All regulations

AVG/GDPR

General Data Protection Regulation (GDPR)

European Union & EEAEffective: May 25, 2018Supported by Consentr

The GDPR is the world's strictest privacy legislation and protects the personal data of all EU citizens. Every organization that processes data of EU residents must comply.

What is the AVG/GDPR?

The General Data Protection Regulation (GDPR) is the European privacy law that has been in effect since May 25, 2018. It gives individuals control over their personal data and imposes strict obligations on organizations that collect, process or store personal data.

Who must comply?

Companies established in the EU that process personal data

Organizations outside the EU that offer goods or services to EU citizens

Companies that monitor or profile the behavior of EU residents

Processors that process personal data on behalf of a data controller

Government agencies and public organizations that manage personal data

Any organization that processes special categories of personal data on a large scale

Key requirements

Lawful basis for processing

Every processing of personal data must be based on one of the six legal bases from Article 6 GDPR: consent, contract, legal obligation, vital interests, public task or legitimate interest.

Informed and freely given consent

When consent is the basis, it must be freely given, specific, informed and unambiguous. Pre-ticked boxes or inactivity do not count as valid consent.

Data subject rights

Individuals have the right to access, rectification, erasure (right to be forgotten), restriction of processing, data portability and objection to processing.

Privacy by design and by default

Data protection must be built into products, services and business processes by default. Only the minimum amount of necessary data may be processed.

Data breach notification obligation

Data breaches must be reported to the competent supervisory authority within 72 hours of discovery. Affected individuals must also be notified if there is a high risk.

Data Protection Impact Assessment (DPIA)

For processing operations with a high risk to the rights and freedoms of data subjects, a DPIA must be carried out before the processing begins.

Penalties for non-compliance

GDPR violations can lead to fines of up to 20 million euros or 4% of global annual turnover (whichever is higher). National supervisory authorities such as the Belgian GBA, Dutch AP and French CNIL actively enforce these rules.

How Consentr helps you

Consentr automates AVG/GDPR compliance so you can focus on your business.

Automatic cookie scanner

Consentr automatically scans your website for cookies and trackers and correctly categorizes them according to the GDPR requirements.

GDPR-compliant cookie banner

Our cookie banner meets all GDPR requirements: no pre-ticked boxes, clear information about each cookie category and easy withdrawal of consent.

Consent recording

Every consent is securely recorded with timestamp, IP address and the exact version of the consent configuration as proof for audits.

Automatic blocking

Scripts and cookies are automatically blocked until the visitor gives explicit consent. This ensures that no data is processed without permission.

Multilingual support

The cookie banner is automatically displayed in the visitor's language, so everyone can give informed consent regardless of their language.

Regular compliance audits

Consentr regularly checks whether your website still complies with the latest GDPR guidelines and alerts you to potential issues.

Frequently asked questions

Does the GDPR also apply to small businesses?

Yes, the GDPR applies to all organizations that process personal data of EU citizens, regardless of their size. However, some obligations like appointing a DPO only apply in specific circumstances.

What is the difference between a data controller and a processor?

The data controller determines the purpose and means of data processing. The processor processes data on behalf of the controller. Both have obligations under the GDPR.

Do I need to appoint a Data Protection Officer (DPO)?

A DPO is mandatory for government agencies, organizations that process special categories of data on a large scale, and organizations whose core activity involves regular and systematic monitoring of data subjects.

How does Consentr help with GDPR compliance for my website?

Consentr offers a fully configured cookie banner, automatic cookie scanning, consent recording with audit trail and automatic script blocking — everything you need for GDPR-compliant cookie management.

Become compliant with AVG/GDPR?

Start for free today and be compliant within 5 minutes.