GDPR stands for General Data Protection Regulation: the European Union’s main privacy law. It requires clear consent for many uses of personal data, security safeguards, and rights such as access, correction, and deletion.
It applies when you process data of people in the EU/EEA — even if your business is in Atlanta. Related US rules (like California’s CCPA) share the same idea: tell people what you collect and give them choices. On websites that often means cookie consent, a clear privacy policy, and careful analytics setup. E-commerce stores that take EU orders need this on the checklist next to HTTPS / SSL.
A real-life example of GDPR
A SaaS tool signs up a customer in Berlin. Under GDPR, the signup must explain what data is stored, why, and how to delete it — not bury that in fine print. If the company later sells email lists without a lawful basis, that is a compliance failure, not a marketing win.
GDPR is not “block all cookies.” It is lawful, transparent processing. For store-level security and compliance context, see E-commerce Technical Pillars.