GDPR
LawWhat is the GDPR?
GDPR stands for General Data Protection Regulation. It is an EU regulation that defines how organizations must handle personal data.
Adopted: April 27, 2016
Entered into force: May 24, 2016
Applicable since: May 25, 2018
What is personal data?
Any information that identifies or can identify a person:
- Names, email addresses, telephone numbers
- IP addresses, cookie IDs
- Location data, health data
- Photographs of people
- Even: “Customer 42” if you can identify who Customer 42 is
Core principle
You may process personal data only if:
- The person has given explicit consent, OR
- You have a legitimate legal basis (contract, legal obligation)
People have rights: access, erasure, and data portability.
History
Before the GDPR
Before 2018, each EU country had its own data protection law.
Problem: 28 different laws with different requirements. Companies faced complexity, and loopholes existed.
Why was it necessary?
During the 2010s, companies such as Facebook and Google collected vast amounts of personal data.
The GDPR was first proposed in 2012 and adopted in 2016. The Cambridge Analytica scandal (which became public in 2018, involving Facebook data from 87 million users being misused for political manipulation) therefore only became public shortly before the GDPR became applicable. It was not the reason for the GDPR, but it made many people aware why such legislation was necessary.
The EU wanted strong, uniform data protection for all citizens.
Development
- 2012: First drafts
- April 27, 2016: Adopted by the European Parliament
- May 24, 2016: Entered into force
- May 25, 2018: Became applicable (two-year transition period between entry into force and applicability)
- Applies directly in all EU Member States (no national implementation required)
Worldwide influence
The GDPR became a model for data protection laws around the world:
- Brazil: LGPD (2020)
- California: CCPA (2020)
- China: PIPL (2021)
- India, Japan, Thailand: Similar laws followed
Scope
Geographic scope
The GDPR applies to:
- Companies established in the EU (regardless of where the data is processed)
- Companies outside the EU that process personal data of people in the EU
Example: A U.S. company with no EU office sells products to customers in Germany → the GDPR still applies.
Personal scope
Applies to:
- Living natural persons (not companies)
- EU citizens and residents
- Also tourists temporarily staying in the EU
Does NOT apply to:
- Deceased persons
- Purely private or personal use (family photos)
- Truly anonymous data
Core principles
Lawfulness
Processing personal data requires a legal basis:
- Consent: The person has agreed
- Contract: Necessary to fulfill a contract
- Legal obligation: Required by law
- Legitimate interest: Legitimate reason (often subject to balancing)
- Public interest: Public authority tasks
- Vital interests: Protection of life
Purpose limitation
Use personal data only for the stated purpose.
Example: An email address collected for a newsletter may only be used for the newsletter—not for advertising from partners unless explicit consent has been given.
Data minimization
Collect only the data you actually need.
Example: A newsletter signup requires an email address, not a postal address, telephone number, or date of birth.
Storage limitation
Delete data once the purpose has been fulfilled.
Example: Delete job application documents after a rejection unless the applicant agrees to longer storage.
Integrity
Store data securely (encryption, access controls).
In the event of a data breach, the supervisory authority must be notified within 72 hours.
Rights of data subjects
Right of access
Anyone may ask: “What data do you have about me?”
You must respond within 30 days—free of charge.
The response must include:
- All stored personal data
- Purpose of processing
- Recipients of the data
- Retention period
Right to erasure
“The right to be forgotten.”
A person may request deletion if:
- The purpose has been fulfilled
- Consent has been withdrawn
- The data has been processed unlawfully
Exceptions: Statutory retention requirements (for example, accounting records).
Right to object
A person may object to processing.
Example: “I no longer want marketing emails.” → You must respect this request.
Right to data portability
A person may request their data in a machine-readable format.
Example: Export all Facebook posts as JSON to move to another social network.
Right to rectification
Incorrect data must be corrected when the person points it out.
Consent
Requirements
Valid consent must be:
- Freely given: No forced consent (for example, “You may use this website only if you consent”)
- Informed: Clearly explain what the data will be used for
- Specific: Separate consent for each purpose
- Active: Pre-checked boxes are INVALID
- Withdrawable: As easy to withdraw as it is to give
Cookie banners
This is why cookie consent banners became much more common in Europe. The actual legal basis, however, is mainly telecommunications and ePrivacy law rather than the GDPR itself (see also the “Controversies” section below).
GDPR-compliant banners:
- “Accept all” AND “Reject all” buttons equally prominent
- “Necessary only” is NOT the same as “Reject”
- No pre-selected options
- Continued use without consent must be possible
Many banners are STILL unlawful (dark patterns).
Withdrawal
A person may withdraw consent at any time.
It must be as easy as giving consent.
Example: Unsubscribe from a newsletter with one click—not by logging in, searching through settings, and confirming multiple dialogs.
Privacy notice
Requirement
Every website or application that processes personal data requires a privacy notice.
It must include:
- Who is responsible
- What data is collected
- For what purpose
- Legal basis
- Who receives the data
- How long the data is stored
- Rights of data subjects
- Right to lodge a complaint with a supervisory authority
Clarity
It must be written in clear, simple language.
