EMZETT.
Login

GDPR (DSGVO)

In short: The General Data Protection Regulation (“Datenschutz-Grundverordnung”, DSGVO in German) — the EU-wide law in force since 2018 that governs how companies may handle personal data.

In more detail: The GDPR applies to every company that processes data of people in the EU — regardless of where the company itself is based. Central principles: data minimisation (only collect what’s really necessary), purpose limitation (only use data for the stated purpose), transparency (users have to know what happens to their data) and comprehensive data subject rights. Violations can be punished with fines of up to 4% of worldwide annual turnover. In Germany, the GDPR is supplemented by the BDSG.

In Depth

The GDPR is built on seven basic principles (Art. 5) that every data processing operation has to meet:

Lawfulness              - there has to be a legal basis (e.g. consent, contract)
Purpose limitation      - only use data for the specified, stated purpose
Data minimisation       - only as much data as needed for the purpose
Accuracy                - data has to be factually correct and up to date
Storage limitation      - don't keep data longer than necessary
Integrity/confidentiality - appropriate technical protective measures
Accountability          - companies have to be able to prove compliance

For companies this means specifically: before any data is collected at all, there has to be a legal basis — usually either the user’s explicit consent (which must be revocable at any time) or necessity for a contract (e.g. a delivery address for an online purchase). “We collect the data because it might be useful” is not a valid legal basis.

In the event of a data breach (e.g. a hacked server with customer data), there’s also a strict 72-hour reporting obligation to the responsible supervisory authority — companies therefore need prepared processes for assessing and reporting an incident quickly, instead of improvising only when it happens.

Origins and scope

After years of negotiation, the GDPR came into force directly across the EU on 25 May 2018 (as a regulation it applies directly in every member state, without first having to be transposed into national law — unlike an EU directive). Its territorial scope deliberately extends beyond the EU: even a company based outside the EU (e.g. in the USA) has to observe the GDPR as soon as it offers goods or services to people in the EU or monitors their behaviour (e.g. via website tracking) — this approach, known as the “marketplace principle”, effectively makes the GDPR a global standard that internationally active companies can hardly escape.

Privacy by design and by default

Art. 25 GDPR requires “privacy by design” and “privacy by default”: data protection shouldn’t be “built into” a finished system afterwards, but should be considered from the start in the architecture (e.g. data minimisation already in the database schema, instead of deleting fields later). “By default” means specifically: default settings have to be the most privacy-friendly option by default — a newly registered user, for example, should NOT be signed up for marketing emails by default, but should have to actively agree (opt-in instead of opt-out).

Fines in practice

The maximum fines of up to 4% of worldwide annual turnover or 20 million euros (whichever is higher) have materialised in several spectacular cases since 2018: in 2021 Amazon received a fine of 746 million euros in Luxembourg for unlawful processing of personal data for advertising purposes, and in 2023 Meta (Facebook/Instagram) received 1.2 billion euros in Ireland for transferring EU user data to the USA without sufficient safeguards. These cases show that, despite initial doubts about its enforceability, the GDPR is now being enforced with considerable financial force — even against the largest tech corporations in the world.

Relationship to other data protection laws worldwide

The GDPR is considered the most influential data protection law internationally and served as a direct model for numerous similar laws in other countries, including California’s CCPA/CPRA, Brazil’s LGPD and South Korea’s PIPA — an effect referred to in legal scholarship as the “Brussels effect”: through the size of its market, the EU de facto sets global regulatory standards, because it’s often easier for internationally active companies to comply worldwide with the strictest applicable standard than to build separate systems for each market.

See also: BDSG, Data subject rights (GDPR), Personal data