October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

What Is the General Data Protection Regulation (GDPR)?

The GDPR is the EU’s data-protection law for personal data. Learn who it covers, the rights it gives individuals, and what organizations must do.
From TheFinanceBase Team11 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The General Data Protection Regulation (GDPR), formally Regulation (EU) 2016/679, is the European Union’s data-protection law. It governs how organizations process personal data and gives people rights over information that identifies them or could identify them. It can also apply to organizations outside Europe when they target people in the EU or monitor their behavior there.

GDPR at a glance

  • Full name: General Data Protection Regulation, or Regulation (EU) 2016/679.
  • Where it applies: The EU and, through its incorporation into the EEA framework, the European Economic Area. The UK has a separate but related regime.
  • When it began applying: May 25, 2018; it entered into force on May 24, 2016.
  • What it covers: Processing of personal data about identifiable living people.
  • Who may have to comply: Organizations established in the EU and, in specified circumstances, organizations outside it.

The European Commission outlines the regulation’s history and place in the EU framework in its data-protection legal framework.

Why the GDPR exists

The GDPR strengthens individuals’ fundamental rights in the digital age, establishes a more consistent data-protection framework across the EU, and gives regulators common enforcement powers. It replaced the 1995 Data Protection Directive as the principal general EU data-protection framework. For organizations operating across the single market, common rules also reduce some of the fragmentation created by differing national approaches.

What counts as personal data and processing?

Personal data

Personal data is information relating to an identified or identifiable living person. It need not include a name. Depending on context, it can include an email address, account or device identifier, IP address, location data, cookie identifier, employment or financial record, or information about health, education, or behavior. Profiles and inferences linked to a person can also qualify.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
  • Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

Pseudonymized information—such as a record that replaces a name with an ID—can remain personal data if it can be linked back to someone. Truly anonymized information is generally outside the GDPR, but removing names alone does not make data anonymous if people can still be singled out or reidentified.

Processing

Processing means almost any operation performed on personal data: collecting, recording, organizing, storing, accessing, analyzing, sharing, using for advertising, combining, transferring, restricting, or deleting it. That breadth brings routine business activity—not just databases or security incidents—within the regulation’s reach. The definitions appear in Article 4 of the GDPR.

Who does the GDPR apply to?

Organizations established in the EU

The GDPR applies when processing takes place in the context of an organization’s EU establishment, even if the data is processed somewhere else.

Organizations outside the EU

A non-EU organization may be covered if it offers goods or services to people in the EU, whether paid or free, or monitors behavior taking place there. A website being technically accessible from Europe does not, by itself, settle the question; targeting and the nature of the processing matter. The European Commission explains the distinction in its guidance on who the law applies to.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Small businesses and sole proprietors

There is no blanket small-business exemption. Some obligations may not apply in particular low-risk circumstances, and the scale of a program should be proportionate to the organization’s activities and risks. But small organizations may still need a lawful basis, transparent notices, appropriate security and retention, a way to handle rights requests, vendor controls, and a breach-response process.

Rank #2
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
  • Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

EU GDPR and UK GDPR are separate

As of October 2026, the EU GDPR and UK GDPR are distinct regimes. The UK GDPR is supplemented by the UK Data Protection Act 2018 and later UK legislation; similar rules do not make the regimes identical. Organizations dealing with people in both places may need to assess both, including their separate international-transfer rules. The UK regulator’s international-transfer guidance concerns the UK framework.

The seven GDPR principles

Article 5 sets the organizing principles for processing. Organizations must be able to show how they comply, not merely assert that they do.

  1. Lawfulness, fairness, and transparency: Have a valid legal basis, treat people fairly, and explain what is happening in clear language.
  2. Purpose limitation: Collect data for specified, explicit purposes and assess whether later uses are compatible.
  3. Data minimization: Collect only what is adequate, relevant, and necessary for those purposes.
  4. Accuracy: Keep information accurate and take reasonable steps to correct or erase inaccurate data.
  5. Storage limitation: Do not keep identifiable data longer than needed for its purpose, subject to applicable exceptions.
  6. Integrity and confidentiality: Protect data against unauthorized or unlawful access, loss, destruction, and damage.
  7. Accountability: Take responsibility for compliance and keep evidence that appropriate measures are in place.

The European Commission describes these GDPR principles.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What lawful bases can an organization use?

