WebinarGeek logo

What Is The General Data Protection Regulation?

Image of Remco

Remco

20 de marzo de 2018 - 3 min - Actualizado: 26 de agosto de 2026

A woman in a dark shirt is pondering beside the text "What is the General Data Protection Regulation?" set against a geometric background.

The General Data Protection Regulation (GDPR) will apply from May 25th, 2018. From that moment on, the same regulations will apply in all of the European Union regarding the protection of personal data. You can read some general information about the GDPR below.

What is GDPR?

The GDPR stands for General Data Protection Regulation. The GDPR will commence on May 25th, 2018. As a result, the same privacy regulations will be valid throughout the EU.

What is the impact of GDPR?

The GDPR has a broad scope and therefore a big effect on many issues. It will impact at least all companies that are located inside the European Union (EU).

Different types of personal information

With the arrival of the GDPR, individuals need to explicitly comply with the collection of personal information. The following falls under personal data:

  • Personal details: Name, Address, City, Phone number, Email, Date of birth, but also GPS location data and for example the device-ID of a mobile phone.

  • Pseudo-anonymous data: aren’t (directly) traceable to a person without the use of additional data. Are traceable to an individual but not to a directly recognizable person. Consider: IP-address, hashed email, order ID, user ID, data via tracking scripts such as Google Analytics.

  • Anonymous data: doesn't apply within the GDPR.

Personal data and pseudo-anonymous data can be used with explicit permission for clearly specifiek, explicit and legitimate goals. The data cannot be processed in ways that aren’t compatible with these goals.

The five most important pillars of the GDPR

The key changes that are enforced with the introduction of the GDPR, can be categorized in the following five pillars:

  • Transparency Companies should inform individuals involved about how personal data is collected and processed. This should be communicated in an understandable way.

  • Accountability Companies are more accountable to show themselves they comply to the legalisation. Companies have a documentation requirement, an obligation of proof and the responsibility to reduce privacy risks that are related to personal data.

  • Consumer rights:

    • The right to view, edit or delete personal data.

    • The right to request personal data in an accessible file format (e.g. Excel) and transferring this data to other companies.

    • The right to be forgotten: companies should delete personal data when the individual concerning the data requests it. This should be executed at once, or at least within the timespan of a month. Please note: this also applies for data that has been shared with third parties.

  • Obligation to report data breaches

    Companies are obliged to report a data breach with 72 hours, unless it can be proven that the breach will not endanger the privacy of the individuals whom it concerns.

  • Privacy by design and privacy by default

    Privacy by design ensures that companies will consider the protection of personal data in the development of new products or services and protect personal data by default when it comes to technical and organizational matters. Privacy by default means companies should take action to only collect the bare minimum of personal information by default for the purpose they serve.

Frequently asked questions

What is GDPR and who does it apply to?

GDPR (General Data Protection Regulation) is the EU-wide law governing how organizations collect, store, and process personal data. It applies to any company that handles personal data of individuals in the EU, regardless of where the company itself is based.

Is my webinar platform required to be GDPR compliant?

Yes, if you collect registrant details such as names, emails, or tracking data from EU-based attendees, your webinar platform needs to process that data in line with GDPR. This includes consent, data storage location, and the right to be forgotten.

What personal data does GDPR cover in a webinar context?

Registration details (name, email, phone number), IP addresses, device IDs, and behavioral data collected through tracking scripts like Google Analytics all fall under GDPR, either as personal data or pseudo-anonymous data.

What happens if a company fails to comply with GDPR?

Non-compliance can lead to investigations and fines from data protection authorities, alongside reputational damage. Companies are also obligated to report data breaches within 72 hours.

How can I make sure my webinars are GDPR compliant?

Look for a webinar platform with EU-based data hosting, built-in consent management, and clear data processing agreements. WebinarGeek is GDPR compliant by default as a European provider.

Where can I learn more about GDPR and WebinarGeek specifically?

Our blog post WebinarGeek and the GDPR covers exactly how our platform handles compliance for your account and attendee data.

Explore webinar hosting today

Start free trial