AI-Ready Data Learn how to make your data ready for AI agents | Register now
A line of European Union flags

What is the GDPR?

The GDPR, defined

The General Data Protection Regulation (GDPR) is a comprehensive data privacy and data protection law that governs how organizations must collect, process, store and transfer the personal data of individuals in the European Union (EU). Through an European Economic Area (EEA) Joint Committee decision rendered on 6 July 2018, the GDPR was extended to cover the EEA.

The GDPR applies to all organizations in the EEA. Article 3 extends the GDPR to cover organizations outside the region that offer goods and services to people in the EEA or monitor their behavior there.applies

First entered into effect on 25 May 2018, the GDPR has become a benchmark for enterprise data governance, privacy engineering and responsible data management worldwide. Rather than undertake a one-time compliance project, companies bound by the GDPR should best view it as an ongoing operational capability.

Organizations that embed GDPR into governance, security and software development can better position themselves to adapt to new privacy regulations and AI governance requirements.

Why was the GDPR created?

The GDPR emerged out of a need to update Europe’s privacy laws to meet the demands of the digital economy. The region’s Data Protection Directive, in effect since 1995, no longer reflected the realities of large-scale digital data processing. Member states had also created their own systems for data protection, which the GDPR sought to rectify through a harmonized system.

In response to the rapid pace of technological development, the European Commission introduced a draft proposal in 2012 to both modernize and unify privacy laws among member states. The European Parliament and Council formally adopted the proposal in 2016, with the GDPR officially going into effect in 2018 after a two-year grace period. From then, organizations would face heavy penalties in response to insufficient data compliance.

GDPR rules apply uniformly across the EU and EEA. Each individual state is responsible for its own data protection authority (DPA), an independent public body that enforces the GDPR. By contrast, the US has no federal DPA. Each state creates and enforces its own privacy laws, such as the California Consumer Privacy Act (CCPA). However, any US company that processes the data of persons within the EU and EEA must comply with the GDPR.

“The regulation has inspired similar data protection laws in countries around the world. What started as a European rulebook has since become a global standard,” argues the European Commission in a blog post celebrating the 10-year anniversary of the legislation.

What is AI Data Management?

Discover, Clean, & Secure Data with AI

Discover how AI Data Management tackles shadow data, poor data quality, and security risks, using AI-powered classification, natural language queries, and anomaly detection to unlock insights and streamline operations.

How does the GDPR work?

The GDPR establishes what type of information counts as personal data and the legal benchmarks organizations must meet to collect it. It also lays out the legal principles justifying its creation and enforcement.

Personal data under the GDPR

Article 4 of the GDPR defines personal data as “any information relating to an identified or identifiable natural person.”

Examples of personal data include a person’s name, email address, IP address, device identifiers, location data, salary and online information. Together with the EU’s ePrivacy rules, the GDPR significantly increased the use of cookie consent mechanisms because many cookies collect personal data or online identifiers.

A special case of personal data is so-called special category data, such as a person’s race or ethnic origin, political opinions and biometric data. Special category data requires extra protections because of the risks associated with misuse.

Key GDPR principles

The GDPR is designed to give data subjects agency over how entities collect and use their data. Its guiding principles include:

  • Lawfulness, fairness and transparency: Data collection should be regulated, reasonable and conducted openly.

  • Data minimization: Under the GDPR, organizations cannot collect any personal data beyond what is necessary for their purposes.

  • Accuracy: The GDPR requires organizations to keep personal data current and correct.

  • Storage limitation: Entities cannot hold onto personal data for longer than needed.

  • Integrity and confidentiality: Organizations must protect against unlawful data processing and ensure appropriate data security protections.

  • Accountability: Controllers must be able to demonstrate compliance with the other principles.

    GDPR requirements extend to two types of organizations: data controllers and data processors. Data controllers actively collect personal data and decide how to use it. Data processors handle personal data, such as by storing it or editing it. The same organization can be both a controller and processor.

     

    Lawful bases for processing data

    GDPR sets out six lawful bases that organizations can claim as justifications for processing personal data. Organizations have to prove that their activities meet one of these bases; otherwise the data processing is illegal.

    The six lawful bases are:

    • Consent

    • Contract

    • Legal obligation

    • Vital interest

    • Public task

    • Legitimate interests

    Consent

    Organizations must obtain a person’s consent before collecting their data. Consent must be freely and affirmatively given, and it must be done so on an informed basis.

    Freely given consent means that the company cannot require the data subject to provide any data outside that which is necessary. The organization cannot attempt to coerce the data subject into providing data.

