Glossary
The GDPR (General Data Protection Regulation) is the European Union’s comprehensive data protection law, governing how organizations collect, process, store, and protect the personal data of individuals in the EU, with significant penalties for non-compliance. It’s the most influential privacy regulation in the world, shaping data-protection practices well beyond Europe and directly affecting how customer identity and data are handled.
Since taking effect in 2018, the GDPR has set the global benchmark for privacy, granting individuals strong rights over their personal data and imposing strict obligations on the organizations that handle it.
The GDPR is built on principles including lawfulness, fairness, and transparency; purpose limitation (data collected for specified purposes); data minimization (collect only what’s needed); accuracy; storage limitation; integrity and confidentiality (security); and accountability (being able to demonstrate compliance). These principles shape how any system that touches personal data (including identity systems) should be designed.
The GDPR grants individuals significant rights over their data: the right to be informed, to access their data, to rectification, to erasure ("right to be forgotten"), to restrict or object to processing, and to data portability. Organizations must be able to honor these requests, which requires knowing what personal data they hold and where, a real operational challenge that argues for unified, well-governed identity and data systems.
Processing personal data under the GDPR requires a lawful basis, consent being one of the most common for customer-facing scenarios. Where consent is the basis, it must be freely given, specific, informed, and unambiguous, and as easy to withdraw as to give. This is why consent management is central to GDPR compliance, and why it belongs in the identity layer where customer data and preferences live.
The GDPR bears directly on customer identity and access management. Identity systems hold personal data, so they must embody GDPR principles: data minimization (collect only necessary identity data: supporting approaches like progressive profiling and privacy-preserving verification), security (protect the data, which strong authentication and reducing stored secrets support), consent management, and the ability to honor access, portability, and erasure requests. Notably, techniques like device fingerprinting are treated as personal-data processing under the GDPR, requiring a lawful basis, which is why they must be used for legitimate security purposes with appropriate transparency.
The GDPR has real teeth: fines can reach up to €20 million or 4% of global annual revenue, whichever is higher, and enforcement has produced multi-hundred-million-euro penalties. Its reach is extraterritorial (it applies to any organization processing the data of EU residents, regardless of where the organization is based) which is why it has become a de facto global standard and why so many organizations worldwide align to it.
The GDPR’s most far-reaching effect may be as a template. Because it set a high, clear bar and applies to anyone handling EU residents’ data, privacy laws around the world have followed its model: California’s CCPA/CPRA, Brazil’s LGPD, and many others echo its principles of transparency, consent, individual rights, and accountability. For multinational businesses, aligning to GDPR often means aligning to the strictest common denominator, which then satisfies many other regimes. This convergence is why GDPR literacy is valuable well beyond Europe: the concepts it codified (data minimization, purpose limitation, lawful basis, the right to erasure) have become the shared vocabulary of modern privacy, and building identity and data systems to GDPR standards is a reasonable default for operating globally.
The GDPR enshrines "privacy by design and by default," meaning data protection should be built into systems from the start, not bolted on. For identity systems this is concrete: minimize the identity data collected (favoring progressive profiling and privacy-preserving verification like proving "over 18" without exposing full details), secure what’s held (strong authentication, and reducing stored secrets by going passwordless so there’s no password database to breach), obtain and honor consent within the identity layer, and make it possible to fulfill access, portability, and erasure requests. Designing identity this way turns GDPR compliance from a reactive burden into a property of the architecture, and, not coincidentally, the same choices that satisfy privacy regulators (collect less, protect more) also reduce breach and fraud exposure.
What is the GDPR?
The EU’s comprehensive data protection regulation governing how organizations collect, use, store, and protect personal data.
What rights does the GDPR give individuals?
Rights to be informed, access, rectification, erasure ("right to be forgotten"), restriction, objection, and data portability.
What is a lawful basis under the GDPR?
A legal justification for processing personal data (such as consent), required for any processing to be lawful.
How does the GDPR affect identity systems?
They must apply data minimization, security, consent management, and support access, portability, and erasure, and treat techniques like fingerprinting as personal-data processing.
What are the penalties for GDPR non-compliance?
Up to €20 million or 4% of global annual revenue, whichever is higher.
Related: CCPA · Consent Management · Data Breach · Digital Identity · Device Fingerprinting · eIDAS