No legal jargon that nobody understands.
In practice: Many privacy notices are still lengthy documents with more than twenty pages of fine print.
Transparency
People must be informed before personal data is collected.
Not: collect first, mention it somewhere later.
Data processing agreements
Concept
If you use a service provider that has access to personal data, a Data Processing Agreement (DPA) is required.
Example: You use Mailchimp for newsletters → you need a DPA with Mailchimp.
Contents of a DPA
- What data the service provider processes
- For what purpose
- Technical and organizational measures (encryption, etc.)
- No disclosure to third parties without authorization
- Instructions from the controller
- Deletion after the contract ends
The U.S. cloud issue
U.S. cloud providers (AWS, Google Cloud, Azure) can be problematic:
- Cloud Act: U.S. authorities may request access
- Privacy Shield was invalidated (2020)
- Standard Contractual Clauses may not fully resolve U.S. government access concerns
Many EU public authorities therefore recommend EU hosting.
Penalties
Fines
The GDPR provides for significant fines:
- Up to €20 million, OR
- 4% of worldwide annual turnover
Whichever amount is higher.
Examples
Largest fines so far:
- Meta (Facebook): €1.2 billion (2023) – Data transfers to the U.S.
- Amazon: €746 million (2021) – Tracking without consent
- WhatsApp: €225 million (2021) – Lack of transparency regarding data sharing
- Google: €90 million (2020) – Cookie banners without a reject option
- H&M: €35 million (2020) – Employee surveillance
Small businesses
Small businesses can also receive fines, although these are usually much lower than the major cases listed above.
Often there is first a warning, followed by a fine if the issue is not corrected.
Supervisory authorities
Germany
- Federal Commissioner for Data Protection and Freedom of Information (federal authorities)
- 16 State Data Protection Authorities (companies within each federal state)
Responsibility depends on where the company has its main establishment.
Across the EU
Each EU Member State has its own supervisory authority.
In cross-border cases, the lead supervisory authority coordinates with the others.
Complaints
Anyone may lodge a complaint with a supervisory authority—free of charge.
The authority must investigate and may require a company to change its practices.
Practical implications
For companies
The GDPR means:
- A Data Protection Officer where required by law
- Maintain records of processing activities
- Implement technical and organizational measures (encryption, etc.)
- Train employees
- Report data breaches
For individuals
More rights:
- Request access
- Request deletion
- Object to marketing
However: Many organizations still ignore or delay such requests.
For website operators
Minimum requirements:
- Privacy notice
- Cookie banner (if tracking cookies are used)
- DPA with the hosting provider (unless self-hosted)
- SSL/TLS encryption
- Secure passwords and backups
Controversies
Cookie banner fatigue
Cookie banners annoy almost everyone.
Problem: The GDPR is often blamed for banners—but it merely requires consent where necessary. It does not itself require banners.
Solution: Simply do not use tracking cookies → no consent banner is required.
Warning letters
Some law firms used the GDPR as the basis for warning letters.
Examples:
- Loading Google Fonts from Google servers
- Missing privacy notice
Later legal changes reduced this practice, but it still exists.
Bureaucracy
Critics argue that the GDPR creates a significant administrative burden for small businesses.
A five-person company often has to maintain documentation similar to that of a large corporation.
U.S. criticism
The United States has criticized the GDPR as protectionist toward U.S. technology companies.
Many of the largest fines have been imposed on U.S. companies (Meta, Google, Amazon).
Workarounds
Consent or Pay
Meta introduced a model in 2023: “Either consent to tracking OR pay €10 per month.”
Legal? Still debated. The EU is examining whether this constitutes freely given consent.
Dark patterns
A huge colorful “Accept all” button and a tiny hidden “Reject” button.
Technically possible, but contrary to the spirit of the GDPR.
Offshore
A company based outside the EU can be more difficult to enforce against.
However: The EU can restrict services if the company does not cooperate.
The Dragons@Work perspective
Core principle
Dragons@Work sees the GDPR as a minimum standard—not as a burden.
Respect for privacy is practiced because it is the right thing to do, not merely because the law requires it.
“Complying with the GDPR happens as a consequence”—not the other way around.
Technical implementation
- NO tracking cookies → no cookie banner
- Plausible Analytics WITHOUT storing IP addresses
- Self-hosting → no third-party access
- Listmonk with explicit opt-in
- Servers in the EU (Hetzner Germany/Finland)
Transparency
Privacy notices written in clear language rather than legal jargon.
They explain WHY decisions were made, not only WHAT is done.
No dark patterns
If cookie consent is required, rejecting must be just as easy as accepting.
Ethics before conversion optimization.
Future
ePrivacy
The planned ePrivacy Regulation is intended to clarify cookie rules.
Status: Still under negotiation after many years.
AI regulation
The EU AI Act (2024) regulates AI-specific issues.
It complements the GDPR for questions relating specifically to AI.
Internationalization
More and more countries are adopting GDPR-inspired legislation.
It may become a global standard, much like SSL/HTTPS.
Sources
Behoerden
Strafen
Sources archived on: 2026-08-02