GDPR: The Complete Guide for 2026
What is the GDPR?
The General Data Protection Regulation is the European Union's core data protection law, applicable since 25 May 2018. It governs processing in an EU or EEA establishment and can also reach organizations elsewhere when they offer goods or services to, or monitor the behavior of, people in the EU.
The GDPR represents the most significant change to data privacy regulation in over 20 years, establishing a new standard for how organizations must respect individual privacy rights.
The Six Legal Bases for Processing
Consent: The data subject has given clear, affirmative consent for processing their personal data for one or more specific purposes.
Contract: Processing is necessary for the performance of a contract to which the data subject is party.
Legal Obligation: Processing is necessary for compliance with a legal obligation to which the controller is subject.
Vital Interests: Processing is necessary to protect the vital interests of the data subject or another person.
Public Task: Processing is necessary for tasks carried out in the public interest or in the exercise of official authority.
Legitimate Interests: Processing is necessary for legitimate interests pursued by the controller or a third party, except where overridden by data subject rights.
Choosing a lawful basis is a purpose-by-purpose accountability decision. Consent is not automatically the safest basis: a contract, legal duty, or carefully assessed legitimate interest may be more appropriate, and special-category data has additional requirements.
Consent Under the GDPR
Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes or implied consent are not valid. Organizations must be able to demonstrate that consent was given and make it easy to withdraw.
A practical record should identify the notice and choices shown, the purposes and vendors covered, the user's action, and the time of the decision. Withdrawal must be as easy as giving consent, and a changed purpose generally requires a fresh assessment and, where needed, renewed consent.
Penalties and Enforcement
GDPR violations can result in fines of up to €20 million or 4% of global annual turnover, whichever is higher. Since 2018, data protection authorities across Europe have issued billions in cumulative fines.
How 1Consent Helps
1Consent helps teams configure purpose-level choices, control consent-dependent scripts, retain evidence, and provide a route to change or withdraw a decision. The organization remains responsible for selecting lawful bases, configuring the experience correctly, and validating its wider GDPR program with appropriate legal advice.
Building transparent consent infrastructure for the modern web.