DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Global laws

What is the General Data Protection Regulation (GDPR)?

Also known as: GDPR, EU GDPR, General Data Protection Regulation (EU)

The General Data Protection Regulation (GDPR) is the European Union's comprehensive data protection law. It regulates how organisations collect, use, store, share and otherwise process personal data relating to individuals.

The GDPR applies not only to organisations established in the European Union, but also to organisations outside the EU in certain circumstances, including when they offer goods or services to individuals in the EU or monitor their behaviour.

The GDPR establishes requirements around lawful processing, transparency, consent, data minimisation, security, data-subject rights, international data transfers and accountability.

For websites, one of the most visible GDPR requirements is cookie and tracker consent. Where consent is the appropriate legal basis, it must be freely given, specific, informed and unambiguous, and organisations must be able to demonstrate that consent was obtained.

What does GDPR mean?

GDPR stands for General Data Protection Regulation.

Its official name is Regulation (EU) 2016/679. It was adopted by the European Union in 2016 and became applicable on 25 May 2018.

The regulation replaced the EU Data Protection Directive 95/46/EC and created a more consistent data-protection framework across the European Economic Area.

The GDPR is designed to protect individuals' fundamental rights in relation to their personal data while establishing consistent obligations for organisations that process that data.

Who does the GDPR apply to?

The GDPR can apply to organisations inside and outside the European Union.

It generally applies when:

  • An organisation is established in the EU and processes personal data as part of its activities.
  • An organisation outside the EU offers goods or services to individuals in the EU.
  • An organisation outside the EU monitors the behaviour of individuals in the EU.

This means a company does not necessarily need an office in Europe for the GDPR to become relevant. A business based elsewhere may still fall within its scope depending on what it offers and how it interacts with individuals in the EU.

What is personal data under GDPR?

The GDPR defines personal data broadly.

Personal data is information relating to an identified or identifiable natural person.

Depending on the circumstances, this can include:

  • Name
  • Email address
  • Telephone number
  • Postal address
  • IP address
  • Online identifiers
  • Cookie identifiers
  • Device identifiers
  • Location information
  • Account information
  • Advertising identifiers
  • Data relating to an individual's behaviour or preferences

Some categories of personal data receive additional protection under the GDPR, including certain health, biometric, genetic, racial or ethnic, religious and other sensitive information.

What is processing under GDPR?

Processing is also defined broadly under the GDPR.

It can include operations such as:

  • Collecting personal data
  • Recording information
  • Organising data
  • Storing data
  • Accessing data
  • Using data
  • Sharing data
  • Analysing data
  • Combining data
  • Deleting data

As a result, GDPR compliance is not limited to data collection. It can apply throughout the lifecycle of personal data.

What are the GDPR's main principles?

The GDPR establishes several core principles for processing personal data.

These include:

Lawfulness, fairness and transparency

Organisations must process personal data lawfully, fairly and transparently.

Purpose limitation

Personal data should be collected for specified, explicit and legitimate purposes and not subsequently processed in an incompatible manner.

Data minimisation

Organisations should process only personal data that is adequate, relevant and limited to what is necessary for the purpose.

Accuracy

Personal data should be accurate and kept up to date where necessary.

Storage limitation

Personal data should not be retained for longer than necessary for its purpose.

Integrity and confidentiality

Organisations must use appropriate security measures to protect personal data.

Accountability

Organisations must be responsible for complying with the GDPR and be able to demonstrate that compliance.

These principles influence everything from privacy notices and data retention to consent management and security controls.

What are the lawful bases under GDPR?

The GDPR does not require consent for every type of personal-data processing.

Article 6 identifies several lawful bases for processing personal data, including:

ConsentContractual necessityLegal obligationVital interestsPublic taskLegitimate interests

Consent is therefore one lawful basis among several.

An organisation should determine the appropriate legal basis for each processing activity rather than automatically treating every processing operation as consent-based.

What is GDPR consent?

Where consent is used as the legal basis for processing, GDPR consent must meet specific requirements.

