General Data Protection Regulation (GDPR)

The General Data Protection Regulation, commonly abbreviated as GDPR, is the main European Union regulation governing the protection of personal data. Applicable since 25 May 2018, the GDPR aims to protect the fundamental rights and freedoms of natural persons during the processing of personal data and to harmonize data protection rules across the European Union. It is not merely a technical regulation about data security; it is a comprehensive data protection framework covering processing principles, data subject rights, company obligations, international data transfers and administrative penalties.

GDPR is often described as a regulation that protects the data of EU citizens, but this description is incomplete. Under certain conditions, the regulation applies to the processing of personal data of individuals who are in the European Union. Companies located outside the EU may also fall within the scope of GDPR if they offer goods or services to individuals in the EU or monitor their behaviour. Therefore, e-commerce websites, SaaS companies, apps, advertising technology providers or digital platforms that are not physically located in Europe may still face GDPR obligations if they process personal data of users in the EU.

Under GDPR, personal data means any information relating to an identified or identifiable natural person. Name, surname, identification number, address, phone number, email address, customer number, location data, IP address, cookie identifiers, device ID and online identifiers can all be considered personal data. In addition, health data, biometric data, genetic data, political opinions, religious beliefs, trade union membership, racial or ethnic origin and similar special categories of data are subject to stricter protection.

One of the most commonly misunderstood areas of GDPR is consent. Under the regulation, not every personal data processing activity has to rely on explicit consent. For personal data processing to be lawful, at least one of the legal bases listed in GDPR must apply. These include consent, performance of a contract, legal obligation, vital interests, public task and legitimate interests. For example, an e-commerce website processing an address to deliver an order may rely on performance of a contract, while advertising cookies or personalized marketing activities may require consent.

When consent is used, it must meet specific conditions. Under GDPR, consent must be freely given, specific, informed and expressed through an unambiguous statement or clear affirmative action. The data subject has the right to withdraw consent at any time, and withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn. The European Data Protection Board also emphasizes that withdrawing consent must be as easy as giving it. (gdpr-info.eu, edpb.europa.eu)

GDPR is highly important for e-commerce and digital marketing. Websites with membership systems, online stores, mobile applications, CRM systems, email marketing platforms, advertising pixels, analytics tools, remarketing systems and cookie-based targeting technologies may process personal data. Therefore, GDPR compliance is not limited to publishing a privacy policy. Data inventories, legal basis analysis, clear privacy notices, cookie management, consent records, data retention periods, third-party data transfers and security measures should be evaluated together.

For websites and e-commerce platforms, users should be clearly informed about which data is collected, why it is collected, on which legal basis it is processed, who it is shared with, how long it is stored and what rights they have. GDPR requires information such as the identity and contact details of the controller, purposes of processing, legal basis, recipients, retention period and data subject rights to be provided to the data subject. For this reason, privacy policies should not consist of generic and vague statements; they should reflect the actual data processing activities.

Individuals have several rights under GDPR. Data subjects may have the right to access their personal data, request correction of inaccurate data, request deletion under certain conditions, restrict processing, receive their data in a portable format, object to certain processing activities and be protected against certain automated decision-making processes. To support these rights, companies must design proper request handling processes, response timelines and internal operations. Failing to respond properly to user requests or leaving the process unclear can create compliance risk.

Penalties for GDPR violations are assessed based on the nature, gravity and duration of the infringement, whether it was intentional or negligent, the number of people affected, the technical and organizational measures taken and the level of cooperation with the supervisory authority. Therefore, it is not accurate to say that a first violation always results only in a written warning. Under Article 83 of GDPR, some infringements may result in administrative fines of up to 10 million euros or 2% of the company’s total worldwide annual turnover of the previous financial year. More serious infringements may result in fines of up to 20 million euros or 4% of global turnover, whichever amount is higher.

GDPR compliance is a technical, legal and operational process. Companies need to know which personal data they collect, why they process it, in which systems they store it, who they share it with and how long they retain it. Avoiding unnecessary data collection, following the principle of data minimization, limiting access permissions, applying encryption and security measures, creating data breach procedures and signing data processing agreements with vendors are important parts of this process.

In summary, GDPR is a comprehensive data protection regulation that governs the protection of personal data in the European Union and can also affect companies outside the EU in certain situations. Processing personal data requires not only explicit consent, but an appropriate legal basis. For companies using e-commerce, digital marketing, analytics, CRM and advertising technologies, GDPR requires a careful compliance process covering transparency, data security, user rights, cookie management, third-party data sharing and international data transfers.

Discover it in the dictionary

Track the digital heartbeat with Kriko

Subscribe to receive curated insights, news, and ideas shaping the digital landscape.