What is GDPR?
The EU's data protection regulation. Governs how businesses may process personal data. Break it and fines can reach millions.
GDPR is the EU's major data protection regulation and stands for General Data Protection Regulation. In simple terms, it is the rulebook for how businesses and organisations may collect, store, and use personal data — any information that can be linked to a person, such as a name, email address, phone number, or purchase history.
The core idea is that the data belongs to the person, not the business. You as a business owner are borrowing it, and certain rules apply: you must have a valid reason to keep it, you may only collect what you actually need, and the person has the right to know what you hold and to be forgotten. Think of it as looking after someone else's valuables — you must be careful and able to account for what you do with them.
GDPR applies to anyone handling personal data about EU residents, regardless of how small the business is. And fines for breaking it can reach millions.
Why is GDPR important for your business?
Almost every business handles personal data — customer records, newsletters, employees. If you do not follow GDPR, you risk hefty fines and damaged trust with your customers.
But handled correctly, GDPR is also a competitive advantage. Customers trust businesses that are clear and responsible with their data.
GDPR in practice
A gym that collects members' names, ID numbers, and training habits must, under GDPR, explain why it stores the data, protect it from leaks, and be able to delete it if a member asks.
At ZORC, we build websites and systems with data protection built in from the start, so you follow GDPR without it becoming a daily hassle.
Common questions about GDPR
What does GDPR mean?
GDPR is the EU's data protection regulation governing how businesses may collect, store, and use personal data. The abbreviation stands for General Data Protection Regulation.
Which businesses must follow GDPR?
Any business or organisation that handles personal data about people in the EU must follow GDPR, regardless of size. That includes small businesses too.
What happens if you break GDPR?
Fines can be very high — in the worst cases, millions. On top of that, you risk damaged trust with customers and employees.
Related terms
Consent Mode
Google's standard for passing consent to its services. Consent Mode v2 has been required since March 2024.
DPA
Data Processing Agreement. Required when someone else processes personal data on your behalf — e.g. cloud providers.
DPF
EU-US Data Privacy Framework. The replacement for Privacy Shield. Allows data transfers to certified US companies.
DPIA
Data Protection Impact Assessment. A required impact assessment for high-risk processing under GDPR Article 35.
IMY
Sweden's data protection authority — the regulator for GDPR. Handles complaints and can issue fines.
Data Processing Agreement
A written agreement for everyone who handles your customers' data on your behalf. Complicated name, simple idea: you decide, they promise to behave.