Glossary
DataMarketinggeneral

GDPR

Also: General Data Protection Regulation, Regulation (EU) 2016/679, Règlement Général sur la Protection des Données, RGPD, Datenschutz-Grundverordnung, DSGVO, EU Data Protection Regulation

EU regulation governing how organizations collect, store and use personal data, with fines tied to global revenue for breaches.

What It Is

GDPR (General Data Protection Regulation) is the European Union law that sets the rules for handling personal data of people in the EU. It applies to any organization that processes EU residents' data, regardless of where that organization is based. A US company selling to French customers is bound by it. Personal data means anything that can identify a person: name, email, IP address, location, purchase history, even a cookie ID.

Why it matters

GDPR carries penalties large enough to reach the CFO's attention: fines can climb to a percentage of worldwide annual turnover, not just local revenue. A single compliance failure can turn a routine marketing campaign into a board-level financial and reputational risk. Beyond fines, it shapes what your teams can actually do. A CMO who wants to buy a third-party audience list, a CDO building a customer data platform, or an AI lead training a model on customer records all hit the same question: do we have a lawful basis to use this data? Consent obtained badly, or data kept longer than needed, becomes a liability rather than an asset.

How it works

GDPR runs on a few core mechanisms. You need a lawful basis for every use of personal data, most often consent or legitimate interest, and you must be able to prove it. Individuals hold rights: to access their data, correct it, delete it ("right to be forgotten") and object to profiling. In practice a leader meets GDPR when signing off a new tool. Example: your team wants to enrich the CRM with an outside data provider. Legal will ask where consent came from, how long records are retained, and whether a Data Protection Impact Assessment is required. If a breach occurs, you generally have a tight window (72 hours) to notify the regulator. Building consent capture, retention limits and deletion workflows into systems from the start is far cheaper than retrofitting them after an audit.