An organization generally needs a lawful basis for each processing purpose. Consent is one option, not a universal requirement or cure-all. The six bases in Article 6 are:

Basis Typical example Important limit
Consent Optional marketing or nonessential tracking Must be freely given, specific, informed, and unambiguous; it must generally be as easy to withdraw as to give.
Contract Processing needed to fulfill an order Only processing necessary for the contract is covered by this basis.
Legal obligation Keeping records required by law The obligation must have a legal basis.
Vital interests Processing necessary to protect someone’s life A narrow basis for exceptional situations.
Public task Public administration carrying out an assigned task Requires an appropriate basis in public interest or official authority.
Legitimate interests Some security or internal business operations Requires necessity and a balance between the interest and people’s rights and freedoms.

Consent must be distinct from unrelated terms, and an organization cannot collect data first and later choose whichever basis seems convenient. Legitimate interests are not a shortcut: the organization should identify the interest, explain why processing is necessary, and assess whether the person’s rights override it. The relevant rules are in Articles 6 and 7.

Rank #3
Seagate Portable 1TB External Hard Drive HDD – USB 3.0 for PC, Mac, PlayStation, & Xbox, 1-Year Rescue Service (STGX1000400) , Black
  • Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

Special-category data

Processing data about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetics, certain biometric identifiers, health, sex life, or sexual orientation is generally restricted. It is not categorically prohibited, but typically requires both an Article 6 lawful basis and a specific Article 9 condition. See Article 9.

What rights do individuals have?

Right What it means Main qualification
Be informed Receive clear information about collection and use. Information must be transparent and accessible; what must be provided depends on how the data was obtained.
Access Ask whether data is being processed and obtain a copy. Rights of others and other legal limits can affect what is disclosed.
Rectification Correct inaccurate or incomplete data. The request concerns data about the requester.
Erasure Request deletion in certain circumstances. Not absolute; legal duties, public interest, expression, and legal claims can provide exceptions.
Restrict processing Limit certain uses while a matter is resolved. Applies in specified circumstances.
Data portability Receive certain data in a structured, commonly used, machine-readable format and transmit it elsewhere. Applies to qualifying processing, including where the basis is consent or contract and processing is automated.
Object Object to certain processing, including direct marketing and some public-task or legitimate-interest processing. The effect depends on the purpose and legal basis; direct-marketing objections receive particular protection.
Protection concerning automated decisions Receive safeguards in relevant cases involving solely automated decisions with legal or similarly significant effects. The right is subject to conditions and exceptions; it is not a ban on all profiling or automation.
Withdraw consent Withdraw consent where it is the lawful basis. Withdrawal does not make earlier lawful processing unlawful.
Complain and seek remedies Complain to a supervisory authority and, where applicable, seek a judicial remedy or compensation. Available routes and outcomes depend on the facts and the regulation.

The GDPR’s rights provisions are in Articles 12–22. A request is generally due for response within one month. For complex or numerous requests, an organization may extend by up to two additional months, but it must tell the requester within the initial month and explain the delay. It may request information reasonably needed to verify identity, and may refuse or charge a reasonable fee for a manifestly unfounded or excessive request under the regulation’s conditions.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What must organizations do?

Explain their practices

A privacy notice should identify the organization and relevant contacts, explain purposes and lawful bases, describe data categories and recipients, state retention periods or criteria, and provide information about transfers, rights, consent withdrawal, and complaints. Where relevant, it should also explain the source of indirectly obtained data and meaningful information about automated decision-making or profiling. Notices should be concise, intelligible, accessible, and written in clear language. The Commission’s principles guidance covers transparency.

Assign roles and control vendors

A controller determines the purposes and means of processing—for example, a retailer deciding why it collects customer details. A processor handles data on a controller’s behalf, such as a cloud host, payroll service, email platform, or support provider. A processor relationship generally requires a written data-processing agreement and documented instructions. Processors also have direct duties under the GDPR; a contract label alone does not determine the actual role. See Articles 4 and 28.

Build privacy into systems

Privacy by design and by default means considering data protection at the start and making the least intrusive practical settings the default. Measures can include collecting fewer fields, limiting access by role, pseudonymizing records, separating identifying details, and automating deletion after a defined retention period. Article 25 sets out the requirement: GDPR text.

