Scope and territorial reach
The General Data Protection Regulation harmonized EU privacy law and replaced Directive 95/46/EC. Direct effect — no national transposition required, though most member states layered additional national acts on top (TTDSG in Germany, Loi I&L in France, DPA 2018 in UK).
Scope
Applies extraterritorially under Art 3(2) — any controller offering goods/services to or monitoring behavior of EU/EEA data subjects.
Where it applies — 20 jurisdictions
+ 8 more — see full list
Seven principles (Article 5)
The constitutional backbone — every processing activity must satisfy all seven simultaneously.
-
01
Lawfulness, fairness, transparency Art 5(1)(a)
Process data on a clear legal basis, fairly, and tell users what you do.
-
02
Purpose limitation Art 5(1)(b)
Collect data for specified, explicit purposes — don't repurpose later.
-
03
Data minimisation Art 5(1)(c)
Only collect what's adequate, relevant, and necessary for the purpose.
-
04
Accuracy Art 5(1)(d)
Keep data accurate and up to date; correct or erase inaccurate data without delay.
-
05
Storage limitation Art 5(1)(e)
Keep data only as long as necessary; define and document retention periods.
-
06
Integrity & confidentiality Art 5(1)(f)
Protect data against unauthorized access, loss, or destruction (security).
-
07
Accountability Art 5(2)
Demonstrate compliance — document everything (ROPA, DPIA, policies).
Six lawful bases (Article 6)
You must identify and document one before processing — and consent isn't always the right one.
Consent
User explicitly opts in (free, specific, informed, unambiguous).
Contract
Necessary to perform a contract with the user.
Legal obligation
Required by law (tax records, AML, GDPR itself).
Vital interests
Necessary to protect someone's life.
Public task
Performing a task in the public interest / official authority.
Legitimate interest
Your interest doesn't override user rights — needs an LIA.
Eight data-subject rights (Articles 12–22)
What individuals can demand from you, with the response window and scope.
| Right | Article | Response | Scope |
|---|---|---|---|
| Right to be informed | Art 13–14 | At collection | At collection — privacy notice must be transparent. |
| Right of access | Art 15 | 30 days | User can request copy of all their data. |
| Right to rectification | Art 16 | 30 days | Correct inaccurate or incomplete data. |
| Right to erasure | Art 17 | 30 days | "Right to be forgotten" — deletion under specific conditions. |
| Right to restrict processing | Art 18 | 30 days | Pause processing while disputes are resolved. |
| Right to data portability | Art 20 | 30 days | Receive data in machine-readable format, transfer to another controller. |
| Right to object | Art 21 | 30 days | Object to processing (esp. direct marketing — absolute right). |
| Rights re: automated decisions | Art 22 | 30 days | Not subject to solely-automated decisions with legal effect. |
Fines & enforcement
Maximum administrative penalty: €20.0M or 4% of global annual turnover (Art 83(5)). Tiered structure: Art 83(4) = 2% / €10M for procedural failures.
-
Meta Platforms Ireland DPC · IE · Art 46(1)
Largest GDPR fine on record. Transfers of EU user data to the US under SCCs without sufficient supplementary measures, following the CJEU Schrems II ruling (C-311/18).
-
Amazon Europe CNPD · LU · Art 6, 12-17, 21
Targeted advertising without valid consent — second-largest GDPR fine. Appealed in Luxembourg administrative court.
-
Instagram (Meta) DPC · IE · Art 5(1)(a/c), 6(1), 12(1), 24, 25(1-2), 35(1)
Children's data: business-account contact info public-by-default; privacy-by-design failures; insufficient DPIA.
-
TikTok DPC · IE · Art 5(1)(a/c/f), 12(1), 13(1)(e), 24, 25(1-2)
Children's data: profiles default-public for minors; data-protection-by-design failures; ineffective transparency for under-13s. Under appeal in Irish High Court.
-
Meta Platforms DPC · IE · Art 25(1-2), 33(3), 33(5)
2018 'View As' breach affecting 29M accounts. Privacy-by-design failures (€130M + €110M sub-fines under Art 25) plus incomplete breach notification.
-
Meta Platforms DPC · IE · Art 33
Late breach notification — 72h rule
-
WhatsApp DPC · IE · Art 12, Art 13, Art 14
Transparency failures — privacy notice unclear about data shared with Facebook.
-
Enel Energia Garante · IT · Art 5, Art 6
Unlawful processing for marketing — re-affirmation of strict opt-in (Garante order 8 Feb 2024).
Sources: national supervisory-authority press releases. Full enforcement database available via CMS Law tracker.
National addons
GDPR is a Regulation — directly applicable, no transposition required. But Member States layer additional rules on top via national acts.
| Country | National act | Stricter than GDPR baseline? | Note |
|---|---|---|---|
| 🇩🇪 Germany DE | TDDDG (ex-TTDSG) + BDSG | Stricter | TTDSG renamed TDDDG on 14 May 2024 to align with EU Digital Services Act; §25 cookie-consent rule unchanged and stricter than ePrivacy. |
| 🇫🇷 France FR | Loi Informatique et Libertés | Stricter | CNIL issued formal notices (mises en demeure) on GA4 from Feb 2022 — no fine, but drove migration. Post-DPF (2023) practical posture relaxed for DPF-certified Google entities. |
| 🇮🇹 Italy IT | Codice Privacy | Stricter | Garante prov. 9782890 (23 Jun 2022, Caffeina Media) ruled pre-DPF GA4 transfers unlawful. Post-DPF (Jul 2023) the transfer dimension shifted; ePrivacy/consent issues remain. |
| 🇦🇹 Austria AT | DSG 2018 | Stricter | DSB precedent on GA4 (2021) |
| 🇪🇸 Spain ES | LOPDGDD | Aligned | AEPD aligned with EDPB baseline |
| 🇳🇱 Netherlands NL | UAVG | Aligned | AP published practical GA config manual |
| 🇮🇪 Ireland IE | Data Protection Act 2018 | Aligned | Lead DPA for many US tech companies |
| 🇵🇱 Poland PL | UODO | Aligned | Standard GDPR baseline |
| 🇧🇪 Belgium BE | Loi du 30 juillet 2018 | Aligned | APD active on cookie banners |
| 🇩🇰 Denmark DK | Databeskyttelsesloven | Aligned | Datatilsynet pragmatic enforcement |
| 🇸🇪 Sweden SE | Dataskyddslag | Aligned | IMY active on legitimate-interest scrutiny |
| 🇫🇮 Finland FI | Tietosuojalaki | Aligned | Standard baseline |
| 🇳🇴 Norway NO | Personopplysningsloven (EEA) | Aligned | Datatilsynet aligned via EEA agreement |
| 🇵🇹 Portugal PT | Lei n.º 58/2019 | Aligned | CNPD baseline |
| 🇬🇷 Greece GR | Law 4624/2019 | Aligned | HDPA baseline |
| 🇬🇧 United Kingdom UK | UK GDPR + DPA 2018 | Aligned | Post-Brexit clone with minor divergences |
Compared to other laws
Side-by-side rule comparison with the same field on each side.