← All compliance guides
European Union

General Data Protection Regulation

Regulation (EU) 2016/679 (GDPR)

Who it applies to

Any business, anywhere in the world, that offers goods or services to people in the EU or monitors their behavior — not limited to businesses based in the EU.

What it requires

  • Opt-in consent before non-essential cookies or trackers fire, not an opt-out model
  • Consent that is freely given, specific, informed, and as easy to withdraw as it was to give
  • A documented lawful basis for every category of data processing
  • Data processing agreements with every processor, and Standard Contractual Clauses for data leaving the EU

What's changed recently

CNIL, France's data protection authority, fined Shein €150M in September 2025 for advertising cookies that fired before visitors interacted with the consent banner, and for a Reject All button that did not actually stop new tracking — the same failure pattern regulators are now finding in the US.

Informational summary, not legal advice. Reviewed for accuracy as of August 2026; laws and enforcement priorities change, so verify current requirements against the official regulator text before relying on this page.

Not sure where European Union leaves you exposed?