Back to Glossary

Entry · Legal

General Data Protection Regulation Gdpr

The General Data Protection Regulation is the European Union's law on how organisations collect, store and use the personal information of people in the EU. It applies to any business that handles that information, wherever the business itself is based.

Breaches can lead to fines calculated as a share of worldwide turnover (total annual sales).

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

GDPR took effect in 2018 and replaced a patchwork of national data protection laws with a single set of rules across the EU. Personal data means anything that can identify a living person, from a name and email address to an IP address or a purchase history.

The law gives individuals rights over that data, including the right to see it, correct it and ask for it to be erased. Businesses must have a lawful basis for using personal data, such as consent, a contract, or a genuine legitimate interest.

They must also collect only what they need, keep it only as long as necessary, and protect it with appropriate security. Serious breaches generally have to be reported to the regulator within 72 hours.

The financial exposure is the reason finance teams care. The upper tier of fines is the greater of a fixed sum of 20 million euros or 4% of worldwide annual turnover, and a lower tier applies to less serious failings.

Fines are only part of the cost, because there are also legal fees, repair work, lost customer trust and possible compensation claims. GDPR applies on the basis of whose data you hold rather than where you are incorporated.

A US software company or a Singapore online retailer that sells to people in the EU, or monitors their behaviour, can fall within scope. Many such businesses appoint a representative in the EU and keep a record of their data activities.

In practice, compliance is a mix of legal, technical and financial work. Typical items include mapping where data sits, writing privacy notices, signing contracts with suppliers who handle data for you, and in some cases appointing a data protection officer.

The costs are real but are usually small compared with the cost of a major enforcement action.

In practice

Real-world examples.

1

Example

A UK online fashion retailer emails customers in Germany and France. Before the next campaign the marketing team checks that each address was collected with clear consent, and removes 12,000 contacts it cannot prove. The list is smaller, but the retailer avoids the risk of complaints.

2

Example

A software supplier in India hosts patient records for a clinic in Ireland. The clinic signs a data processing agreement with the supplier, setting out what the supplier may do with the data and how quickly it must report an incident.

3

Example

A marketing agency is offered a purchased mailing list of 200,000 contacts at a bargain price. Its finance director asks for proof of consent, receives none, and declines the purchase.

Formula

Calculation

Maximum fine (upper tier) = the greater of 20 million euros or 4% of worldwide annual turnover For simple arithmetic, treat 1 euro as $1. Company A has worldwide turnover of $1,000,000,000, so 4% is 0.04 x $1,000,000,000 = $40,000,000. That is higher than the fixed $20,000,000, so its maximum fine is $40,000,000. Company B has turnover of $100,000,000, so 4% is $4,000,000, which is lower than the fixed $20,000,000, so its maximum fine is $20,000,000. In practice regulators set fines according to the seriousness of the failing, so real fines are usually well below these ceilings.

Case study

Seen in the real world.

Meridian Journeys is an illustrative, fictional online travel company with customers across Europe and Asia. A coding error exposed the booking details of 50,000 customers for several days, and the company reported the incident to the regulator within the required window.

The direct costs were tallied by the finance team: $150,000 for the investigation, $60,000 for notifying customers and $90,000 in legal fees, a total of $300,000. The regulator examined whether the company had sound security and record keeping, and the fine was far below the legal maximum because the company had a data map and a prepared response plan.

Afterwards the CFO moved data protection spending from a discretionary line to a standing budget item. The illustrative point is that preparation is cheaper than a clean-up, and regulators take notice of it.

Watch out

Common mistakes.

  • Believing GDPR only applies to companies based in the EU, when it applies to anyone handling the data of people in the EU.
  • Treating consent as a pre-ticked box or a line buried in terms and conditions, when it must be clear, specific and easy to withdraw.
  • Assuming the headline maximum fine is the normal fine, or that only large companies are ever penalised.

Questions

People also ask.

Does GDPR apply to business-to-business data?

Yes, whenever the data relates to an identifiable person, such as a named work email address.

What is a data processor?

A supplier that handles personal data on your behalf, such as a payroll provider or cloud host; you remain responsible for it and need a written contract.

How long do we have to report a breach?

Generally within 72 hours of becoming aware of it, where the breach is likely to put individuals at risk.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.