TL;DR — The essentials of the GDPR
The General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) is the European regulation governing the processing of personal data. It applies to any controller or processor established in the EU, or offering services to data subjects in the EU. It requires six legal bases (Art. 6), guarantees eight rights to data subjects, mandates security measures (Art. 32), regulates international transfers (Arts. 44-49) and provides for fines of up to €20 million or 4% of global turnover. In Spain it is complemented by the LOPDGDD (Organic Law 3/2018) and the AEPD is the supervisory authority.
Key milestones timeline
The GDPR and its regulatory environment have evolved since 2018. These are the relevant milestones:
For details on each milestone, see the GDPR glossary and the AI Act vs GDPR comparison.
Key areas of the GDPR
The Regulation is structured around six fundamental areas. Obligations are proportional to the risk of the processing:
Legal bases
Six bases under Art. 6 (consent, contract, legal obligation, vital interests, public task, legitimate interests) plus Art. 9 bases for special data.
Examples: Explicit consent, legitimate interest, contract
Data subject rights
Eight rights: access, rectification, erasure, restriction, portability, objection, no automated decision and complaint to the AEPD.
Examples: Right to be forgotten, portability, objection
Security and breaches
Technical and organisational measures (Art. 32). Breach notification within 72 hours (Art. 33).
Examples: Encryption, pseudonymisation, breach register
International transfers
Countries with adequacy decision or appropriate safeguards: SCCs, BCRs, codes of conduct, certifications.
Examples: SCCs 2021, BCRs, EU-US Framework
DPO and DPIA
Data Protection Officer mandatory in Art. 37 cases. Data Protection Impact Assessment mandatory in Art. 35 cases.
Examples: Internal or external DPO, DPIA
Fines
Up to €20 million or 4% of global turnover (upper level). Up to €10 million or 2% (lower level).
Examples: CaixaBank €6M, BBVA €5M, Vodafone €8M
GDPR resources
Glossary, tools, services and training for Regulation compliance:
GDPR Glossary
45+ key terms of Regulation (EU) 2016/679 and the Spanish LOPDGDD with article references.
AI Act vs GDPR
Comparative table of both regulations: scope, obligations, fines and points of intersection.
GDPR Compliance Checker
Free self-assessment tool with 15 questions across 12 areas. No email or registration.
DPO as a Service
External Data Protection Officer service for SaaS and technology companies.
GDPR Training for Product Managers
Practical workshop for product teams designing features with personal data.
AI & Data Regulation Service
Integrated advisory on GDPR, AI Act and data governance.
Sector GDPR guides
Vertical-specific analyses with use cases, applicable legal bases, rulings and AEPD fines:
GDPR for Fintech
Credit scoring, Art. 22 GDPR, Schufa ruling and AEPD fines in the financial sector.
GDPR for SaaS
Controller-sub-processor contracts (Art. 28), international transfers and cloud security.
GDPR for Healthtech
Health data (Art. 9), mandatory DPIA, healthcare legal bases and AEPD cases.
GDPR for Edtech
Children's data (LOPDGDD Art. 7), exam biometrics, parental consent and AEPD.
GDPR for E-commerce
Cookies (LSSI), profiling, automated decisions, dark patterns and AEPD fines.
Related articles
AI Act timeline for startups: key dates and how to prepare
Detailed analysis of the EU AI Act implementation timeline for tech startups. Deadlines, phase-by-phase obligations, and progressive compliance strategy.
How much does AI Act compliance cost: a guide for startups
Realistic breakdown of AI Act compliance costs by risk category. Indicative budgets, cost factors, and strategies to optimise investment for AI startups.
AI Regulation: system classification and compliance requirements
Practical guide to classify AI systems according to risk level and determine the transparency, documentation and governance requirements applicable to each category.
International data transfers post-Schrems II
International data transfer mechanisms compliant with CJEU case law: standard contractual clauses, BCR, impact assessments and supplementary measures.
Frequently asked questions
What is the GDPR and who does it apply to?
The General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) is the European regulation governing the processing of personal data. It applies to any controller or processor established in the EU that processes personal data, or to anyone not established in the EU who offers goods or services to data subjects in the EU or monitors their behaviour. In Spain it is complemented by the LOPDGDD (Organic Law 3/2018).
What is the difference between controller and processor?
The controller (Art. 4(7)) is the entity that determines the purposes and means of processing (e.g. a company collecting customer data). The processor (Art. 4(8)) is the entity that processes data on behalf of the controller (e.g. a cloud provider, a CRM, a marketing agency). The relationship between them is governed by a data processing agreement (Art. 28) that sets out security, confidentiality and sub-processor obligations.
When is a DPO mandatory?
The Data Protection Officer (DPO) is mandatory (Art. 37) when: (a) the processing is carried out by a public authority or body; (b) the controller's core activities consist of processing operations requiring systematic and large-scale assessment (e.g. credit scoring, monitoring); or (c) large-scale processing of special categories of data (health, biometrics) or criminal conviction data. It may be internal or external (DPO as a Service).
When is a Data Protection Impact Assessment (DPIA) mandatory?
A DPIA is mandatory (Art. 35) for high-risk processing, including: systematic and extensive evaluation of personal aspects (scoring), large-scale processing of special categories of data, systematic large-scale monitoring of public areas, or where required by the AEPD. It must document the risk analysis, mitigation measures and residual assessment. It is a prerequisite before starting the processing.
What fines does the GDPR provide for?
The GDPR sets two levels: upper level (up to €20 million or 4% of global annual turnover, whichever is higher) for breaches of basic principles, data subject rights and transfers; lower level (up to €10 million or 2%) for breaches of technical obligations, DPO, breach notification and cooperation with the authority. The AEPD has imposed fines of up to €6 million (CaixaBank, 2021) and €5 million (BBVA, 2020).
How are international data transfers made?
Transfers to countries with an adequacy decision (Japan, Switzerland, United Kingdom, EU-US Framework) require no authorisation. For the rest, appropriate safeguards are needed: Standard Contractual Clauses (SCCs 2021), Binding Corporate Rules (BCRs), codes of conduct or certifications. In addition, a Transfer Impact Assessment (TIA) must be carried out to verify that the country offers an essentially equivalent level of protection (EDPB Recommendations 01/2020).
What is the right not to be subject to automated decisions?
Art. 22 GDPR grants the data subject the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects or similarly significantly affects them. The CJEU confirmed in the Schufa case (2023) that credit scoring constitutes an automated decision under Art. 22. Exceptions: contract, legal authorisation, explicit consent, with additional safeguards.
Which authority supervises the GDPR in Spain?
The Spanish Data Protection Agency (AEPD) is the competent supervisory authority in Spain. At the European level, the European Data Protection Board (EDPB) coordinates enforcement between Member States through the one-stop-shop mechanism (Art. 56). The AEPD publishes sectoral guidance, infringement decisions and maintains a register of fines above €1 million.