---
title: "The EU GDPR and Its Impact | heureka e-Business GmbH"
canonical_url: "https://heureka.com/en/resources/blog/die-eu-dsgvo-und-ihre-auswirkungen"
last_updated: "2026-09-04T20:10:14.414Z"
meta:
  author: "heureka e-Business GmbH"
  description: "An overview of supervisory authorities, privacy principles, lawfulness, data-subject rights, and security under the EU GDPR."
  "og:description": "An overview of supervisory authorities, privacy principles, lawfulness, data-subject rights, and security under the EU GDPR."
  "og:title": "The EU GDPR and Its Impact"
  "twitter:description": "An overview of supervisory authorities, privacy principles, lawfulness, data-subject rights, and security under the EU GDPR."
  "twitter:title": "The EU GDPR and Its Impact"
---

[Back to Resources](https://heureka.com/en/resources)

**Blog** 2018-04-30 3 min read Michael Wycisk

# **The EU GDPR and Its Impact**

A historical overview of the EU GDPR's scope, principles, data-subject rights, and security requirements.

## Introduction

The EU General Data Protection Regulation has applied since 25 May 2018. Its purpose is to harmonize privacy law across Europe. It covers organizations and establishments in the European Union that process personal data.

Under certain conditions, it also applies to organizations outside the EU when processing relates to offering goods or services to people in the Union or monitoring their behavior.

Organizations therefore need to understand the requirements for lawful processing, the obligations the regulation creates, and the potential consequences of non-compliance.

## Supervisory Authorities

Supervisory authorities monitor and enforce application of the regulation. They handle questions and complaints from data subjects, raise awareness of controllers' obligations, and investigate whether requirements are being observed.

Their powers range from warnings to instructions intended to protect data-subject rights. Depending on the infringement, penalties can reach EUR 20 million or four percent of worldwide annual turnover in the preceding financial year.

## Data Protection Principles

The regulation is built around central principles for processing personal data. Data must be:

- processed lawfully, fairly, and transparently for the data subject,
- collected for specified, explicit, and legitimate purposes,
- limited to what is necessary for those purposes,
- accurate and kept up to date,
- and stored only for as long as the processing purpose requires.

Security and protection against unauthorized or unlawful processing, accidental loss, destruction, or damage are equally important. Appropriate technical and organizational measures should safeguard these objectives. Controllers must be able to demonstrate compliance with the principles.

## Lawfulness

Processing may be based on the data subject's consent. Other possible legal bases include performance of a contract, compliance with a legal obligation, a task carried out in the public interest, and legitimate interests pursued by a controller or third party. The appropriate basis depends on the specific processing activity.

## Data-Subject Rights

Data subjects have rights concerning their personal data, including:

- the right of access
- the right to rectification
- the right to erasure
- the right to restrict processing
- the right to data portability
- the right to object
- the right not to be subject solely to an automated individual decision
- the right to withdraw consent

## Security of Processing

Controllers must implement appropriate technical and organizational measures after considering the nature, scope, circumstances, and purpose of the processing. The measures should be proportionate to the activities and risks, while accounting for implementation costs and the state of the art.

The measures described include:

- pseudonymization and encryption of personal data,
- the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of systems and services,
- the ability to restore availability and access following a physical or technical incident,
- and a process for regularly testing, assessing, and evaluating the effectiveness of the measures.

This article reflects the information available at the time of publication and does not constitute legal advice.

## **Ready to move forward?**

Talk to our experts about your specific challenges. We provide honest assessments and actionable recommendations.

[Talk to Experts](https://heureka.com/en/contact)

**Practical implementation**

## **Turn this resource into an actionable next step**

Discuss your current situation with heureka. Together, we can clarify priorities, ownership, and the most useful place to start.

## **More resources you might like**

**Checklist ****· Exclusive**

### [ITSM Readiness Checklist](https://heureka.com/en/resources/checklists/itsm-readiness-checklist)

12 min read

[**Get the checklist → **](https://heureka.com/en/resources/checklists/itsm-readiness-checklist)

**Whitepaper ****· Exclusive**

### [AI Starts with Data Modelling: Why 'Model First' Matters More Than Ever](https://heureka.com/en/resources/whitepapers/ai-starts-with-data-modelling-model-first)

16 min read

[**Get the whitepaper → **](https://heureka.com/en/resources/whitepapers/ai-starts-with-data-modelling-model-first)

**Assessment **

### [Data Governance Maturity Assessment](https://heureka.com/en/resources/assessments/data-governance-maturity-assessment)

5 min

[**Start assessment → **](https://heureka.com/en/resources/assessments/data-governance-maturity-assessment)