# GDPR Overview | Secureframe

> Learn the basics of GDPR, including how it applies to your business and customers, who enforces it, and the consequences of non-compliance.

canonical: https://secureframe.com/hub/gdpr/overview

[46% of consumers](https://www.cisco.com/c/dam/en_us/about/doing_business/trust-center/docs/cisco-cybersecurity-series-2021-cps.pdf?CCID=cc000742&DTID=esootr000875&OID=rptsc027438) feel they are unable to effectively protect their data today, with 76% explaining it’s too hard for them to understand what’s going on and how their information is being used.

As consumers' concerns about their privacy continue to grow, some governments are implementing regulations to help address the privacy risks facing consumers today. 

In 2018, the European Union implemented General Data Protection Regulation (GDPR) to create one legal framework for collecting and processing personal information from European Union (EU) residents. This landmark legislation has already inspired similar data privacy laws around the world, including in the United States, Japan, South Korea, Brazil, and China. 

While GDPR is known for its data privacy violation punishments, complying with this data privacy law goes beyond avoiding fines. It’s about keeping data safe while giving people more power over who can process their personal data and why. 

You understand the importance of these objectives, especially if you’re trying to gain customer trust and grow your business.

In this overview for beginners, we’ve broken down GDPR’s privacy regulations into clear-cut fundamentals so you can quickly and easily understand whether you need to be compliant. 

You’ll learn the essentials of the EU’s data protection law, how it applies to your business and customers, who enforces it, and the consequences of non-compliance.

## Beginner: I'm New to GDPR

**Let’s start from the beginning. **

Understanding the basics of [GDPR compliance](https://secureframe.com/blog/gdpr-announcement) helps streamline the entire preparation and audit process, allowing you to get compliant faster and with less stress.

Here are the essentials you need to know.

![](https://images.prismic.io/secureframe-com/a995a16b-a991-4129-a8f2-35a0e33ec932_GDPR+announcement.png?auto=compress,format)

## The Basics of GDPR

General Data Protection Regulation (commonly known as GDPR) is a law passed by the European Union to establish data privacy and security laws.

Although it was drafted and passed by the EU, it applies to any organization that targets or collects data from EU residents.

GDPR is known for cracking down on violations by implementing steep fines, with penalties in the tens of millions of euros. 

## The History and Purpose of GDPR

Although the GDPR was passed just a few years ago, its roots stretch back to the 1950s. The European Convention on Human Rights of 1950 states that everyone has a fundamental right to privacy. 

As the internet became more prominent, the EU began to recognize the need for more modern protections. It passed the European Data Protection Directive in 1995, which established some baseline data privacy and information security standards. Each EU member state implemented its own law based on those guidelines.

Then in the late 2000s and early 2010s, the EU recognized the need for a more comprehensive solution for keeping data safe while giving people more power over who can process their personal data and why. They began considering ways to update the 1995 directive. 

The GDPR was passed by the European Parliament in 2016 and went into effect on May 25, 2018. 

## How do you become GDPR compliant? 

To achieve compliance, organizations must follow certain requirements for the processing of personal data.

[Key requirements](https://secureframe.com/hub/gdpr/compliance-requirements) include:

- **Establishing a legal basis for data processing:** Organizations must have a valid legal basis for collecting and processing personal data, like fulfilling contractual or legal obligations.
- **Obtaining explicit consent from data subjects:** Organizations must explain how they process data in a form — most opt for a clearly-written privacy notice. 
- **Implementing technical and organizational safeguards:** Organizations must implement safeguards to ensure customer data is handled securely. Safeguards may include appropriate logical access controls and conducting annual security and privacy awareness training. 
- **Sending breach notifications:** In the event of a data breach, organizations must notify the supervisory authority within 72 hours.
- **Appointing a data protection officer (if applicable):** Certain organizations are required to appoint a data protection officer to oversee the organization’s data protection strategy and its implementation.
- **Honoring data subject rights:** Data subjects have certain rights under GDPR, including the right to be informed, the right of access, and the right to object. 

Now that you have a solid understanding of what GDPR is, let’s dive deeper into the compliance process. 

Getting GDPR compliant can be a difficult and long process due to complicated legal requirements and unclear expectations, so you’ll want to understand the steps involved before you get started. 

The following section dives into the what and why of GDPR, including how it applies to your business and customers, who enforces it, and the consequences of non-compliance.
