EU GDPR · Practical guide · Checked 11 September 2026

Your data. Your rights.

Know what a service collects, why it needs it and what you can change. GDPR applies to personal data in everyday services and AI. Cookie choices are one part of that picture.

Read alongside the DMA guide to platform competition and EU AI Act guide. Each law asks a different question.

Start with the data

A name is only one way to identify you.

GDPR governs processing of information about an identified or identifiable living person.

Look beyond the name field

Email addresses, account identifiers, location traces, recordings and combinations of facts can identify someone. Replacing a name with a code usually leaves personal data if it can be linked back. Truly anonymous information is different.

GDPR can apply to organisations established in the EU and to organisations outside it offering goods or services to people in the EU or monitoring their behaviour there. Citizenship alone is not the test.

Identify who makes the decisions

The controller decides why and how personal data is used. A processor handles it on the controller's behalf. A cloud or AI provider's role depends on the actual processing and terms; “we use a vendor” does not transfer every responsibility away.

Ask for the purpose, lawful basis, recipients, retention period and rights process before handing over information. A useful explanation tells you what will happen, in language you can understand.

Track the whole chain

A service may involve a brand, a regional controller, a processor, an ad partner, an identity provider and a model host. Map who decides the purpose, who runs each step and who receives the data. A list of company names without roles is not a data map.

Why follow more than social apps?

The same person can appear in an account record, an advertising profile, a recruitment file, a driver account or a biometric search index. The rule follows the processing and its effects, not the company's sector or the novelty of the AI label.

Your Europe: GDPR scope, roles and obligations; GDPR, Articles 3-5 and 13-14.

A reason for each use

Consent is one lawful basis.

A service cannot turn every use of your data into a requirement simply by adding it to its terms.

GDPR has six lawful bases: consent, contractual necessity, legal obligation, vital interests, public task and legitimate interests. Each has conditions. Fulfilling an order may require an address; building an advertising profile is a separate purpose. Legitimate interests requires a necessity and balancing assessment.

When consent is used

It must be freely given, specific, informed and unambiguous. You need a real affirmative choice, with withdrawal as easy as giving consent. Silence and pre-ticked boxes do not count. Power imbalances, including employment, can make consent unsuitable.

Some data needs extra protection

Health information, political opinions and other special categories need an Article 9 condition as well as an Article 6 basis. A photograph is not automatically biometric special-category data; processing it to uniquely identify a person can make it so.

Commission: lawful bases, consent and sensitive data.

Practical control

Ask to see it, correct it or challenge its use.

Rights have conditions and exceptions. An organisation should explain a refusal, rather than simply ignore a request.

Access and correction
Ask whether your data is processed, get a copy and relevant context, and correct inaccurate or incomplete information.
Erasure and restriction
Ask for deletion when a ground applies, or for processing to be limited in qualifying circumstances. Necessary legal records and other exceptions can prevent immediate deletion.
Portability
For qualifying automated processing based on consent or contract, receive the personal data you provided in a reusable format and transfer it where technically feasible.
Objection and withdrawal
Object to direct marketing at any time. Other objections depend on the basis and circumstances. Withdraw consent for future processing without undoing the lawfulness of earlier use.

Commission: rights, conditions and how to exercise them.

The banner is a choice

Refusing should be straightforward.

The device-storage rule mainly comes from the ePrivacy Directive and national implementing law. GDPR supplies the consent standard and governs personal-data processing.

Cookies and similar storage used for non-essential tracking generally need consent before they are set or read. Strictly necessary storage for a service the user explicitly requests can be exempt. Calling analytics “essential”, or moving an identifier into local storage, does not create an exemption.

  1. Explain the actual purpose. Name the provider, data, storage duration and how to change the choice.
  2. Offer a clear refusal. Do not hide rejection behind misleading links or unreadable styling while making acceptance obvious.
  3. Wait for a positive choice. Scrolling, continued browsing and preselected options do not supply valid consent.
  4. Make withdrawal easy. Keep settings available after the banner disappears. Stop future optional collection when permission is withdrawn.

A site that uses only exempt storage need not manufacture an “accept all” banner. It still needs appropriate transparency. A banner by itself is not proof that a website follows its stated choice.

Your Europe: cookie rules; EDPB cookie-banner taskforce report; ePrivacy Directive, Article 5(3).

isaiuseful.com

Analytics stays off until you allow it.

This section explains this site's cookie choice and browser storage. Rejecting analytics leaves the site usable.

The production site offers equally prominent Reject analytics and Allow analytics buttons. Before an explicit opt-in, it does not load the Google Analytics tag or send Analytics cookieless pings. Local previews do not load Analytics or display the consent panel.