Consent must be:

Freely givenSpecificInformedUnambiguous

It must also involve a clear affirmative action.

Silence, inactivity and pre-ticked boxes do not constitute valid GDPR consent.

A consent request should also be clearly distinguishable from other information, use understandable language and explain what the person is agreeing to.

What does GDPR require for consent records?

Organisations relying on consent must be able to demonstrate that the individual consented.

This makes consent records an important part of GDPR compliance.

A useful consent record can capture information such as:

  • Consent status
  • Date and time
  • Purpose or purposes
  • Consent mechanism
  • Relevant notice or privacy-policy version
  • Categories of processing
  • Withdrawal status
  • Relevant identifier or consent receipt

The exact information an organisation should retain depends on its processing activities and compliance requirements.

The important principle is that an organisation should not have to rely solely on a user's memory or an unverifiable database flag to prove consent. Article 7 specifically requires the controller to be able to demonstrate consent where processing is based on it.

Can GDPR consent be withdrawn?

Yes.

Individuals have the right to withdraw consent at any time when processing is based on consent.

The GDPR also requires that withdrawing consent be as easy as giving it. Withdrawal does not retroactively make earlier consent-based processing unlawful, but the organisation must stop relying on consent for future processing where no other lawful basis applies.

For websites, this is why a consent system should provide an accessible way to revisit and change privacy preferences.

What is GDPR cookie consent?

GDPR cookie consent refers to obtaining valid consent where cookies or similar technologies involve processing for which consent is required.

Common examples include:

  • Advertising trackers
  • Behavioural analytics
  • Social-media tracking
  • Marketing pixels
  • Some embedded third-party technologies
  • Other non-essential tracking technologies

A cookie banner by itself does not automatically make a website GDPR compliant.

A compliant consent implementation should ensure that the appropriate technologies do not perform the relevant processing before the necessary consent has been obtained.

This is where prior consent and prior blocking become important.

What is prior blocking under GDPR?

Prior blocking means preventing non-essential cookies, scripts and trackers from executing until the visitor has made the required consent choice.

This is different from simply displaying a consent banner.

For example, if an analytics or advertising script loads before the user has made a choice, showing a banner afterward does not undo what has already happened.

A technically enforced consent system should therefore connect the user's decision to the technologies that perform the processing.

ConsentX describes this approach as prior-script blocking, where non-essential trackers remain blocked until the appropriate choice is made.

What rights do individuals have under GDPR?

The GDPR provides individuals with a range of rights concerning their personal data.

Depending on the circumstances, these include:

  • Right to be informed
  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Rights relating to automated decision-making and profiling

These rights are an important part of GDPR compliance and require organisations to have processes for receiving, authenticating, evaluating and responding to data-subject requests.

What is a data controller under GDPR?

A data controller is the organisation or person that determines the purposes and means of processing personal data.

The controller is responsible for ensuring that processing complies with applicable GDPR requirements.

For example, a company operating an ecommerce website may determine:

  • What customer information is collected
  • Why it is collected
  • How it is used
  • How long it is retained
  • Which service providers receive it

That company may therefore act as a controller for those processing activities.

What is a data processor under GDPR?

A data processor processes personal data on behalf of a controller.

Examples can include certain:

  • Cloud service providers
  • Email platforms
  • Customer relationship management systems
  • Analytics providers
  • Hosting providers
  • Payment or fulfilment providers

The controller remains responsible for selecting appropriate processors and meeting its GDPR obligations, while processors also have obligations under the regulation.

The controller-processor relationship should be clearly documented and governed by the appropriate contractual arrangements.

What is GDPR compliance?

GDPR compliance means implementing the organisational, legal and technical measures necessary to meet applicable GDPR requirements.

A GDPR compliance programme may include:

  • Mapping personal-data processing
  • Identifying lawful bases
  • Maintaining privacy notices
  • Managing cookie consent
  • Recording consent
  • Implementing data-subject request processes
  • Establishing retention policies
  • Managing processors
  • Implementing security measures
  • Assessing high-risk processing
  • Managing international transfers
  • Maintaining compliance documentation
  • Demonstrating accountability

Compliance is therefore broader than installing a cookie banner.

