Privacy & regulation · also called General Data Protection Regulation
GDPR
The GDPR (General Data Protection Regulation) is the European Union's data protection law, applying since May 2018, which governs how organisations collect and use personal data about people in the EU.
The GDPR sets rules for anyone processing personal data about people in the EU, wherever the company is based. Personal data is defined broadly: names and emails, but also cookie IDs, advertising IDs, IP addresses and anything that can single out a person.
Core principles include lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation and security. Every use needs a lawful basis, such as consent or legitimate interest. People have rights to access, correct, delete and object. Fines can reach €20 million or 4% of global annual turnover, whichever is higher; Ireland's regulator fined Meta €1.2 billion in 2023 over data transfers.
For advertising, GDPR works alongside the ePrivacy Directive, which requires consent for storing or reading information on a user's device, such as cookies, except where strictly necessary. That is why European sites show consent banners run by CMPs, often using the IAB IAB TCF. The UK has its own near-identical version, the UK GDPR.
Think of it like this
GDPR is like a building code for personal data: every room (use) needs a permit (lawful basis), fire exits (user rights) and inspections (regulators).
An example
A US ad tech company that serves ads to readers in Spain must have a lawful basis for processing their cookie IDs, honour access and deletion requests from Spanish users, and can be fined by EU regulators.
Related terms
IAB TCF (Transparency & Consent Framework)
The IAB TCF (Transparency & Consent Framework) is IAB Europe's standard for collecting users' GDPR consent and objections through CMPs and passing those choices to ad tech vendors in a consent string.
CMP (consent management platform)
A CMP (consent management platform) is software that shows users privacy choices, such as a cookie banner, records their consent or opt-outs, and passes them to the site's partners.
Legitimate interest
Legitimate interest is one of the GDPR's six lawful bases for processing personal data, allowing processing without consent when it is necessary for a genuine interest not overridden by the individual's rights.
Data minimization
Data minimization is the privacy principle that organisations should collect and keep only the personal data that is adequate, relevant and necessary for a specific, stated purpose.
Pseudonymous data
Pseudonymous data is personal data where direct identifiers are replaced with a code, such as a hashed email or random ID, so it cannot identify someone without additional information kept separately.
Consent string
A consent string is a compact encoded value recording a user's privacy choices, such as the TCF TC String or a GPP string, that travels with ad requests to vendors.
Sources: General Data Protection Regulation (EU) 2016/679, EUR-Lex, GDPR full text (gdpr-info.eu), GDPR Article 6: lawfulness of processing