
General Data Protection Regulation
The General Data Protection Regulation is a European Union law that governs how companies and authorities are allowed to handle people's personal data. It has applied in all EU countries since 2018 and allows fines of up to four percent of worldwide annual revenue.
The General Data Protection Regulation is a law of the European Union. It sets out what companies and authorities are allowed to do with data about individual people. This means any information that relates to a specific person: name, address, date of birth, photos, location, purchase history, or the number under which a device can be reached on the internet. The law has applied since May 2018, simultaneously in all member states. It is usually abbreviated as GDPR, or DSGVO in German. The basic idea is simple: your data belongs to you, and anyone who wants to use it needs a good reason.
Why a European law applies worldwide
Before 2018, every EU country had its own data protection rules. Companies therefore liked to pick the country with the loosest requirements. The GDPR put an end to this evasion by setting the same rules everywhere. Also decisive is the so-called market-location principle. It states that the law applies to any company that has people in Europe as customers, no matter where its headquarters is located.
That is why American and Chinese corporations also have to comply with it. This is exactly what makes the GDPR a topic in business news. The fines are high enough to hit even large corporations: up to 20 million euros or four percent of worldwide annual revenue, whichever is higher. In 2023, Meta had to pay around 1.2 billion euros because European user data flowed to the US without authorization.
For AI companies, the regulation is particularly delicate. Language models are trained on huge amounts of text from the internet, and this inevitably contains information about real people. Italy temporarily blocked ChatGPT in 2023 for exactly this reason. The GDPR is not the same as the EU AI Act: one protects personal data, the other regulates AI systems according to their risk. A company can violate both at the same time.
Permission, purpose, and the rights of those affected
The law reverses the usual logic. Data processing is fundamentally prohibited unless there is a permission for it. The regulation names six such permissions. The best known is consent, meaning your active yes. Others are a contract, a legal obligation, or a legitimate interest of the company.
On top of that come a few basic principles. Data may only be collected for a purpose defined in advance. You may not collect more than is necessary for that purpose. And you must delete it once the purpose has been fulfilled. An online shop needs your address for shipping, but not your political opinion.
On the other side stand your rights. You are allowed to find out what data a company has stored about you. You are allowed to correct false information and, in many cases, demand its deletion. You are also allowed to take your data with you in a common file format, for example when switching to another provider. A company usually has to respond to requests of this kind within one month.
Cookie banners, school software, and data breaches
The GDPR is most visible in the consent pop-ups that appear when you open a website. They ask whether small text files called cookies are allowed to track your behavior. Legally, these banners originate from an older directive, but the GDPR determines what valid consent must look like. Declining must be just as easy as accepting. Many banners still fail to meet this requirement today and are therefore flagged by supervisory authorities.
The topic also comes up in schools. Whether a learning platform or a video conferencing service may be used often depends on where the data is stored. A common misconception, by the way, is that the GDPR prohibits transferring data to the US. That is not true. Such transfers are allowed, but they require additional legal safeguards.
In the news, you usually encounter the term in connection with data breaches. If a customer database is hacked, the company must inform the supervisory authority within 72 hours. In cases of high risk, those affected must also be notified. This is exactly why the public now learns about security incidents that in the past would have quietly gone unmentioned.