Glossary · Term

GDPR explained

The GDPR is the central EU data protection law. It sets out how organisations may process personal data, what rights data subjects have and what duties apply to data security.

At a glance
Legal basis
Regulation (EU) 2016/679 (General Data Protection Regulation)
Applicable since
25 May 2018
Who is covered?
Anyone processing the personal data of people in the EU
Fines
Up to EUR 20 million or 4 % of total worldwide annual turnover
Updated
June 2026
Editorial team
Compliance Compass

What is the GDPR?

The GDPR stands for the General Data Protection Regulation. It is an EU-wide regulation on the protection of personal data. Being a regulation rather than a directive, it applies directly in every Member State without a national transposing act, and it creates one common framework for how organisations must handle data such as names, addresses, e-mail addresses, IP addresses or health data.

Which principles apply?

What rights do data subjects have?

People have, among other things, the right to access, rectification, erasure (the right to be forgotten), data portability and the right to object to processing. Organisations normally have to answer such requests within one month.

What fines are possible?

Breaches can be punished with fines of up to EUR 20 million or 4 % of total worldwide annual turnover – whichever is the higher amount. Unlike the NIS2 ceilings, which Member States may raise, this figure is fixed by the regulation itself and is therefore the same everywhere in the EU. That makes the GDPR one of the strictest data protection laws in the world.

How do the GDPR and NIS2 fit together?

The GDPR and NIS2 pursue different aims – data protection on one side, cybersecurity on the other – but they overlap heavily on security measures. They also reach you in different ways: the GDPR is a regulation and binds you directly, while NIS2 is a directive that only binds you through the transposing law of your Member State. In practice, anyone running an ISMS and implementing technical and organisational measures (TOMs) often meets requirements from both sets of rules at the same time. The duties towards service providers interlock too: where the GDPR requires a data processing agreement (DPA) under Article 28, NIS2 demands that the supply chain be secured.

If a ransomware attack disrupts a service that matters for NIS2 and encrypts personal customer data at the same time, the organisation has to serve two reporting routes in parallel: the personal data breach within 72 hours to the data protection supervisory authority under the GDPR, and the NIS2 chain of an early warning within 24 hours, a notification with a first assessment within 72 hours and a final report within one month to the competent authority. Because the two routes lead to different bodies, a single shared incident response process is what stops a deadline being overlooked.

Further reading: EUR-Lex – General Data Protection Regulation (EU) 2016/679

Frequently asked questions

What is the GDPR in simple terms?

The General Data Protection Regulation, Regulation (EU) 2016/679, is the central EU data protection law and has applied directly in every Member State since 25 May 2018. Because it is a regulation and not a directive, it needed no national transposing act: the same wording binds organisations in every Member State. It governs how organisations must process, protect and document personal data such as names, addresses, e-mail addresses or health data. Its core principles are lawfulness, purpose limitation, data minimisation and accountability, which means being able to demonstrate compliance.

Who does the GDPR apply to?

The GDPR applies to every organisation that processes the personal data of people in the EU – regardless of its size, and under the marketplace principle also to providers established outside the EU where they address people in the EU. Data subjects have rights of access, rectification, erasure and data portability, which organisations normally have to satisfy within one month.

What fines apply for GDPR breaches?

Breaches of the GDPR can be punished with fines of up to EUR 20 million or 4 % of total worldwide annual turnover, whichever is the higher amount. Because the GDPR is a regulation, that ceiling is the same in every Member State, which makes it one of the strictest data protection laws in the world. It sits well above the NIS2 figures, where Article 34 sets a minimum ceiling of EUR 10 million or 2 % of turnover for essential entities and lets Member States go higher.

Compliance

Data protection & security from one place

Compliance Compass brings risk management, evidence and measures together – GDPR-compliant and hosted in Germany.