
The General Data Protection Regulation was first proposed in 2012, and what followed was four years of discussions, debates, and amendments, with the regulation finally adopted by the European Parliament in 2016. Countries, companies, and organisations were given two years to comply, with the regulation being enforced from 25 May 2018. What originally seemed like a reasonable amount of time to prepare has passed quickly, and at the time of this writing, enforcement of the GDPR is barely 5-months away.
Much has already been written and discussed in the public domain regarding the GDPR, but still, many business owners are a little unsure of what the GDPR entails, and whether or not they are affected. With this GDPR guide, I hope to add some clarity, explaining what the General Data Protection Regulation is, which businesses it affects – and how – along with answers to some common questions frequently asked about the GDPR, and some steps you can take to move your business towards compliance.
We’ve put together a neat contents table to quickly jump to whatever it is you need to know about GDPR.
Table of Contents
- 1 In Plain English: Everything You Need to Know About the GDPR
- 2 Real-Life GDPR Compliance Examples
- 3 Big Questions About the General Data Protection Regulation
- 3.1 Will the GDPR affect me?
- 3.2 Will the GDPR apply after Brexit?
- 3.3 Will the GDPR replace the DPA?
- 3.4 Will the GDPR affect cold calling?
- 3.5 Will the GDPR be delayed?
- 3.6 Will the GDPR happen?
- 3.7 Will the GDPR affect B2B?
- 3.8 When will the GDPR come into effect?
- 3.9 What does the GDPR mean for marketing?
- 3.10 What does the GDPR mean for companies?
- 3.11 GDPR and Third-Party Data Processors
- 4 The Role of Data Protection Authorities (DPAs)
- 5 Recent GDPR Enforcement Actions
- 6 Impact of GDPR on Website Performance
- 7 Abandonment of Proposed EU Technological Regulations
- 8 How to Minimise the Impact of the GDPR on Your Business
- 9 Understanding Lawful Basis for Data Processing
- 9.1 What is Meant by Lawful Bases for Processing?
- 9.2 Using Customer Consent as a Basis to Process Data
- 9.3 Processing Children’s Data
- 9.4 Reporting Data Breaches
- 9.5 Data Protection Impact Assessments (DPIA) and Data Protection by Design and Default
- 9.6 Data Protection Officers
- 9.7 International Organisations and the GDPR
In Plain English: Everything You Need to Know About the GDPR
We’ve seen how technology is disrupting industries both old and new: Uber and Lyft are disrupting transport, Netflix is disrupting how movies and TV shows are produced and consumed, and AI is threatening to disrupt every single industry in ways we never before thought possible. But technology also disrupts the laws and regulations implemented by countries, with the GDPR designed to replace a modern directive that itself was no longer sufficient: Directive 95/46/EC (a data protection directive).
The General Data Protection Regulation is, obviously, centred around data protection, but it doesn’t regulate all data protection. Instead, it is focused on the personal data of individuals, specifically individuals residing in any EU member state. It updates existing – and introduces new – regulations relating to the collection and processing of the personal data of any individual residing in any EU member state. And it doesn’t only apply to businesses and organisations with a physical presence in any EU member state. Businesses and organisations throughout the world will need to be compliant with the GDPR if they collect and process the personal data of any individuals residing in the EU.

