses the entire corporate group’s global revenue, not just the subsidiary that committed the violation. For a multinational technology company, 4% of global revenue can represent billions of euros.

Notable enforcement actions include the €1.2 billion fine against Meta (May 2023) for transferring EU user data to the US without adequate safeguards, and the €746 million fine against Amazon (2021) for targeted advertising practices.

Data Protection Officer (DPO)

Under Article 37, organizations must designate a Data Protection Officer (DPO) when [3]:

  • The processing is carried out by a public authority or body
  • Core activities require regular and systematic monitoring of data subjects on a large scale
  • Core activities involve large-scale processing of special categories of data (racial/ethnic origin, political opinions, religious beliefs, health data, biometric data, etc.)

The DPO must have expert knowledge of data protection law, operate independently, report to the highest management level, and not have conflicts of interest with other duties. A single DPO may serve multiple entities within a corporate group.

Even when not mandatory, many organizations voluntarily appoint a DPO to demonstrate accountability and manage compliance risk.

GDPR and AI: the intersection

The GDPR’s relevance to AI systems has grown significantly since 2018:

Automated decision-making (Article 22) — Individuals have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. Organizations using AI for hiring, credit scoring, insurance pricing, or other consequential decisions must either provide meaningful human oversight or meet specific exceptions.

Data Protection Impact Assessments (DPIA) — Article 35 requires a DPIA when processing is likely to result in high risk to individuals’ rights and freedoms. AI systems that process personal data at scale, use special category data, or involve systematic monitoring typically require a DPIA.

Right to explanation — While not explicitly stated in the GDPR, Recital 71 and Article 22 together imply that individuals affected by automated decisions should receive ‘meaningful information about the logic involved.’ This has been interpreted as requiring some degree of explainability in AI systems [4].

Bias and fairness — The GDPR’s accuracy and fairness principles apply to AI models. Article 10(5) of the EU AI Act explicitly permits processing special categories of personal data (like racial or ethnic origin) when strictly necessary to monitor, detect, and correct bias in high-risk AI systems, relying on the GDPR’s ‘substantial public interest’ derogation [4].

GDPR and the EU AI Act

The EU AI Act (Regulation (EU) 2024/1689), which entered into force in August 2024, operates alongside the GDPR—not as a replacement [4]:

  • Complementary regimes — The GDPR protects personal data; the AI Act regulates AI systems as products. Both apply simultaneously to AI systems that process personal data.
  • Impact assessments — The AI Act requires Fundamental Rights Impact Assessments (FRIA) for high-risk AI systems. These complement, but do not replace, GDPR Data Protection Impact Assessments (DPIAs).
  • Transparency — Both regimes impose transparency and accountability obligations, but the AI Act adds AI-specific requirements like risk classification, conformity assessments, and CE marking.
  • Practical implication — Organizations deploying AI in the EU must comply with both: maintaining GDPR legal bases for training and inference data, applying special-category safeguards for bias detection, and aligning AI logging with data minimization and data subject rights.

Limitations and open challenges

The GDPR faces several ongoing challenges:

  • Enforcement inconsistency — DPAs in different member states have varying resources, priorities, and interpretations, leading to uneven enforcement across the EU.
  • Complexity for small organizations — The compliance burden disproportionately affects startups and small businesses that lack dedicated legal and compliance teams.
  • Cross-border data transfers — After the invalidation of Safe Harbor (2015) and Privacy Shield (2020), the legal framework for EU-US data transfers remains complex. The EU-US Data Privacy Framework (2023) provides a new mechanism, but its long-term stability is uncertain.
  • AI-specific gaps — The GDPR was drafted before the current generation of foundation models and AI agents. While Article 22 addresses automated decision-making, the regulation does not specifically address training data consent, model explainability requirements, or AI agent accountability.
  • Global fragmentation — While the GDPR has inspired similar legislation worldwide, the lack of a single global standard creates compliance complexity for multinational organizations.

Frequently asked questions

Does the GDPR apply to my US-based company?

Yes, if you offer goods or services to individuals in the EU/EEA, or if you monitor their behavior (e.g., tracking website visitors, targeted advertising). The GDPR applies regardless of where your company is headquartered. If you have European customers, users, or website visitors, you likely need to comply.

What is the maximum fine for GDPR violations?

The maximum fine is €20 million or 4% of total worldwide annual turnover (whichever is higher) for severe violations, such as processing data without a lawful basis or violating data subject rights. For less severe violations, the maximum is €10 million or 2% of global turnover. The turnover calculation uses the entire corporate group’s revenue.

How does the GDPR affect AI systems?

The GDPR requires a lawful basis for processing personal data used to train AI models, grants individuals the right to human intervention in automated decisions (Article 22), and requires Data Protection Impact Assessments for high-risk AI processing. The EU AI Act adds AI-specific requirements on top of the GDPR’s data protection rules.

What is the difference between GDPR and the EU AI Act?

The GDPR protects personal data and grants individuals rights over their data. The EU AI Act regulates AI systems based on their risk level, requiring conformity assessments, transparency, and human oversight for high-risk systems. They operate in tandem: if your AI system processes personal data, you must comply with both.

Maintained by Theodore Wren · updated Jul 19, 2026