Data protection in the European Union is governed primarily by the General Data Protection Regulation, known as GDPR, which sets binding rules for any organisation that processes personal data of EU residents. Non-compliance carries fines of up to four percent of global annual turnover or twenty million euros, whichever is higher. This guide covers the current legal framework, recent regulatory developments, core obligations for businesses, cross-border data transfer rules, enforcement trends, and practical steps to maintain compliance.
The General Data Protection Regulation is a directly applicable EU regulation that entered into force across all member states simultaneously and replaced the previous patchwork of national data protection directives. It applies to any controller or processor established in the EU, and equally to organisations outside the EU that offer goods or services to EU residents or monitor their behaviour. This extraterritorial reach is one of the most significant features of the framework and catches many non-EU businesses off guard.
GDPR is built around seven core principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Each principle imposes concrete obligations. Purpose limitation means that data collected for one specific reason cannot simply be repurposed without a fresh legal basis. Data minimisation requires that only the data strictly necessary for the stated purpose is collected and retained.
Legal bases for processing are central to compliance. The regulation identifies six lawful bases: consent, contract performance, legal obligation, vital interests, public task, and legitimate interests. Consent must be freely given, specific, informed and unambiguous. Legitimate interests can be a flexible basis but requires a balancing test against the rights of data subjects, and regulators scrutinise it closely when used by large platforms or data brokers.
Data subject rights are enforceable directly against controllers. These include the right of access, the right to rectification, the right to erasure (the so-called right to be forgotten), the right to data portability, and the right to object to processing. Controllers must respond to most requests within one calendar month, with a possible two-month extension for complex cases. Failure to respond on time is itself a breach.
Every organisation subject to GDPR must maintain a Record of Processing Activities, commonly called an RoPA. This internal document maps every processing activity, its purpose, legal basis, categories of data, retention periods, and any third-party recipients. Supervisory authorities can request the RoPA at any time, and its absence is treated as evidence of systemic non-compliance.
Data Protection Impact Assessments, known as DPIAs, are mandatory before any processing that is likely to result in a high risk to individuals. High-risk scenarios include large-scale processing of sensitive data, systematic profiling, and use of new technologies. A DPIA must describe the processing, assess necessity and proportionality, and identify measures to address the risks. Where residual risk remains high, the controller must consult the competent supervisory authority before proceeding.
Privacy by design and by default is a legal requirement, not a best practice. Controllers must integrate data protection measures into systems and processes from the outset, and default settings must be the most privacy-protective available. In practice, this means product and engineering teams need legal input at the design stage, not after launch.
Data breach notification operates on a strict timeline. Controllers must notify their lead supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to individuals. If the breach is likely to result in a high risk, affected individuals must also be notified without undue delay. Many organisations underestimate the operational readiness required to meet the 72-hour window, particularly when breaches are discovered outside business hours.
Appointment of a Data Protection Officer, or DPO, is mandatory for public authorities, organisations that carry out large-scale systematic monitoring, and those that process special categories of data on a large scale. The DPO must have expert knowledge of data protection law, must operate independently, and cannot be dismissed or penalised for performing their tasks. The DPO';s contact details must be published and communicated to the supervisory authority.
In practice, founders and compliance teams should consider that the DPO role cannot be assigned to someone with a conflict of interest, such as the CEO or the head of IT who controls the systems being audited. A common mistake is treating the DPO appointment as a formality and assigning the role to a senior manager without genuine independence or expertise.
Transferring personal data from the EU to a third country is permitted only when an adequate level of protection is ensured. The European Commission can issue an adequacy decision confirming that a third country';s legal framework provides equivalent protection. Countries with current adequacy decisions include the United Kingdom, Japan, South Korea, Canada for commercial organisations, and several others. The United States operates under the EU-US Data Privacy Framework, which replaced the invalidated Privacy Shield arrangement following the Schrems II ruling of the Court of Justice of the European Union.
Where no adequacy decision exists, transfers must rely on appropriate safeguards. Standard Contractual Clauses, known as SCCs, are the most widely used mechanism. The European Commission issued modernised SCCs covering controller-to-controller, controller-to-processor, and processor-to-processor transfers. Binding Corporate Rules, or BCRs, are available for intra-group transfers and require approval from the lead supervisory authority. Certification mechanisms and codes of conduct approved under GDPR can also serve as transfer tools, though their use remains limited in practice.
