Skip to main content
Explainer · Updated August 26, 2026

What Is GDPR?

The General Data Protection Regulation (GDPR) is the European Union’s data-protection regulation. It establishes principles and data-subject rights, can apply outside the EU when Article 3 territorial-scope conditions are met, and sets upper administrative-fine limits in Article 83 of up to €20 million or 4% of worldwide annual turnover, whichever is higher, for the relevant tier of infringement.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated August 26, 2026

At a glance

Full name
Regulation (EU) 2016/679
Application date
May 25, 2018
Territorial scope
EU/EEA context plus Article 3 conditions
Response deadline
One month; up to two further months for complex or numerous requests
Oversight
National supervisory authorities, with EDPB consistency functions
Upper fine limit
€20M or 4% worldwide turnover for the applicable tier

Core principles (Article 5)

Lawfulness, fairness, transparency

Processing must have a legal basis (consent, contract, legal obligation, vital interests, public interest, or legitimate interest) and be communicated clearly.

Purpose limitation

Data collected for one specified purpose should not be further processed in a way incompatible with that purpose, subject to the Regulation’s compatibility rules and exceptions.

Data minimization

Only data necessary for the specified purpose may be collected. No speculative or "just in case" data.

Accuracy

Personal data must be accurate and kept up to date. Inaccurate data must be erased or rectified without delay.

Storage limitation

Data must not be kept longer than necessary for the purpose. Retention periods must be justified.

Integrity and confidentiality

Controllers must implement technical and organizational measures to protect data from unauthorized access, loss, or damage.

Accountability

Controllers must be able to demonstrate compliance with the principles through appropriate measures and records; DPIAs, records of processing, and audit evidence are required or useful when the Regulation and risk call for them.

The 8 individual rights

1. Right to be informed

Arts. 13-14

Clear, concise notice of what data is processed, why, and how.

2. Right of access

Art. 15

Obtain a copy of personal data held about you.

3. Right to rectification

Art. 16

Correct inaccurate or incomplete personal data.

4. Right to erasure

Art. 17

The "right to be forgotten", demand deletion under specified conditions.

5. Right to restrict processing

Art. 18

Limit how data is used pending resolution of a dispute.

6. Right to data portability

Art. 20

Receive data in structured, machine-readable format to transfer.

7. Right to object

Art. 21

Object in specified circumstances; objections to direct marketing receive stronger protection.

8. Rights re: automated decisions

Art. 22

Not be subject to solely automated decisions with significant effects, with exceptions.

Generate requests in under 60 seconds

Generate GDPR-aware erasure request drafts for $9 one-time

OfflistMe prepares user-reviewed Article 17 request drafts for the available broker catalog. Review the wording and send from your own inbox; a draft is not a legal determination, provider acceptance, or deletion outcome.

Illustrative Global Rights & Fine-Limit Tools

Compare recorded rights fields across selected privacy regimes and explore the GDPR Article 83 upper fine-limit formula. These tools are educational and cannot determine which law, right, exemption, or penalty applies to a specific organization or request.

Primary source and limits

Reviewed August 26, 2026 against the official EUR-Lex regulation text, especially Articles 3, 5, 12, 15–22, and 83. The dated enforcement examples are linked to the EDPB, Luxembourg CNPD, Irish DPC, and CNIL. National law, regulator guidance, exemptions, later amendments, and the current status of an appeal can affect a real request. This page is educational content, not legal advice.

FAQ

What does GDPR stand for?+

GDPR stands for the General Data Protection Regulation, formally Regulation (EU) 2016/679. It has applied since May 25, 2018, after replacing the 1995 Data Protection Directive. It is directly applicable across the EU and applies in the EEA context through the EEA Agreement, while national and sector-specific rules can still affect how a request works.

Who does GDPR apply to?+

GDPR can apply to an organization established in the EU even when processing occurs elsewhere, and to an organization outside the EU when its processing is connected with offering goods or services to people in the Union or monitoring their behavior there. A person's location alone does not automatically trigger GDPR for every organization or activity; Article 3, exclusions, the processing purpose, and the facts control.

What is the "right to be forgotten"?+

The right to be forgotten is the informal name for the right to erasure under GDPR Article 17. It lets individuals demand that a controller erase personal data about them when: the data is no longer necessary for the original purpose, consent is withdrawn, the data has been unlawfully processed, or the individual objects and there is no overriding legitimate interest. Exceptions apply for freedom of expression, legal obligations, and public interest.

What are the 8 GDPR rights?+

The GDPR sets out several data-subject rights, including information, access, rectification, erasure, restriction, portability, objection, and safeguards for certain solely automated decisions. A controller generally must respond without undue delay and within one month, with a possible two-month extension for complex or numerous requests and notice of the extension.

What are GDPR penalties?+

Article 83 provides administrative-fine ceilings of up to €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher, for the relevant higher tier. The lower tier is up to €10 million or 2%. Dated examples include Meta (€1.2B, 2023), Amazon (€746M, 2021), WhatsApp (€225M, 2021), and Google (€50M, 2019); these are not a complete or current ranking, and the issuing authority records control the decision and status.

How do I make a GDPR request?+

Contact the relevant controller through the privacy email address, data protection officer, or web form in its privacy notice. Identify the right you are exercising and provide information reasonably needed to locate or verify the request. The usual GDPR response period is one month, subject to permitted extensions and notice. Most requests are free, but the regulation contains exceptions for manifestly unfounded or excessive requests. If appropriate, complain to the relevant national supervisory authority.

Does GDPR apply to me if I am not in Europe?+

Not automatically. Article 3 can apply to an organization outside the EU when its processing is connected with offering goods or services to people in the Union or monitoring their behavior there. A person outside the GDPR territorial scope does not gain a universal GDPR claim merely by mentioning the regulation; the organization, activity, and facts must be assessed.

What is the difference between GDPR and CCPA?+

GDPR and CCPA use different definitions, scope tests, rights, exemptions, and enforcement structures. GDPR processing may rely on several Article 6 legal bases, not consent alone; the CCPA applies to covered businesses and gives California consumers rights such as know, delete, correct, opt out of sale or sharing, and limit certain sensitive-information uses. Compare the actual law and current regulator guidance for the request at issue.

GDPR-inspired laws around the world

GDPR was the template. Here are the jurisdictions that adapted it, each with its own scope, regulator, and enforcement approach.

Related concepts & guides