Коротко
- GDPR is an EU regulation from 25 May 2018: unified rules for processing personal data in the EU/EEA.
- It also applies to businesses outside the EU if they offer goods/services to EU/EEA residents or monitor their behavior (cookies, ads, analytics).
- Seven principles + one of six lawful bases before processing starts; accountability must be demonstrable.
- Two-tier fines: up to €10M/2% or €20M/4% of global turnover — plus claims by data subjects.
Not legal advice
A guide for the account owner and marketer: how to read GDPR next to smart links, pixels, and banners. Specific bases and DPIA — with a lawyer / DPO.
A guide to structure and facts: www.cookieyes.com/… · www.cookieyes.com/… · www.cookieyes.com/…. Summary KB section: CookieYes → GDPR. Not legal advice and not a verbatim translation.
What GDPR is
General Data Protection Regulation — the European privacy law that entered into force on 25 May 2018. It replaced fragmented national implementations of the old Data Protection Directive with a single regulation, binding in all EU member states and in the EEA.
The goal is to strengthen people's rights over personal data (privacy as a fundamental right) and make controllers accountable: privacy by design, transparency, security, documentation.
GDPR became a «template» for many laws worldwide (including elements of CPRA). Compliance is not only about fines, but also about trust in B2B/B2C funnels.
Key terms
- Personal data — any information that directly or indirectly identifies a living natural person (name, email, ID, location, online identifiers, cookie ID, IP in context, etc.).
- Special categories — «sensitive» data under Art. 9: race/ethnicity, politics, religion, biometrics, health, sex life/orientation, and others. A general processing ban + narrow exceptions.
- Data subject — the person whose data is processed (a clicker of your link, a subscriber, a customer).
- Controller — determines the purposes and means of processing.
- Processor — processes data on behalf of the controller under instructions (a DPA is often required).
- Consent — freely given, specific, informed, unambiguous consent (affirmative action).
Who it applies to (Art. 3)
- Organizations established in the EU/EEA — almost always, even if data is stored outside the EU;
- Organizations outside the EU that offer goods/services to EU/EEA residents (currency, language, delivery, targeting the EU — signs of intention);
- Organizations outside the EU that monitor behaviour of EU/EEA residents (cookies, analytics, behavioral advertising, profiling).
Site «availability from Europe» alone may not suffice for offer, but tracking EU visitors easily falls under monitoring. Non-profit can also be in scope — there is no revenue threshold like CCPA.
Who is usually out of scope
- Purely personal / household activity;
- Data of the deceased (mostly) and legal entities as such (but contact persons are living persons);
- Certain derogations for SMEs on record-keeping — not a full exemption from GDPR.
UK GDPR after Brexit
In the UK, UK GDPR + Data Protection Act 2018 apply — a regime close to EU GDPR, but with its own regulator (ICO) and transfer nuances. Sites with a UK audience often need a separate assessment («EU GDPR + UK GDPR»), not a mark of «Brexit = GDPR not needed».
The CookieYes KB has cards such as «Is GDPR still valid in the UK?» / «What is UK GDPR?» — the GDPR section.
Seven principles (Art. 5)
| Принцип | Meaning for marketing / the site |
|---|---|
| Lawfulness, fairness, transparency | There is a basis; honest; a clear notice |
| Purpose limitation | Collected for X — do not divert to Y without a new basis |
| Data minimisation | Only needed fields, cookies, pixels |
| Accuracy | Accurate data; the right to rectification |
| Storage limitation | Retention periods + deletion/anonymization |
| Integrity & confidentiality | TOMs: encryption, access, backups |
| Accountability | Be able to prove: ROPA, consent logs, DPA, policies |
Accountability is end-to-end: «we have a banner» is not enough; you need processes and evidence.
Six lawful bases (Art. 6)
Fix the basis before collection. «We'll invent it later» is a risk. Consent is not the only and not always the best basis.
- Consent — marketing cookies, newsletter, part of advertising; withdrawal as easy as giving.
- Contract — data necessary to perform a contract with the data subject (order, account).
- Legal obligation — a legal requirement (KYC, taxes, etc.).
- Vital interests — protection of life in extreme cases.
- Public task — public tasks / official authority.
- Legitimate interests — a balance of business interests and the subject's rights; often discussed for security/fraud prevention; for intrusive ads it is contested, many take consent.
More on the bases: Data Processing Under GDPR (CookieYes). On consent and cookies — a separate article.
Special categories (Art. 9)
By default processing is not allowed. Typical exceptions: explicit consent; employment/social security; vital interests when unable to consent; made public by the subject; legal claims; healthcare; archiving/research/statistics with safeguards.
For advertising funnels on ClikBy do not specially collect health/biometrics «into a pixel» without a legal assessment. Precise geolocation and inferences about health are a high-risk zone.
Fines and enforcement
- Нижний тир: до €10 млн or 2% годового мирового оборота;
- Верхний тир: до €20 млн or 4% — принципы, consent, права субъектов, transfers, игнор приказов DPA;
- They consider gravity, intent, repetition, cooperation;
- The data subject may claim compensation for material/non-material damage;
- Enforcement: national DPAs + EDPB coordination.
How it connects to the ClikBy product
- The clicker of an EU link is a data subject; you determine the campaign purpose → controller; ClikBy writes visits → processor.
- IP, UA, geo, UTM, fingerprint_*, vendor pixels — treat as personal data / online identifiers.
- The ClikBy Policy names an EU representative (Barcelona) — for the platform operator; your campaign may need its own representative/Art. 27 assessment.
- Do not promise «ClikBy = automatic GDPR compliance» — it is infrastructure + consent controls.
In ClikBy for clicks on the client's links: Customer = controller, ClikBy = processor (privacy-policy §1.9). The EU representative in the Policy is Barcelona. Levers: Cookie Consent, pixel_notification on the redirect, a DPA if needed.
FAQ
Does GDPR apply to personal blogs?
Purely household activity — often out of scope; a commercial blog with analytics/ads for an EU audience is closer to «yes». Check with counsel.
Does a non-profit need GDPR?
Yes, it can apply: lack of profit ≠ exemption.