GDPR (General Data Protection Regulation) is the EU’s main privacy law, in force since 2018. It gives people rights over their own data: to see it, correct it, delete it, and move it elsewhere. Companies that handle European data must follow GDPR rules, wherever the company itself is based. Fines for serious breaches can reach 4% of a company’s global revenue. GDPR does not stop US companies from serving European users. It sets rules they must follow, but a US company can still be reached by US laws like the The CLOUD Act is a US law. It lets US authorities request data from US companies, even when the data sits on servers in Europe. Learn more → at the same time.
Frequently asked questions
What does GDPR stand for?
GDPR stands for General Data Protection Regulation. It is a regulation, not just a guideline. This means it applies the same way in every EU country. No country needs to pass its own separate version of the law.
GDPR took effect on 25 May 2018. Before that date, EU countries had a two-year period to prepare. GDPR replaced many older national privacy laws. Those older laws were different from country to country, which made things confusing for both companies and users.
Who does GDPR actually apply to?
GDPR applies to any organization that handles personal data of people in the EU. It does not matter where the organization itself is based. A company in California serving European customers must follow GDPR, just like a company based in Berlin.
This is sometimes called GDPR's "long reach" rule. It's why many US tech companies without European offices still publish GDPR pages. Some even appoint an EU representative. The rule follows where the person is, not where the company sits.
What happens if a company breaks GDPR?
National privacy regulators can investigate a company that breaks GDPR. They can also issue fines. For the most serious violations, a fine can reach €20 million. Or it can reach 4% of the company's total global revenue, whichever is higher. This is based on the company's worldwide income, not just what it earns in the EU.
Most real GDPR fines are smaller than this maximum. They usually target specific mistakes, like asking for consent in the wrong way or storing data insecurely. But a few large fines have hit major US tech companies. Those fines show that the maximum penalty is not just a symbolic number.
Does GDPR protect Europeans from US surveillance laws?
Not directly. GDPR sets rules for how companies must handle personal data. It limits sending that data outside the EU without proper safeguards. But GDPR is a data protection law. It cannot stop a foreign government from using its own surveillance laws.
A company can follow GDPR perfectly and still be forced to hand over data under US law. This can happen through the CLOUD Act or FISA 702. This exact gap, between GDPR's rules and US surveillance law, was the problem the Schrems II ruling dealt with.
Is GDPR still enforced in 2026?
Yes. GDPR has no end date. It remains the EU's main privacy law. National data protection authorities in every EU country continue to actively enforce it.
Enforcement has generally become stricter over time, not weaker. Regulators have built up years of case decisions and now cooperate more across borders. GDPR also works alongside newer EU digital laws now, like the DMA, the DSA, and the NIS2 Directive.