General Data Protection Regulation (GDPR)
The GDPR is the EU's data protection law. It also applies to companies outside the EU that offer goods or services to people in the EU or monitor their behaviour.
What is the GDPR?
The General Data Protection Regulation (GDPR) is the European Union’s data protection law. It has applied since 25 May 2018 in all EU member states and the wider European Economic Area, and it sets the rules for how personal data – names, email addresses, IP addresses, online identifiers and more – may be collected and used.
For international marketers, one point matters above all: the GDPR also applies to companies outside the EU if they offer goods or services to people in the EU or monitor their behaviour, for example through tracking. A US or Australian company running campaigns in Germany is therefore covered.
In digital marketing, the GDPR affects:
- Tracking and analytics: most analytics and advertising cookies need prior consent, managed through a consent banner (alongside the ePrivacy rules). This directly affects data in Google Analytics 4 and ad platforms.
- Lead generation: forms must explain how data is used, collect only what is needed and have a legal basis such as consent.
- Email marketing: newsletters generally require opt-in consent.
- Data transfers: sending personal data outside the EU needs a valid transfer mechanism.
Fines can reach EUR 20 million or 4% of worldwide annual turnover, whichever is higher. Other markets have similar laws, such as Brazil’s LGPD, so international marketing needs a privacy setup per market – this entry is an overview, not legal advice.
