Technologytechnology

EU GDPR: 8 Core Principles for Business

Understand the GDPR's core principles, data subject rights, lawful bases for processing, penalties, and extraterritorial scope. A practical guide for operators and investors.
gdpr-simplified

The General Data Protection Regulation (GDPR) was adopted on 14 April 2016 by the European Parliament and the Council of the European Union. It came into force on 24 May 2016, and its enforcement began on 25 May 2018, after a two-year transition. It replaced the 1995 Data Protection Directive and established a new global standard for data privacy law.

The regulation applies to all 27 member states of the European Union, plus Iceland, Liechtenstein, and Norway (the European Economic Area). Its reach extends well beyond those borders. Any organization handling the personal data of people in the EU must comply, regardless of where the organization is based. That extraterritorial scope is the feature most likely to surprise a US or Asian company that has no physical presence in Europe.

The maximum fine for the most serious infringements is 20 million euros or 4% of an undertaking's total worldwide annual turnover of the preceding financial year, whichever is higher. For less serious infringements, the maximum is 10 million euros or 2% of annual turnover. Those numbers are not theoretical. Supervisory authorities across the EEA have issued fines that run into the hundreds of millions of euros since 2018.

European Parliament Strasbourg hemicycle
Diliff, Wikimedia Commons, CC BY-SA 3.0

Controllers, Processors, and the Seven Principles

The Two Roles

The GDPR draws a clear line between two roles. A data controller determines the purposes and means of handling personal data. A data processor acts on behalf of the controller. The distinction matters because controllers bear primary responsibility for compliance, but processors also have direct obligations under the regulation, including maintaining records of processing activities and implementing appropriate security measures.

The Seven Principles

Seven principles govern all data handling: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. The last principle, accountability, is the one that changes behavior. It requires the controller to demonstrate compliance, not just comply. That means documented policies, data protection impact assessments, and records of processing activities must exist and be available for inspection.

The Oversight Body

The European Data Protection Board (EDPB) is the independent body that ensures consistent application of these principles across the EEA. Its guidelines, though not legally binding in the same way as the regulation itself, carry significant weight in enforcement actions.

Six Lawful Bases and Eight Data Subject Rights

The Six Lawful Bases

Handling personal data is prohibited unless it falls under one of six lawful bases: consent; contract performance; legal obligation; vital interests; public task; and legitimate interests. The two most commonly invoked bases are consent and legitimate interest, and they are frequently misunderstood.

Consent must be freely given, specific, informed, and unambiguous. Silence or pre-ticked boxes do not constitute consent. The data subject must be able to withdraw consent as easily as they gave it. Legitimate interest is broader but requires a balancing test. The controller must document that its interest is not overridden by the interests or rights of the data subject. That test is harder to pass than many organizations assume.

The Eight Rights

People have eight rights under the GDPR: the right to be informed; right of access; right to rectification; right to erasure (the right to be forgotten); right to restrict processing; right to data portability; right to object; and rights related to automated decision-making and profiling. The right to erasure is not absolute. It applies only in specific circumstances, such as when the data is no longer necessary for the purpose for which it was collected.

Breach Notification and the Data Protection Officer

Breach Notification

When a personal data breach occurs, the controller must notify the relevant supervisory authority within 72 hours of becoming aware of it. The notification must describe the nature of the breach, the categories and approximate number of data subjects and records concerned, and the measures taken or proposed to address it. If the breach is likely to result in a high risk to the rights and freedoms of people, the controller must also communicate the breach to those people without undue delay.

The Data Protection Officer

A Data Protection Officer (DPO) is required in three cases. First, when the processing is carried out by a public authority or body. Second, when the core activities of the controller or processor require large-scale, regular, and systematic monitoring of people. Third, when the core activities involve large-scale handling of special categories of data or data relating to criminal convictions and offences. The DPO must be independent, report directly to the highest management level, and cannot be penalized for performing their tasks.

Many organizations appoint a DPO voluntarily even when not legally required, because the role provides a single point of accountability that simplifies compliance across multiple jurisdictions.

What the GDPR Means in Practice

Engineering and Product

Engineering teams must build privacy into systems from the design stage, not bolt it on later. That means data minimization by default, pseudonymization where possible, and clear access controls. Product managers must understand that features which collect personal data require a documented lawful basis before launch.

Legal and Leadership

Legal departments must maintain records of processing activities and be able to demonstrate compliance on demand. The regulation's global reach means that a startup in Singapore or a manufacturer in Brazil that sells to EU customers must comply. The cost of getting it wrong is not just the fine. It is the reputational damage, the loss of customer trust, and the operational disruption of a supervisory authority investigation.

The GDPR is now more than six years into enforcement. The standards are established, the precedents are accumulating, and the expectation is that organizations treat data protection as a core operational requirement, not a compliance afterthought.

Key Facts

  • Full name: General Data Protection Regulation (GDPR), Regulation (EU) 2016/679
  • Adopted: 14 April 2016
  • Enforcement date: 25 May 2018
  • Replaces: 1995 Data Protection Directive (Directive 95/46/EC)
  • Applies in: All 27 EU member states plus Iceland, Liechtenstein, and Norway (EEA)
  • Maximum fine (serious): 20 million euros or 4% of total worldwide annual turnover, whichever is higher
  • Maximum fine (less serious): 10 million euros or 2% of total worldwide annual turnover, whichever is higher
  • Consistency body: European Data Protection Board (EDPB)

Frequently Asked Questions

Does the GDPR apply to my company if we are based outside the EU?

Yes. The GDPR has extraterritorial scope. It applies to any organization handling the personal data of people in the EU, regardless of where the organization is located.

What is the difference between a data controller and a data processor?

A data controller determines the purposes and means of handling personal data. A data processor acts on behalf of the controller. Controllers bear primary responsibility, but processors also have direct obligations under the regulation.

When must we notify a supervisory authority of a data breach?

The controller must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach.

Is consent always required to process personal data?

No. Consent is one of six lawful bases for handling personal data. Others include contract performance, legal obligation, and legitimate interest. The appropriate basis depends on the specific processing activity.

About the author

, Editor

Kenneth Ma is the editor of LeadMonitor.ai, covering the companies, deals and policy decisions shaping business and technology markets.

View all 427 articles by Kenneth Ma  ·  Our editorial policy

Recent Stories

How to make money selling Canva templates

How to highlight text in Canva

How to print from Canva without quality loss

How to check if Canva is down right now

How to group and ungroup elements in Canva

How to stretch an image in Canva

How to make a QR code in Canva

Convert Canva to PowerPoint and Google Slides