How GDPR Actually Works (And Why It Changed Global Tech)
If you have clicked “Accept all cookies,” downloaded a copy of your personal data, or received an email asking you to update your privacy preferences, you have probably encountered the effects of GDPR.
By Aidan Mays on September 17, 2026

Getty Images
If you have clicked “Accept all cookies,” downloaded a copy of your personal data, or received an email asking you to update your privacy preferences, you have probably encountered the effects of GDPR.
The General Data Protection Regulation became applicable across the European Union on May 25, 2018. It was designed to strengthen people’s rights over their personal information while creating a more consistent set of data-protection rules across Europe.
But GDPR became much more than a European privacy law.
Because global technology companies wanted continued access to European users, many had to redesign how they collected, stored, shared, and explained their use of personal information. European privacy concepts consequently began influencing technology products and privacy legislation far beyond the EU.
The easiest way to understand GDPR is not as a giant collection of cookie rules. Its basic principle is much simpler: if an organization uses people’s personal data, it needs a legitimate reason for doing so and must handle that information responsibly.
GDPR protects much more than your name
“Personal data” under GDPR has a broad meaning.
It includes obvious information such as someone’s name, home address, or identification number. But it can also include an IP address, cookie identifier, advertising identifier, and other information that can identify someone directly or indirectly.
Processing is equally broad.
Collecting personal information counts. So does storing it, analyzing it, consulting it, transferring it, modifying it, and deleting it.
Imagine an online store.
It collects your name and address to deliver an order. It stores your email address. Its analytics software may collect information about how you use the website. Its advertising technology may attempt to track your behavior.
GDPR potentially affects all of those activities.
Consent is only one way to legally use data
One of the biggest misconceptions about GDPR is that companies always need your consent before processing personal information.
They do not.
Consent is one legal basis, but GDPR recognizes several others. Processing may, for example, be necessary to perform a contract, comply with a legal obligation, protect someone’s vital interests, perform certain public-interest tasks, or pursue legitimate interests under appropriate circumstances.
Consider buying a pair of shoes online.
The retailer does not need to ask, “Do you consent to us using your address to deliver the shoes?” Processing the address is necessary to fulfill the transaction.
Using the same information for an unrelated advertising purpose is a different question.
That distinction is central to GDPR: companies should know why they are processing information rather than collecting data first and figuring out what to do with it later.
Companies are supposed to collect what they actually need
GDPR establishes seven core principles for handling personal data, including lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability.
“Data minimization” is particularly important.
A business should collect information that is adequate, relevant, and limited to what is necessary for its purpose.
If an app only needs your email address to send a newsletter, asking for your home address, passport number, employer, birthday, and precise location would require considerably more justification.
Purpose limitation works alongside this principle.
Organizations should identify why information is being collected and should not simply reuse it for completely unrelated purposes without considering whether that new use is legally permitted.
GDPR therefore changed an old technology instinct: collect everything because the data might become useful someday.
Under GDPR, “we might want it later” is not a sufficient data strategy.
Users received much stronger rights
GDPR also gives individuals a collection of rights over their information.
Depending on the circumstances, people can request access to personal data, correct inaccurate information, request deletion, restrict certain processing, object to processing, and receive certain information in a portable format. There are also protections concerning automated decision-making and profiling.
The famous “right to be forgotten” is part of this broader framework, although it is not an unlimited right to erase anything you dislike from the internet.
Organizations may sometimes have legitimate or legal reasons to retain information.
A bank, for example, cannot necessarily erase every record of a customer immediately simply because the customer requests deletion. Other laws may require certain financial records to be retained.
GDPR creates rights, but those rights operate alongside other legal obligations.
GDPR can follow companies outside Europe
This is where GDPR became particularly important to the global technology industry.
The rules are not limited exclusively to companies headquartered inside the EU.
They can also apply to organizations outside the EU when those organizations offer goods or services to people in the EU or monitor their behavior there.
Imagine a technology startup headquartered in the United States.
It has no European office, but it deliberately sells subscriptions to customers in France, Germany, Italy, and Spain.
Being physically located in America does not automatically place it outside GDPR’s reach.
This extraterritorial element dramatically increased the regulation’s influence. Global technology companies could not simply treat European privacy rules as an issue affecting European companies.
The penalties made companies pay attention
GDPR also came with meaningful enforcement powers.
Depending on the violation, regulators can issue warnings and reprimands, restrict or prohibit processing, and impose administrative fines. For the most serious categories of infringement, fines can reach €20 million or 4% of a company’s total annual worldwide turnover, whichever applicable ceiling is higher.
For a small business, €20 million is enormous.
For a global technology corporation, calculating penalties using worldwide revenue makes the rules much harder to dismiss as another minor compliance expense.
But fines are only part of the risk.
Being ordered to stop processing particular data can potentially be more disruptive for a technology company whose entire business depends on that information.
GDPR changed how products are designed
The deeper impact of GDPR happened inside companies.
Privacy increasingly became something engineers, designers, marketers, product managers, and executives needed to consider while building products.
The regulation includes the concepts of data protection “by design” and “by default.” Organizations should incorporate appropriate privacy protections into processing activities from the beginning rather than attempting to add them after a product launches.
That helped push features such as privacy dashboards, data-download tools, deletion processes, consent-management systems, retention controls, and clearer privacy notices deeper into mainstream technology.
It also helped create an entire privacy-technology industry devoted to helping businesses understand, map, protect, and govern personal data. Research on GDPR’s broader economic effects has identified substantial growth in technologies designed specifically around privacy compliance.
Europe effectively exported its privacy philosophy
GDPR’s biggest achievement may be its influence beyond its formal jurisdiction.
Researchers describe European data-protection rules as an important example of the “Brussels Effect”: the ability of EU regulation to influence standards and business practices outside Europe because multinational companies want access to the European market.
Privacy laws in numerous countries have subsequently incorporated concepts resembling parts of the European approach, although they are not necessarily copies of GDPR. Academic research published in 2026 describes European data-protection norms as having become a major international reference point for privacy regulation.
Global companies also face a practical problem.
Maintaining completely different privacy systems for every country can be complicated. Sometimes it is easier to introduce stronger privacy controls across multiple markets rather than build an entirely separate European product.
That is how a European regulation can influence what someone sees on a website thousands of kilometers away.
GDPR changed the default question
Before GDPR, many technology companies operated according to a relatively simple philosophy: if data could be collected, collecting it might eventually create value.
GDPR forced a different set of questions.
What information are we collecting? Why do we need it? What legal basis allows us to process it? How long should we keep it? Who can access it? How is it protected? And what rights does the person behind that data have?
Those questions are now deeply embedded in modern technology governance.
GDPR did not end online tracking, eliminate data breaches, or solve every privacy problem. It also created significant compliance costs and remains the subject of debate over enforcement and complexity.
But it permanently changed the relationship between technology companies and personal information.
Its most important idea is surprisingly simple: personal data is not merely a resource for companies to collect.
There is a person on the other side of it.



















