Selling online into Europe
A store shipping into the Union, pricing in euros or translating its site for a European market falls within the regulation's scope.
The GDPR (General Data Protection Regulation) is the European regulation governing the processing of personal data. Applicable since 25 May 2018, it requires a legal basis for every processing activity, minimisation of the data collected, enforceable rights for individuals, breach notification, and penalties reaching 4% of worldwide annual turnover.
In one sentence
The GDPR governs any processing of personal data as soon as it targets people located in the European Union.
Key points
Term at a glance
The GDPR does not ask you to stop collecting data: it asks you to be able to justify every collection. That is the main reversal — the burden of proof sits with the organisation, which must demonstrate its compliance rather than wait for a breach to be proven against it. This principle, called accountability, explains why documentation counts as much as technology.
Territorial reach is the point most often misread on this side of the Atlantic. The regulation follows people, not companies: it applies as soon as an organisation, wherever established, offers goods or services to people located in the Union, or monitors their behaviour. A Quebec SME selling online into Europe, or targeting European visitors with advertising, falls within scope.
Every processing activity must rest on one of the legal bases set out in Article 6. Consent is only one of them, and not the most convenient: it must be freely given, specific, informed, unambiguous and as easy to withdraw as to give. Many activities rest more solidly on contract performance or legitimate interest, the latter requiring a documented balancing test.
Two principles govern system design: minimisation, which forbids collecting beyond the stated purpose, and data protection by design and by default, which requires the most protective setting to be the one applied without any user action. A pre-ticked box satisfies neither.
For a Canadian organisation, GDPR compliance and Law 25 compliance overlap substantially — processing register, transparency, incident handling, individual rights — without being identical. The two frameworks are best worked together rather than as separate projects.
Check for an offer of goods or services into the Union, or monitoring of the behaviour of people located there. Pricing in euros, shipping to Europe or advertising to an EU country are strong indicators.
The record of processing activities lists what is collected, why, on which legal basis, who accesses it, where it is hosted and how long it is kept. It comes before everything else.
Each purpose gets its basis. Where that is consent, it must be actively collected, logged and revocable — which directly drives how the cookie banner is configured.
Remove unused form fields, shorten retention periods and limit internal access to what is strictly necessary. It is the most effective measure, and the cheapest.
A procedure must allow you to answer an access, rectification or erasure request within one month, including for data held by your processors.
The 72-hour deadline leaves no room for improvisation: roles, risk assessment criteria and a notification template are written in calm conditions.
Every supplier processing data on your behalf must be bound by an Article 28 compliant contract, and transfers outside the EU must rest on a valid mechanism.
A manufacturer in Saint-Jérôme opens an online store shipping to France and Belgium. It assumes only Law 25 applies, until a French customer requests erasure of their account. The audit reveals three gaps: the cookie banner drops advertising trackers before any choice is made, no procedure allows a reply within one month, and orders are kept indefinitely with no defined retention period. All three are fixed in a few weeks — but discovered through a complaint rather than a register, they would have exposed the company to proceedings.
A store shipping into the Union, pricing in euros or translating its site for a European market falls within the regulation's scope.
Monitoring the behaviour of people located in the Union is enough to trigger application, even without a sale.
As a processor you must offer contractual guarantees compliant with Article 28 — often a condition of winning the contract.
Data on European candidates and employees falls under the regulation, including in an HR tool hosted in Canada.
| GDPR | Law 25 (Quebec) | |
|---|---|---|
| Territory | People located in the European Union | Organisations operating in Quebec |
| Authority | National authorities, coordinated by the EDPB | Commission d'accès à l'information du Québec |
| Incident notification | 72 hours to the authority where there is risk | Promptly where there is a risk of serious injury |
| Maximum penalty | €20M or 4% of worldwide turnover | Up to CA$25M or 4% of worldwide turnover |
| Designated officer | DPO mandatory in certain cases | Privacy officer mandatory |
For a Quebec company the GDPR is rarely a project started by choice: it arrives through a European client, a tender, or a first erasure request. Handling it early costs far less than discovering it under pressure, because the fixes touch structural choices — what you collect, where it is hosted, how long it is kept — that are hard to rework on a live system. Most of that work also serves Law 25, which applies regardless: done once properly, it covers both.
Yes, if it offers goods or services to people located in the European Union, or monitors their online behaviour. Where the company is established is not the test: what matters is where the targeted individuals are.
No. It is one of the six legal bases in Article 6. Contract performance, legal obligation or legitimate interest are often a better fit. Non-essential cookies, however, do require prior consent.
Both pursue the same goal with different scopes: the GDPR covers people in the EU, Law 25 covers organisations operating in Quebec. The obligations overlap substantially — register, transparency, incidents, rights — which makes it sensible to handle them together.
Up to €20 million or 4% of worldwide annual turnover, whichever is higher. In practice authorities scale penalties to severity, cooperation and the measures already in place.
No. The banner covers only part of the subject, and a banner that drops trackers before any choice is itself a breach. The processing register, retention periods and the exercise of rights carry more weight.
Selling or recruiting in Europe and wondering where you actually stand?
Get your compliance assessed