What is GDPR? Plain-English Overview
Anitha Rajmohan Director - Cyber Assurance
January 18, 2026
18 min read
In This Guide
What is GDPR?
Who Does It Apply To?
Key Terms
Seven Principles
Data Subject Rights
Key Obligations
What is GDPR?
The General Data Protection Regulation (GDPR) is the European Union's comprehensive data protection law that came into effect on May 25, 2018. It replaced the 1995 Data Protection Directive and represents the most significant change to EU data protection law in over two decades.
GDPR aims to:
Give individuals control over their personal data
Simplify the regulatory environment for international business
Harmonize data protection laws across EU member states
Strengthen and unify data protection for individuals within the EU
GDPR by the Numbers
Metric Detail
Effective Date May 25, 2018
Applies To Any organization processing EU residents' personal data
Maximum Fine (Upper Tier) EUR 20 million or 4% of global annual turnover
Maximum Fine (Lower Tier) EUR 10 million or 2% of global annual turnover
Cumulative Fines Since 2018 Over EUR 4.8 billion
Who Does GDPR Apply To?
Organizations Established in the EU
Any organization with an establishment in the EU that processes personal data, regardless of whether the processing takes place in the EU.
Organizations Outside the EU (Article 3)
Organizations not established in the EU that process personal data of EU residents when:
Offering goods or services: Free or paid, to EU data subjects
Monitoring behavior: Tracking behavior that takes place within the EU
Who is NOT Covered
Purely personal or household activities
Law enforcement and national security (separate frameworks apply)
Organizations with no EU presence and no EU customers
Key Terms Explained
Term Definition
Personal Data Any information relating to an identified or identifiable natural person
Data Subject An identified or identifiable natural person whose data is processed
Processing Any operation performed on personal data (collection, storage, use, deletion)
Controller Entity that determines the purposes and means of processing
Processor Entity that processes personal data on behalf of the controller
The Seven GDPR Principles
Article 5 establishes the core principles for processing personal data:
1. Lawfulness, Fairness, and Transparency
Personal data must be processed lawfully, fairly, and in a transparent manner.
2. Purpose Limitation
Data must be collected for specified, explicit, and legitimate purposes.
3. Data Minimization
Personal data must be adequate, relevant, and limited to what is necessary.
4. Accuracy
Personal data must be accurate and kept up to date.
