General Data Protection Regulation (GDPR)
Definition
General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR) is the European Union’s law on data privacy, governing how any organization collects, uses, stores, and transfers personal data of EU residents. It took effect May 25, 2018, and applies to anyone handling that data globally.
Any business that processes EU personal data falls under GDPR’s reach, whether it’s an outsourcing partner, cloud vendor, e-commerce site, or offshore business process outsourcing provider. Location of servers or staff doesn’t matter.
Fines are the sharpest edge of the rule. Regulators can levy penalties up to €20 million or 4% of a company’s global annual turnover — whichever is higher — plus reputational damage and lost contracts.
Outsourcing amplifies the risk. When a controller hires a processor (an outsourcing vendor) that ships personally identifiable information across borders, both parties carry obligations under Articles 28 and 46. The controller stays legally accountable.
Key takeaways
- GDPR took effect May 25, 2018 as the European Union’s core data-privacy law.
- The rule applies to any organization worldwide handling personal data of EU residents.
- Fines reach up to €20 million or 4% of global annual turnover, whichever is higher.
- Seven principles cover lawfulness, transparency, minimisation, accuracy, storage, security, and accountability.
- Outsourcing buyers stay liable when a vendor breaches, since vendor slips attach to the controller.
How it works
GDPR sets seven principles for handling personal data and grants EU residents eight rights over it. Any controller or processor must document a lawful basis, minimise what it collects, secure it, and report breaches within 72 hours.
The rule is codified in EU Regulation 2016/679 and enforced by national data protection authorities in each member state, backed by the European Commission’s data protection framework.
| GDPR principle | Practical obligation |
|---|---|
| Lawfulness | Have a valid legal basis (consent, contract, legitimate interest) before processing. |
| Purpose limitation | Use data only for the reason stated at collection. |
| Data minimisation | Collect the smallest set of fields needed. |
| Accuracy | Keep records correct and current; fix errors on request. |
| Storage limitation | Delete or anonymise data once its purpose ends. |
| Integrity and security | Encrypt, restrict access, and log processing activity. |
| Accountability | Document compliance and prove it on demand. |
Cross-border data transfers need extra work. Sending EU personal data outside the bloc requires an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules.
After the 2020 Schrems II ruling, a documented transfer impact assessment is also required for exports to third countries, as clarified by the European Data Protection Board.
The scale is real. According to gdpr.eu, penalties can reach 4% of global annual turnover or €20 million (whichever is higher) — a threshold Meta hit in 2023 with a record €1.2 billion fine from Ireland’s Data Protection Commission.
Examples
GDPR enforcement bites regardless of size or country. From tech giants to European telecoms and offshore outsourcers, regulators have levied nine- and ten-figure fines when consent, transparency, or transfer safeguards fell short.
- Meta Platforms (Ireland, 2023): the Irish Data Protection Commission fined Meta €1.2 billion for illegally transferring Facebook user data from the EU to the United States, the largest GDPR penalty on record.
- Amazon (Luxembourg, 2021): Luxembourg’s National Commission for Data Protection fined Amazon €746 million for GDPR consent violations tied to targeted advertising.
- Google (France, 2019): France’s National Commission on Informatics and Liberty (CNIL) fined Google €50 million for insufficient GDPR consent transparency when new Android users set up accounts.
- British Airways (United Kingdom, 2020): the Information Commissioner’s Office fined British Airways £20 million under GDPR after a 2018 breach exposed personal and payment data of roughly 400,000 customers.
Related terms
- Data protection: the technical and procedural safeguards that keep personal data secure and compliant.
- Data privacy: the broader discipline of shielding personal information from misuse.
- Compliance: the broader obligation of meeting laws and standards.
- Data breach: the incident type GDPR requires reporting within 72 hours.
- Data security: the technical controls (encryption, access management) GDPR requires under its integrity principle.
FAQ
Does GDPR apply to companies outside the European Union?
Yes. GDPR applies to any organization anywhere in the world that processes the personal data of people located in the EU, whether the business is European or not. Territorial scope is set out in Article 3.
What is the maximum GDPR fine?
Regulators can impose fines up to €20 million or 4% of a company’s worldwide annual turnover, whichever is higher. Meta received the record penalty of €1.2 billion in 2023 from Ireland’s Data Protection Commission.
How does GDPR affect outsourcing to non-EU countries?
Sending EU personal data to a non-EU country requires a lawful transfer mechanism, such as an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules. Buyers stay liable when a vendor breaches the standard, so vendor due diligence is essential.
Who enforces GDPR?
Each EU member state has its own Data Protection Authority, such as Ireland’s Data Protection Commission, France’s CNIL, and Germany’s BfDI. The European Data Protection Board coordinates their decisions across the bloc.
What are the seven principles of GDPR?
Lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and security, and accountability. Together they set the compliance floor every controller and processor must meet.
For a shortlist of GDPR-compliant outsourcing partners vetted for cross-border data handling, browse the Outsource Accelerator directory.







Independent




