← All compliance guides
European Union
General Data Protection Regulation
Regulation (EU) 2016/679 (GDPR)Who it applies to
Any business, anywhere in the world, that offers goods or services to people in the EU or monitors their behavior — not limited to businesses based in the EU.
What it requires
- Opt-in consent before non-essential cookies or trackers fire, not an opt-out model
- Consent that is freely given, specific, informed, and as easy to withdraw as it was to give
- A documented lawful basis for every category of data processing
- Data processing agreements with every processor, and Standard Contractual Clauses for data leaving the EU
What's changed recently
CNIL, France's data protection authority, fined Shein €150M in September 2025 for advertising cookies that fired before visitors interacted with the consent banner, and for a Reject All button that did not actually stop new tracking — the same failure pattern regulators are now finding in the US.
Informational summary, not legal advice. Reviewed for accuracy as of August 2026; laws and enforcement priorities change, so verify current requirements against the official regulator text before relying on this page.