• AUG Certified badgeAUG (Authorized User Group) Certified
  • IND Recognised SponsorIND Recognised Sponsor
  • Nasscom Certified badgeNasscom Certified
  • SNA Certified badgeSNA Certified
  • AUG Certified badgeAUG (Authorized User Group) Certified
  • IND Recognised SponsorIND Recognised Sponsor
  • Nasscom Certified badgeNasscom Certified
  • SNA Certified badgeSNA Certified
  • 4.9 stars on G2
European Directives & Compliance

What Is GDPR?

European Directives & Compliance 4 min read Updated Jun 2026

GDPR (the General Data Protection Regulation) is the EU's core data protection law, setting rules for how organizations collect, process, store, and protect the personal data of individuals in the EU. It applies to any company handling EU residents' data, regardless of where that company is based, and carries some of the largest regulatory fines in the world.

Quick Fact

GDPR fines scale with company size: the maximum penalty is €20 million or 4% of a company's total worldwide annual turnover, whichever is higher, meaning the ceiling grows with the size of the offending organization.

GDPR at a Glance

AttributeDescription
Applies ToAny organization processing personal data of individuals in the EU
Tier 1 FinesUp to €10 million or 2% of global annual turnover
Tier 2 FinesUp to €20 million or 4% of global annual turnover
Breach NotificationMust notify the supervisory authority within 72 hours
Key RequirementA documented lawful basis for every data processing activity
Enforced ByNational data protection authorities in each EU member state

Why Does It Matter?

For employers, GDPR governs everything from storing employee records and running payroll to using HR software and background-check vendors. Non-compliance carries serious financial exposure, cumulative GDPR fines since 2018 have exceeded €7 billion, and enforcement has intensified rather than eased over time. Any company managing employee or candidate data in the EU needs a documented, defensible data protection process.

When Is It Used?

GDPR obligations apply whenever a company:

  • Collects, stores, or processes personal data of employees, candidates, or customers based in the EU.
  • Shares employee data with a third-party payroll provider, HR platform, or Employer of Record.
  • Experiences a data breach and must assess notification obligations within the 72-hour window.
Example

A Canadian company using an EOR to hire staff in France must ensure the EOR, as a data processor, handles employee payroll and personal data under a compliant data processing agreement, with appropriate security measures and a lawful basis for each processing activity, since both the Canadian company and the EOR share GDPR responsibilities.

Common Misconceptions

“GDPR only applies to companies based in the EU.”

No. Any organization processing personal data of individuals in the EU falls within scope, regardless of where the company itself is headquartered.

“Small companies are exempt from GDPR fines.”

No. GDPR applies to organizations of any size; fines are simply scaled to be proportionate to the company's turnover and the severity of the violation.

“A data breach only needs to be reported if it's severe.”

Not entirely. Most breaches must be reported to the supervisory authority within 72 hours unless the employer can show the breach is unlikely to result in risk to individuals.

“Using a third-party payroll or HR vendor shifts all GDPR responsibility to them.”

No. The employer, as data controller, retains responsibility alongside the vendor (data processor), and both need a compliant data processing agreement in place.

Bottom Line

GDPR sets binding data protection rules for any company handling EU residents' personal data, backed by fines that can reach into the hundreds of millions of euros for serious violations. Employers managing staff data, whether directly or through third-party providers, need documented, compliant processes from day one.

Handling employee data in the EU?

We'll make sure your data processing, DPAs, and transfer mechanisms are fully GDPR-compliant.

Book a demo