Law & jurisdiction

What is GDPR?

Also known as: General Data Protection Regulation
Definition

The GDPR is the EU regulation governing processing of personal data of people in the EU, regardless of where the processing happens. It follows the data subject rather than the server, so hosting outside the EU does not exempt you — it adds a transfer-mechanism obligation such as standard contractual clauses.

Why GDPR matters

It follows the data subject rather than the server, so hosting outside the EU does not exempt you — it adds a transfer-mechanism obligation such as standard contractual clauses.

GDPR in practice

Operationally, GDPR is a paper-trail exercise. You must know which fields you store for EU-resident users, why you store them, and your legal basis. Then you write that down. You update the process when something changes. A breach means documenting the leak and sometimes notifying, which eats time you did not budget. Ignore it and a supervisory authority can fine you; then your anonymity on the platform does not help, because the regulator follows the data, not the server.

What people get wrong about GDPR

The common error is assuming that because you host outside the EU, GDPR does not apply. It does apply if you process data of people in the EU. Being offshore adds an obligation, not immunity. You still need a transfer mechanism, such as standard contractual clauses, or a lawful basis like consent.

GDPR — common questions

Does GDPR apply to a server outside the EU?

Yes. GDPR follows the data subject, not the server location. If you process personal data of people in the EU, you are in scope wherever you host. Offshore hosting adds a transfer-mechanism obligation, such as standard contractual clauses, rather than exempting you.

What happens if I ignore GDPR?

If you are a data controller or processor, a breach can bring fines and enforcement from EU regulators, even for a server outside the EU. Also, responding to data subject requests takes effort. Ignoring it does not make it go away; it makes it worse when you have to explain why.

More from law & jurisdiction

Warrant canary
A warrant canary is a regularly republished statement that a provider has not received a secret legal demand; its disappearance implies that one has arrived.
KYC
KYC is the set of identity-verification duties imposed on regulated financial institutions before providing services.
No-KYC hosting
No-KYC hosting is server hosting that requires no identity verification — no government ID, billing address, phone number or payment card.
Offshore hosting
Offshore hosting means placing a server in a jurisdiction other than your own, typically one outside the Fourteen Eyes alliances and outside EU data-retention rules.
Five Eyes
The Five Eyes is a signals-intelligence sharing alliance between the United States, United Kingdom, Canada, Australia and New Zealand.
Fourteen Eyes
The Fourteen Eyes is the widest of the signals-intelligence sharing groupings, comprising the Five Eyes plus Denmark, France, the Netherlands, Norway, Belgium, Germany, Italy, Spain and Sweden.
MLAT
An MLAT is a treaty through which one country formally requests another to gather evidence on its behalf.
DMCA
The DMCA is United States copyright statute whose notice-and-takedown procedure and safe harbour apply to service providers situated in the United States.