• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR)

Definition

General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) is the European Union’s law on data privacy, governing how any organization collects, uses, stores, and transfers personal data of EU residents. It took effect May 25, 2018, and applies to anyone handling that data globally.

Any business that processes EU personal data falls under GDPR’s reach, whether it’s an outsourcing partner, cloud vendor, e-commerce site, or offshore business process outsourcing provider. Location of servers or staff doesn’t matter.

Fines are the sharpest edge of the rule. Regulators can levy penalties up to €20 million or 4% of a company’s global annual turnover — whichever is higher — plus reputational damage and lost contracts.

Outsourcing amplifies the risk. When a controller hires a processor (an outsourcing vendor) that ships personally identifiable information across borders, both parties carry obligations under Articles 28 and 46. The controller stays legally accountable.

Key takeaways

  • GDPR took effect May 25, 2018 as the European Union’s core data-privacy law.
  • The rule applies to any organization worldwide handling personal data of EU residents.
  • Fines reach up to €20 million or 4% of global annual turnover, whichever is higher.
  • Seven principles cover lawfulness, transparency, minimisation, accuracy, storage, security, and accountability.
  • Outsourcing buyers stay liable when a vendor breaches, since vendor slips attach to the controller.

How it works

GDPR sets seven principles for handling personal data and grants EU residents eight rights over it. Any controller or processor must document a lawful basis, minimise what it collects, secure it, and report breaches within 72 hours.

The rule is codified in EU Regulation 2016/679 and enforced by national data protection authorities in each member state, backed by the European Commission’s data protection framework.

GDPR principlePractical obligation
LawfulnessHave a valid legal basis (consent, contract, legitimate interest) before processing.
Purpose limitationUse data only for the reason stated at collection.
Data minimisationCollect the smallest set of fields needed.
AccuracyKeep records correct and current; fix errors on request.
Storage limitationDelete or anonymise data once its purpose ends.
Integrity and securityEncrypt, restrict access, and log processing activity.
AccountabilityDocument compliance and prove it on demand.

Cross-border data transfers need extra work. Sending EU personal data outside the bloc requires an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules.

After the 2020 Schrems II ruling, a documented transfer impact assessment is also required for exports to third countries, as clarified by the European Data Protection Board.

The scale is real. According to gdpr.eu, penalties can reach 4% of global annual turnover or €20 million (whichever is higher) — a threshold Meta hit in 2023 with a record €1.2 billion fine from Ireland’s Data Protection Commission.

Examples

GDPR enforcement bites regardless of size or country. From tech giants to European telecoms and offshore outsourcers, regulators have levied nine- and ten-figure fines when consent, transparency, or transfer safeguards fell short.

  • Meta Platforms (Ireland, 2023): the Irish Data Protection Commission fined Meta €1.2 billion for illegally transferring Facebook user data from the EU to the United States, the largest GDPR penalty on record.
  • Amazon (Luxembourg, 2021): Luxembourg’s National Commission for Data Protection fined Amazon €746 million for GDPR consent violations tied to targeted advertising.
  • Google (France, 2019): France’s National Commission on Informatics and Liberty (CNIL) fined Google €50 million for insufficient GDPR consent transparency when new Android users set up accounts.
  • British Airways (United Kingdom, 2020): the Information Commissioner’s Office fined British Airways £20 million under GDPR after a 2018 breach exposed personal and payment data of roughly 400,000 customers.

Related terms

  • Data protection: the technical and procedural safeguards that keep personal data secure and compliant.
  • Data privacy: the broader discipline of shielding personal information from misuse.
  • Compliance: the broader obligation of meeting laws and standards.
  • Data breach: the incident type GDPR requires reporting within 72 hours.
  • Data security: the technical controls (encryption, access management) GDPR requires under its integrity principle.

FAQ

Does GDPR apply to companies outside the European Union?

Yes. GDPR applies to any organization anywhere in the world that processes the personal data of people located in the EU, whether the business is European or not. Territorial scope is set out in Article 3.

What is the maximum GDPR fine?

Regulators can impose fines up to €20 million or 4% of a company’s worldwide annual turnover, whichever is higher. Meta received the record penalty of €1.2 billion in 2023 from Ireland’s Data Protection Commission.

How does GDPR affect outsourcing to non-EU countries?

Sending EU personal data to a non-EU country requires a lawful transfer mechanism, such as an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules. Buyers stay liable when a vendor breaches the standard, so vendor due diligence is essential.

Who enforces GDPR?

Each EU member state has its own Data Protection Authority, such as Ireland’s Data Protection Commission, France’s CNIL, and Germany’s BfDI. The European Data Protection Board coordinates their decisions across the bloc.

What are the seven principles of GDPR?

Lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and security, and accountability. Together they set the compliance floor every controller and processor must meet.

For a shortlist of GDPR-compliant outsourcing partners vetted for cross-border data handling, browse the Outsource Accelerator directory.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image