Get the date in your calendar!
The purpose of the regulations is not to make it more difficult for businesses to sell, market, or perform any of their normal business functions. Instead, it is designed to give individuals greater control over who collects and processes their personal data, what it is used for, and how it is kept safe.
It does this by first differentiating between personal data and sensitive personal data, with personal data being any information which makes it possible to identify an individual – either directly, or indirectly. It includes data such as names, identification numbers, location data, and online identifiers. Sensitive personal data also makes it possible to identify an individual, but through an expanded scope of specific factors, including elements of their physical appearance, physiology, genetics, mental health, economic, cultural, or social identity. The collection and processing of sensitive personal data is not allowed, except under very specific circumstances, with additional requirements in terms of data safety.
Next, the GDPR refines the principle of consent, requiring:
- The explicit consent of individuals.
- The elimination of blanket consent, consent by default, and consent as a condition of sale, service, or general terms and conditions.
- The ability for individuals to easily withdraw consent.
There are provisions within the GDPR for times when consent is not necessary, but these all relate to very specific lawful bases for collecting and processing personal data.
The GDPR then clarifies the rights of individuals in terms of their personal data, broken down as follows:
- The right to be informed, typically covered by your privacy notice. Detailed information regarding who is collecting and processing the personal data, along with how it will be used, must be freely available, and written in clear, plain language.
- The right of access. Individuals can request confirmation from you that their data is being processed. They can also request a copy of all their information that you hold, along with any supplementary information. It should be provided free of charge, and within one month of the request being made.
- The right to rectification. Individuals can request you to correct any incomplete or inaccurate information that you hold, with you then being responsible for passing the corrected information onto any third-parties you previously shared the data with.
- The right to erase. This is not an absolute right to be forgotten, but rather a provision for individuals to request the deletion of their data by you when there is no longer a legitimate reason for you to continue processing it, or they withdraw their consent.
- The right to restrict processing. Under certain circumstances, individuals can request that the further processing of their data be restricted. This is different to the right to erase in that you are still permitted to store some personal data, just not process it further.
- The right to data portability allows individuals to obtain their data from you, and reuse it for their own purposes across other services. However, this only applies in circumstances where the individual provided a controller with their personal data, typically during the performance of a contract application.
- The right to object. Unless you have compelling legitimate reasons to process an individual’s data, they retain the right to object to processing for a number of reasons.
- Rights in relation to automated decision making and profiling. The GDPR requires that safeguards be put in place for any automated processing and decision making, to minimise the risk of any damaging or adverse decisions being made without the possibility of human intervention, or the ability to seek an explanation.
The GDPR goes into great detail in relation to accountability and governance within businesses and organisations. This addresses matters such as:
- The implementation of measures that ensure and demonstrate compliance. This may include internal data protection policies such as staff training, internal audits of processing activities, and reviews of internal HR policies.
- Maintaining relevant documentation of all processing activities.
- Identifying whether your organisation is a data processor, a data controller, or both. You need to understand the purpose and requirements of these distinct roles in terms of the GDPR, and where appropriate, you may need to appoint a data protection officer.
- The implementation of measures that satisfy the principles of data protection by design, and data protection by default. This could include:
- data minimisation
- pseudonymisation or anonymisation of data
- the ability for individuals to monitor the processing of their data
- ongoing improvement of security features
Real-Life GDPR Compliance Examples
Real-life case studies provide valuable insights into how companies have navigated GDPR compliance. For instance, Microsoft embraced the regulations proactively, integrating GDPR standards into their global privacy practices. This approach focused on building customer trust, with initiatives such as strengthening their privacy tools across platforms and offering transparency reports.
Another example is IBM, which implemented comprehensive data governance frameworks to ensure compliance across its various international branches. They invested in staff training and revised their data management policies, highlighting how comprehensive internal processes can support compliance. These examples illustrate the importance of embedding GDPR principles into company culture and leveraging them as a competitive advantage.
Finally, the GDPR introduces new requirements for how personal data is processed to ensure security, along with requirements for how businesses and organisations need to respond to data breaches.
It is important to remember that the GDPR does not affect all businesses and organisations, only those who collect and/or process personal data, either of their clients, or on behalf of another organisation. If you don’t collect or process any personal data of individuals, you have nothing to worry about. And if you do, the primary matter you should be concerned about, is ensuring that you are fully compliant with the requirements of the GDPR. The GDPR should in no way prevent your business from continuing to operate, though it may force you to change some of your processes, making it more difficult to perform some tasks, but never making it impossible to operate.
The heavy fines possible under the GDPR are not meant to harm businesses, but rather to serve as a deterrent against relevant businesses and organisations from ignoring the regulations, and putting the personal data of individuals at risk.
But as with any new regulation, we will have to wait until it is enforced, and new case law established, to ascertain any true material impact on organisations, and individuals, and whether or not this will change over time.
Big Questions About the General Data Protection Regulation

Will the GDPR affect me?
The short answer is, yes. As an individual, the GDPR prescribes when and how organisations and companies can process or control any personally identifiable data relating to you. And if you are part of an organisation or business that processes or controls personal data of any EU individual, the GDPR prescribes when you may do this, and how you should do this. That means that the GDPR doesn’t only apply to businesses and organisations with a physical presence in any EU member state, but also those that offer goods or services to citizens of any EU member state, even if they have no physical presence in the EU.
Will the GDPR apply after Brexit?

