Glossary
General Data Protection Regulation (GDPR)
The European Union's comprehensive data protection law governing how personal data of people in the EU is collected and used.
Also called: GDPR
The General Data Protection Regulation, GDPR, is the European Union's comprehensive data protection law, in effect since 2018, governing how organizations collect, store, process, and share the personal data of people located in the EU, regardless of where the organization processing it is based. It defines "personal data" broadly, covering anything relating to an identifiable person, and requires a valid legal basis, such as consent or legitimate interest, before that data can be processed.
For analytics teams, GDPR's most direct effects are on tracking and measurement: cookie and pixel-based tracking generally requires informed consent, handled in practice through a consent management platform, and individuals have enforceable rights to access, correct, or delete their data, which analytics systems need to be able to honor. GDPR differs from sector- or state-specific laws like California Consumer Privacy Act or Health Insurance Portability and Accountability Act in being broader in scope and generally stricter in its consent requirements, though the specifics of each overlap only partially, and it also constrains where data can be transferred, an issue closely tied to data residency.
GDPR matters to analytics work because it shapes what data can be collected at all, not just how it's secured after the fact, and non-compliance carries substantial financial penalties. Techniques like pseudonymization and data minimization are explicitly encouraged as risk-reducing measures. This is a general description, not legal advice; specific obligations depend on the nature of the processing, and organizations should consult qualified counsel for compliance decisions.
Last reviewed September 22, 2026