close
breadcrumb right arrowGlossary
breadcrumb right arrowGDPR Compliance
GDPR Compliance

GDPR applies to any organization that processes the personal data of people in the EU, regardless of where the organization itself is based, which is why it became a global compliance baseline rather than a regional rule most companies could ignore.

The six lawful bases and the rights they support

Every instance of processing personal data needs one of six lawful bases: consent, contractual necessity, legal obligation, protecting someone's vital interests, performing a public-interest task, or legitimate interests. Consent gets the most attention publicly, but in practice most business processing relies on contractual necessity or legitimate interests, since consent has to be freely given and easily withdrawable, which makes it a poor fit for anything the business actually needs to keep running.

GDPR gives individuals a specific set of rights over their own data: access to what's held about them, correction of inaccurate data, erasure (the "right to be forgotten"), restriction of processing, data portability to move their data to another provider, and the right to object, including to automated decision-making. In practice, GDPR compliance means documenting a lawful basis for every category of data processed, appointing a data protection officer where required, and being able to respond to any of these requests within a defined timeframe.

Higher-risk processing, large-scale profiling, systematic monitoring, or processing sensitive categories like health data at scale, triggers a mandatory Data Protection Impact Assessment before the processing begins. A breach that risks harm to individuals must be reported to the relevant regulator within 72 hours of the organization becoming aware of it. And a company outside the EU that processes EU residents' data without an EU establishment often has to appoint a formal EU representative under Article 27, a requirement that surprises a lot of non-EU companies who assume the regulation doesn't reach them.

Penalties for non-compliance can reach the greater of 20 million euros or 4 percent of global annual revenue, which is why GDPR compliance is usually owned jointly by legal, security, and whichever team actually holds the data in question, not treated as a single department's responsibility.

Frequently Asked Questions

What are the six lawful bases GDPR recognizes for processing data?

Consent, contractual necessity, legal obligation, vital interests, public task, and legitimate interests. Most routine business processing relies on contractual necessity or legitimate interests rather than consent.

What rights does GDPR give individuals over their own data?

Access, correction, erasure, restriction of processing, data portability, and the right to object, including to automated decision-making.

When is a Data Protection Impact Assessment required?

Before any processing likely to result in high risk to individuals, most commonly large-scale profiling, systematic monitoring, or large-scale processing of sensitive data categories like health information.

Does GDPR apply to a US company with no EU office?

Yes, if it processes the personal data of people in the EU. Without an EU establishment, that company typically also needs to appoint a formal EU representative under Article 27.