Rank #4
Seagate Portable 4TB External Hard Drive HDD – USB 3.0, 1-Year Rescue
  • Easily store and access 4TB of content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

Assess high-risk processing and appoint a DPO when required

A Data Protection Impact Assessment (DPIA) is required before processing likely to result in high risk to people. Examples can include large-scale processing of sensitive data, systematic extensive monitoring, large-scale profiling, and certain biometric or location-data systems. A DPIA describes the processing, assesses necessity and proportionality, identifies risks, and records mitigation measures. A Data Protection Officer is required for public authorities or bodies (with a judicial-capacity exception), or where core activities involve large-scale regular and systematic monitoring or large-scale processing of special-category or criminal-conviction data. Organizations may appoint one voluntarily; not every company needs one. See Articles 35 and 37–39 and the EDPB guidance index.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect data and keep it only as long as needed

Organizations need security appropriate to the risk, purpose-based retention rules, vendor oversight, and procedures for responding to rights requests and incidents. Encryption can be an important safeguard, but it does not replace lawful-basis analysis, transparency, retention controls, or transfer safeguards.

Handle international transfers correctly

Transfers of personal data outside the EEA require an applicable mechanism or derogation. Mechanisms can include adequacy decisions, Standard Contractual Clauses, or Binding Corporate Rules; some cases also require transfer-risk assessments and supplementary measures. The destination, recipient, data flow, applicable mechanism, and current status all matter. A U.S. vendor is not automatically unlawful or automatically compliant. See the Commission’s business rules and the GDPR’s Chapter V.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What happens after a personal-data breach?

A breach can involve unauthorized disclosure or access, loss, destruction, or alteration. The controller generally must notify the supervisory authority within 72 hours after becoming aware of a qualifying breach unless it is unlikely to create risk to people’s rights and freedoms. If the breach is likely to create a high risk, affected people may also need to be told without undue delay. The processor must notify the controller without undue delay, and organizations should document breaches, including those not reported to the regulator.

  1. Detect and contain the incident.
  2. Assess what data and people are affected and the likely risk.
  3. Record the incident and the reasons for notifying or not notifying.
  4. Notify the supervisory authority within the applicable deadline if the risk threshold is met.
  5. Inform affected people without undue delay when the high-risk threshold applies.

The 72-hour period is not a universal deadline for discovering every incident. See Articles 33–34 and the EDPB breach-notification guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
UnionSine 500GB Ultra Slim Portable External Hard Drive HDD-USB 3.0
  • [Upgraded Version] - This external hard drive features a mirrored logo stripe combined with a striped anti-slip design, and the rounded corners of the casing make it easier to grip. The stripes also have a heat dissipation function, ensuring stable and fast data transfer.
  • 【Ultra-thin and quiet】 - The motherboard adopts JMicron 578 noise-free solution, giving you a quiet working environment. Lightweight and portable size designed to fit in your pocket for easy portability.
  • 【Ultra-Fast Data Transfers】 - Pairing this external hard drive with JMicron 578 solution USB 3.0 and USB 2.0 interfaces enables blazing-fast data transfer. It boasts theoretical read speeds of up to 125MB/s and write speeds of up to 103MB/s.
  • 【Plug and Play】 - With no software to install, just plug it in and the drive is ready to use.The hard disk chip is wrapped with an aluminum anti-interference layer to increase heat dissipation and protect data.
  • 【What You Get】 - 1 x Portable Hard Drive, 1 x USB 3.0 Cable, 1 x User Manual, Gift-type shell packaging ,Three-year manufacturer's warranty and free technical support services.

What are the fines?

The maximum administrative-fine tiers are up to €10 million or, for an undertaking, 2% of total worldwide annual turnover from the preceding financial year, whichever is higher, for certain infringements; and up to €20 million or 4% of that turnover, whichever is higher, for more serious infringements. These are statutory ceilings, not automatic penalties. Authorities consider factors including the nature, gravity, duration, intent or negligence, mitigation, prior infringements, cooperation, affected data, and compliance measures. The rules are in Articles 83–84.

How GDPR relates to cookies, marketing, AI, and cloud services

Cookies and consent banners

The GDPR regulates personal-data processing, not cookies as a standalone subject. Cookies and similar identifiers can involve personal data when they identify, distinguish, profile, or can be linked to a person. EU cookie rules also interact with the ePrivacy framework and national implementation. A banner saying “we use cookies” does not by itself prove valid consent; necessary cookies and optional analytics, advertising, or personalization may be treated differently. Check the applicable ePrivacy and national rules as well as GDPR requirements.

