Glossary · Records and compliance

GDPR

The EU's General Data Protection Regulation (EU) 2016/679, applied since 25 May 2018, which governs the processing of personal data about people in the EU.

The GDPR, the General Data Protection Regulation (Regulation (EU) 2016/679), is the European Union law that governs how organizations process personal data about people in the EU.

Status. It was adopted on 27 April 2016, replaced Directive 95/46/EC, and has applied since 25 May 2018.

Who it reaches. It applies to controllers and processors established in the EU. Under Article 3(2) it also applies to those outside the EU when they offer goods or services to people in the EU or monitor their behaviour there. A business outside Europe whose agent serves EU customers can therefore fall within its scope.

Core rules. Article 5 sets the principles, including purpose limitation, data minimisation and storage limitation, which allows data to be kept in identifying form no longer than its purposes need. Controllers need a lawful basis for each processing purpose. People have rights to access, correct, erase and object. Where feasible, a personal data breach must be notified to the supervisory authority within 72 hours of the controller becoming aware of it (Article 33). The highest tier of administrative fines reaches €20 million or 4% of total worldwide annual turnover for the preceding financial year, whichever is higher (Article 83(5)).

Automated decisions. Article 22 gives people a right not to be subject to a decision based solely on automated processing that produces legal effects for them or similarly significantly affects them, subject to exceptions and safeguards. It can become relevant when an AI agent, with no person involved, decides something like a claim or a credit request about an identifiable person.

Proposed changes. On 19 November 2025 the European Commission proposed targeted GDPR amendments in its Digital Omnibus (COM(2025) 837), including changes to the notion of personal data, AI training, and rules for cookies and terminal equipment. As of 26 September 2026, EUR-Lex lists the procedure (2025/0360/COD) as ongoing, with no final act adopted. The current text applies until any amendment is adopted and takes effect.

Neighbouring terms. PIPEDA is Canada’s federal counterpart. Data retention is where storage limitation becomes an engineering schedule.

Sources

  1. Regulation (EU) 2016/679 (General Data Protection Regulation), EUR-Lex (accessed )
  2. COM(2025) 837: Digital Omnibus proposal (19 November 2025), EUR-Lex (accessed )
  3. EUR-Lex procedure 2025/0360/COD (accessed )