The General Data Protection Regulation (GDPR) is a comprehensive data privacy and data protection law that governs how organizations must collect, process, store and transfer the personal data of individuals in the European Union (EU). Through an European Economic Area (EEA) Joint Committee decision rendered on 6 July 2018, the GDPR was extended to cover the EEA.
The GDPR applies to all organizations in the EEA. Article 3 extends the GDPR to cover organizations outside the region that offer goods and services to people in the EEA or monitor their behavior there.applies
First entered into effect on 25 May 2018, the GDPR has become a benchmark for enterprise data governance, privacy engineering and responsible data management worldwide. Rather than undertake a one-time compliance project, companies bound by the GDPR should best view it as an ongoing operational capability.
Organizations that embed GDPR into governance, security and software development can better position themselves to adapt to new privacy regulations and AI governance requirements.
Join security leaders who rely on the Think Newsletter for curated news on AI, cybersecurity, data and automation. Learn fast from expert tutorials and explainers—delivered directly to your inbox twice weekly. See the IBM Privacy Statement.
The GDPR emerged out of a need to update Europe’s privacy laws to meet the demands of the digital economy. The region’s Data Protection Directive, in effect since 1995, no longer reflected the realities of large-scale digital data processing. Member states had also created their own systems for data protection, which the GDPR sought to rectify through a harmonized system.
In response to the rapid pace of technological development, the European Commission introduced a draft proposal in 2012 to both modernize and unify privacy laws among member states. The European Parliament and Council formally adopted the proposal in 2016, with the GDPR officially going into effect in 2018 after a two-year grace period. From then, organizations would face heavy penalties in response to insufficient data compliance.
GDPR rules apply uniformly across the EU and EEA. Each individual state is responsible for its own data protection authority (DPA), an independent public body that enforces the GDPR. By contrast, the US has no federal DPA. Each state creates and enforces its own privacy laws, such as the California Consumer Privacy Act (CCPA). However, any US company that processes the data of persons within the EU and EEA must comply with the GDPR.
“The regulation has inspired similar data protection laws in countries around the world. What started as a European rulebook has since become a global standard,” argues the European Commission in a blog post celebrating the 10-year anniversary of the legislation.
The GDPR establishes what type of information counts as personal data and the legal benchmarks organizations must meet to collect it. It also lays out the legal principles justifying its creation and enforcement.
Article 4 of the GDPR defines personal data as “any information relating to an identified or identifiable natural person.”
Examples of personal data include a person’s name, email address, IP address, device identifiers, location data, salary and online information. Together with the EU’s ePrivacy rules, the GDPR significantly increased the use of cookie consent mechanisms because many cookies collect personal data or online identifiers.
A special case of personal data is so-called special category data, such as a person’s race or ethnic origin, political opinions and biometric data. Special category data requires extra protections because of the risks associated with misuse.
The GDPR is designed to give data subjects agency over how entities collect and use their data. Its guiding principles include:
Lawfulness, fairness and transparency: Data collection should be regulated, reasonable and conducted openly.
Purpose limitation: Firms must have “specific, explicit and legitimate” purposes for collecting personal data and limit processing to those purposes.
Data minimization: Under the GDPR, organizations cannot collect any personal data beyond what is necessary for their purposes.
Accuracy: The GDPR requires organizations to keep personal data current and correct.
Storage limitation: Entities cannot hold onto personal data for longer than needed.
Integrity and confidentiality: Organizations must protect against unlawful data processing and ensure appropriate data security protections.
Accountability: Controllers must be able to demonstrate compliance with the other principles.
GDPR requirements extend to two types of organizations: data controllers and data processors. Data controllers actively collect personal data and decide how to use it. Data processors handle personal data, such as by storing it or editing it. The same organization can be both a controller and processor.
GDPR sets out six lawful bases that organizations can claim as justifications for processing personal data. Organizations have to prove that their activities meet one of these bases; otherwise the data processing is illegal.
The six lawful bases are:
Organizations must obtain a person’s consent before collecting their data. Consent must be freely and affirmatively given, and it must be done so on an informed basis.
Freely given consent means that the company cannot require the data subject to provide any data outside that which is necessary. The organization cannot attempt to coerce the data subject into providing data.
Affirmative consent means that the data subject is asked to opt in. Organizations cannot assume consent and expect the data subject to actively withdraw it. Companies cannot require that data subjectsprovide data unless that data is necessary for the service or transaction.
If an organization will use a subject’s data for multiple purposes, they must collect consent separately for each purpose. Data subjects must be able to withdraw consent at any time, and the company must stop processing their data at this point.
Informed consent means that the company must explain which data it is collecting and what it will do with it, such as through a privacy notice. The company should also explain how data subjects can control the use of their data. Purposes cannot be changed after acquiring consent.
Companies are allowed to collect personal data for the purposes of entering into or executing a contract, either with the subject or on their behalf.
Some organizations have a legal obligation to collect and process data. For example, healthcare providers and financial institutions are both required to keep records.
A situation of vital interest is one in which the subject’s data must be collected to protect them or avoid harm. Organizations can process personal data without consent in the interest of saving the data subject’s life.
