GDPR means General Data Protection Regulation. It is the European Union’s core data protection law, and it touches nearly every sector: technology, medicine, advertising, banking, payments, and beyond. The regulation does not concern only EU citizens and companies. Any organization that handles the personal data of people in the EU falls within its scope, regardless of where that organization is based.

Key Definitions
GDPR works with a broad definition of “personal data”: any information that can identify a living person, directly or indirectly. That covers obvious identifiers like a name or ID number, but also location data, IP addresses, online identifiers, and factors specific to a person’s physical, economic, cultural, or social identity.
Business owners have to learn the difference between a data controller and a data processor. If a firm collects data from EU residents and decides why and how it is processed, that firm is a data controller. If a company processes data on behalf of a data controller, it is a data processor. One organization can act as both a data controller and a data processor at the same time, depending on the activity.
The rules also regulate how companies monitor data subjects. For instance, tracking EU residents online through cookies, or using data processing methods to profile individuals and their behavior.
Data Processing and GDPR
GDPR sets out core principles that govern how personal data may be processed:
Legitimacy, justice, and transparency — all information on the objectives, methods, and volumes of personal data processing must be presented as accessibly and simply as possible.
Purpose limitation — data can only be collected for stated and declared purposes.
Data minimization — organizations are not allowed to collect more data than they need to achieve those stated objectives.
Accuracy — inaccurate personal data must be removed or corrected at the request of the user.
Limited retention — the period and form of data storage must correspond to the purposes of processing.
Integrity and confidentiality — a company that processes personal data must ensure it is protected from unauthorized access, destruction, or damage.
Key Provisions of GDPR
GDPR gives EU citizens and residents a set of enforceable rights:
- the right to confirmation — a data subject can request confirmation that their data is being processed, along with related information, the conditions of processing, and correction of any inaccuracy;
- the right to erasure — a data subject can require that their personal data be erased without undue delay, once they have requested it;
- the right to data portability — a controller must provide a data subject with their personal data in a structured, commonly used format on request, and, where feasible, transmit it to another controller.
Territorial Scope
GDPR has extraterritorial effect. It applies to any organization that processes the personal data of EU residents and citizens, regardless of where that organization is headquartered. Foreign companies with EU customers or users must be just as compliant as EU-based ones.
This is particularly true for organizations that store and process large volumes of consumer data. Such companies typically need to designate a Data Protection Officer (DPO) to monitor compliance. A DPO’s duties also include notifying the relevant regulatory authority, and affected data subjects where necessary, of any data breach within 72 hours of its detection.
GDPR in 2026: Enforcement, Numbers, and New Rules
Cumulative GDPR fines across the EU have now passed €7 billion since enforcement began in 2018, according to the DLA Piper GDPR Fines and Data Breach Survey, with roughly €1.2 billion issued in 2025 alone. Ireland’s Data Protection Commission remains the single largest enforcer by value. It has issued over €4 billion in fines, largely because so many global technology companies base their EU operations there, while Spain has issued the largest number of individual fines. France has overtaken Luxembourg as the second-largest enforcer by total value, driven by aggressive action from the CNIL on cookie consent and ad-tech practices, including nine-figure decisions against Google and Shein in 2025.
Media, telecoms, and broadcasting remains the most heavily fined sector, accounting for close to 70% of all corporate fine value. Regulators have also kept up pressure on the payments and fintech-adjacent space: breach-related fines tied to weak authentication and prolonged retention of financial identifiers, such as the tens of millions of euros levied against a major French telecom operator over a 2024 breach exposing tens of millions of customer records, show that supervisory authorities are treating security failures and poor data retention practices as GDPR violations in their own right, not just privacy issues.
Two developments are reshaping the compliance landscape for 2026 and beyond.
The Digital Omnibus. In November 2025, the European Commission proposed a package of “targeted amendments” to GDPR, bundled with related changes to the AI Act, ePrivacy rules, NIS2, and DORA. The stated aim is to cut administrative overhead. The Commission estimates the reform could reduce compliance costs for smaller businesses by up to 25%, without lowering the level of protection for individuals. Proposed changes include a single entry point for breach notifications across multiple EU laws, clearer standards for cookie consent (including standardized, machine-readable consent signals), and adjustments to the legal basis available for training AI models on personal data. The package is still moving through the European Parliament and Council, and officials have been explicit that this is not a reopening of GDPR itself: the maximum penalty of €20 million or 4% of global annual turnover is not on the table. Businesses should treat the Omnibus as a signal of direction rather than a finished rulebook, and continue operating under the existing GDPR requirements until changes are formally adopted, which is not expected before late 2026 at the earliest.
UK GDPR under the Data (Use and Access) Act. The UK’s Data (Use and Access) Act 2025 (DUAA) is the most significant reform to UK GDPR since Brexit. Core data protection provisions came into force in February 2026, giving businesses more flexibility around automated decision-making (the stricter regime now applies mainly to special category data), introducing a “recognised legitimate interests” lawful basis, and clarifying timelines for responding to data subject access requests. From 19 June 2026, all controllers subject to UK GDPR must also have a formal complaints-handling process in place for data protection complaints. Companies operating in both the EU and UK now need to track two frameworks that are diverging in places, even though both still trace back to the original GDPR text.
For payments and fintech businesses specifically, three consequences stand out. First, the AI Act’s high-risk provisions are converging with GDPR obligations around profiling, credit scoring, and fraud detection systems, creating a second layer of compliance risk on top of existing data protection duties. Second, international data transfers remain a persistent enforcement flashpoint. The Meta transfer case and its record €1.2 billion fine are a reminder that transfer mechanisms need active maintenance, not a one-time sign-off. Third, breach response speed and data retention discipline are increasingly what separates a manageable incident from a headline fine: several of the largest recent penalties trace back to data kept far longer than necessary, or breach notifications that failed to explain consequences to affected customers clearly enough.
How to Comply With GDPR
- Conduct a comprehensive assessment of the methods and systems used for personal data processing to confirm they align with GDPR requirements;
- Review the privacy policy and user agreements, and keep them updated as the Digital Omnibus and, where relevant, UK DUAA reforms take effect;
- Develop internal policies that strengthen the data protection mechanism, including regular staff training and ongoing scrutiny of data processing operations;
- Map international data transfers and confirm the legal mechanism behind each one still holds up;
- Review retention schedules — regulators are increasingly fining companies for holding data, including financial identifiers, longer than necessary.
The Cost of Non-Compliance
Under GDPR, penalties for non-compliance can reach €20 million or 4% of a company’s global annual turnover for that year, whichever is higher, and that ceiling is not changing under the current reform proposals. The average fine issued so far sits at roughly €2.4 million, though most penalties cluster well below that figure; it is a small number of very large cases against major technology and telecom companies that pull the average up. For businesses handling payments data in particular, the practical lesson from recent enforcement is that GDPR compliance is judged as much on security practices and retention discipline as on paperwork.