    Affirmative consent means that the data subject is asked to opt in. Organizations cannot assume consent and expect the data subject to actively withdraw it. Companies cannot require that data subjectsprovide data unless that data is necessary for the service or transaction.

    If an organization will use a subject’s data for multiple purposes, they must collect consent separately for each purpose. Data subjects must be able to withdraw consent at any time, and the company must stop processing their data at this point.

    Informed consent means that the company must explain which data it is collecting and what it will do with it, such as through a privacy notice. The company should also explain how data subjects can control the use of their data. Purposes cannot be changed after acquiring consent.

    Contract

    Companies are allowed to collect personal data for the purposes of entering into or executing a contract, either with the subject or on their behalf.

    Legal obligation

    Some organizations have a legal obligation to collect and process data. For example, healthcare providers and financial institutions are both required to keep records.

    Vital interest

    A situation of vital interest is one in which the subject’s data must be collected to protect them or avoid harm. Organizations can process personal data without consent in the interest of saving the data subject’s life.

    Public task

    Controllers can collect and process data in the public interest or under official authority, such as when collecting data during an election or in other official functions.

    Legitimate interests

    Data processing is permitted when it is necessary for a legitimate interest of the controller or a third party. The rights and freedoms of the data subject override the legitimate interests of the controller.

    Legitimate interests must pass three criteria:

    • Purpose test: identify why the data must be processed.

    • Necessity test: identify whether the personal data is integral to the activity described in the purpose test. 

    • Balancing test: consider whether the rights of affected individuals override the legitimate interest.

    What rights does the GDPR give individuals?

    In addition to establishing how controllers and processors must handle data, the GDPR also lays out a set of rights[EXT] that apply to all “data subjects” in the EU and EEA. Under the GDPR, a data subject is the person to whom a piece of data relates. Data subjects need not be EU citizens—residency in the region is enough to qualify for GDPR protections, which include:

    • The right to be informed: Data subjects have a right to know who is collecting their data, how they are doing so and why.

    • The right of access: Data subjects have the right to access their data from any entity possessing it.

    • The right to rectification: Data subjects can update or correct any personal data.

    • The right to erasure (right to be forgotten): Data subjects have the right to request the deletion of their data. Companies must comply unless required otherwise.

    • The right to restrict processing: Data subjects can request that controllers limit the processing of their data, such as if it is incorrect or not required for the company’s purposes. Controllers must comply unless their interests supersede the request.

    • The right to data portability: Data subjects can move their data between organizations, who must provide the data in a sharable format or send it to another party as requested.

    • The right to object: Subjects can object to the processing of their data at any time. Controllers must concede unless they can prove that further processing is required.

    • Rights related to automated decision-making and profiling: Individuals have the right not to be subject to certain automated decisions that yield legal or other significant outcomes, with some limited exceptions. Subjects can appeal automated decisions with mandatory human review. 

    GDPR requirements for organizations

    The GDPR creates a framework for enterprise-level data governance at scale. Controllers must implement the GDPR through a set of governance and accountability measures to ensure that personal data is kept safe and used lawfully. The GDPR obliges organizations to conduct data processing activities in accordance to a standardized set of procedures, including:

    • Data inventories and processing records

    • Privacy by design and by default

    • Data protection impact assessments (DPIAs)

    • Security controls

    • Data breach notifications

    • Data protection officers (DPOs)

    • Data transfer procedure

    Data inventories and processing records

    Companies must maintain comprehensive inventories of all the personal data they hold. These records form the basis of all ongoing compliance activities, most specifically the Records of Processing Activities (ROPA) requirement—though firms with fewer than 250 employes are exempt under some circumstances. Data inventories also facilitate the timely fulfillment of Data Subject Access Requests (DSARs).

    Privacy by design and by default

    The GDPR enshrines privacy-by-design and privacy-by-default as legally required standards. Privacy-by-design means that organizations must integrate data protections into their systems from the earliest stages of development. With privacy-by-default, organizations should collect and process only the personal data necessary for each specific purpose unless users choose otherwise.

    Data protection impact assessments (DPIAs)

    A data protection impact assessment (DPIA) is an assessment that companies must conduct ahead of any processing that is “likely to result in a high risk to the rights and freedoms of individuals.” Any unmitigated risks must be addressed through a consultation with the relevant DPA.

    Security controls

    The GDPR mandates various data protections that companies must implement to maintain compliance. Organizational security includes employee training and formal data governance policies, while technical security covers software and hardware tools such as data encryption.

    Data breach notifications

    After a data breach, organizations must submit a report within 72 hours to the relevant supervisory authority. Should the personal data breach put data subjects at risk, the organization must also directly notify anyone whose data was compromised. A public announcement is typically ruled as insufficient notification.