Controllers can collect and process data in the public interest or under official authority, such as when collecting data during an election or in other official functions.
Data processing is permitted when it is necessary for a legitimate interest of the controller or a third party. The rights and freedoms of the data subject override the legitimate interests of the controller.
Legitimate interests must pass three criteria:
In addition to establishing how controllers and processors must handle data, the GDPR also lays out a set of rights[EXT] that apply to all “data subjects” in the EU and EEA. Under the GDPR, a data subject is the person to whom a piece of data relates. Data subjects need not be EU citizens—residency in the region is enough to qualify for GDPR protections, which include:
The GDPR creates a framework for enterprise-level data governance at scale. Controllers must implement the GDPR through a set of governance and accountability measures to ensure that personal data is kept safe and used lawfully. The GDPR obliges organizations to conduct data processing activities in accordance to a standardized set of procedures, including:
Companies must maintain comprehensive inventories of all the personal data they hold. These records form the basis of all ongoing compliance activities, most specifically the Records of Processing Activities (ROPA) requirement—though firms with fewer than 250 employes are exempt under some circumstances. Data inventories also facilitate the timely fulfillment of Data Subject Access Requests (DSARs).
The GDPR enshrines privacy-by-design and privacy-by-default as legally required standards. Privacy-by-design means that organizations must integrate data protections into their systems from the earliest stages of development. With privacy-by-default, organizations should collect and process only the personal data necessary for each specific purpose unless users choose otherwise.
A data protection impact assessment (DPIA) is an assessment that companies must conduct ahead of any processing that is “likely to result in a high risk to the rights and freedoms of individuals.” Any unmitigated risks must be addressed through a consultation with the relevant DPA.
The GDPR mandates various data protections that companies must implement to maintain compliance. Organizational security includes employee training and formal data governance policies, while technical security covers software and hardware tools such as data encryption.
After a data breach, organizations must submit a report within 72 hours to the relevant supervisory authority. Should the personal data breach put data subjects at risk, the organization must also directly notify anyone whose data was compromised. A public announcement is typically ruled as insufficient notification.
The GDPR mandates that some types of organizations must appoint data protection officers (DPOs) to oversee GDPR compliance. All public authorities and other entities whose core activities involve regular and systemic large-scale monitoring, especially with special category and criminal defense data, must appoint a DPO.
Organizations cannot impede or retaliate against DPOs. Some organizations located outside the EEA might need to appoint a legal representative within the region to handle similar responsibilities if they process the data of EU residents.
Controllers assume full responsibility for all personal data shared with other parties, such as processors, who are forbidden from using the data for their own purposes. Such cooperation is typically regulated through legally binding contracts known as data processing agreements (DPAs).
The GDPR strictly regulates data transfers to countries outside the EEA. Transfers are limited to entities in “third countries” with sufficient privacy protections, or to specific parties with appropriate safeguards. Sometimes, such as with binding corporate rules (BCRs), the GDPR might allow for transfers to other organizations if the controller can guarantee protection.
For many organizations operating in Europe, GDPR compliance is a foundational component of a broader digital sovereignty strategy. The GDPR establishes privacy as a foundational element of digital trust. Data subjects are more likely to feel good about entrusting their data to organizations that can demonstrate a comprehensive commitment to keeping their information safe.
Modern organizations are increasingly elevating digital sovereignty to a strategic pillar. This shift is driven in part by the need to maintain control over where data resides, who can access it and how it is governed across jurisdictions. Strong data sovereignty grants organizations full control over data at rest, in use and in motion.
The intersection between the GDPR and digital sovereignty extends beyond data controls. A digitally sovereign organization also maintains control over its operational resilience, regulatory compliance, cybersecurity and critical digital infrastructure. All these factors directly affect GDPR compliance.
To achieve sovereignty, organizations need to maintain both visibility and control over their data, workloads and encryption, regardless of where those operations physically take place. This control helps achieve regulatory compliance while also facilitating business flexibility.
As organizations increasingly deploy artificial intelligence (AI) across business operations, the GDPR stands as a foundational legal framework governing the responsible use of personal data in AI systems.
Any AI systems that process personal data are subject to the GDPR. AI systems also fall under the automated decision-making and profiling requirements if used in those capacities, such as with AI-powered recruitment automation.
Organizations who are training or deploying AI systems that process personal data must still comply with GDPR principles such as data minimization, purpose limitation and lawful processing. Observable and explainable AI systems make it easier for organizations to prove compliance when needed.
The GDPR works alongside the EU AI Act to regulate AI use. While the GDPR addresses data privacy, its newer counterpart is concerned with the risks surrounding AI use.
While the GDPR as described above is current law, several changes have been proposed, which would streamline some aspects of the GDPR while making others more flexible. The proposal is currently under consideration by the European Parliament and Council.
Among its suggested changes are:
As of this writing in August 2026, these proposals have not been implemented into the GDPR.
Operationalize trustworthy AI by monitoring models, managing risk and enforcing governance across your AI lifecycle.
Gain control of your data with governance tools that improve quality, ensure compliance and enable trusted analytics and AI.
Establish responsible AI practices with expert guidance to manage risk, meet regulations and operationalize trustworthy AI at scale.