What Is GDPR?
GDPR (the General Data Protection Regulation) is the EU's core data protection law, setting rules for how organizations collect, process, store, and protect the personal data of individuals in the EU. It applies to any company handling EU residents' data, regardless of where that company is based, and carries some of the largest regulatory fines in the world.
GDPR fines scale with company size: the maximum penalty is €20 million or 4% of a company's total worldwide annual turnover, whichever is higher, meaning the ceiling grows with the size of the offending organization.
GDPR at a Glance
| Attribute | Description |
|---|---|
| Applies To | Any organization processing personal data of individuals in the EU |
| Tier 1 Fines | Up to €10 million or 2% of global annual turnover |
| Tier 2 Fines | Up to €20 million or 4% of global annual turnover |
| Breach Notification | Must notify the supervisory authority within 72 hours |
| Key Requirement | A documented lawful basis for every data processing activity |
| Enforced By | National data protection authorities in each EU member state |
Why Does It Matter?
For employers, GDPR governs everything from storing employee records and running payroll to using HR software and background-check vendors. Non-compliance carries serious financial exposure, cumulative GDPR fines since 2018 have exceeded €7 billion, and enforcement has intensified rather than eased over time. Any company managing employee or candidate data in the EU needs a documented, defensible data protection process.
When Is It Used?
GDPR obligations apply whenever a company:
- Collects, stores, or processes personal data of employees, candidates, or customers based in the EU.
- Shares employee data with a third-party payroll provider, HR platform, or Employer of Record.
- Experiences a data breach and must assess notification obligations within the 72-hour window.
A Canadian company using an EOR to hire staff in France must ensure the EOR, as a data processor, handles employee payroll and personal data under a compliant data processing agreement, with appropriate security measures and a lawful basis for each processing activity, since both the Canadian company and the EOR share GDPR responsibilities.
Common Misconceptions
No. Any organization processing personal data of individuals in the EU falls within scope, regardless of where the company itself is headquartered.
No. GDPR applies to organizations of any size; fines are simply scaled to be proportionate to the company's turnover and the severity of the violation.
Not entirely. Most breaches must be reported to the supervisory authority within 72 hours unless the employer can show the breach is unlikely to result in risk to individuals.
No. The employer, as data controller, retains responsibility alongside the vendor (data processor), and both need a compliant data processing agreement in place.
GDPR sets binding data protection rules for any company handling EU residents' personal data, backed by fines that can reach into the hundreds of millions of euros for serious violations. Employers managing staff data, whether directly or through third-party providers, need documented, compliant processes from day one.
Handling employee data in the EU?
We'll make sure your data processing, DPAs, and transfer mechanisms are fully GDPR-compliant.
AUG (Authorized User Group) Certified
IND Recognised Sponsor
Nasscom Certified
SNA Certified
Nasscom Certified