The GDPR will still apply after Brexit, because the GDPR is designed to regulate how any business or organisation processes and controls the personal data of any EU citizen, regardless of where the business or organisation is based. Additionally, the UK Data Protection Bill was introduced to the House of Lords on 13 September 2017. The Data Protection Bill replaces the Data Protection Act, and it not only ensures implementation of GDPR standards when it comes to data processing and control, but also governs UK specific requirements. This includes agreed modifications in areas such as academic research, financial services and child protection.
Will the GDPR replace the DPA?
Yes, and no. In the short-term, the General Data Protection Regulation (GDPR) does replace the Data Protection Act of 1998 (DPA). But Britain is also preparing for Brexit, and while the GDPR regulates the protection of data of any EU citizen, after Brexit there will be a need regulating data protection of UK citizens too. The UK Data Protection Bill was introduced in 2017, and comes into effect in May 2018. The bill applies the same standards as GDPR, while clarifying the context of some GDPR definitions within a UK context.
The Data Protection Act 1998 (c 29) is a United Kingdom Act of Parliament designed to protect personal data stored on computers or in an organised paper filing system.
Will the GDPR affect cold calling?

The General Data Protection Regulation (GDPR) will most definitely affect all forms of cold calling, including cold email marketing. The GDPR sets a high standard for consent, placing an emphasis on leaving the individual (the prospect/customer) in control, and building trust and engagement.
Proper consent under the GDPR means the following:
- Consent must be explicit, and via a positive opt-in. This means you can no longer use consent by default, consent as a condition of sale or service, or even pre-ticked consent boxes on forms.
- Consent cannot be vague. The individual must give a specific statement of consent, while knowing what they are consenting to, and who they are giving consent to. If any third-party controllers will also be relying on the individual’s consent, they must be named.
- Consent should be separate from any other terms and conditions.
- Evidence of consent must be recorded and retained. This includes records of who, when, how, and what.
- It must be easy for individuals to withdraw consent, and they must be informed of how they can withdraw consent.
You should regularly review your records of consent, making sure nothing has changed in terms of the relationship, the processing of the data, or the purpose of the consent. Refresh as necessary.
Will the GDPR be delayed?
Any delay in the enforcement of the GDPR is highly unlikely. The GDPR was approved by the EU Parliament in 2016, with member states given two years to prepare for enforcement.
Will the GDPR happen?
The GDPR was approved by the EU Parliament in 2016, with enforcement coming into effect on 25 May 2018. Any delay in the enforcement of the GDPR is highly unlikely, with the prospect of Brexit also not offering any reprieve.
Will the GDPR affect B2B?

The GDPR specifically applies to individuals, so in the context of B2B relationships – existing and new – the impact of GDPR will depend on the contact information you use to communicate with your B2B clients. Whenever your contact information includes personal data, you would need to follow the regulations relating to explicit – and recorded – consent to opt-in. This would extend to also include regulations regarding data protection.
If, however, your records only include generic contact information (a contact number or email address with no name attached) you don’t necessarily have to record explicit consent, but you must make it easy for the company or organisation to opt-out, and keep a record of this.
When will the GDPR come into effect?
The GDPR was approved by the EU Parliament in 2016, with enforcement coming into effect on 25 May 2018. Any organisations found to be non-compliant after this date could face heavy fines.
What does the GDPR mean for marketing?