A non-obvious requirement is the Transfer Impact Assessment, or TIA. Even when SCCs are in place, controllers must assess whether the legal framework of the destination country allows authorities to access the data in ways that undermine the protection the SCCs provide. If the TIA reveals a problematic legal environment, supplementary technical measures - such as end-to-end encryption where the importer holds no keys - may be required. Many organisations implement SCCs without conducting a TIA, which creates regulatory exposure.
Scenario one: a mid-sized EU e-commerce company uses a US-based cloud analytics provider. The company must execute SCCs with the provider, conduct a TIA covering US surveillance law, and document the outcome. If the TIA identifies risks, it must implement supplementary measures or switch to an EU-based provider.
Scenario two: a multinational with EU and non-EU subsidiaries wants to centralise HR data in a Singapore data centre. BCRs would be the appropriate mechanism, but the approval process typically takes one to two years. In the interim, SCCs between each EU entity and the Singapore entity are required, each supported by a TIA.
Supervisory authorities across the EU have significantly increased enforcement activity in recent periods. The Irish Data Protection Commission, which acts as lead supervisory authority for many large technology platforms under the one-stop-shop mechanism, has issued landmark fines against major platforms for unlawful data transfers, lack of valid consent for behavioural advertising, and insufficient transparency. The Luxembourg National Commission for Data Protection has similarly taken action against global financial services firms.
The ePrivacy Directive, which governs cookies, electronic communications and direct marketing, continues to operate alongside GDPR. Cookie consent requirements remain a major compliance focus. Regulators in France, Spain, Italy and Germany have issued guidance and enforcement decisions requiring that cookie banners offer a genuine and equally prominent option to refuse non-essential cookies. Pre-ticked boxes and dark patterns that nudge users toward consent are treated as invalid.
The AI Act, which entered into force recently, intersects significantly with GDPR. AI systems that process personal data must comply with both frameworks simultaneously. High-risk AI systems as defined by the AI Act require conformity assessments that overlap with GDPR';s DPIA requirements. Controllers deploying AI for automated decision-making with significant effects on individuals must also comply with GDPR Article 22, which gives data subjects the right not to be subject to solely automated decisions.
The Data Act and the Data Governance Act introduce additional rules on data sharing, access rights and intermediary services. While these instruments are primarily aimed at non-personal data and data spaces, they interact with GDPR where personal data is involved. Businesses operating in industrial IoT, health data ecosystems or public sector data sharing arrangements need to map their obligations across all three frameworks.
A common mistake among foreign businesses entering the EU market is assuming that GDPR compliance achieved for one member state automatically satisfies all national implementing legislation. Member states retain discretion in areas such as employee data, health data, freedom of expression derogations, and the age of digital consent, which varies between thirteen and sixteen across member states.
If your organisation is navigating the intersection of GDPR, the AI Act and cross-border transfer requirements, contact info@vlolawfirm.com. We can help structure the compliance framework correctly from the outset.
GDPR identifies special categories of personal data that attract heightened protection. These include data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data used for identification, health data, and data concerning sex life or sexual orientation. Processing such data is prohibited unless one of the specific exceptions in Article 9 applies, such as explicit consent, employment law obligations, vital interests, or substantial public interest.
Health data is subject to particularly detailed national implementing rules. Several member states have enacted sector-specific health data legislation that supplements GDPR. The European Health Data Space regulation, which is progressing through the legislative process, will create a dedicated framework for primary and secondary use of health data across the EU, with specific governance structures and patient rights.
Financial services firms must comply with GDPR alongside sector-specific instruments including the Payment Services Directive, the Anti-Money Laundering Directives, and MiFID II. These instruments sometimes require retention of personal data for defined periods that may appear to conflict with GDPR';s storage limitation principle. The resolution is that legal obligation under AML or financial regulation provides a lawful basis and overrides the default minimisation requirement, but only for the specific data and period required by law.
Telecommunications and digital services providers face obligations under both GDPR and the ePrivacy Directive. Location data, traffic data and content of communications are subject to strict confidentiality requirements. The proposed ePrivacy Regulation, which would replace the current directive, has been under negotiation for several years and remains pending, meaning the current directive continues to apply.
