Skip to content

What is the GDPR? Definition, reach and obligations

The GDPR (General Data Protection Regulation) is the European regulation governing the processing of personal data. Applicable since 25 May 2018, it requires a legal basis for every processing activity, minimisation of the data collected, enforceable rights for individuals, breach notification, and penalties reaching 4% of worldwide annual turnover.

In one sentence

The GDPR governs any processing of personal data as soon as it targets people located in the European Union.

Key points

  • It applies outside Europe as soon as an organisation targets people located in the EU — a Quebec site selling into France is covered.
  • Every processing activity must rest on an explicit legal basis: consent, contract, legal obligation, legitimate interest, among others.
  • Individuals hold enforceable rights: access, rectification, erasure, portability, objection, restriction.
  • A breach presenting a risk must be notified to the supervisory authority within 72 hours.
  • Penalties reach €20 million or 4% of worldwide annual turnover, whichever is higher.

Term at a glance

GDPR
RGPD · General Data Protection Regulation · Regulation (EU) 2016/679
French term
RGPD — Règlement général sur la protection des données
Domain
Cybersecurity
Category
Compliance
Reference
Regulation (EU) 2016/679
Applicable since
25 May 2018
Quebec equivalent
Law 25

What the GDPR actually changes

The GDPR does not ask you to stop collecting data: it asks you to be able to justify every collection. That is the main reversal — the burden of proof sits with the organisation, which must demonstrate its compliance rather than wait for a breach to be proven against it. This principle, called accountability, explains why documentation counts as much as technology.

Territorial reach is the point most often misread on this side of the Atlantic. The regulation follows people, not companies: it applies as soon as an organisation, wherever established, offers goods or services to people located in the Union, or monitors their behaviour. A Quebec SME selling online into Europe, or targeting European visitors with advertising, falls within scope.

Every processing activity must rest on one of the legal bases set out in Article 6. Consent is only one of them, and not the most convenient: it must be freely given, specific, informed, unambiguous and as easy to withdraw as to give. Many activities rest more solidly on contract performance or legitimate interest, the latter requiring a documented balancing test.

Two principles govern system design: minimisation, which forbids collecting beyond the stated purpose, and data protection by design and by default, which requires the most protective setting to be the one applied without any user action. A pre-ticked box satisfies neither.

For a Canadian organisation, GDPR compliance and Law 25 compliance overlap substantially — processing register, transparency, incident handling, individual rights — without being identical. The two frameworks are best worked together rather than as separate projects.

How to approach GDPR compliance

  1. 01

    Determine whether you are in scope

    Check for an offer of goods or services into the Union, or monitoring of the behaviour of people located there. Pricing in euros, shipping to Europe or advertising to an EU country are strong indicators.

  2. 02

    Map the processing activities

    The record of processing activities lists what is collected, why, on which legal basis, who accesses it, where it is hosted and how long it is kept. It comes before everything else.

  3. 03

    Set a legal basis per activity

    Each purpose gets its basis. Where that is consent, it must be actively collected, logged and revocable — which directly drives how the cookie banner is configured.

  4. 04

    Reduce what is collected

    Remove unused form fields, shorten retention periods and limit internal access to what is strictly necessary. It is the most effective measure, and the cheapest.

  5. 05

    Organise the exercise of rights

    A procedure must allow you to answer an access, rectification or erasure request within one month, including for data held by your processors.

  6. 06

    Prepare breach notification

    The 72-hour deadline leaves no room for improvisation: roles, risk assessment criteria and a notification template are written in calm conditions.

  7. 07

    Frame processors and transfers

    Every supplier processing data on your behalf must be bound by an Article 28 compliant contract, and transfers outside the EU must rest on a valid mechanism.

A concrete example

A manufacturer in Saint-Jérôme opens an online store shipping to France and Belgium. It assumes only Law 25 applies, until a French customer requests erasure of their account. The audit reveals three gaps: the cookie banner drops advertising trackers before any choice is made, no procedure allows a reply within one month, and orders are kept indefinitely with no defined retention period. All three are fixed in a few weeks — but discovered through a complaint rather than a register, they would have exposed the company to proceedings.

When the GDPR concerns you

Selling online into Europe

A store shipping into the Union, pricing in euros or translating its site for a European market falls within the regulation's scope.

Targeting European visitors with ads

Monitoring the behaviour of people located in the Union is enough to trigger application, even without a sale.

Processing data for a European client

As a processor you must offer contractual guarantees compliant with Article 28 — often a condition of winning the contract.

Employing or recruiting in the Union

Data on European candidates and employees falls under the regulation, including in an HR tool hosted in Canada.

What the framework brings and what it costs

  • A single framework across 27 member states instead of 27 national regimes
  • Clear rights for individuals, which strengthen trust in the service
  • A data governance discipline that pays off well beyond compliance
  • Broad overlap with Law 25: the work serves both frameworks at once
  • A real compliance cost, especially on legacy systems
  • Concepts open to interpretation, such as legitimate interest or genuine anonymisation
  • Transfers outside the EU on unstable legal ground since Privacy Shield was invalidated
  • Compliance that has to be maintained: every new tool reopens the subject

GDPR and Law 25: what are the differences?

GDPRLaw 25 (Quebec)
TerritoryPeople located in the European UnionOrganisations operating in Quebec
AuthorityNational authorities, coordinated by the EDPBCommission d'accès à l'information du Québec
Incident notification72 hours to the authority where there is riskPromptly where there is a risk of serious injury
Maximum penalty€20M or 4% of worldwide turnoverUp to CA$25M or 4% of worldwide turnover
Designated officerDPO mandatory in certain casesPrivacy officer mandatory

Why this matters strategically

For a Quebec company the GDPR is rarely a project started by choice: it arrives through a European client, a tender, or a first erasure request. Handling it early costs far less than discovering it under pressure, because the fixes touch structural choices — what you collect, where it is hosted, how long it is kept — that are hard to rework on a live system. Most of that work also serves Law 25, which applies regardless: done once properly, it covers both.

Frequently asked questions

Is a Quebec company subject to the GDPR?

Yes, if it offers goods or services to people located in the European Union, or monitors their online behaviour. Where the company is established is not the test: what matters is where the targeted individuals are.

Is consent always required?

No. It is one of the six legal bases in Article 6. Contract performance, legal obligation or legitimate interest are often a better fit. Non-essential cookies, however, do require prior consent.

What is the difference between the GDPR and Law 25?

Both pursue the same goal with different scopes: the GDPR covers people in the EU, Law 25 covers organisations operating in Quebec. The obligations overlap substantially — register, transparency, incidents, rights — which makes it sensible to handle them together.

What is actually at risk?

Up to €20 million or 4% of worldwide annual turnover, whichever is higher. In practice authorities scale penalties to severity, cooperation and the measures already in place.

Is installing a cookie banner enough?

No. The banner covers only part of the subject, and a banner that drops trackers before any choice is itself a breach. The processing register, retention periods and the exercise of rights carry more weight.

Related terms

Sources and references

Selling or recruiting in Europe and wondering where you actually stand?

Get your compliance assessed
Glossary