Title: General Data Protection Regulation (GDPR)
Author: Kriko
Published: Feb 17, 2021
Last modified: Jul 14, 2026

---

 1.  [Home](https://kriko.io/) /
 2.  [Glossary](https://kriko.io/glossary) /
 3.  G Letter

# General Data Protection Regulation **(GDPR)**

The **General Data Protection Regulation**, commonly abbreviated as GDPR, is the
main European Union regulation governing the protection of personal data. Applicable
since 25 May 2018, the GDPR aims to protect the fundamental rights and freedoms 
of natural persons during the processing of personal data and to harmonize data 
protection rules across the European Union. It is not merely a technical regulation
about data security; it is a comprehensive data protection framework covering processing
principles, data subject rights, company obligations, international data transfers
and administrative penalties.

GDPR is often described as a regulation that protects the data of EU citizens, but
this description is incomplete. Under certain conditions, the regulation applies
to the processing of personal data of individuals who are in the European Union.
Companies located outside the EU may also fall within the scope of GDPR if they 
offer goods or services to individuals in the EU or monitor their behaviour. Therefore,
e-commerce websites, SaaS companies, apps, advertising technology providers or digital
platforms that are not physically located in Europe may still face GDPR obligations
if they process personal data of users in the EU.

Under GDPR, **personal data** means any information relating to an identified or
identifiable natural person. Name, surname, identification number, address, phone
number, email address, customer number, location data, IP address, cookie identifiers,
device ID and online identifiers can all be considered personal data. In addition,
health data, biometric data, genetic data, political opinions, religious beliefs,
trade union membership, racial or ethnic origin and similar special categories of
data are subject to stricter protection.

One of the most commonly misunderstood areas of GDPR is consent. Under the regulation,
not every personal data processing activity has to rely on explicit consent. For
personal data processing to be lawful, at least one of the legal bases listed in
GDPR must apply. These include consent, performance of a contract, legal obligation,
vital interests, public task and legitimate interests. For example, an e-commerce
website processing an address to deliver an order may rely on performance of a contract,
while advertising cookies or personalized marketing activities may require consent.

When consent is used, it must meet specific conditions. Under GDPR, consent must
be freely given, specific, informed and expressed through an unambiguous statement
or clear affirmative action. The data subject has the right to withdraw consent 
at any time, and withdrawal does not affect the lawfulness of processing carried
out before consent was withdrawn. The European Data Protection Board also emphasizes
that withdrawing consent must be as easy as giving it. ([gdpr-info.eu](https://gdpr-info.eu/art-7-gdpr/),
[edpb.europa.eu](https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en))

GDPR is highly important for e-commerce and digital marketing. Websites with membership
systems, online stores, mobile applications, CRM systems, email marketing platforms,
advertising pixels, analytics tools, remarketing systems and cookie-based targeting
technologies may process personal data. Therefore, GDPR compliance is not limited
to publishing a privacy policy. Data inventories, legal basis analysis, clear privacy
notices, cookie management, consent records, data retention periods, third-party
data transfers and security measures should be evaluated together.

For websites and e-commerce platforms, users should be clearly informed about which
data is collected, why it is collected, on which legal basis it is processed, who
it is shared with, how long it is stored and what rights they have. GDPR requires
information such as the identity and contact details of the controller, purposes
of processing, legal basis, recipients, retention period and data subject rights
to be provided to the data subject. For this reason, privacy policies should not
consist of generic and vague statements; they should reflect the actual data processing
activities.

Individuals have several rights under GDPR. Data subjects may have the right to 
access their personal data, request correction of inaccurate data, request deletion
under certain conditions, restrict processing, receive their data in a portable 
format, object to certain processing activities and be protected against certain
automated decision-making processes. To support these rights, companies must design
proper request handling processes, response timelines and internal operations. Failing
to respond properly to user requests or leaving the process unclear can create compliance
risk.

Penalties for GDPR violations are assessed based on the nature, gravity and duration
of the infringement, whether it was intentional or negligent, the number of people
affected, the technical and organizational measures taken and the level of cooperation
with the supervisory authority. Therefore, it is not accurate to say that a first
violation always results only in a written warning. Under Article 83 of GDPR, some
infringements may result in administrative fines of up to 10 million euros or 2%
of the company’s total worldwide annual turnover of the previous financial year.
More serious infringements may result in fines of up to 20 million euros or 4% of
global turnover, whichever amount is higher.

GDPR compliance is a technical, legal and operational process. Companies need to
know which personal data they collect, why they process it, in which systems they
store it, who they share it with and how long they retain it. Avoiding unnecessary
data collection, following the principle of data minimization, limiting access permissions,
applying encryption and security measures, creating data breach procedures and signing
data processing agreements with vendors are important parts of this process.

In summary, **GDPR** is a comprehensive data protection regulation that governs 
the protection of personal data in the European Union and can also affect companies
outside the EU in certain situations. Processing personal data requires not only
explicit consent, but an appropriate legal basis. For companies using e-commerce,
digital marketing, analytics, CRM and advertising technologies, GDPR requires a 
careful compliance process covering transparency, data security, user rights, cookie
management, third-party data sharing and international data transfers.

## Discover it in the dictionary

###  Keyword Density

Keyword density is an SEO metric that shows how often a keyword or keyword phrase
appears in a piece of content compared with the…

###  Data Mart

A data mart is a data storage structure designed to meet the information and analytical
needs of a specific department or business function within…

###  Database Management Systems

Database Management Systems, commonly abbreviated as DBMS, are software systems 
used to store, organise, manage, query, update and delete data. A DBMS creates a…

###  Doorway Pages

Doorway pages are low-quality pages created to gain visibility in search engines
for specific queries, while offering little real value to users and mainly…

###  Search Engine Optimization (SEO)

Search Engine Optimization, commonly abbreviated as SEO, is the practice of improving
a website so that search engines can crawl, understand and index it…

###  Data Visualisation

Data visualisation is the practice of presenting information through charts, maps,
diagrams and other visual formats. It helps users understand complex datasets and
identify…

###  Frequency Capping

Frequency is a media metric that shows how many times, on average, an advertisement
is shown to a specific user or target audience. Frequency…

###  Google Tag Manager (GTM)

Google Tag Manager, commonly abbreviated as GTM, is a free tag management system
that allows marketing, analytics and measurement tags used on websites or…

###  Demand Forecasting

Demand forecasting is the process of estimating future demand for a product or service
by using data, assumptions and analytical methods. Businesses use this…

## Track the digital heartbeat  with Kriko

Subscribe to receive curated insights, news, and ideas shaping the digital landscape.

  By checking this box, you acknowledge and accept our [privacy policy](https://kriko.io/privacy-policy).