GDPR
The EU's data protection law governing how businesses collect, store and use personal data from EU residents.
In practice
It applies to any business handling EU residents' data, regardless of where the business itself is located, and requires clear consent for data collection, the right for individuals to request their data be deleted, and prompt breach notification.
A US-based store selling to EU customers adds a cookie-consent banner and a data-deletion request form specifically to comply with GDPR.
Why it matters
It applies based on whose data is being handled, not where the business is located - a US-only company selling to EU customers is still fully in scope, regardless of where its servers or offices are.
Worth knowing
- Requires clear, informed consent before collecting personal data, not a pre-checked opt-in box.
- Grants individuals rights including data access, correction, and deletion requests.
- Non-compliance can carry fines calculated as a percentage of global revenue.
Start the conversation
Let's talk it through
Tell us where things stand with putting gdpr into practice and we'll respond with next steps, no forms, no waiting in a queue.
- A specialist replies directly, not a support queue
- Whichever channel is fastest for you, call, WhatsApp or email
- No long-term contract to start the conversation