Privacy laws · European Union

General Data Protection Regulation.

The world's most comprehensive data protection regulation. Applies to any business that offers goods or services to EU residents or monitors their behavior, regardless of where the business is located. Requires lawful basis for processing, explicit consent, and grants extensive data subject rights.

/ Diagnostic check ClearConsent scans your storefront for signals related to this law — consent banner state, GPC support, Do Not Sell links, privacy policy disclosures, cookies, and trackers.

/ Effective
2018-05-25
Effective date
When the law took effect or will take effect.
/ Consumers
None
Consumer threshold
The number of European Union residents whose data triggers compliance.
/ Revenue
None
Revenue threshold
Annual revenue trigger for compliance, if applicable.
01 / Key requirements

What the law requires.

  • 01Lawful basis for each processing activity (consent, contract, legitimate interest, etc.)
  • 02Explicit, informed, freely-given consent for data processing
  • 03Right to access personal data (Subject Access Request)
  • 04Right to rectification of inaccurate data
  • 05Right to erasure ('right to be forgotten')
  • 06Right to data portability
  • 07Right to restrict processing
  • 08Right to object to processing
  • 09Data Protection Impact Assessments (DPIAs) for high-risk processing
  • 10Data Protection Officer (DPO) appointment when required
  • 1172-hour breach notification to supervisory authority
  • 12Privacy by design and by default
  • 13Records of processing activities (Article 30)
  • 14Cross-border data transfer safeguards (SCCs, adequacy decisions)
  • 15Clear cookie consent (opt-in, not pre-checked boxes)
02 / Enforcement

Penalties & cure period.

Penalties

Up to 4% of annual global turnover or €20 million, whichever is greater (for most serious violations). Up to 2% or €10 million for lesser violations.

Cure period

None (DPAs may issue warnings before fines)

Enforcement agency

National Data Protection Authorities (DPAs)

03 / E-commerce

What this means for
your store.

Applies if you sell to or track EU visitors regardless of your location. Cookie consent must be opt-in (no pre-checked boxes). Consent must be as easy to withdraw as to give. Google Consent Mode v2 compliance is critical for running Google Ads in the EU.

Scan your store for GDPR privacy gaps →