What the cookie choice controls
Storage or servicePurpose and durationYour control
Analytics preferenceA local browser preference records allow or reject for 180 days. It is stored under isaiuseful.analytics-consent.Change it through Cookie settings. Clearing site storage also removes the saved choice.
Google Analytics cookies_ga identifies a browser; _ga_6LXW5XRJJP maintains session state. Configured for 180 days without extending expiry on each visit, after opt-in.Reject to prevent activation. Withdraw to disable future Analytics collection and remove this site's _ga cookies. Data already sent is not recalled.
Offline files and preferencesSite files can be cached for offline use. App-install and screensaver preferences remain in the browser until cleared, expired by their feature or removed by the browser.Manage these through your browser's site-data settings. Analytics rejection does not delete offline files or functional preferences.

What Google receives after opt-in

Viewed pages, referrer, browser and device details, approximate location and session or engagement data help measure site use. Enabled Enhanced Measurement can add scrolls, outbound links, downloads, search terms, supported video events and form metadata.

The tag disables advertising storage, Google Signals and ad personalisation. Google may process data internationally. Cookie expiry differs from the Analytics property's server-side retention: user-level event data can be retained for up to 14 months under its setting, and aggregate reports may remain longer.

Change your choice

Use Cookie settings in the footer on the live site to review or withdraw permission. Choosing Reject analytics stops future collection through this site's Analytics tag and clears its Analytics cookies.

Other connections are separate: embedded YouTube players use the privacy-enhanced domain and may load as they approach the viewport. That can contact YouTube before playback. Following external links contacts the destination. Rejecting Analytics does not block all third-party network activity.

GA4 cookies; Enhanced Measurement; Analytics retention settings; Google's partner-site data explanation.

Before the prompt or training run

AI does not remove the data question.

Check the actual information flow: input, retrieval, model provider, logs, outputs and subsequent reuse.

Public data is not automatically free to reuse

The EDPB says anonymity of AI models needs case-by-case assessment. A model trained with personal data cannot simply be assumed anonymous. Legitimate interests may be considered for development or deployment, but requires a legitimate purpose, necessity and a balancing test.

For a work task, remove unnecessary personal details, check whether the provider reuses prompts for training, and establish retention and deletion arrangements. Running locally can reduce disclosure to a provider, but does not resolve every duty concerning the people in the data. When an AI system also falls within the EU AI Act, check its Article 50 transparency route alongside the data-protection analysis.

EDPB opinion on AI models and personal data.

Consequential automated decisions need scrutiny

Article 22 concerns decisions based solely on automated processing that have legal or similarly significant effects. It has exceptions and safeguards; it is not a general right to demand a human response to every chatbot message.

If an automated system decides a loan or similarly consequential matter, ask which rule permits that use and how to contest it. Applicable safeguards can include human intervention and the opportunity to express your view.

European Data Protection Supervisor: automated decisions.

EDPB guidance on anonymisation and web scraping for generative AI, 8 July 2026; CNIL analysis of AI model status under GDPR, 5 January 2026.

Enforcement record · Checked 11 September 2026

The companies change. The failure modes repeat.

A curated record across platforms, advertising, retail, recruitment, biometrics, security and AI. A fine issued is not always money collected.

GDPR is enforced by national data protection authorities working through the one-stop-shop and EDPB cooperation rules. The cases below are selected for the practical lesson they add, not ranked as a complete list. Amounts are the regulator's issued amount unless the status says otherwise.

