Home
ClikBy
ClikBy Knowledge Base
GDPR

What GDPR is

The European privacy law since 2018: who it applies to, which principles and processing bases, what fines threaten, and how it fits with smart links.

16–20 min Updated: July 2026
25 May 2018entry into force
Art. 5–6principles / bases
EU/EEA+ UK GDPR

Коротко

  • GDPR is an EU regulation from 25 May 2018: unified rules for processing personal data in the EU/EEA.
  • It also applies to businesses outside the EU if they offer goods/services to EU/EEA residents or monitor their behavior (cookies, ads, analytics).
  • Seven principles + one of six lawful bases before processing starts; accountability must be demonstrable.
  • Two-tier fines: up to €10M/2% or €20M/4% of global turnover — plus claims by data subjects.

Not legal advice

A guide for the account owner and marketer: how to read GDPR next to smart links, pixels, and banners. Specific bases and DPIA — with a lawyer / DPO.

A guide to structure and facts: www.cookieyes.com/… · www.cookieyes.com/… · www.cookieyes.com/…. Summary KB section: CookieYes → GDPR. Not legal advice and not a verbatim translation.

What GDPR is

General Data Protection Regulation — the European privacy law that entered into force on 25 May 2018. It replaced fragmented national implementations of the old Data Protection Directive with a single regulation, binding in all EU member states and in the EEA.

The goal is to strengthen people's rights over personal data (privacy as a fundamental right) and make controllers accountable: privacy by design, transparency, security, documentation.

GDPR became a «template» for many laws worldwide (including elements of CPRA). Compliance is not only about fines, but also about trust in B2B/B2C funnels.

Key terms

  • Personal data — any information that directly or indirectly identifies a living natural person (name, email, ID, location, online identifiers, cookie ID, IP in context, etc.).
  • Special categories — «sensitive» data under Art. 9: race/ethnicity, politics, religion, biometrics, health, sex life/orientation, and others. A general processing ban + narrow exceptions.
  • Data subject — the person whose data is processed (a clicker of your link, a subscriber, a customer).
  • Controller — determines the purposes and means of processing.
  • Processor — processes data on behalf of the controller under instructions (a DPA is often required).
  • Consent — freely given, specific, informed, unambiguous consent (affirmative action).

Who it applies to (Art. 3)

  • Organizations established in the EU/EEA — almost always, even if data is stored outside the EU;
  • Organizations outside the EU that offer goods/services to EU/EEA residents (currency, language, delivery, targeting the EU — signs of intention);
  • Organizations outside the EU that monitor behaviour of EU/EEA residents (cookies, analytics, behavioral advertising, profiling).

Site «availability from Europe» alone may not suffice for offer, but tracking EU visitors easily falls under monitoring. Non-profit can also be in scope — there is no revenue threshold like CCPA.

Who is usually out of scope

  • Purely personal / household activity;
  • Data of the deceased (mostly) and legal entities as such (but contact persons are living persons);
  • Certain derogations for SMEs on record-keeping — not a full exemption from GDPR.

UK GDPR after Brexit

In the UK, UK GDPR + Data Protection Act 2018 apply — a regime close to EU GDPR, but with its own regulator (ICO) and transfer nuances. Sites with a UK audience often need a separate assessment («EU GDPR + UK GDPR»), not a mark of «Brexit = GDPR not needed».

The CookieYes KB has cards such as «Is GDPR still valid in the UK?» / «What is UK GDPR?» — the GDPR section.

Seven principles (Art. 5)

ПринципMeaning for marketing / the site
Lawfulness, fairness, transparencyThere is a basis; honest; a clear notice
Purpose limitationCollected for X — do not divert to Y without a new basis
Data minimisationOnly needed fields, cookies, pixels
AccuracyAccurate data; the right to rectification
Storage limitationRetention periods + deletion/anonymization
Integrity & confidentialityTOMs: encryption, access, backups
AccountabilityBe able to prove: ROPA, consent logs, DPA, policies

Accountability is end-to-end: «we have a banner» is not enough; you need processes and evidence.

Six lawful bases (Art. 6)

Fix the basis before collection. «We'll invent it later» is a risk. Consent is not the only and not always the best basis.

  • Consent — marketing cookies, newsletter, part of advertising; withdrawal as easy as giving.
  • Contract — data necessary to perform a contract with the data subject (order, account).
  • Legal obligation — a legal requirement (KYC, taxes, etc.).
  • Vital interests — protection of life in extreme cases.
  • Public task — public tasks / official authority.
  • Legitimate interests — a balance of business interests and the subject's rights; often discussed for security/fraud prevention; for intrusive ads it is contested, many take consent.

More on the bases: Data Processing Under GDPR (CookieYes). On consent and cookies — a separate article.

Special categories (Art. 9)

By default processing is not allowed. Typical exceptions: explicit consent; employment/social security; vital interests when unable to consent; made public by the subject; legal claims; healthcare; archiving/research/statistics with safeguards.

For advertising funnels on ClikBy do not specially collect health/biometrics «into a pixel» without a legal assessment. Precise geolocation and inferences about health are a high-risk zone.

Fines and enforcement

  • Нижний тир: до €10 млн or 2% годового мирового оборота;
  • Верхний тир: до €20 млн or 4% — принципы, consent, права субъектов, transfers, игнор приказов DPA;
  • They consider gravity, intent, repetition, cooperation;
  • The data subject may claim compensation for material/non-material damage;
  • Enforcement: national DPAs + EDPB coordination.

How it connects to the ClikBy product

  • The clicker of an EU link is a data subject; you determine the campaign purpose → controller; ClikBy writes visits → processor.
  • IP, UA, geo, UTM, fingerprint_*, vendor pixels — treat as personal data / online identifiers.
  • The ClikBy Policy names an EU representative (Barcelona) — for the platform operator; your campaign may need its own representative/Art. 27 assessment.
  • Do not promise «ClikBy = automatic GDPR compliance» — it is infrastructure + consent controls.

In ClikBy for clicks on the client's links: Customer = controller, ClikBy = processor (privacy-policy §1.9). The EU representative in the Policy is Barcelona. Levers: Cookie Consent, pixel_notification on the redirect, a DPA if needed.

FAQ

Does GDPR apply to personal blogs?

Purely household activity — often out of scope; a commercial blog with analytics/ads for an EU audience is closer to «yes». Check with counsel.

Does a non-profit need GDPR?

Yes, it can apply: lack of profit ≠ exemption.

Where to read next?

CookieYes KB → GDPR · Consent and cookies · CCPA vs GDPR.

What’s next?

Next — consent and cookies

Work out when an opt-in banner is needed and what to block until Accept.