What Is GDPR? A Plain-English Guide
The EU's General Data Protection Regulation, its scope and principles, and why it became the template for privacy law worldwide.
8 min read
The General Data Protection Regulation (GDPR) is the European Union's comprehensive privacy law. In force since 2018, it governs how organizations collect, use, store, and share the personal data of people in the EU and UK, and it carries real penalties, up to the higher of a set cash ceiling or a percentage of global annual turnover. It is the law most other modern privacy regimes were modeled on.
What GDPR Covers
GDPR applies to personal data, meaning any information relating to an identifiable person: a name, an email, an IP address, a device ID, and more. It sets rules for the full lifecycle of that data, from the legal basis you need to collect it, through how you secure and retain it, to the rights people can exercise over it.
The Core Principles
GDPR is built on a handful of principles that run through everything else:
- Lawfulness, fairness, and transparency: have a valid legal basis, and be clear about what you do.
- Purpose limitation: collect data for specified purposes, not open-ended use.
- Data minimization: collect only what you need.
- Accuracy: keep data correct and up to date.
- Storage limitation: keep data only as long as you need it.
- Integrity and confidentiality: secure the data.
- Accountability: be able to demonstrate compliance, not just claim it.
That last principle, accountability, is why documentation matters so much under GDPR: you have to be able to show your work.
Why It Became the Global Template
GDPR's reach and its rights-based approach influenced privacy laws around the world, from Brazil's LGPD to the wave of US state laws. Once you understand GDPR, most other privacy regimes read as variations on the same ideas, which is why it is the right place to start.
Who Has to Comply
GDPR's reach extends well beyond the EU: any organization that processes the data of people in the EU or UK can be in scope, regardless of where the company is based. For the specifics, see Who Must Comply With GDPR.
How Concord Fits
The operational core of GDPR, valid consent, honoring data subject rights, and keeping records of what you do with personal data, maps directly onto Concord Privacy: consent management, privacy request handling, and data mapping in one platform, so compliance is a workflow rather than a spreadsheet.