Scenario three: a health technology startup collects biometric data from wearable devices to provide personalised health insights to EU consumers. It must identify a valid Article 9 exception - most likely explicit consent - maintain a DPIA, appoint a DPO given the large-scale processing of special category data, and ensure any transfer of data to non-EU servers is covered by SCCs with a completed TIA. The startup must also comply with any applicable national health data legislation in each member state where it operates.
Building a sustainable data protection programme requires governance structures that embed accountability throughout the organisation. The accountability principle under GDPR requires not just compliance but the ability to demonstrate compliance. This means documented policies, training records, audit trails, and regular reviews.
A practical compliance programme typically includes the following elements. First, a comprehensive data mapping exercise to identify all personal data flows, systems and third-party processors. Second, a gap analysis against GDPR requirements to prioritise remediation. Third, updated privacy notices that are genuinely transparent and written in plain language. Fourth, a vendor management programme that ensures data processing agreements are in place with all processors and that processors'; security measures are assessed. Fifth, an incident response plan that enables the organisation to meet the 72-hour breach notification deadline.
Processor relationships require written contracts that include the mandatory clauses set out in GDPR Article 28. These clauses must specify the subject matter, duration, nature and purpose of processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller. Using a processor that refuses to sign a compliant data processing agreement is itself a breach by the controller.
Many underestimate the importance of retention schedules. Keeping personal data longer than necessary is a breach of the storage limitation principle and has been the subject of enforcement action. A retention schedule maps each data category to a retention period justified by a specific legal, contractual or business purpose, and triggers deletion or anonymisation when the period expires.
Employee data deserves particular attention. Processing employee personal data for monitoring, performance management or HR purposes must comply with GDPR and, in many member states, with works council consultation requirements or specific national employment data rules. A common mistake is deploying monitoring software or HR analytics tools without conducting a DPIA or consulting employee representatives where required.
To discuss your organisation';s data protection obligations and governance structure, contact info@vlolawfirm.com. We can assist with documents, filings, DPO support and regulatory engagement across EU member states.
Does GDPR apply to my business if it is based outside the EU?
GDPR applies to any organisation outside the EU that offers goods or services to individuals in the EU, or that monitors the behaviour of individuals in the EU. This includes e-commerce platforms, SaaS providers, mobile app developers and analytics companies, regardless of where they are incorporated. Such organisations must designate an EU representative under GDPR Article 27 unless they qualify for the limited exemptions available to occasional, low-risk processors. The EU representative acts as a point of contact for supervisory authorities and data subjects and can be held liable alongside the controller.
How long does it take to build a GDPR-compliant programme, and what does it cost?
The timeline depends heavily on the size and complexity of the organisation. A small business with straightforward processing activities can achieve a baseline compliance posture in six to twelve weeks with focused effort. A mid-sized company with multiple systems, international data flows and a large vendor base typically requires three to six months for an initial programme build. Costs vary significantly: internal resource costs, legal advisory fees, and technology investments all contribute. Professional fees for legal advisory work on a mid-sized GDPR programme typically start from the low thousands of euros for scoped engagements and scale upward for complex multinational programmes.
What is the difference between a data controller and a data processor, and why does it matter?
A data controller is the entity that determines the purposes and means of processing personal data. A data processor processes personal data on behalf of a controller and only on the controller';s documented instructions. The distinction matters because controllers bear primary responsibility for compliance and must ensure that processors provide sufficient guarantees. Processors have direct obligations under GDPR, including security requirements and breach notification to the controller, but cannot process data beyond the controller';s instructions. Misclassifying a relationship - for example, treating a cloud provider as a mere tool rather than a processor - leads to missing mandatory contractual requirements and creates regulatory exposure for both parties.
Data protection in the European Union is a mature, actively enforced framework that demands genuine organisational commitment rather than paper compliance. GDPR, the AI Act, the ePrivacy Directive and emerging sector-specific instruments create overlapping obligations that require coordinated legal and operational responses. Enforcement is increasing in scope and scale, and regulators are focusing on systemic failures rather than isolated incidents.
VLO Law Firms advises international clients on data protection matters in the European Union. We can assist with GDPR compliance programmes, DPO support, cross-border transfer mechanisms, data processing agreements, regulatory engagement and privacy governance frameworks. To request a consultation, contact: info@vlolawfirm.com