What Is GDPR?

GDPR (General Data Protection Regulation) is the European Union's data protection law, governing how the personal data of people in the EU is collected, processed, and protected. It applies to any organization worldwide that handles EU residents' data, not just companies based in Europe, and its fines are large enough to make it a standing fixture in GRC work everywhere.

The core principles

GDPR is built around a handful of recurring obligations: get clear, informed consent before processing personal data; collect only what's actually necessary (data minimization); be transparent about what's collected and why; be able to demonstrate compliance, not just claim it (accountability); and report qualifying data breaches to the relevant authority within 72 hours of discovery.

What the fines actually look like

Penalties are tiered. The most serious violations — core data protection failures — carry fines of up to €20 million or 4% of the company's total worldwide annual revenue, whichever is higher. Less severe issues, like failing to appoint a required Data Protection Officer, cap at €10 million or 2% of revenue. The revenue-based scaling is what makes GDPR fines genuinely painful for large multinational companies, not just a fixed cost of doing business.

Why "based in Europe" is the wrong test

The law applies based on whose data is being processed, not where the company is headquartered. A company in India or the US selling to EU customers, or simply tracking EU visitors on a website, can be squarely in scope — which is exactly why GDPR shows up in GRC work at organizations that have never had a European office.

GDPR isn't the only regional law you'll run into

It's the most widely referenced model, but plenty of other jurisdictions now have their own version: India's DPDP Act, Saudi Arabia and the UAE's separate PDPL laws, and sector-specific US rules like HIPAA for healthcare or PCI DSS for payment card data. Each borrows GDPR's basic shape — consent, breach notification, cross-border transfer rules — while differing on the details that actually matter for compliance work.

How this shows up in GRC work

GDPR compliance is tracked the same way any regulation is: mapped to internal controls, tested with audit evidence that data-handling practices actually match the requirement, and logged as a risk register entry when a gap is found. It's one more line item in the same compliance workflow that covers ISO 27001, SOC 2, and industry-specific rules.

Common Questions

Does GDPR only apply to companies based in Europe?

No. GDPR applies to any organization, anywhere in the world, that processes the personal data of people located in the EU — a company based in India or the US selling to EU customers is still in scope.

What's the actual maximum GDPR fine?

Up to €20 million or 4% of the company's total worldwide annual revenue, whichever is higher, for the most serious violations. Less severe infractions, like failing to appoint a Data Protection Officer when required, cap at €10 million or 2% of revenue.

How does GDPR relate to a GRC Analyst's day-to-day work?

It's a compliance requirement tracked and evidenced the same way any other regulation is: mapped to internal controls, tested for evidence that data-handling actually follows the rule, and logged as a risk if a gap is found — the same GRC loop used for ISO 27001 or SOC 2.

Want hands-on practice with compliance work?

Try the GRC Track in CX Challenges, or get a personalized roadmap through 1:1 GRC mentorship.

Keep Reading

What Is GRC?

Governance, Risk, and Compliance, explained from the ground up.