Email marketing and advertising

The GDPR does not categorically ban targeted advertising or require consent for every use. The lawful basis, transparency, profiling, objection rights, and any separate marketing and cookie rules must be considered for the particular activity. A consent checkbox cannot cure excessive collection, poor security, incompatible purposes, or unlawful retention.

Artificial intelligence

The GDPR can apply when AI systems process personal data for training or fine-tuning, profiling, automated decisions, fraud detection, personalization, workplace monitoring, facial recognition, or customer support. It does not prohibit AI generally. Relevant questions include lawful basis, transparency, purpose, minimization, accuracy, security, safeguards for significant automated decisions, and transfers. The GDPR and EU AI Act are separate instruments and can apply at the same time.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloud and other service providers

Using a cloud, analytics, payroll, or email provider does not transfer all responsibility away from the organization that decides why data is processed. Check roles, processing terms, security commitments, subprocessors, retention and deletion, breach notification, and any international transfer mechanism.

A practical starting checklist for an organization

This is an orientation checklist, not a guarantee of compliance. A small local business and a large ad-tech company may need very different controls, but both should assess their processing.

  1. Map the data: Record what personal data is collected, whose data it is, its source, purpose, storage locations, recipients, retention, transfers, and use in profiling or automated decisions.
  2. Identify roles: Determine whether the organization is a controller, joint controller, processor, or subprocessor for each activity. The facts matter more than a contract label.
  3. Assign a lawful basis: Document a basis for each purpose; separate purposes may require separate analysis.
  4. Check heightened risks: Review processing involving sensitive data, children, large-scale monitoring, biometrics, automated decisions, workplace surveillance, location tracking, high-volume profiling, or international transfers.
  5. Provide notices: Make clear explanations available at the relevant point in the data relationship.
  6. Review vendors: Check processing agreements, subprocessors, security, retention, deletion, incident duties, and transfer mechanisms.
  7. Set up rights handling: Define intake, identity checks, search and correction or deletion methods, ownership, escalation, exemptions, and deadline tracking.
  8. Prepare for breaches: Decide how incidents are detected, assessed, escalated, documented, and notified when required.
  9. Set retention rules: Establish purpose-based review and deletion triggers rather than keeping data indefinitely.
  10. Keep evidence: Maintain appropriate records, assessments, policies, training, contracts, and proof that controls operate in practice.

What GDPR does not mean

  • It is not limited to companies based in Europe, but it does not automatically cover every company with a European website visitor.
  • It does not require consent for every processing activity; several lawful bases exist.
  • It does not make the right to erasure absolute.
  • It does not mean every breach must be reported to a regulator within 72 hours; the risk threshold matters, though breaches should be assessed and documented.
  • It does not make every business appoint a DPO or pay a fine equal to a fixed percentage of revenue.
  • It is not just a cookie law, a privacy policy, a certification, or a software product.
  • It is not the only relevant privacy, cybersecurity, employment, communications, marketing, consumer-protection, or AI law.

Organizations with uncertain territorial scope, sensitive or high-risk processing, cross-border transfers, or a significant incident should seek advice from a privacy professional or qualified lawyer familiar with the relevant jurisdiction. This article is general information, not individualized legal advice.

Quick Recap

SaleBestseller No. 1
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$119.99
Bestseller No. 2
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
Seagate Portable 5TB External Hard Drive HDD – USB 3.0 for PC, Mac, PS4, & Xbox - 1-Year Rescue Service (STGX5000400), Black
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$229.99
Bestseller No. 3
Seagate Portable 1TB External Hard Drive HDD – USB 3.0 for PC, Mac, PlayStation, & Xbox, 1-Year Rescue Service (STGX1000400) , Black
Seagate Portable 1TB External Hard Drive HDD – USB 3.0 for PC, Mac, PlayStation, & Xbox, 1-Year Rescue Service (STGX1000400) , Black
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$119.80
Bestseller No. 4
Seagate Portable 4TB External Hard Drive HDD – USB 3.0, 1-Year Rescue
Seagate Portable 4TB External Hard Drive HDD – USB 3.0, 1-Year Rescue
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$151.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.