What it means
GDPR took effect in 2018 and replaced a patchwork of national data protection laws with a single set of rules across the EU. Personal data means anything that can identify a living person, from a name and email address to an IP address or a purchase history.
The law gives individuals rights over that data, including the right to see it, correct it and ask for it to be erased. Businesses must have a lawful basis for using personal data, such as consent, a contract, or a genuine legitimate interest.
They must also collect only what they need, keep it only as long as necessary, and protect it with appropriate security. Serious breaches generally have to be reported to the regulator within 72 hours.
The financial exposure is the reason finance teams care. The upper tier of fines is the greater of a fixed sum of 20 million euros or 4% of worldwide annual turnover, and a lower tier applies to less serious failings.
Fines are only part of the cost, because there are also legal fees, repair work, lost customer trust and possible compensation claims. GDPR applies on the basis of whose data you hold rather than where you are incorporated.
A US software company or a Singapore online retailer that sells to people in the EU, or monitors their behaviour, can fall within scope. Many such businesses appoint a representative in the EU and keep a record of their data activities.
In practice, compliance is a mix of legal, technical and financial work. Typical items include mapping where data sits, writing privacy notices, signing contracts with suppliers who handle data for you, and in some cases appointing a data protection officer.
The costs are real but are usually small compared with the cost of a major enforcement action.
In practice
Real-world examples.
Example
A UK online fashion retailer emails customers in Germany and France. Before the next campaign the marketing team checks that each address was collected with clear consent, and removes 12,000 contacts it cannot prove. The list is smaller, but the retailer avoids the risk of complaints.
Example
A software supplier in India hosts patient records for a clinic in Ireland. The clinic signs a data processing agreement with the supplier, setting out what the supplier may do with the data and how quickly it must report an incident.
Example
A marketing agency is offered a purchased mailing list of 200,000 contacts at a bargain price. Its finance director asks for proof of consent, receives none, and declines the purchase.
Formula
Calculation
Maximum fine (upper tier) = the greater of 20 million euros or 4% of worldwide annual turnover
For simple arithmetic, treat 1 euro as $1. Company A has worldwide turnover of $1,000,000,000, so 4% is 0.04 x $1,000,000,000 = $40,000,000. That is higher than the fixed $20,000,000, so its maximum fine is $40,000,000. Company B has turnover of $100,000,000, so 4% is $4,000,000, which is lower than the fixed $20,000,000, so its maximum fine is $20,000,000. In practice regulators set fines according to the seriousness of the failing, so real fines are usually well below these ceilings.Case study
Seen in the real world.
Meridian Journeys is an illustrative, fictional online travel company with customers across Europe and Asia. A coding error exposed the booking details of 50,000 customers for several days, and the company reported the incident to the regulator within the required window.
The direct costs were tallied by the finance team: $150,000 for the investigation, $60,000 for notifying customers and $90,000 in legal fees, a total of $300,000. The regulator examined whether the company had sound security and record keeping, and the fine was far below the legal maximum because the company had a data map and a prepared response plan.
Afterwards the CFO moved data protection spending from a discretionary line to a standing budget item. The illustrative point is that preparation is cheaper than a clean-up, and regulators take notice of it.
Watch out
Common mistakes.
- Believing GDPR only applies to companies based in the EU, when it applies to anyone handling the data of people in the EU.
- Treating consent as a pre-ticked box or a line buried in terms and conditions, when it must be clear, specific and easy to withdraw.
- Assuming the headline maximum fine is the normal fine, or that only large companies are ever penalised.
Questions
People also ask.
Does GDPR apply to business-to-business data?
Yes, whenever the data relates to an identifiable person, such as a named work email address.
What is a data processor?
A supplier that handles personal data on your behalf, such as a payroll provider or cloud host; you remain responsible for it and need a written contract.
How long do we have to report a breach?
Generally within 72 hours of becoming aware of it, where the breach is likely to put individuals at risk.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