The GDPR is not a death knell for marketing, it is simply a way of regulating certain aspects of marketing. It doesn’t kill off direct marketing, it merely hands control of direct marketing to individuals. This means that marketers now need to ensure that they have explicit consent from individuals to market to them directly (be it via phone calls, email campaigns, or even direct mailing). It means marketers now need to inform individuals:
- Who will be marketing to them (company or organisation name). If any third-party controllers will also be using the individual’s personal data, they too must be named.
- How their personal information will be used, and what it will be used for.
- That they can opt-out at any time, while also explaining the process for opting out.
Marketers also need to understand that blanket consent is no longer allowed. Under the GDPR, individuals give consent for a specific campaign or purpose, and should that campaign or purpose change, they need to give consent again. If your customer gives consent to receive marketing communications relating to your range of lawn furniture, you cannot suddenly switch to marketing your new range of bathroom products to them.
What does the GDPR mean for companies?
Companies and organisations collecting and processing the personal data of individuals residing in the EU, regardless of the company’s physical location, need to be aware of the following:
- The GDPR clearly defines different roles to controllers and processors. Data processors carry out the actual processing of personal data, while data controllers specify why and how personal data is processed. Data controllers are also responsible for ensuring that data processors adhere to all the requirements of the GDPR.
- Some companies and organisations are required to also appoint a Data Protection Officer(DPO). The Article 29 Working Party has published separate guidelines on DPOs, along with some helpful FAQs.
- The GDPR explicitly holds third-party data processors liable for compliance alongside data controllers. Organisations must ensure that contracts with third-parties include specific clauses that address GDPR requirements, such as data protection measures, breach notification protocols, and specific instructions regarding data handling activities.
This necessitates thorough due diligence when selecting third-party vendors, ensuring they adhere to the same standards. Regular audits and assessments can help verify ongoing compliance, fostering a secure data processing environment. These stipulations highlight the necessity for well-defined contractual agreements that establish the responsibilities and expectations of all parties involved.
- Companies and organisations are required to obtain – and record – an individual’s explicit consent for the personal data to be stored and used. They also need to explain to the individual how the personal data will be used.
- Data breaches that are likely to result in a risk to the rights and freedoms of individuals need to be reported to the relevant supervisory authority within 72-hours. When a data breach is likely to result in a high risk to the rights and freedoms of individuals, those affected need to be notified directly.
- Individuals have the right to request a copy of their personal data and supplementary information, as processed by any company or organisation. This allows individuals to be aware of, and to verify the lawfulness of the processing.
- The GDPR provides individuals with a right to erasure, sometimes referred to as a right to be forgotten. The allows individuals to request the deletion or removal of their personal data where there is no valid or compelling reason for it to continue being processed. The right is not absolute, and companies and organisations can refuse to delete data under certain circumstances.
- Data portability gives individuals the right to obtain and reuse their personal data across different services. This allows individuals to move, copy, or transfer their own personal data from one environment to another, for a number of reasons.
- While privacy by design has always been an implicit requirement of data protection, under the GDPR, companies and organisations are now obliged to implement measures to integrate data protection with data processing activities.
GDPR and Third-Party Data Processors
The Role of Data Protection Authorities (DPAs)
Data Protection Authorities (DPAs) are crucial in enforcing GDPR. These bodies are responsible for monitoring compliance, conducting investigations, and enforcing the law with fines and corrective measures as necessary. Each EU member state has its own DPA, which operates under a cooperative network called the European Data Protection Board (EDPB).
Authorities provide guidance on interpreting GDPR, offering businesses insights into best practices and compliance frameworks. They ensure organisations understand their obligations under GDPR, helping prevent breaches and mitigate risks associated with data processing. Through collaboration, DPAs also help maintain a uniform application of GDPR across Europe, providing a consistent approach to data protection.
What does the GDPR mean for HR?

