惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
博客园_首页
博客园 - 三生石上(FineUI控件)
V
Visual Studio Blog
Hugging Face - Blog
Hugging Face - Blog
美团技术团队
小众软件
小众软件
T
Tailwind CSS Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
月光博客
月光博客
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
博客园 - 【当耐特】
Apple Machine Learning Research
Apple Machine Learning Research
罗磊的独立博客
V
V2EX
酷 壳 – CoolShell
酷 壳 – CoolShell
IT之家
IT之家
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Recent Announcements
Recent Announcements
M
MIT News - Artificial intelligence
阮一峰的网络日志
阮一峰的网络日志
The GitHub Blog
The GitHub Blog

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
A Quick Overview of European Privacy Laws | iubenda
Alice Perseval · 2023-02-15 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

Do you need to get a better grasp of European privacy laws? Are you looking for specific information for your compliance? Our European Privacy Laws Overview is what you need!

👀 In this guide, we give basic information regarding major EU laws such as the GDPR or the ePrivacy, and provide many further resources for you to dive deeper into your topics of interest.

The current privacy landscape in Europe

A need for better data protection: the importance of European privacy laws

A strong framework for data protection was necessary when companies started to heavily collect, use and store personal data of individuals in order to get relevant insights on customers, provide them with personalized experiences or ads, and more.

Privacy laws have been crucial for protecting individuals’ personal data and ensuring it is not being abused by organizations. They helped to:

  • give power back to individuals over their data, granting them critical rights;
  • regulate usage, processing and storage (with special measures for high-risk data);
  • implement sanctions and reduce data breaches;
  • impose rules for organizations to set up internally (organizational and technical measures) and externally (user-focused, i.e.disclosures, collecting consent, etc.)

European privacy laws overview – the most relevant laws

🇪🇺 The General Data Protection Regulation (GDPR)

🗓️ When? The GDPR is a European regulation that became fully enforceable on May 25th, 2018. It is the most robust and strictest privacy law to date.

💬 What? At its most basic, the GDPR specifies how personal data should be lawfully processed, collected, shared, used, protected or interacted with in general.

📍 Where? The GDPR can apply to you whether your organization is based in the EU or not.

Who does the GDPR apply to?

The GDPR applies to:

  • an entity’s base of operations is in the EU (this applies whether the processing takes place in the EU or not);
  • an entity not established in the EU offers goods or services to people in the EU; or where
  • an entity is not established in the EU, but it monitors the behavior of people who are in the EU, provided that such behavior takes place in the EU.

🔍 Check out our dedicated section below for useful resources on the GDPR.

🇬🇧 UK Privacy Laws

The UK privacy landscape has been undergoing some changes after Brexit, but the GDPR still applies (until a new bill is passed) and is now referred to as the UK GDPR and enforced by the UK DPA, called ICO.

The Privacy and Electronic Communications Regulations (PECR) is a British law that gives people specific privacy rights in relation to electronic communications. It sits alongside the UK GDPR.

🇪🇺 The ePrivacy Directive (or Cookie Law)

🗓️ When? 2022, ePrivacy Directive 2002/58/EC (or Cookie Law).

💬 What? It establishes guidelines for the protection of electronic privacy, including email marketing and cookie usage, and it still applies today. It works hand in hand with the GDPR.

📍 Where? The ePrivacy is an EU law. It applies if you do business in the EU (regardless of whether you are based in the EU or not), and more practically, if your website can be visited by European users and it uses cookies.

🔍 Check out our dedicated section below for useful resources on the Cookie Law.

Enforcement by European Data Protection Authorities

While the GDPR and the ePrivacy are on an EU-level, some independent public authorities called DPAs (Data Protection Authorities) oversee the enforcement of data protection laws on a country-level. They also conduct investigations, issue fines and sanctions, and provide guidance on best practices, i.e. on cookie usage.

The most active DPAs include:

  • 🇫🇷 The “CNIL” in France, and its law “La loi Informatique et Libertés” – see here for their guidance on cookies;
  • 🇮🇹 The “Garante” in Italy – see here for their guidance on cookies;
  • 🇪🇸 The “AEPD” in Spain – see here for more information on the DPA (in Spanish) and their guidance on cookies here;

and many more such as the Irish, Belgian, Danish, Austrian, German DPAs…

european privacy laws overview

Note: the information outlined below is simplified information, and as a business, you should discuss your specific situation with legal professionals. In the meantime, keep reading! Our resources can give you a head start with your compliance.

As part of our European privacy laws overview, here’s a collection of resources on everything you should know about GDPR compliance.

European Privacy Laws: GDPR’s main provisions

If you process personal data, the GDPR requires you to have a valid legal basis for doing so. If consent is your legal basis, before collecting any personal data, you will have to obtain explicit user consent and keep records of this consent.

You must also honor user rights and requests, as well as implement organizational measures (assessments, appointing a person responsible for privacy) and keep the data safe when stored.

🔍 Check out these resources for further detail on GDPR standards:

Must-read guides for your GDPR compliance

These guides will give you practical tips and tools for simplifying your website/app’s compliance:

Focus on: the ePrivacy directive (Cookie Law)

As part of our European privacy laws overview, here’s a collection of resources on everything you should know about ePrivacy and cookie compliance.

European Privacy Laws: Cookie Law’s main provisions

The ePrivacy directive applies to any type of trackers that store or access information on a user’s device, including cookies.
Here again, working along the GDPR, the Cookie Law requires you to inform users and obtain their consent before using such technologies. Common practice is to use a cookie banner.

The vast majority of EU countries’ DPAs (mentioned before) have established cookie rules following the ePrivacy, adding the need for keeping records of cookie consent (to align with the GDPR).

Before sending direct marketing communications in electronic form (emails, newsletters, etc.), user consent is required as well. As always, users must also be given the right to withdraw (opt-out, or unsubscribe in the case of emails) at any time.

🔍 Check out these resources for further detail on the ePrivacy directive:

Must-read guides for your ePrivacy compliance

These guides will give you practical tips and tools for simplifying your website/app’s compliance:

Not sure what privacy laws actually apply to you?

Do this free 1-min quiz to find out

About us

iubenda

Attorney-level solutions to make your websites and apps compliant with the law across multiple countries and legislations.

www.iubenda.com