Skip to content
Xavi Creus

Security & compliance

GDPR (General Data Protection Regulation)

GDPR (General Data Protection Regulation) is the EU law on how organisations collect, use and protect personal data, with fines up to 4% of turnover.

Definition

GDPR, the General Data Protection Regulation, is the European Union's data protection law, in force since 25 May 2018. It sets the rules for how any organisation, inside or outside the EU, may collect, use, store and share the personal data of people in the EU. Personal data means anything that identifies a person, from a name to an IP address. GDPR gives individuals rights over their data and lets regulators fine companies up to €20 million or 4% of global annual turnover, whichever is higher.

In a company, GDPR shows up in a lawful basis for every use of personal data, consent mechanisms for marketing and cookies, privacy notices that explain what you do, contracts with every vendor that processes data on your behalf, the ability to export or delete a customer's data on request, and a duty to report serious breaches to the regulator within 72 hours. Companies handling data at scale or sensitive categories must appoint a Data Protection Officer. Since Brexit, the UK runs a parallel regime.

Enforcement is real. Cumulative fines passed €7 billion by 2026, with €1.2 billion imposed in 2025 alone, including a €530 million fine against TikTok for unlawful data transfers. The misconception is that GDPR is only about cookie banners. It is about governance: knowing what personal data you hold, why, and for how long. In 2026 it intersects with AI directly, since training or running models on customer data requires a lawful basis and transparency, and the EU AI Act adds obligations on top.

In practice

A B2B company with customers in 20+ countries was asked by an enterprise prospect for its data processing agreement, its list of sub-processors and its breach procedure before signing. Having them ready shortened a three-month procurement to three weeks; a competitor without them lost the deal.

Why it matters

GDPR compliance is both a legal obligation and a sales asset: enterprise buyers now check it before they buy. Treat it as a discipline of knowing your own data rather than as paperwork, and it also makes your AI initiatives safer.

Frequently asked questions

Does GDPR apply to companies outside the EU?
Yes, if they offer goods or services to people in the EU or monitor their behaviour, regardless of where the company is based. A US or Asian SaaS company with European users must comply. Regulators have fined non-EU companies, and EU customers require compliance contractually.
What are the penalties for a GDPR violation?
Up to €20 million or 4% of global annual turnover for the most serious violations, whichever is higher, with a lower tier of €10 million or 2% for others. Regulators also issue orders to stop processing, which can be more damaging than the fine. Total fines exceeded €7 billion by 2026.

Need this explained for your company?

One hour with me is usually enough to turn the vocabulary into a decision.

Book a session