Concept Page
European Union's General Data Protection Regulation (GDPR)
The European Union's General Data Protection Regulation is a law protecting personal data. It is significant for ensuring data privacy. Introduced in 2018, it applies to all EU members.
The General Data Protection Regulation (GDPR) is the European Unionâs comprehensive legal framework governing the collection, processing, storage, and transfer of personal data of individuals residing in the EU. Enforced from 25 May 2018, it replaces the 1995 Data Protection Directive and introduces uniform, enforceable rights for data subjects while imposing strict accountability on organisations worldwide that handle EUâresident data. Its extraterritorial scope, hefty penalties, and detailed consent regime have made it the benchmark for modern dataâprivacy law. ## Origins / Historical Background The GDPR traces its lineage to Directive 95/46/EC, which first codified dataâprotection principles across the thenâ15âmember Community. In 2012 the European Commission launched a âData Protection Reformâ proposal to address digitalâera challenges such as cloud computing and social media. After extensive trilogue negotiations, the European Parliament and Council adopted Regulation (EU) 2016/679 on 27 April 2016, formally designating it as a regulation rather than a directive to ensure direct applicability in all member states. A twoâyear transition allowed businesses to adapt before the mandatory startâdate of 25 May 2018. ## Key Provisions Article 5 codifies the âdataâprotection principlesâ: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality. Lawful processing is confined to the six bases listed in Article 6, notably consent, contract performance, and legitimate interests. Specialâcategory dataâsuch as health, biometric, or political informationâare protected under Article 9, requiring explicit consent or a narrow set of exceptions. Dataâsubject rights span Articles 12â23, granting access (Art 15), rectification (Art 16), erasure (âright to be forgottenâ, Art 17), restriction (Art 18), data portability (Art 20), and objection (Art 21). Accountability is reinforced by mandatory recordâkeeping (Art 30) and the requirement for a Data Protection Officer in certain cases (Art 37). Breach notification must occur within 72 hours of discovery (Art 33), and supervisory authorities can levy fines up to âŹ20 million or 4 % of global annual turnover, whichever is higher (Art 83). ## How It Works / Mechanism The regulation distinguishes between data controllersâentities that determine the purposes of processingâand data processorsâthose that act on the controllerâs behalf. Controllers must conduct Data Protection Impact Assessments (DPIAs) when processing is likely to result in high risk, as stipulated in Article 35. Where DPIAs reveal substantial risk, prior consultation with the relevant supervisory authority is mandatory. Crossâborder transfers outside the European Economic Area rely on adequacy decisions (e.g., Canadaâs âcommercial organisationsâ regime) or Standard Contractual Clauses (SCCs) updated in June 2021. Consent, the most scrutinised lawful basis, must be a clear, affirmative act, freely given, specific, informed, and unambiguous, per Recital 32 and Article 7. Controllers are also obliged to publish concise privacy notices, maintain logs of processing activities, and cooperate with the European Data Protection Board (EDPB), the successor to the Article 29 Working Party. ## International Comparison Unlike the United States, where sectorâspecific statutes such as HIPAA and the CCPA coexist, the GDPR offers a single, harmonised regime that applies to any organisation handling EUâresident data, regardless of industry. Brazilâs Lei Geral de Proteção de Dados (LGPD), enacted in 2020, mirrors GDPRâs principles, penalties, and dataâsubject rights, reflecting the regulationâs global influence. Indiaâs Personal Data Protection Bill 2023, still pending parliamentary approval, adopts GDPRâstyle consent and dataâlocalisation clauses but caps fines at 4 % of domestic turnover, a lower threshold than the EUâs 4 % of worldwide revenue. These parallels illustrate GDPRâs role as a template for emerging privacy frameworks worldwide. ## Current Status / Implementation Since 2018, the European Data Protection Board has issued over 200 guidelines, ranging from AIâdriven profiling to eâprivacy cookie consent, shaping practical compliance. Major enforcement actions underscore the regimeâs potency: the French CNIL fined Google âŹ50 million in 2019 for insufficient transparency, the Luxembourg regulator imposed a âŹ746 million penalty on Amazon in 2021 for alleged marketplace monitoring, and the Irish Data Protection Commission levied a âŹ1.2 billion fine on Meta in 2022 for GDPR breaches related to targeted advertising. As of 2024, compliance costs for large enterprises average âŹ7 million annually, while smallâ and mediumâsize firms report a 30 % increase in dataâgovernance staffing. Ongoing legislative work includes the proposed ePrivacy Regulation, slated for 2025, and the EUâs AI Act, which will intersect with GDPRâs provisions on