Data privacy is a core business issue that affects risk, reputation, and long-term value. One of the most important developments in this space is the European Union’s General Data Protection Regulation (GDPR). The GDPR is a comprehensive data privacy law designed to protect personal information and give individuals more control over how their data is used. Important to understand is that businesses do not need to be located in the EU to fall under its rules. If your company is located in the EU, sells goods or services to EU residents, or monitors their behavior, GDPR applies.
Since its implementation in 2018, GDPR has influenced laws globally and set a new benchmark for privacy regulation. It has also increased awareness among consumers, who now expect greater transparency and control over their data.
As Kamran Salour of Lewis Brisbois explains, GDPR is fundamentally about planning, implementation, and compliance across the lifecycle of data use. It forces companies to think carefully about how they collect, store, and use personal information.
To understand compliance, it first helps to know the key roles defined by GDPR.
These include:
These roles determine responsibility. Controllers bear the primary burden of compliance, while processors must follow strict contractual obligations.
One of GDPR’s core requirements is that every use of personal data must have a clearly defined lawful basis, meaning that before a company collects, analyzes, or shares any personal information, it must be able to explain why it is legally allowed to do so.
Julian Schneider of Dornkamp LLP emphasizes that the question of legal basis should be the very first question companies consider when planning to use a customer’s personal data. Getting this step right sets the tone for the entire compliance framework.
In practice, most organizations rely on three primary lawful bases: consent, contracts, and legitimate interests.
Consent is often the most visible basis, particularly in consumer-facing applications. It requires clear, affirmative permission from the individual, typically through opt-in mechanisms. However, consent comes with a significant limitation: it can be withdrawn at any time. That means a company may suddenly lose its legal right to use the data, which can disrupt operations, analytics, or customer engagement strategies. For this reason, consent is not always the most stable foundation for ongoing business processes.
Contracts are generally more reliable. When data processing is necessary to fulfill a contractual obligation, companies can rely on this basis with greater confidence. Unlike consent, contractual necessity is not easily revoked, which makes it particularly useful for core business functions.
Legitimate interest is often viewed as a flexible fallback, but it is also the most nuanced. It requires a balancing test: the company must weigh its own business interests against the rights and expectations of the individual. If the individual’s privacy rights outweigh the company’s interest, the processing may not be lawful. Regulators tend to scrutinize this basis closely, making documentation and justification especially important.
GDPR fundamentally shifts the balance of power toward individuals (data subjects) by giving them a suite of enforceable rights over their personal data.
Among the most important are:
From an operational perspective, these rights can be difficult to implement. Companies must build systems that allow them to:
This is easier said than done. As Alex Sharpe of Sharpe Management Consulting LLC notes, in practice, many organizations do not have a complete or up-to-date picture of their data environment, which makes responding to these requests time-consuming.
One of GDPR’s most forward-looking concepts is ‘privacy by design.’ Rather than treating data protection as a compliance exercise after systems are built, GDPR requires organizations to integrate privacy considerations into the design and development of their processes, technologies, and products from the outset. This approach represents a shift in mindset.
As Bruce de’Medici of Grey Oar observes, privacy has effectively become a new category of corporate governance. Companies must now evaluate privacy risks alongside financial, operational, and strategic risks when making decisions.
At the center of this framework is the Data Protection Impact Assessment (DPIA). A DPIA is a structured risk assessment used to evaluate how a particular data processing activity might affect individuals’ rights and freedoms. It is required for high-risk activities, such as:
A DPIA is essentially about asking: What could go wrong, and how do we prevent it? It requires organizations to document:
Importantly, a DPIA is not just a one-time exercise. It should be revisited as systems evolve, new risks emerge, or regulatory expectations change.
From a practical standpoint, DPIAs and privacy by design more broadly enable organizations to identify potential issues early, reduce the likelihood of regulatory scrutiny, and build greater trust with customers and stakeholders.
The rapid adoption of artificial intelligence has added a new layer of complexity to data privacy, placing GDPR at the center of an evolving regulatory landscape. AI systems, by their nature, depend on large volumes of data, often including personal data, to train models, generate insights, and automate decision-making. This raises immediate and important questions around transparency, lawful use, bias, and accountability.
At its core, GDPR was not written specifically for AI, but its principles apply directly. AI doesn’t replace the obligations of GDPR; it amplifies them. If collecting certain data without consent was not permitted before, using AI to analyze that same data does not suddenly make it acceptable.
That said, AI does introduce new risks that GDPR alone does not fully address. For example:
To address these gaps, the European Union has introduced the EU AI Act, a complementary regulatory framework that builds on GDPR. While GDPR focuses on how data is handled, the AI Act focuses more directly on how AI systems are designed and used.
In short, AI may be changing how data is used, but it is not changing the fundamental expectation that data be handled responsibly, transparently, and with respect for individual rights.
GDPR may seem complex, but its core principles are straightforward. Companies need to understand their data, have a clear reason for using it, and be transparent about their practices.
GDPR is known for its potentially large fines, which can reach up to 4% of global revenue or €20 million. However, in practice, enforcement is often more nuanced.
Regulators typically focus on whether a company has made a genuine effort to comply. Documentation, transparency, and cooperation can go a long way in reducing penalties.
Many enforcement actions are less about the specific violation and more about the decision-making process behind it. If a company can show that it acted reasonably and thoughtfully, regulators are often more lenient.
While fines get the headlines, the bigger risk for many companies is reputational damage. Losing customer trust can be far more costly than any regulatory penalty. In today’s environment, consumers are increasingly aware of privacy issues and expect companies to handle their data responsibly. This shift means that good privacy practices can create a competitive advantage within an industry.
To learn more about this topic, view Introduction to EU General Data Protection Regulation: Planning, Implementation, and Compliance. The quoted remarks referenced in this article were made either during this webinar or shortly thereafter during post-webinar interviews with the panelists. Readers may also be interested to read other articles about cybersecurity.
This article was originally published on April 30, 2026.
©2026. DailyDACTM, LLC d/b/a/ Financial PoiseTM. This article is subject to the disclaimers found here.
Michele has been a director with Financial Poise since 2012. Share this page: