European Law · European Union
GDPR Compliance Basics: What Every Business Handling EU Data Should Know
A practical overview of the GDPR's core principles, who it applies to, and the first compliance steps a business should take before processing personal data from the EU.
The General Data Protection Regulation (GDPR) is often described as strict, but most of its requirements come down to a handful of principles applied consistently. This guide covers the basics any business should understand before it starts collecting data from people in the EU.
Who has to comply
The GDPR applies to any organization that processes the personal data of people located in the EU — regardless of where the organization itself is based. A company in Brazil or the US selling to EU customers, or simply tracking EU visitors on its website, can fall within scope. This extraterritorial reach is one of the most misunderstood parts of the law.
The core principles
Nearly every GDPR obligation traces back to a small set of principles:
- Lawfulness, fairness, and transparency. You need a valid legal basis to process data (consent, contract, legal obligation, and a few others), and people must be told clearly what happens to their data.
- Purpose limitation. Data collected for one purpose shouldn’t quietly be reused for something unrelated.
- Data minimization. Collect only what you actually need.
- Storage limitation. Don’t keep data longer than necessary.
- Integrity and confidentiality. Appropriate security measures are required, proportionate to the risk.
Rights the GDPR gives individuals
The regulation grants people a set of enforceable rights over their own data, including the right to access what’s held about them, request correction or deletion, restrict certain processing, and receive their data in a portable format. Businesses need a real process for handling these requests, not just a policy document.
First steps toward compliance
For a small or mid-sized business, a reasonable starting point looks like:
- Map what personal data you collect, where it’s stored, and why.
- Identify the legal basis for each processing activity.
- Update your privacy policy to reflect that mapping accurately.
- Put a data processing agreement in place with any third-party vendor that touches EU personal data (hosting providers, analytics tools, email platforms).
- Set up a documented process for responding to access and deletion requests within the required timeframe.
Penalties are real, but proportionality matters
Fines can reach up to €20 million or 4% of global annual turnover for the most serious violations, but regulators generally scale enforcement to the severity and nature of the breach, especially for smaller organizations acting in good faith. That said, “we didn’t know” is not treated as a defense — the obligation to comply exists regardless of company size.
This article is a general overview and not a substitute for advice from a qualified data protection professional, particularly for businesses processing sensitive categories of data or operating at scale.
- GDPR
- data protection
- privacy
- compliance
This article is provided for general informational purposes only and does not constitute legal advice. Read our full disclaimer.