GDPR and website compliance

For websites, GDPR compliance often involves several connected systems.

A website may need to:

  • Identify cookies, scripts and third-party technologies.
  • Determine which processing activities require consent.
  • Display clear information before collecting consent.
  • Provide meaningful choices.
  • Prevent relevant non-essential processing before consent.
  • Record the user's decision.
  • Honour changes and withdrawals.
  • Maintain evidence of the consent decision.
  • Review changes to scripts and third-party services over time.

This is why automated scanning and continuous monitoring can be useful alongside a consent-management platform.

ConsentX provides a scanner designed to identify cookies, trackers, scripts and third-party technologies that load on a website before visitors provide consent.

GDPR and privacy by design

The GDPR also promotes a proactive approach to privacy.

Organisations should consider data protection requirements when designing products, websites, applications and processing systems rather than treating compliance as something added after launch.

For consent management, this means privacy preferences should be reflected in the technical behaviour of the website.

A banner that says "Do Not Track" while trackers continue to load does not provide the same level of control as a system that actually enforces the user's choice.

GDPR penalties

The GDPR provides for significant administrative fines for certain infringements.

Depending on the type of violation, fines can reach:

Up to €10 million or 2% of worldwide annual turnover, whichever is higher, for certain infringements.

Up to €20 million or 4% of worldwide annual turnover, whichever is higher, for more serious infringements.

The applicable maximum depends on the specific GDPR provision involved.

Penalties are only one part of the enforcement framework. Organisations should therefore focus on building sustainable compliance controls rather than treating the maximum fine as the definition of GDPR compliance.

How ConsentX helps with GDPR consent management

ConsentX is a Consent Management Platform (CMP) designed to help organisations operationalise privacy and consent requirements across websites.

Its consent-management capabilities include:

Website scanning

Consent banners

Prior-script blocking

Granular consent choices

Consent withdrawal

Tamper-evident consent receipts

Geo-aware privacy rules

Audit exports

Data-subject request workflows

ConsentX describes its platform as helping businesses block non-essential trackers before consent and maintain tamper-evident consent records.

The technology does not replace an organisation's legal assessment or broader GDPR compliance programme. Instead, it can provide the technical layer needed to make consent choices enforceable and auditable.

GDPR compliance checklist

A practical GDPR website checklist includes:

  • Identify the personal data your website processes.
  • Map cookies, trackers and third-party technologies.
  • Determine the lawful basis for each relevant processing activity.
  • Provide clear privacy information.
  • Obtain valid consent where consent is the applicable legal basis.
  • Do not use pre-ticked consent boxes.
  • Block relevant non-essential trackers before consent.
  • Make rejection and withdrawal accessible.
  • Record and preserve consent evidence.
  • Provide mechanisms for exercising data-subject rights.
  • Review third-party processors and contracts.
  • Maintain appropriate security controls.
  • Regularly scan the website for changes.

GDPR: Key takeaways

The General Data Protection Regulation (GDPR) is one of the world's most influential data-protection laws.

The most important points are:

  • GDPR regulates the processing of personal data.
  • It can apply to organisations outside the EU.
  • Consent is only one of several lawful bases for processing.
  • GDPR consent must be freely given, specific, informed and unambiguous.
  • Pre-ticked boxes and inactivity do not constitute valid consent.
  • Organisations relying on consent must be able to demonstrate it.
  • Individuals can withdraw consent at any time.
  • Withdrawal should be as easy as giving consent.
  • GDPR provides extensive data-subject rights.
  • Website compliance requires more than displaying a cookie banner.
  • Technical enforcement and consent records are important parts of an auditable consent system.

Make GDPR consent enforceable and provable

GDPR compliance is not just about showing users a privacy notice or cookie banner. The technical implementation needs to respect the user's choice, prevent relevant processing before consent, support withdrawal and maintain reliable evidence of what happened. ConsentX helps organisations collect, enforce and prove consent across their websites. Start building audit-ready consent management with ConsentX.

Frequently asked questions