The General Data Protection Regulation (GDPR) is the EU's comprehensive privacy law (effective 2018, UK GDPR post-Brexit for UK). It governs how organizations process personal data about people in the EU/UK.
Who GDPR applies to
GDPR applies if you:
- Offer goods or services to people in the EU/UK, or
- Monitor behavior of people in the EU/UK (e.g., analytics, profiling)
Location of your company does not exempt you. US SaaS with EU customers typically must comply.
Key consumer rights
- Access — copy of personal data held
- Rectification — correct inaccurate data
- Erasure ("right to be forgotten") — delete in certain cases
- Restriction — limit processing
- Portability — receive data in machine-readable format
- Object — to processing including direct marketing
- Automated decision-making — safeguards for profiling
Your privacy policy must explain these rights and how to contact you.
Privacy notice requirements (Article 13–14)
Notices must include controller identity, DPO contact if applicable, purposes and legal bases, recipients, retention, rights, and whether you use automated decision-making.
Clerica generator includes GDPR-oriented sections; counsel should review high-risk processing.
GDPR vs cookie consent
GDPR requires lawful basis for processing and clear notices. Cookie banners and CMP are separate products — Termly/Iubenda lead there. Clerica focuses on readable privacy notices on your domain with verify proof. Cookie consent is not our focus today — may come later.
Practical steps for SMB publishers
- Map data inventory and legal bases
- Publish GDPR-aligned privacy policy on your domain
- Document subprocessors (Article 28 DPAs where required)
- Establish request handling for access/deletion emails
- Update policy when processing changes
Related: GDPR privacy policy requirements · GDPR compliance hub · Privacy laws by country · GDPR template
Clerica is not a law firm and does not provide legal advice. This guide is educational. Consult qualified counsel for jurisdiction-specific requirements.