General Data Protection Regulation — the European Union's comprehensive privacy law, in force since May 2018, that governs how personal data of EU residents may be collected, processed, and stored.

GDPR applies to any organization — regardless of where it is located — that processes personal data of people in the EU. It establishes rights for data subjects (access, rectification, erasure, portability, objection), obligations for data controllers and processors, and significant penalties for non-compliance.

Key GDPR principles include: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability.

GDPR is not Canadian law. However, Canadian organizations that handle data of EU residents — for example, through a website accessible in Europe — may be subject to GDPR requirements. GDPR has also influenced Canadian privacy law reform discussions.

Example: A Canadian e-commerce company sells products to customers in France. Because it processes personal data of EU residents, it must comply with GDPR — including providing a privacy notice, obtaining valid consent for marketing, and honouring requests to delete customer data.

This is educational information, not legal advice. Consult a qualified privacy professional for guidance on GDPR compliance.

Related Terms

Learn More

← Back to Glossary Français →