Back to Glossary

What Is GDPR (General Data Protection Regulation)?

Legal & Compliance

Updated 18 September 2026

Quick Answer

GDPR (General Data Protection Regulation) is UK/EU law governing how businesses collect, store, and use personal data — requiring clear consent, a privacy policy, and specific rights for individuals over their own data.

GDPR vs. Privacy Policy — What's the Difference?

GDPRPrivacy Policy
What it isThe legal requirement itselfThe document a business publishes to comply with it, among other things

Why It Matters

  • It applies to essentially any business collecting personal data (including a simple contact form or email list), not just large companies.
  • Non-compliance carries real legal and financial risk, regardless of business size.

How It Works

  1. A business identifies what personal data it collects (contact forms, email lists, cookies).
  2. It establishes a lawful basis for collecting it, typically clear consent, and documents this in a privacy policy.
  3. It provides ways for individuals to access, correct, or request deletion of their data.

Key Takeaways

  • GDPR governs how businesses collect, store, and use personal data.
  • It applies to businesses of any size collecting data from UK/EU individuals.
  • A privacy policy and clear consent mechanisms (like cookie banners) are core compliance requirements.

Frequently Asked Questions

Does GDPR apply to a small business?

Yes — it applies regardless of business size if you collect personal data from UK/EU individuals, including through a simple website contact form.

Do I need a cookie consent banner because of GDPR?

Yes, if your site uses non-essential cookies like tracking or analytics, you need clear consent before they're set.

What happens if I don't comply with GDPR?

Non-compliance carries potential fines and legal risk, regardless of business size — though enforcement typically focuses on genuine misuse rather than minor technical oversights.