Back to Glossary
What Is GDPR (General Data Protection Regulation)?
Legal & Compliance
Updated 18 September 2026
Quick Answer
GDPR (General Data Protection Regulation) is UK/EU law governing how businesses collect, store, and use personal data — requiring clear consent, a privacy policy, and specific rights for individuals over their own data.
GDPR vs. Privacy Policy — What's the Difference?
| GDPR | Privacy Policy | |
|---|---|---|
| What it is | The legal requirement itself | The document a business publishes to comply with it, among other things |
Why It Matters
- It applies to essentially any business collecting personal data (including a simple contact form or email list), not just large companies.
- Non-compliance carries real legal and financial risk, regardless of business size.
How It Works
- A business identifies what personal data it collects (contact forms, email lists, cookies).
- It establishes a lawful basis for collecting it, typically clear consent, and documents this in a privacy policy.
- It provides ways for individuals to access, correct, or request deletion of their data.
Key Takeaways
- GDPR governs how businesses collect, store, and use personal data.
- It applies to businesses of any size collecting data from UK/EU individuals.
- A privacy policy and clear consent mechanisms (like cookie banners) are core compliance requirements.
Frequently Asked Questions
Does GDPR apply to a small business?
Yes — it applies regardless of business size if you collect personal data from UK/EU individuals, including through a simple website contact form.
Do I need a cookie consent banner because of GDPR?
Yes, if your site uses non-essential cookies like tracking or analytics, you need clear consent before they're set.
What happens if I don't comply with GDPR?
Non-compliance carries potential fines and legal risk, regardless of business size — though enforcement typically focuses on genuine misuse rather than minor technical oversights.