What Is GDPR? Complete Guide to EU Data Protection (2026)

By Recording Law Editorial TeamReviewed May 20, 202623 min read
What Is GDPR? Complete Guide to EU Data Protection (2026)

Frequently Asked Questions

What does GDPR stand for?

GDPR stands for General Data Protection Regulation. It is Regulation (EU) 2016/679 of the European Parliament and of the Council, adopted on April 14, 2016, and enforceable since May 25, 2018. The regulation standardizes data protection law across all EU member states and the European Economic Area, replacing the 1995 Data Protection Directive.

Does the GDPR apply outside of Europe?

Yes. Article 3 gives the GDPR extraterritorial reach. Any organization worldwide that offers goods or services to EU residents, or that monitors the behavior of EU residents (such as through website analytics, behavioral advertising, or tracking), must comply with the GDPR regardless of where it is based. A company in the United States, Canada, or Japan is subject to the GDPR if it processes EU residents' personal data in these contexts.

What are the seven principles of the GDPR?

The seven principles under Article 5 are: (1) lawfulness, fairness, and transparency; (2) purpose limitation; (3) data minimization; (4) accuracy; (5) storage limitation; (6) integrity and confidentiality (security); and (7) accountability. These principles apply to all processing of personal data. The accountability principle places the burden on the controller to demonstrate compliance with the other six.

What is the difference between a data controller and a data processor?

A controller decides the purposes and means of processing personal data and bears primary GDPR compliance responsibility. A processor handles personal data on behalf of the controller, following the controller's instructions. For example, a retailer (controller) that uses a cloud hosting provider (processor) to store customer data. Controllers and processors must enter into a written data processing agreement under Article 28.

What are the six lawful bases for processing?

Article 6 sets out six lawful bases: (1) consent of the data subject; (2) contractual necessity; (3) compliance with a legal obligation; (4) protection of vital interests; (5) performance of a task in the public interest or exercise of official authority; and (6) legitimate interests of the controller or a third party. Every processing activity must be justified under one of these bases before processing begins.

What are the maximum GDPR fines?

The highest tier of GDPR fines is EUR 20 million or 4% of total worldwide annual turnover from the preceding financial year, whichever is higher. This applies to violations of core principles, lawful bases, data subject rights, and international transfer rules. A lower tier of EUR 10 million or 2% applies to more procedural violations. The largest single GDPR fine to date is EUR 1.2 billion, issued to Meta by Ireland's DPC in 2023 for unlawful data transfers.

What is the GDPR Procedural Regulation?

Regulation (EU) 2025/2518, known as the GDPR Procedural Regulation, was published in December 2025 and entered into force on January 1, 2026, with application from April 2, 2027. It introduces binding deadlines for cross-border enforcement cases (a 15-month investigation window, extendable by 12 months), standardized procedural rights for complainants and parties under investigation, and improved transparency. It does not change the substantive obligations in the GDPR itself.

What is the EU Digital Omnibus and how does it affect the GDPR?

The Digital Omnibus is a legislative proposal adopted by the European Commission on November 19, 2025 that would amend multiple EU digital laws including the GDPR. As of May 2026 it is still under co-legislative negotiation between the European Parliament and the Council and has not been enacted. Proposed changes to the GDPR include narrowing record-keeping obligations for smaller organizations, modifying information rights, adjusting breach notification rules, and refining automated decision-making rules. The current GDPR text remains in force until any amendments are formally adopted and published.

When did the GDPR take effect?

The GDPR was adopted on April 14, 2016, published on May 4, 2016, and took effect on May 25, 2018, after a two-year transition period. It replaced the 1995 Data Protection Directive (Directive 95/46/EC). The GDPR was adopted on April 14, 2016 and became applicable on May 25, 2018. May 25, 2026 marked the eighth anniversary of the GDPR becoming applicable.

Updates

Expanded from 2,850 to approximately 4,800 words; added dedicated sections on data subject rights overview (Chapter III table), GDPR and national implementing laws, and Recent Developments (2024-2026) covering the GDPR Procedural Regulation (Regulation (EU) 2025/2518), the Digital Omnibus proposal (proposal only, not enacted), and EU AI Act interplay; updated enforcement statistics through early 2026 (EUR 7.1 billion cumulative, EUR 530M TikTok fine, EDPB 10th anniversary); added new FAQ entries; expanded citations to 23 sources

Initial publication

Sources and References

  1. GDPR Full Text — Regulation (EU) 2016/679(eur-lex.europa.eu).gov
  2. Directive 95/46/EC — 1995 Data Protection Directive(eur-lex.europa.eu).gov
  3. GDPR Consolidated Text (EUR-Lex)(eur-lex.europa.eu).gov
  4. European Data Protection Board (EDPB)(edpb.europa.eu).gov
  5. EDPB Guidelines 3/2018 on Territorial Scope (Article 3)(edpb.europa.eu).gov
  6. EDPB — Article 5 Principles(edpb.europa.eu).gov
  7. EDPB Guidelines 1/2024 on Legitimate Interests (Article 6(1)(f))(edpb.europa.eu).gov
  8. EDPB Guidelines 07/2020 — Controller and Processor(edpb.europa.eu).gov
  9. EDPB SME Guide — Data Controller vs Data Processor(edpb.europa.eu).gov
  10. EDPB SME Guide — Respecting Individuals Rights(edpb.europa.eu).gov
  11. EDPB and EDPS Joint Opinion on Digital Omnibus (2026)(edpb.europa.eu).gov
  12. EDPB — Marking 10 Years of the GDPR (2026)(edpb.europa.eu).gov
  13. EDPS — History of the GDPR(edps.europa.eu).gov
  14. European Commission — Principles of the GDPR(commission.europa.eu).gov
  15. European Commission — Controller vs Processor(commission.europa.eu).gov
  16. European Commission — Data Protection Explained(commission.europa.eu).gov
  17. European Commission — Adequacy Decisions(commission.europa.eu).gov
  18. European Commission — Data Protection in the EU(commission.europa.eu).gov
  19. ICO — Guide to the Data Protection Principles(ico.org.uk).gov
  20. Article 3 GDPR — Territorial Scope(gdpr-info.eu)
  21. Article 5 GDPR — Principles(gdpr-info.eu)
  22. Article 6 GDPR — Lawfulness of Processing(gdpr-info.eu)
  23. GDPR Chapter 3 — Rights of the Data Subject(gdpr-info.eu)
Share: