GDPR — the General Data Protection Regulation
Regulation (EU) 2016/679 (CELEX 32016R0679) · In force across the EU/EEA since 25 May 2018
The GDPR (General Data Protection Regulation) governs how personal data may be collected and processed in the EU/EEA. It applies to every organisation that processes personal data about people in the EU — regardless of where the organisation itself is based.
// In brief
- Directly applicable across the EU/EEA since 25 May 2018 (Regulation (EU) 2016/679).
- Built on seven principles in Article 5 — including purpose limitation, data minimisation and accountability.
- All processing needs a lawful basis (Article 6): e.g. consent, contract, legal obligation or legitimate interests.
- Personal data breaches must be notified to the supervisory authority within 72 hours (Article 33).
- Fines of up to €20 million or 4% of global annual turnover (Article 83). Supervisory authority in Sweden: IMY.
Who and what does the GDPR cover?
The GDPR applies to the processing of personal data — any information that directly or indirectly relates to an identifiable living person (name, email address, IP address, customer ID, and so on). It covers both controllers (whoever determines the purposes and means of processing) and processors (whoever processes data on a controller's behalf).
Territorially (Article 3), it applies to organisations established in the EU, but also to companies outside the EU that offer goods or services to, or monitor the behaviour of, people in the EU.
The seven principles (Article 5)
- Lawfulness, fairness and transparency — process data lawfully and openly.
- Purpose limitation — collect data for specified, explicit purposes.
- Data minimisation — only what is actually needed.
- Accuracy — keep data correct and up to date.
- Storage limitation — keep data no longer than necessary.
- Integrity and confidentiality — protect data against unauthorised access.
- Accountability — be able to demonstrate compliance.
Lawful bases (Article 6)
No processing without a lawful basis. The six bases are: consent, performance of a contract, legal obligation, protection of vital interests, a task carried out in the public interest and legitimate interests. Special categories of data (Article 9) additionally require a specific exemption.
Data subject rights
Individuals have the right to, among other things, information, access (a subject access request), rectification, erasure ("the right to be forgotten"), restriction of processing, data portability and to object to processing — as well as protection against decisions based solely on automated processing (Article 22).
Obligations in practice
Depending on your operations, you may need: records of processing activities (Article 30), data processing agreements (Article 28), a data protection impact assessment (DPIA) where the risk is high (Article 35), a data protection officer (Article 37) and data protection by design and by default (Article 25). In the event of a breach: notify the supervisory authority — in Sweden, IMY (the Swedish Authority for Privacy Protection), within 72 hours — and inform affected individuals if the risk is high.
How ZORC helps
We build with data protection at the core: lawful bases and consent management in place, EU-based hosting, encryption, access control and clear documentation. Talk to us about privacy-first architecture →
This page is informational and fact-checked against the primary source, but it does not constitute legal advice. For a binding assessment of your specific organisation — talk to us or your legal counsel.
Frequently asked questions
What is the GDPR in simple terms?
The GDPR is the EU's data protection regulation. It sets the rules for how companies and public bodies may collect and handle personal data. Its purpose is to protect people's privacy and give them control over their own data.
Which companies does the GDPR apply to?
Every organisation that processes personal data about people in the EU/EEA — regardless of size and regardless of where the organisation itself is based. Sole traders and non-profits are covered too.
What are the penalties for breaching the GDPR?
Administrative fines of up to €20 million or 4% of global annual turnover, whichever is higher. Less serious infringements can lead to fines of up to €10 million or 2%.
Do we have to report a personal data breach?
Yes. A personal data breach must be notified to the supervisory authority — in Sweden, IMY (the Swedish Authority for Privacy Protection) — without undue delay and no later than 72 hours after becoming aware of it. Affected individuals must be informed if the risk to them is high.
How does the GDPR apply in Sweden?
The GDPR is an EU regulation and applies directly in Sweden. It is supplemented by the Swedish Data Protection Act (2018:218), which fills in national details such as age limits and exemptions. The Swedish supervisory authority is IMY.
// Primary sources
Last fact-checked: 2026-06-02.
// More laws
NIS2
The EU cybersecurity directive — who is covered, what it requires and how it applies in Sweden.
Cybersecurity Act
Sweden's new law implementing NIS2 — who is covered, the obligations and the penalty fees.
AI Act
The EU's AI regulation — risk categories, high-risk requirements, timeline and penalties.
Need help complying with GDPR?
We build secure, compliant solutions and help you map exactly what applies to your organisation.