Concept Page

European Union's General Data Protection Regulation (GDPR)

The European Union's General Data Protection Regulation is a law protecting personal data. It is significant for ensuring data privacy. Introduced in 2018, it applies to all EU members.

The General Data Protection Regulation (GDPR) is the European Union’s comprehensive legal framework governing the collection, processing, storage, and transfer of personal data of individuals residing in the EU. Enforced from 25 May 2018, it replaces the 1995 Data Protection Directive and introduces uniform, enforceable rights for data subjects while imposing strict accountability on organisations worldwide that handle EU‑resident data. Its extraterritorial scope, hefty penalties, and detailed consent regime have made it the benchmark for modern data‑privacy law. ## Origins / Historical Background The GDPR traces its lineage to Directive 95/46/EC, which first codified data‑protection principles across the then‑15‑member Community. In 2012 the European Commission launched a “Data Protection Reform” proposal to address digital‑era challenges such as cloud computing and social media. After extensive trilogue negotiations, the European Parliament and Council adopted Regulation (EU) 2016/679 on 27 April 2016, formally designating it as a regulation rather than a directive to ensure direct applicability in all member states. A two‑year transition allowed businesses to adapt before the mandatory start‑date of 25 May 2018. ## Key Provisions Article 5 codifies the “data‑protection principles”: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality. Lawful processing is confined to the six bases listed in Article 6, notably consent, contract performance, and legitimate interests. Special‑category data—such as health, biometric, or political information—are protected under Article 9, requiring explicit consent or a narrow set of exceptions. Data‑subject rights span Articles 12‑23, granting access (Art 15), rectification (Art 16), erasure (“right to be forgotten”, Art 17), restriction (Art 18), data portability (Art 20), and objection (Art 21). Accountability is reinforced by mandatory record‑keeping (Art 30) and the requirement for a Data Protection Officer in certain cases (Art 37). Breach notification must occur within 72 hours of discovery (Art 33), and supervisory authorities can levy fines up to €20 million or 4 % of global annual turnover, whichever is higher (Art 83). ## How It Works / Mechanism The regulation distinguishes between data controllers—entities that determine the purposes of processing—and data processors—those that act on the controller’s behalf. Controllers must conduct Data Protection Impact Assessments (DPIAs) when processing is likely to result in high risk, as stipulated in Article 35. Where DPIAs reveal substantial risk, prior consultation with the relevant supervisory authority is mandatory. Cross‑border transfers outside the European Economic Area rely on adequacy decisions (e.g., Canada’s “commercial organisations” regime) or Standard Contractual Clauses (SCCs) updated in June 2021. Consent, the most scrutinised lawful basis, must be a clear, affirmative act, freely given, specific, informed, and unambiguous, per Recital 32 and Article 7. Controllers are also obliged to publish concise privacy notices, maintain logs of processing activities, and cooperate with the European Data Protection Board (EDPB), the successor to the Article 29 Working Party. ## International Comparison Unlike the United States, where sector‑specific statutes such as HIPAA and the CCPA coexist, the GDPR offers a single, harmonised regime that applies to any organisation handling EU‑resident data, regardless of industry. Brazil’s Lei Geral de Proteção de Dados (LGPD), enacted in 2020, mirrors GDPR’s principles, penalties, and data‑subject rights, reflecting the regulation’s global influence. India’s Personal Data Protection Bill 2023, still pending parliamentary approval, adopts GDPR‑style consent and data‑localisation clauses but caps fines at 4 % of domestic turnover, a lower threshold than the EU’s 4 % of worldwide revenue. These parallels illustrate GDPR’s role as a template for emerging privacy frameworks worldwide. ## Current Status / Implementation Since 2018, the European Data Protection Board has issued over 200 guidelines, ranging from AI‑driven profiling to e‑privacy cookie consent, shaping practical compliance. Major enforcement actions underscore the regime’s potency: the French CNIL fined Google €50 million in 2019 for insufficient transparency, the Luxembourg regulator imposed a €746 million penalty on Amazon in 2021 for alleged marketplace monitoring, and the Irish Data Protection Commission levied a €1.2 billion fine on Meta in 2022 for GDPR breaches related to targeted advertising. As of 2024, compliance costs for large enterprises average €7 million annually, while small‑ and medium‑size firms report a 30 % increase in data‑governance staffing. Ongoing legislative work includes the proposed ePrivacy Regulation, slated for 2025, and the EU’s AI Act, which will intersect with GDPR’s provisions on

    European Union's General Data Protection Regulation (GDPR) — UPSC Concept | TheKnowledgeOrbits