GDPR
Also known as: General Data Protection Regulation · EU data protection regulation
The GDPR is the European regulation governing the processing of personal data, and it applies as soon as an organization targets people located in the European Union.
Its reach is extraterritorial: a Canadian company with no European presence falls under it if it offers goods or services to people there, or monitors their behaviour. Selling online to one French customer is enough to raise the question.
It rests on principles rather than a checklist: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality — and accountability for demonstrating all of it.
That last idea is the one that surprises people most: being compliant is not enough, you must be able to show it. Hence the record of processing activities, processor contracts, and documented decisions.
What it means for a small business
The most common trigger at a young company is not a European office — it is a first European customer, usually signed without anyone connecting it to a regulatory obligation.
So what actually applies to you?
A definition tells you what a term means, not what your organization must do. The assessment answers the second question — free, no credit card.
Updated September 1, 2026 · Educational definition; not legal advice.