General Data Protection Regulation

The GDPR replaced the 1995 EU Data Protection Directive and fundamentally reshaped the global privacy landscape. It applies to any organization, regardless of where it's based, that processes personal data of individuals in the European Economic Area (EEA). This extraterritorial reach means US companies, Asian manufacturers, and any business with EU customers must comply.

At its core, the GDPR requires that personal data be processed lawfully, fairly, and transparently; collected only for specific, legitimate purposes; limited to what is necessary; kept accurate; not stored longer than needed; and protected with appropriate security.

The regulation's enforcement mechanism is its most significant differentiator from prior law: fines of up to 20 million euros or 4% of global annual revenue for the most serious violations. The GDPR established the baseline that most subsequent privacy legislation, including the CCPA, CPRA, Brazil's LGPD, and dozens of US state laws, has modeled or reacted to.

Learn more about GDPR requirements with Transcend’s Complete Guide to the GDPR.

Additional resources