Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

What GDPR Changed for Individuals and Businesses

The GDPR strengthened individual data rights and organizational accountability from 25 May 2018, while leaving some details to national law and risk-specific application.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The General Data Protection Regulation (GDPR) has applied since 25 May 2018. It replaced the EU’s 1995 Data Protection Directive with a directly applicable framework that strengthened people’s control over their personal data and made organizations more accountable for how they collect, use and protect it. It applies across the EU and, through the EEA Agreement, throughout the European Economic Area (EEA), although national laws still specify some matters.

What changed when the GDPR took effect?

The GDPR was not a clean break from earlier European data-protection law: it built on existing principles while clarifying and modernizing them. The main structural change was replacing a directive, which Member States implemented through national laws, with a regulation that applies directly across the EU. The European Commission described the transition and its aims in its 2018 guidance on the GDPR.

The Regulation was adopted in 2016 and applied from 25 May 2018, after a two-year transition. A more common set of rules was intended to reduce fragmentation for people and organizations operating across borders. The one-stop-shop mechanism also provides a lead supervisory authority for certain cross-border cases. Harmonization is not absolute: the GDPR leaves room for national specification in some areas, and its application to a particular organization or activity depends on the facts.

Area What the GDPR changed
Rules across the EU Moved from a directive implemented through national laws to a directly applicable regulation, while retaining some national variation.
Individual control Set out clearer rights, stronger transparency duties and a stricter standard for consent.
Organizational responsibility Emphasized accountability, data protection by design and default, and duties calibrated to the nature and risk of processing.
Breaches and enforcement Established risk-based breach notification duties and strengthened cooperation on cross-border cases.

What does the GDPR mean for individuals?

People gained clearer ways to learn what an organization does with their personal data and to exercise rights over it. The European Commission’s overview of the EU data-protection framework lists rights including access, rectification, erasure, objection and data portability. These rights are not identical in effect in every situation; their availability depends on the applicable rule and circumstances.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Access, correction and deletion

  • Access: A person can request access to personal data an organization holds about them, subject to the Regulation’s conditions.
  • Rectification: A person can ask for inaccurate personal data to be corrected.
  • Erasure: A person can ask for data to be erased where the right applies. This is not an unconditional right to have every record removed in every circumstance.

Objection and portability

The right to object lets a person challenge certain processing. Portability can allow them to receive data they provided when processing is based on consent or a contract and carried out by automated means. Where technically feasible, the data may be transmitted directly to another organization. The aim is to make it easier to move data between services, not to guarantee that every kind of information can be transferred in every case.

Clearer information and valid consent

Organizations have stronger duties to explain their data practices. Where an organization relies on consent, it must obtain an affirmative indication: silence or inactivity does not count as consent. But consent is only one possible lawful basis for processing. The GDPR does not require an organization to obtain consent for every use of personal data; it must have an appropriate lawful basis for the specific processing.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

What happens after a data breach?

Under the Commission’s 2018 guidance, a supervisory authority must be notified within 72 hours when a personal-data breach is likely to pose a risk to individuals’ rights and freedoms. Affected people must also be informed in certain circumstances. The response depends on the breach and its likely impact; the same notification steps do not apply automatically to every incident.

What must businesses and public bodies do differently?

The GDPR makes accountability a central part of compliance. Organizations need to understand what personal data they handle, why they handle it and what safeguards fit the processing. The duties are risk-based: the Regulation does not impose every measure on every organization in the same way.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build protection into processes

Data protection by design and by default means considering privacy when developing a product, service or process and limiting personal data to what is needed by default. Organizations also need to provide required information transparently and maintain appropriate security and breach-response practices.

Assess risk and document responsibility

Organizations should assess the nature and risk of their processing and be able to demonstrate that they meet applicable obligations. High-risk processing may require a data protection impact assessment (DPIA). A data protection officer (DPO) is required in specified circumstances, including certain activities involving regular and systematic monitoring or large-scale processing of sensitive data. Neither a DPIA nor a DPO is automatically required of every small business. The Commission’s business guidance on GDPR application explains that duties depend on scope and risk.

Check whether the Regulation applies

GDPR applicability is not determined solely by whether a business is large or based in the EU. The Regulation can apply to organizations established in the EU and, in specified circumstances, to organizations outside the EU that offer goods or services to people in the EU or monitor their behavior there. The details are fact-dependent; national-law provisions, exemptions and the lawful basis for a specific activity also matter. The Commission’s guidance is a starting point, not a substitute for advice on a particular organization’s circumstances.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What do early GDPR figures tell us?

The Commission’s 2020 retrospective reported early indicators of public awareness and enforcement activity. These are historical figures for the periods stated, not current totals or proof that the GDPR caused a particular outcome.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways
Reported measure Figure and period
Visits to the Commission’s online GDPR portal 4.3 million citizens and businesses over the two years preceding the Commission’s 2020 publication.
Awareness of the GDPR 69% of the EU population over age 16 had heard about it; the Commission page does not state the survey year in the displayed material.
Awareness of national data protection authorities 71% of people in the EU had heard about their national authority, according to the Commission’s 2020 retrospective.
Individual complaints 275,000 complaints lodged with national data protection authorities between May 2018 and November 2019.
Fines 785 fines issued by 22 EU/EEA data protection authorities between May 2018 and November 2019.

The figures were reported in the Commission’s 2020 account of the GDPR’s early impact. They indicate awareness and enforcement activity during that period, but do not establish how well organizations complied overall.

What has changed since 2018?

The Commission’s publication list identifies a second report on GDPR application, published on 25 July 2024. In May 2025, the EU agreed on procedural rules intended to make the handling of large cross-border GDPR cases faster and more effective. According to the Commission, those rules concern enforcement procedure; they do not change substantive data-subject rights, controller or processor duties, or lawful bases for processing. See the Commission’s current legal-framework overview and reports on GDPR application.

What should a reader take away?

For individuals, the practical change is a clearer set of rights and stronger requirements for organizations to explain and justify how they use personal data. For businesses and public bodies, the change is a more explicit obligation to understand their processing, choose a lawful basis, protect data and demonstrate accountability. The GDPR provides a common EU framework, but national provisions and the facts of a particular case still matter.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.