Articles 6(1)(c) and (e) of the GDPR allows member states to introduce more specific provisions in terms of the lawful bases for processing of personal data. At least one of six conditions must be met, with two specific conditions being that:
- “(c) processing is necessary for compliance with a legal obligation”;
- “(e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.”
This suggests that processing personal data of employees for certain legitimate HR operations do not require explicit consent. However, all other aspects of the GDPR in terms of personal data would still apply, including:
- How and what the data is used for.
- Privacy by design.
- Data portability and right to erasure.
- Use of personal data by third-parties.
Recent GDPR Enforcement Actions
In 2024 and early 2025, there was a significant uptick in GDPR enforcement actions. A notable instance is the €345 million fine imposed by the Irish Data Protection Commission (DPC) on TikTok. This was due to violations concerning children’s data privacy, highlighting insufficient safeguards for young users.
In January 2025, Meta faced a colossal €1.2 billion fine for unlawful data transfers between the EU and the US, making it one of the largest GDPR fines to date. These actions reflect the increased scrutiny and enforcement strategy being employed by data protection authorities, showing a commitment to upholding the privacy rights delineated under GDPR.
Who does the GDPR apply to?
The GDPR applies to all companies and organisations collecting and processing the personal data of individuals residing in the EU, regardless of the company’s physical location. This means the regulations are enforceable on any business, even those with no physical presence in any EU member state.
Are GDPR fines insurable?
There is no definitive answer to this question yet, but the current view of brokers is that fines relating to the GDPR are unlikely to be insurable. And with fines of up 4 percent of a company’s annual global turnover being possible, any non-compliance with the GDPR can end up being very costly to any organisation. Proper guidance will only be possible once the new legislation comes into effect, and new case law has been established. However, specialist cyber insurance policies could cover the costs associated with a data breach, such as compensation claims, legal costs, notification and reputation management, etc.
How will the GDPR affect US companies?

The GDPR applies to all companies and organisations collecting and processing the personal data of individuals residing in the EU, regardless of the company’s physical location. As such, US companies – and companies in other countries around the world – are still expected to comply with the new regulations if any of the personal data they collect and process is that of resident of an EU member state. This remains true even if the company does not have any physical presence in any EU member state. While the GDPR is unlikely to affect a small florist in Rock Springs, Wyoming, any business – US based, or other – collecting and processing personal data of EU residents will need to put measures in place in order to comply with the GDPR. This includes, amongst others, ensuring:
- Explicit, recorded consent to collect and process the personal data of the individual.
- Clear explanation of how and what the data the data will be used for.
- Privacy by design, along with compliance relating to data breaches.
- Support for data portability and right to erasure.
- Compliance with the GDPR requirements for the use of personal data by third-parties.
Many businesses are used to using landing pages and newsletter subscription forms to build out their customer database. Under the GDPR, this will no longer be acceptable when it comes to the personal data of EU residents, because blanket consent is no longer allowed. The GDPR only recognises explicit consent being given for a specific purpose, which must be stated when the individual gives consent. If an EU resident signs up for your weekly email newsletter, they will be giving explicit consent to receive just that: a weekly email newsletter. You cannot later switch to sending them daily deals via email, because they did not consent to that. Whenever the purpose of collecting and processing personal data changes, new consent must be given.
How does the GDPR change the rules for research?
The GDPR makes provision for organisations that collect and process personal data for research purposes, though we will have to wait until the GDPR is enforced to see whether these are sufficient, or whether they have been too loosely interpreted. The GDPR allows for the collecting and processing of personal data without consent, but only for specified lawful purposes. In terms of research, Articles 9 of the GDPR make specific mention of health, social care, scientific research, and historical research. What would still apply in all cases are the requirements in terms of data protection, privacy, and data breaches, which are less stringent when the data has been anonymised to such a degree that data subjects are no longer identifiable.
Impact of GDPR on Website Performance
A study conducted in 2024 revealed that GDPR has had tangible effects on website performance metrics. Specifically, the regulations have led to a 12% reduction in both EU user website page views and overall website revenue. This impact is attributed to the stringent data protection measures that have altered how user data is handled, affecting site analytics and personalised marketing strategies.
For marketers and businesses, this highlights the importance of balancing regulatory compliance with effective engagement strategies that do not compromise user experience.
How does the GDPR affect data science?

The key areas within data science that will be impacted by the GDPR include:
- The ability to collect data. Consent – and being informed of why the data is being collected, and how it will be processed – are important considerations here. The provisions for the lawful bases for processing data do have specific requirements that won’t apply in all circumstances, or to all organisations.
- The ability to use data. Where consent has been granted, it is important to remember that the consent applies to the data being processed as originally communicated to individuals. If the purpose of collecting and processing changes, new consent must be given. At the same time, individuals have the right to block processing, object to processing, and the right to erasure, which can impact, or limit, the results of data science-related processing.
