Glossary
GDPR (General Data Protection Regulation)
The GDPR (General Data Protection Regulation) is the European Union's data protection law, governing how organisations collect, use, store and transfer personal data, including employee data, with fines reaching up to 4% of a company's global annual turnover.
Reviewed by Teamed's in-house employment-law team·Last updated 28 July 2026
Also known as: General Data Protection Regulation, Regulation (EU) 2016/679
What is GDPR (General Data Protection Regulation)?
The GDPR, or General Data Protection Regulation, is the European Union's core data protection law. It sets out how personal data, meaning any information about an identifiable person, must be collected, used, stored, shared and deleted. It applies to organisations inside the EU and to those outside it that handle the data of people in the EU.
The regulation gives individuals rights over their data, such as access, correction and erasure, and places duties on the organisations that hold it, including keeping data secure, using it only for stated purposes, and restricting transfers to other countries. These rules cover employee data across the whole HR lifecycle, not just customer data.
Enforcement has teeth. Serious breaches can attract fines of up to 20 million euros, or 4% of global annual turnover, whichever is higher. For any company employing people in Europe, GDPR shapes how recruitment, payroll, benefits and termination records are handled from start to finish.
Does GDPR apply to employee data?
Yes, fully. GDPR covers personal data across the entire employment lifecycle: recruitment, onboarding, payroll, performance records, and termination. Employers must have a lawful basis for processing staff data, keep it secure, and respect employees' rights over it. It is a common misconception that the regulation only concerns customer or marketing data.
Because so much HR activity involves personal data, GDPR touches almost every stage of employing someone in Europe.
Who does GDPR apply to?
Any organisation established in the EU, and any organisation outside it that offers goods or services to, or monitors, people in the EU. A company based elsewhere still falls under GDPR when it employs or processes data about people located in the European Union, which is why global employers cannot ignore it.
What are the penalties for breaching GDPR?
The regulation has a two-tier fine structure. Lower-tier breaches can reach 10 million euros or 2% of global annual turnover. The most serious breaches, such as unlawful processing, can reach 20 million euros or 4% of global annual turnover, whichever figure is higher. Regulators also weigh how serious and deliberate the breach was.
Key facts
- Maximum GDPR fine
- The most serious GDPR breaches can attract administrative fines of up to 20 million euros, or 4% of a company's total worldwide annual turnover for the preceding year, whichever is higher, under Article 83(5).Source: GDPR, gdpr-info.eu· verified 2026-07-28
Frequently asked questions
What does GDPR stand for?
GDPR stands for the General Data Protection Regulation. It became enforceable across the EU in May 2018, replacing the 1995 Data Protection Directive. It creates a single, EU-wide framework for how personal data must be protected, and it applies directly in every EU member state.Does GDPR apply to companies outside the EU?
It can. GDPR reaches beyond EU borders whenever an organisation processes the personal data of people located in the EU, for example by employing them or offering them services. A United States or Asian company with EU-based staff or customers may therefore need to comply, despite having no EU office.What rights does GDPR give employees over their data?
Employees can ask to see the personal data an employer holds about them, have inaccurate data corrected, and in some cases have it erased or its use restricted. They can also object to certain processing. Employers must be able to respond to these requests within the timescales the regulation sets.How does GDPR affect using an EOR or payroll provider?
When you share employee data with a provider, GDPR treats you as the controller and them as a processor, and requires a data processing agreement between you. Any transfer of that data outside the European Economic Area also needs a safeguard, such as standard contractual clauses, to be lawful.
Related terms
Note
Glossary
Have a global hiring question?
Ask a real person, or run the numbers yourself with the free calculators.
Talk to us about GDPR-compliant employmentLast verified 2026-07-28