GDPR was adopted as Regulation (EU) 2016/679 of the European Parliament and of the Council on 27 April 2016. It entered into force after publication in the Official Journal of the European Union and began to apply from 25 May 2018. As an EU regulation, it is directly applicable in all EU Member States, which means that it does not need separate national implementation in the same way as a directive. It replaced the older Data Protection Directive 95/46/EC, which had been created in 1995, long before today’s digital economy, social media platforms, large-scale tracking, cloud services and behavioural advertising became common.
The main purpose of GDPR was to create one consistent data protection framework across the European Union and to strengthen the rights of individuals. The regulation introduced core legal principles such as lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability. It also clarified the legal bases for processing personal data, including consent, contract performance, legal obligation, vital interests, public task and legitimate interest. In practice, this means that companies must always know why they process personal data, on what legal basis, for how long, who has access to it and how it is protected.
GDPR also gave individuals stronger rights, including the right of access, rectification, erasure, restriction of processing, data portability, objection and the right not to be subject to certain automated decisions. It introduced stricter duties for controllers and processors, such as privacy by design, privacy by default, breach notification, data processing agreements, records of processing activities and stronger security obligations. One of the most important enforcement tools is the possibility of administrative fines, which can reach up to €20 million or 4% of the total worldwide annual turnover, depending on the type and seriousness of the infringement.
Important court judgments and regulatory decisions have shaped the practical meaning of GDPR. One of the most significant was the Schrems II judgment of the Court of Justice of the European Union on 16 July 2020, which invalidated the EU-US Privacy Shield and made international data transfers much more sensitive legally. The Court confirmed that transfers of personal data outside the EU must ensure a level of protection essentially equivalent to EU law. This affected many companies using cloud, analytics, advertising and software services based outside the European Economic Area.
Another important area of enforcement concerns online advertising and large technology platforms. In January 2023, the Irish Data Protection Commission announced final decisions against Meta Ireland, including fines of €210 million for Facebook and €180 million for Instagram, related to GDPR breaches concerning the legal basis used for personalised advertising. Meta was also ordered to bring its processing operations into compliance. Later, the European Data Protection Board adopted an urgent binding decision concerning Meta’s behavioural advertising practices across the European Economic Area, showing that GDPR is not only a formal privacy law but also a major legal framework for digital advertising and platform business models.
In short, GDPR was introduced because the older legal framework no longer matched the realities of the digital world. It was designed to give individuals more control over their personal data, force organisations to be more transparent and accountable, and create a common legal standard for data protection across the European Union. Its importance has grown through major court judgments, enforcement decisions and high-profile cases involving international transfers, online advertising, consent, legitimate interest and the use of personal data by large technology companies.