Selected GDPR fines and enforcement decisions in Europe
DecisionWhat the authority foundStatus and reader takeaway
Meta, Facebook€1.2 billion12 May 2023The Irish DPC found that Facebook's EU/EEA transfers to the United States lacked sufficient safeguards under Article 46, and ordered a suspension of the transfers.Pending appeal in the DPC's public fines table. This is a transfer and safeguards case, not a general ban on US cloud services. DPC decision.
Uber€824.99 million21 August 2026The Dutch AP said Uber's systems temporarily or permanently blocked drivers for suspected fraud or low ratings without a human assessment, and did not adequately explain the automated decision-making.Uber says it will appeal, so this is not final. It makes Article 22 concrete for algorithmic management: losing access to work is a significant effect, not just a technical support issue. Dutch AP current enforcement notices; Reuters report on the decision.
Meta, Instagram€405 million2 September 2022The DPC found shortcomings affecting child users, including public-by-default settings and transparency around accounts and contact details.Pending appeal. Default settings, age context and accessible explanations matter together; publishing a policy is not the same as protecting a child in the product flow. DPC decision.
TikTok€345 million1 September 2023The DPC addressed child users, public-by-default settings, age verification, Family Pairing and transparency obligations.Pending appeal in the DPC table. A child-safety review has to examine defaults and the actual user journey, not only the platform's age policy. DPC enforcement notice.
LinkedIn€310 million24 October 2024The DPC found that LinkedIn's behavioural analysis and targeted advertising processing did not meet GDPR requirements for lawfulness, fairness and transparency.Pending appeal. Employment and professional data can be used for advertising analysis even when a service is not described as a social network; purpose and legal basis must still match. DPC enforcement notice.
Meta, Facebook and Instagram€390 million31 December 2022The DPC found that treating a contract as the legal basis for behavioural advertising on Facebook and Instagram did not satisfy GDPR requirements.Pending appeal. A service contract for an account does not automatically make every later advertising purpose contractually necessary. DPC decision.
WhatsApp€225 million2 September 2021The DPC, following an EDPB binding decision, found transparency problems affecting users and non-users and the explanation of data sharing with Facebook.Pending appeal. A privacy notice must explain the processing to people affected by it, not only to paying customers or account holders. DPC enforcement notice.
Clearview AI€30.5 million16 May 2024The Dutch AP found illegal collection of images for facial recognition, including biometric processing without a lawful basis, poor transparency and no EU representative.The AP decision says collection was deferred while legal proceedings continue. Scraping public images can still create a biometric dataset; the public source does not settle the purpose or Article 9 analysis. EDPB summary of the AP decision.
FREE and FREE MOBILE€42 million13 January 2026CNIL fined the telecom companies €27 million and €15 million after a security breach affected around 24 million subscriber contracts, including IBAN data.A recent security case outside social media and AI. Security is a GDPR obligation with operational consequences, not a document-only exercise. CNIL decision.
Amazon€746 million15 July 2021Luxembourg's CNPD found a lack of sufficient legal basis and transparency in Amazon's processing.The fine was annulled on 12 March 2026 after the court required the negligence analysis to be reassessed; the core findings were not simply erased. Do not count this as a settled payable fine. CNPD status update; Court of Justice case summary.
OpenAI€15 million2 November 2024The Italian Garante's decision addressed transparency and the legal basis for personal data used in training after its investigation into OpenAI.The Garante page says the decision was temporarily removed after a Rome Court judgment published on 18 March 2026 upheld OpenAI's appeal. Treat it as a contested former fine, not a current final amount. Garante decision and current status.

Cookie fines are often ePrivacy fines

Cookie storage rules are usually enforced under the ePrivacy Directive as implemented in national law. Do not label every cookie penalty a GDPR fine. CNIL's 2025 overview counted 83 sanctions worth €486.8 million overall, including 21 entities sanctioned over cookies and trackers; that is not a GDPR-only technology total.

Recent cookie and tracker sanctions under French national ePrivacy law
DecisionWhat the authority foundWhy the label matters
Google€325 million1 September 2025CNIL found ads inserted between Gmail messages without valid consent and cookies placed during account creation without valid consent.CNIL applied French national rules, not the GDPR one-stop-shop. The consent question can be real even when the headline says “cookie fine”. CNIL decision.
SHEIN€150 million1 September 2025CNIL said cookies were placed before consent, refusal and withdrawal choices were not respected, and the information presented to users was incomplete.This is an ePrivacy enforcement example against a retailer. A compliant banner needs correct storage behaviour and a durable withdrawal route, not only two buttons. CNIL decision.

Irish DPC fines table, including appeal and collection notes; EDPB enforcement and fines overview.

Put the duty into practice

Document the processing, not just the policy.

Use this as a starting checklist for a specific workflow, with specialist review when its risks require it.

  1. Map and minimise. Record the people, data, purpose, recipients and retention rule. Collect only what the task needs.
  2. Set responsibilities. Establish controller and processor roles, instructions, contracts, access controls and an owner for rights requests.
  3. Check transfers. An EU data-centre label does not settle who can access the data from elsewhere. Assess the applicable international-transfer mechanism and safeguards.
  4. Assess high risk before starting. A data protection impact assessment is required where processing is likely to pose high risk. Consult the authority when high residual risk remains.
  5. Prepare for incidents. Notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to risk people's rights and freedoms. High-risk breaches can also require informing affected people.

Commission: organisational obligations, impact assessments and breaches; Your Europe: protection for international transfers.

Use a concrete request

Say which data and which right.

Contact the organisation responsible for the processing, or its data protection officer where one exists. Keep your request and its response.

Organisations generally must respond without undue delay and within one month. Complex or numerous requests can justify up to two further months, but the organisation must explain that extension within the first month. Proportionate identity checks may be needed.

You can complain to a data protection authority, in particular where you habitually live, work or where an alleged infringement occurred. Cookie enforcement may also involve the authority responsible for national ePrivacy rules. A competition complaint about a platform's access restrictions belongs on a different track. See the DMA rulebook for that question.

Commission: exercising your rights; Find your national data protection authority; GDPR Articles 12 and 77.