GDPR (General Data Protection Regulation) is the European Union's data protection law, governing how the personal data of people in the EU is collected, processed, and protected. It applies to any organization worldwide that handles EU residents' data, not just companies based in Europe, and its fines are large enough to make it a standing fixture in GRC work everywhere.
The core principles
GDPR is built around a handful of recurring obligations: get clear, informed consent before processing personal data; collect only what's actually necessary (data minimization); be transparent about what's collected and why; be able to demonstrate compliance, not just claim it (accountability); and report qualifying data breaches to the relevant authority within 72 hours of discovery.
What the fines actually look like
Penalties are tiered. The most serious violations — core data protection failures — carry fines of up to €20 million or 4% of the company's total worldwide annual revenue, whichever is higher. Less severe issues, like failing to appoint a required Data Protection Officer, cap at €10 million or 2% of revenue. The revenue-based scaling is what makes GDPR fines genuinely painful for large multinational companies, not just a fixed cost of doing business.
Why "based in Europe" is the wrong test
The law applies based on whose data is being processed, not where the company is headquartered. A company in India or the US selling to EU customers, or simply tracking EU visitors on a website, can be squarely in scope — which is exactly why GDPR shows up in GRC work at organizations that have never had a European office.
GDPR isn't the only regional law you'll run into
It's the most widely referenced model, but plenty of other jurisdictions now have their own version: India's DPDP Act, Saudi Arabia and the UAE's separate PDPL laws, and sector-specific US rules like HIPAA for healthcare or PCI DSS for payment card data. Each borrows GDPR's basic shape — consent, breach notification, cross-border transfer rules — while differing on the details that actually matter for compliance work.
How this shows up in GRC work
GDPR compliance is tracked the same way any regulation is: mapped to internal controls, tested with audit evidence that data-handling practices actually match the requirement, and logged as a risk register entry when a gap is found. It's one more line item in the same compliance workflow that covers ISO 27001, SOC 2, and industry-specific rules.