Skip to main content
The new Teacher Workspace is here. Your first 3 assignments are free. Try it →

GDPR

GDPR, the General Data Protection Regulation, is the European Union law that sets rules for collecting, using, storing, and deleting personal data. In Intro to Public Policy, it shows how governments regulate digital data and corporate behavior.

Last updated July 2026

What is GDPR?

GDPR is the European Union’s main data privacy law, and in Intro to Public Policy it’s a clear example of how governments set rules for digital life. It tells organizations how they can collect, use, store, and share personal data, and it gives people more control over the information tied to them.

The law took effect in 2018 and applies to any organization that handles the personal data of people in the EU, even if that company is based somewhere else. That cross-border reach is a big policy lesson: once data moves online, national borders do not really limit regulation the way they used to.

GDPR centers on a few core ideas. Organizations need a lawful reason to process data, they must be transparent about what they are collecting, and they should only gather data that is actually needed for a specific purpose. This is where the policy language of data minimization and purpose limitation comes in. Instead of letting a company stockpile everything, the law pushes it to justify each data use.

The regulation also gives individuals rights over their data. People can ask to see what information a company has about them, request corrections, and sometimes ask for deletion. In public policy terms, that shifts some power away from firms and toward the public, especially in markets where users often do not know how much data is being tracked.

You will often see GDPR discussed alongside forms, consent pop-ups, privacy notices, breach reports, and government enforcement actions. A common classroom example is a social media app that wants to collect location, contacts, and browsing behavior. Under GDPR, the company cannot treat all of that as automatic. It has to explain why each category matters, and it can face heavy fines if it ignores those rules.

Why GDPR matters in Intro to Public Policy

GDPR matters in Intro to Public Policy because it shows how policy responds to a fast-changing technology problem. Digital platforms collect huge amounts of information, and lawmakers have to decide how much control companies should have versus how much control individuals should have over their own data.

It also gives you a real-world model of regulation. You can see how a policy sets standards, creates compliance duties, and uses enforcement penalties to shape behavior. That makes it useful for comparing with other policy tools, like taxes, subsidies, or voluntary guidelines.

GDPR is also a good case for studying policy tradeoffs. Strong privacy rules can protect citizens, but they can also raise costs for firms and make data-driven services more complicated. In class, that tension often shows up in discussions about innovation, consumer rights, and government oversight.

Because the law applies across the EU and to outside companies that handle EU residents’ data, it is also a strong example of why digital governance often becomes international. One country’s policy choice can influence business practices far beyond its borders.

Keep studying Intro to Public Policy Unit 14

Official unit cheatsheet

open one-pager

How GDPR connects across the course

Data Privacy

GDPR is one of the clearest policy examples of data privacy in action. Data privacy is the broader concern, while GDPR is the rule set that turns that concern into legal requirements. If a prompt asks how governments protect people from intrusive data collection, GDPR is a strong case to use.

Personal Data

GDPR is built around personal data, which means information that can identify a person directly or indirectly. In policy questions, you often need to recognize what counts as personal data because the law’s protections depend on that category. The term helps you see why emails, device IDs, and location data can all matter.

Data Subject

A data subject is the person whose information is being collected or processed. GDPR gives data subjects specific rights, like access, correction, and deletion. That makes the term useful when you are tracing who has power in a data policy case, the company collecting data or the individual the data is about.

Cybersecurity Policy

Cybersecurity policy focuses on protecting systems and data from unauthorized access, while GDPR focuses more on lawful handling and user rights. The two overlap when breaches happen, because a security failure can become a privacy violation too. In policy analysis, they are related but not identical problems.

Is GDPR on the Intro to Public Policy exam?

A quiz question or case-analysis prompt may give you a scenario about a company collecting user data and ask what rule applies, what rights the user has, or what the government can require. GDPR is the term you use when the issue is privacy regulation, especially in the EU or any company dealing with EU residents.

In a short essay or discussion response, you might use GDPR as evidence that governments can shape digital markets through regulation. If a prompt asks about policy tools, enforcement, or the tradeoff between innovation and consumer protection, GDPR is a strong concrete example. A good answer usually names the rule, explains what it restricts, and connects it to transparency, consent, or enforcement.

GDPR vs Data Privacy

Data privacy is the broad policy goal of protecting personal information, while GDPR is a specific law that puts that goal into practice. If you mix them up, remember this: privacy is the issue, GDPR is one regulatory response to the issue.

Key things to remember about GDPR

  • GDPR is the European Union’s major data privacy law, and it shapes how organizations collect, use, and store personal data.

  • It is a strong example of digital governance because it regulates online data practices across borders, not just inside one country.

  • The law gives people rights over their information, including access, correction, and sometimes deletion.

  • GDPR uses enforcement and fines to make privacy rules real, not just symbolic.

  • In Intro to Public Policy, you can use GDPR to discuss regulation, accountability, consent, and the tradeoffs of digital oversight.

Frequently asked questions about GDPR

What is GDPR in Intro to Public Policy?

GDPR is the European Union law that regulates how organizations collect and use personal data. In Intro to Public Policy, it is a major example of how governments respond to digital privacy problems with rules, enforcement, and user rights.

Is GDPR the same as data privacy?

No. Data privacy is the broader policy concern about protecting personal information. GDPR is one specific law that tries to protect privacy by setting rules for consent, transparency, access, and deletion.

What does GDPR require companies to do?

Companies have to explain why they are collecting data, gather only what they need, and give people control over their information. They also need a legal reason to process personal data and can face large fines if they do not comply.

How do you use GDPR in a public policy essay?

Use it as a real-world example of regulation in digital governance. You can point to it when discussing government oversight, consumer rights, international policy reach, or the tradeoff between privacy and business convenience.

GDPR | Intro To Public Policy | Fiveable