What is GDPR?
GDPR is General Data Protection Regulation. The EU law governing how companies handle personal data of EU residents.
Definition
GDPR (General Data Protection Regulation) is the European Union's sweeping data protection law, effective since 2018. It applies to any company processing data of EU residents, regardless of where the company is based. Key requirements include lawful basis for processing, data subject rights (access, deletion, portability), and strict consent rules.
Why It Matters
GDPR has teeth. Fines can reach €20 million or 4% of global annual revenue, whichever is higher. Even US companies selling to European customers must comply. GDPR also influenced other privacy laws worldwide, including CCPA. It's the de facto global standard for data protection.
Example
A US SaaS company serves European customers. They implement cookie consent banners, add data processing clauses to contracts, appoint a Data Protection Officer, and create processes to handle data access and deletion requests.
Tools for GDPR
Find the Right GDPR Tool
Not sure which tool fits your needs? Check out our curated recommendations: