
What is the EU's GDPR, and How Does it Work?
Whether you’re a corporation that works with healthcare documentation or a small business that accepts credit cards, you need to know how to process customer data. In the United States, consumer data security laws vary slightly from state to state, and there isn’t one overarching set of commandments that needs to be followed across the nation. In the European Union, there is: the General Data Protection Regulation (GDPR).
The GDPR is an 88 page omnibus regulation that dictates the way businesses and organizations treat their customers’ personal data. While it was created in the European Union, it almost definitely applies to your U.S.-based company if you do business with consumers in the EU. The guidelines are complex and the penalties of non-compliance are severe, so you should know how it all works before expanding your business overseas.
This guide breaks down what the GDPR requires, whether it applies to you, the principles underneath it, and the steps your business should take to get compliant. If you’re looking for a financial platform that can help you expand across borders and move money overseas, you may also want to learn about Slash.¹ Slash can help a company’s GDPR compliance initiatives by providing documented privacy practices and security controls for the personal & financial data it handles.
The standard in finance
Slash goes above with better controls, better rewards, and better support for your business.

Key Takeaways
- The GDPR follows the person rather than the company, so a US business with European customers is covered even without offices, staff, or servers in Europe.
- Being compliant isn't enough on its own; you also have to be able to show your work. Regulators usually treat undocumented compliance as non-compliance.
- If you're a public authority, your core activities involve regular and systematic monitoring of people on a large scale, or you process a special category of data, you need to appoint a Data Protection Officer (DPO).
- You have 72 hours to report a data breach to your supervisory authority, and you’ll likely also need to report it to your customers.
- An internal audit can help you discover personal data you forgot you had, which can be costly if left untouched.
What is the General Data Protection Regulation?
The General Data Protection Regulation is the European Union's law governing how organizations collect, store, and use personal data. It allows EU citizens to know what data organizations hold, why, and for how long, and it gives them the right to see it, correct it, and have it deleted. Organizations, in turn, should collect only what’s absolutely necessary and make sure it’s protected properly.
In 1995, the EU passed a Data Protection Directive setting minimum standards that each member state implemented separately. Those regulations quickly became obsolete as the internet grew. From 2012 to 2016, the European Commission worked on a draft of a new all-encompassing set of data security regulations that we now know as the GDPR. It passed the European Parliament in 2016 and officially went into effect in May 2018.
As of mid-2026, more changes may be on the way. In November 2025, the European Commission published a Digital Omnibus package proposing amendments to the GDPR. These GDPR changes would limit information and access obligations in defined circumstances where compliance is impossible or disproportionate, and estimates suggest consent would no longer be needed for around 60% of cookies (temporary browser files that track customer data). While nothing’s been made official yet, it’s wise to monitor regulatory changes as technology evolves.
The consequences of failing GDPR compliance are pretty severe. There are two tiers of fines:
- Lower-level infringements carry a maximum penalty of up to €10 million or 2% of the company’s total annual revenue, whichever is higher
- More severe infringements come with a maximum penalty of up to €20 million or 4% of the company’s revenue, whichever is higher
Since you’ll be hit with the larger of the two fines, corporations can lose a huge sum of money based on a percentage of their revenue, while smaller businesses may need to pay a flat number that’s difficult to afford. The customers whose data was illegally processed can also seek compensation on their own time.
What is personal data?
It’s tough to follow the GDPR if you don’t know what counts as personal data in the first place. Personal data is any information relating to a person who can potentially be identified, either directly or indirectly. The obvious examples are names, credit card/bank information, phone numbers, and addresses (home, email, and IP). Some of the more obscure ones include cookie identifiers, device IDs, and specific location data. You also have to watch out for pieces of data that relate to your business in particular; a customer reference number, for example, counts if it can ultimately be traced back to a person.
There are also quite a few non-numeric categories that can catch some businesses off guard. Article 9 designates data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, health data, and information about sex life or sexual orientation as special categories, which are prohibited from processing unless a specific exception applies.
You can anonymize this data to stay GDPR compliant, but it has to truly be anonymous. If you replace identifiers with codes, but they can still be theoretically linked back to a person, it falls outside of the regulation.
Who needs to be GDPR compliant?
The GDPR applies to each and every business within the European Union that processes any sort of personal data. While there are lighter documentation requirements for organizations under 250 employees in certain circumstances, the same rules generally apply to every business from mom-and-pop shop to megacorporation.
Once you leave the EU, it gets a little bit hazier. As a rule, the GDPR applies to organizations outside the EU if they offer goods or services to people in the EU, or if they monitor their behavior. A US software company with European customers is covered, as is one running analytics that track European visitors. What doesn't trigger it is incidental access, since a European happening to find your website doesn't immediately qualify you for GDPR judgment. It’s a matter of whether you're deliberately targeting or tracking people in the EU.
Key Principles of GDPR Compliance
Knowing the principles the GDPR revolves around can help you understand what the regulations and articles cover without having to memorize all 88 pages. Here are the tenets you should keep in mind as you manage customer data:
Accountability
Not only do you have to follow the GDPR’s rules, but you have to be able to demonstrate that you comply along the way. That means compliance is a documentation exercise as much as a technical one. If you believe you're compliant but can't show your reasoning, regulators can essentially treat that as non-compliance. In practice, this means keeping records of what data you hold, why you have it, where it lives, and who’s responsible for it. You’ll also likely need to train your staff and put data processing agreements in place with any third party handling data on your behalf.
Security
The GDPR requires appropriate technical and organizational measures to keep data secure. The exact measures aren’t specified, since the strategies a hospital should take won’t apply to a bakery. Ultimately, regulators need to conclude that you’ve put the right guardrails in place based on the data your business handles.
Technical measures may include multi-factor authentication on systems holding personal data, encryption in transit and at rest, and access logging. You also need to keep organizational measures in mind, such as creating a written data privacy policy and restricting data access so only the employees who need particular information can reach it. If a breach occurs, you need to inform affected individuals as soon as possible, and you have precisely 72 hours to notify your supervisory authority.
Data Protection
As listed in Article 5, there are seven specific data protection principles that must be followed. These include:
- Lawfulness and transparency: Data processing must be lawful, fair, and transparent to the subject.
- Purpose limitation: You must only process data for the reasons specified explicitly to the subject when you collected it.
- Data minimization: Collect and use only the data that is absolutely needed for the specific goals of your business.
- Accuracy: All personal data you keep must be accurate and up to date.
- Storage limitation: You can only store personally identifying data for as long as necessary.
- Integrity and confidentiality: As you process data, you must ensure appropriate security, integrity, and confidentiality.
- Accountability: The business is responsible for being able to demonstrate compliance with all of these principles.
If you want to read the exact principles the way they’re detailed within the regulation, you can read all 88 pages of the GDPR here.
Consent
When it comes to data protection, consent isn’t as straightforward as you may think. Valid consent must be freely given, specific, informed, and unambiguous. That means businesses can’t get away with bundling consent into terms and conditions or burying it in dense legal text.
Requests must be clearly separated from other matters and written in plain language, and people must be able to withdraw consent as easily as they gave it. You also need to keep evidence that consent was given and the form it appeared in.
When You Can Process Data
Finally, you need to know when you’re allowed to process data to begin with. According to Article 6, processing is only considered necessary if and when:
- It allows you to execute or to prepare to enter a contract in which the subject is involved
- It’s connected to a legal obligation relating to the subject
- It protects the vital interests of the subject (in other words, their health and safety)
- It’s tied to a task or an official function that relates to public interest
- Your business has a legitimate interest in acquiring the data, except in cases where “such interests are overridden by the interests or fundamental rights and freedoms of the data subject”. This is the most flexible one, but the “fundamental rights and freedoms” inclusion almost always overrides your interest, especially when the subject is under 16 and cannot legally consent to data collection.
It’s important to note that none of these principles count as “necessary” if the subject doesn’t willingly consent in the first place.
Steps for Businesses to Achieve GDPR Compliance
Now that you know more about what the GDPR outlines, you can begin adjusting your data intake practices accordingly. Here are some steps you can take to keep your business GDPR compliant:
Conducting a Data Audit
You won’t be able to protect or document data you can’t fully locate. A data audit identifies what personal data you hold, where it came from, why you have it, where it's stored, who has access, who you share it with, and how long you keep it.
Once you start looking, you might be surprised by what you find. Geotracking data from an old marketing campaign, spreadsheets of former customer contact info, and customer cookies stuck in an obscure computer file can all break GDPR rules. It’s also important to document the way you carry out this audit, as it can serve as proof of accountability.
Implementing Data Protection Policies
Policies can come in a lot of different forms. You need a privacy notice telling data subjects what you do with their data in plain language, an internal data protection policy telling staff how to handle it, a retention schedule specifying how long each data type is kept before deletion, and a breach response procedure that allows you to inform customers and authorities within 72 hours.
In many circumstances, you’ll also have to make data processing agreements with your vendors. If a third party processes personal data for you, whether that's a cloud provider, a payroll service, or a CRM, you’ll need a contract that addresses it.
Designating a Data Protection Officer
Something we haven’t touched on is the GDPR Data Protection Officer (DPO), the internal or external privacy expert who oversees an organization's data compliance and acts as a contact point for regulators. If you're a public authority, your core activities involve regular and systematic monitoring of people on a large scale, or you process a special category of data like health, biometrics, political information, or criminal records, a DPO is mandatory.
That said, plenty of organizations appoint one even if they fall outside those lines. It’s a good idea to hire a professional who knows the ins and outs of the GDPR, especially for growing teams that may not have the time to memorize the fine details and repeatedly train new hires.
Common Challenges in Achieving Compliance
Staying compliant with such an expansive set of regulations isn’t easy, even if you know them well and you’ve appointed a Data Protection Officer. Here are a few hurdles you should prepare for as you start making your business compliant:
- Vague regulations: Some passages, such as Article 6’s guide to data processing scenarios, are deliberately left a bit open-ended to allow for unique scenarios and judgments. While this can give your business more flexibility, it also opens the door for misinterpretations that leave you thinking you’re compliant when you actually aren’t.
- Scattered data: If you’ve spent years using different tools, systems, and spreadsheets to track customer contact info and personal data, you’ll have a tough time locating and erasing it all when you conduct an audit.
- Vendor agreements: You’re accountable for data processed on your behalf by a third party. Therefore, every tool that touches personal data needs a processing agreement and some due diligence.
- Compliance is an ongoing project: As your business shifts through new tools, markets, and strategies, you’ll often encounter new types of data and new difficulties in processing them. Even if you have it all nailed down right now, the new Omnibus package passing through the European Commission may shake things up within the next year.
How Slash Can Help Your Business Stay GDPR Compliant
Slash is a business banking platform built for companies that need more from their financial stack than a basic checking account. Whether a company's just getting started, growing their team, managing complex spending, or trying to get better visibility into their cash flow, Slash can be the answer. Users can issue corporate cards, organize team spending, earn on treasury balances, automate workflows, move money, and connect their finances to the tools they already use.⁶
As a banking platform first and foremost, we can’t exactly help your business meet all the rules and requirements found in the General Data Protection Regulation. However, Slash can be a valuable asset when it comes to financial data security. All data is protected with 256-bit encryption in transit and at rest. Multi-factor authentication secures every login, with support for biometrics and hardware tokens. We allow administrators to set granular permissions regarding who can view, approve, or execute financial actions, supporting least-privilege access. Additionally, Slash is SOC 2 Type II attested and PCI compliant.
With a robust API and prebuilt integrations with popular accounting platforms, Slash can help centralize certain business spending and financial records. This may make it easier for a company to understand where relevant data is held and to apply consistent internal access and recordkeeping practices. No matter what platform you use, however, your business remains responsible for establishing a lawful basis for processing personal data, providing required notices, honoring data-subject rights, limiting retention, and securing its own systems.
Outside of its data security tools, businesses can also take advantage of features like:
- Diverse payment rails: Slash supports a wide range of payment methods, including card spend, global ACH, international wire transfers to over 180 countries via SWIFT, and real-time domestic payments through RTP and FedNow.
- Global USD: The Slash Global USD Account is designed as an alternative for foreign founders who want access to USD without forming a US entity.³ Balances are backed by Slash’s USDSL stablecoin, which is designed to maintain a one-to-one value with the US dollar.
- Working capital financing: Access short-term financing with flexible 30-, 60-, or 90-day repayment terms to help bridge cash flow gaps.⁵
- High-yield treasury: Earn up to 3.86% annualized yield on idle funds with money market investments from BlackRock and Morgan Stanley, managed directly within your Slash account.
- Accounting & ERP integrations: Sync transaction data with QuickBooks Online, Xero, NetSuite, or Sage Intacct to streamline reconciliation, reporting, and month-end close.
Apply in less than 10 minutes today
Join the 10,000+ businesses already using Slash.
Frequently Asked Questions
Does the GDPR apply to a small business?
Yes, if you process the personal data of people in the EU. There's no revenue or headcount threshold that exempts you, though organizations under 250 employees can get some relief from record-keeping requirements in certain circumstances.
The Top Business Cards for Small Businesses in 2026
What counts as personal data?
Lots of things. Names and email addresses obviously qualify, but so do location data, banking info, IP addresses, cookie identifiers, biometric data, and anything else that can identify someone directly or indirectly. Special categories including health, ethnicity, religious beliefs, and political opinions carry further rules
What happens if you have a data breach?
From the moment you learn about it, you have 72 hours to notify your supervisory authority. You must also tell affected individuals without unnecessary delay, unless the data was protected by measures like encryption that render it unusable. Either way, you have to document the breach and the details surrounding it.
Business Fraud Prevention: A Guide for Protecting Your Company
In the context of data privacy, what’s the age of consent in the EU?
The digital age of consent for online services in the EU is set at 16 by default. However, some individual EU member states, such as Ireland and Sweden, have lowered this limit to 13.