    Data protection officers (DPOs)

    The GDPR mandates that some types of organizations must appoint data protection officers (DPOs) to oversee GDPR compliance. All public authorities and other entities whose core activities involve regular and systemic large-scale monitoring, especially with special category and criminal defense data, must appoint a DPO. 

    Organizations cannot impede or retaliate against DPOs. Some organizations located outside the EEA might need to appoint a legal representative within the region to handle similar responsibilities if they process the data of EU residents.

    Data transfer procedures

    Controllers assume full responsibility for all personal data shared with other parties, such as processors, who are forbidden from using the data for their own purposes. Such cooperation is typically regulated through legally binding contracts known as data processing agreements (DPAs).

    The GDPR strictly regulates data transfers to countries outside the EEA. Transfers are limited to entities in “third countries” with sufficient privacy protections, or to specific parties with appropriate safeguards. Sometimes, such as with binding corporate rules (BCRs), the GDPR might allow for transfers to other organizations if the controller can guarantee protection.

    The GDPR and digital sovereignty

    For many organizations operating in Europe, GDPR compliance is a foundational component of a broader digital sovereignty strategy. The GDPR establishes privacy as a foundational element of digital trust. Data subjects are more likely to feel good about entrusting their data to organizations that can demonstrate a comprehensive commitment to keeping their information safe.

    Data sovereignty

    Modern organizations are increasingly elevating digital sovereignty to a strategic pillar. This shift is driven in part by the need to maintain control over where data resides, who can access it and how it is governed across jurisdictions. Strong data sovereignty grants organizations full control over data at rest, in use and in motion.

    How the GDPR informs a sovereignty strategy

    The intersection between the GDPR and digital sovereignty extends beyond data controls. A digitally sovereign organization also maintains control over its operational resilience, regulatory compliance, cybersecurity and critical digital infrastructure. All these factors directly affect GDPR compliance.

    To achieve sovereignty, organizations need to maintain both visibility and control over their data, workloads and encryption, regardless of where those operations physically take place. This control helps achieve regulatory compliance while also facilitating business flexibility.

    The GDPR and AI

    As organizations increasingly deploy artificial intelligence (AI) across business operations, the GDPR stands as a foundational legal framework governing the responsible use of personal data in AI systems.

    Any AI systems that process personal data are subject to the GDPR. AI systems also fall under the automated decision-making and profiling requirements if used in those capacities, such as with AI-powered recruitment automation.

    Organizations who are training or deploying AI systems that process personal data must still comply with GDPR principles such as data minimization, purpose limitation and lawful processing. Observable and explainable AI systems make it easier for organizations to prove compliance when needed.

    The GDPR works alongside the EU AI Act to regulate AI use. While the GDPR addresses data privacy, its newer counterpart is concerned with the risks surrounding AI use.

    Will the GDPR be updated?

    While the GDPR as described above is current law, several changes have been proposed, which would streamline some aspects of the GDPR while making others more flexible. The proposal is currently under consideration by the European Parliament and Council.

    Among its suggested changes are:

    • Redefining the concept of “personal data” so that pseudonymized data will not count as personal data for entities who lack the means to re-identify the corresponding data subject.

    • Allowing companies to use personal data for AI training and operation under the “legitimate interest” legal basis.

    • Taking over the ePrivacy Directive’s cookie consent rules and expanding the list of data processing activities that do not require consent.

    • Allowing users to apply one-click consent for six months or as per their device preferences.

    • Streamlining DPIA and breach reporting requirements.

    As of this writing in August 2026, these proposals have not been implemented into the GDPR.

     

      Ivan Belcic

      Staff writer

      David Zax

      Staff Writer

      IBM Think

      Related solutions
      IBM watsonx.governance®

      Operationalize trustworthy AI by monitoring models, managing risk and enforcing governance across your AI lifecycle.

      Explore watsonx.governance
      Data governance solutions

      Gain control of your data with governance tools that improve quality, ensure compliance and enable trusted analytics and AI.

      Explore data governance solutions
      AI governance consulting

      Establish responsible AI practices with expert guidance to manage risk, meet regulations and operationalize trustworthy AI at scale.

      Explore AI governance consulting
      Take the next step

      Discover how IBM Sovereign Core empowers enterprises, governments and service providers with purpose-built sovereign software to create, deploy and manage AI-ready environments, while maintaining full autonomy over data, infrastructure and technology.

      1. Discover IBM Sovereign Core
      2. Explore digital sovereignty solutions