GDPR has been in force since 2018, and it still gets misquoted constantly, sometimes by organisations trying to over-comply out of caution, and sometimes by organisations using a myth as an excuse to under-comply. Both directions cause real problems. Here are eight of the most persistent misconceptions and what the regulation actually says.
• Consent is one of six lawful bases under Article 6, not the only one, and treating it as mandatory for everything leads to unnecessary and sometimes invalid consent requests.
• GDPR has no employee-count or revenue exemption. The only size-based carve-out is a narrow record-keeping exemption under Article 30(5).
• GDPR applies to organisations outside the EU whenever they offer goods or services to, or monitor, people in the EU, regardless of where the organisation itself is based.
• Not every data breach needs to be reported to a regulator. Article 33 only requires notification where the breach poses a risk to people’s rights and freedoms.
No. Article 6 GDPR sets out six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Consent is simply the most visible one, largely because cookie banners and marketing opt-ins have made it the basis people encounter most often online.
Treating consent as the default for every processing activity causes two practical problems. First, it generates unnecessary consent requests for processing that already has a valid basis, such as using a customer’s address to ship an order under a contract. Second, consent has stricter validity requirements than most other bases: it must be freely given, specific, and revocable at any time, which makes it a genuinely weaker choice in contexts like employment, where a power imbalance can make consent difficult to obtain validly in the first place.
No, not in any general sense. GDPR applies to any organisation processing personal data belonging to people in the EU, regardless of the organisation’s size, turnover, or number of employees. A five-person company that holds a customer email list is processing personal data just as much as a multinational.
The one size-related carve-out is narrow: Article 30(5) exempts organisations with fewer than 250 employees from keeping full written records of processing activities, but only where the processing is occasional, unlikely to create a risk to individuals’ rights, and does not involve special category data. This is a paperwork exemption covering one specific obligation. It does not exempt a smaller organisation from the rest of GDPR, including lawful basis requirements, security obligations, or individual rights.
No. Article 3 GDPR sets out an extraterritorial scope that catches organisations established anywhere in the world if they offer goods or services to people in the EU, even where no payment is required, or if they monitor the behaviour of people located in the EU, for example through website analytics or online tracking.
A US-based online retailer that ships to EU customers, or a SaaS company anywhere in the world that tracks visitors from EU countries through analytics tools, falls within GDPR’s scope on this basis, regardless of having no physical presence, office, or incorporation in the EU. This is one of the more consequential misconceptions, because organisations that assume geography alone determines applicability often skip compliance work they are actually legally required to do.
No. Article 33 GDPR requires notification to the relevant supervisory authority only where a breach is likely to result in a risk to the rights and freedoms of the individuals affected, and generally within 72 hours of the controller becoming aware of it. A breach assessed as unlikely to cause risk, for example a misdirected internal email caught and deleted before anyone else opened it, does not trigger the same notification obligation, though it should still be logged internally.
Where the risk is high rather than merely present, Article 34 adds a further requirement to notify the affected individuals directly, not just the regulator. Getting this risk assessment wrong in either direction causes problems: over-reporting floods regulators with low-risk notifications, while under-reporting a genuinely high-risk breach is itself a compliance failure. Our guide to breach notification requirements covers how to make that risk assessment in practice.
Only if the anonymisation is genuinely irreversible. This is one of the most commonly confused pairs of terms in the regulation. Truly anonymised data, where no reasonable means exist to re-identify the individual it came from, falls outside GDPR entirely. Pseudonymised data, where identifiers have been replaced with codes or tokens but could be reversed using a separately held key, remains personal data and stays fully within GDPR’s scope.
Many organisations describe data as “anonymised” when it is actually pseudonymised, which leads them to treat data as exempt from GDPR obligations it is still subject to. Our comparison of pseudonymisation versus anonymisation works through the practical distinction in more detail.
Generally, no. This is a specific and commonly repeated misconception that the UK’s ICO directly addressed in guidance published in September 2025: where the ePrivacy rules governing cookies and similar storage and access technologies require consent, an organisation cannot instead rely on legitimate interests under GDPR to justify the same activity. The ICO was also explicit that an organisation cannot use consent to place a cookie and then switch to legitimate interests for whatever processing follows, since doing so would strip the control that consent was meant to give the user in the first place.
Legitimate interest remains available for storage and access technologies that fall outside the consent requirement altogether, such as those that are strictly necessary to deliver a service the user has actively requested. It is not a substitute basis for the ones that do require consent.
No. The right to erasure under Article 17 is commonly referred to as the “right to be forgotten,” but it comes with specific conditions and equally specific exceptions. A controller does not have to comply with an erasure request where the processing is necessary for compliance with a legal obligation, for the establishment or defence of legal claims, for reasons of public interest, such as public health, or for exercising the right of freedom of expression and information.
A business that retains an invoice for the period required by tax law, despite a customer’s deletion request, is not necessarily breaching GDPR. It is relying on one of these exceptions, provided the retained data is limited to what the legal obligation actually requires and is not kept for unrelated purposes.
No. Headline fines like Meta’s €1.2 billion penalty and Amazon’s €746 million penalty dominate coverage of GDPR enforcement, but they represent the extreme end of a much wider range. Article 83 GDPR sets maximum fine tiers of up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements, but the actual fine issued in any given case depends on factors including the nature and duration of the infringement, whether it was intentional, and what mitigating steps the organisation took.
The great majority of GDPR fines issued across the EU and UK to date have been far smaller than the maximum tier, often in the thousands or low tens of thousands of euros, reflecting smaller-scale or less severe infringements.
Our breakdown of how GDPR fines and penalty percentages work sets out how regulators calculate these figures in practice.
Most GDPR myths persist because a genuine rule got simplified into a catchier but inaccurate version somewhere along the way: consent became “the” basis instead of one of six, extraterritorial scope became “only applies in the EU,” and a narrow record-keeping exemption became “small businesses don’t need to worry about it.”
None of these simplified versions is accurate, and relying on them tends to produce either compliance gaps or work that the actual rule never required. Reading the specific article a claim is supposedly based on is usually enough to tell the difference.
Not automatically. GDPR’s extraterritorial scope under Article 3 is triggered by offering goods or services to people in the EU or monitoring their behaviour, not simply by being reachable from the EU online. A business with genuinely no EU customers and no monitoring of EU-based individuals generally falls outside GDPR’s scope on this basis, though other data protection laws may still apply depending on where it operates.
Yes. A Data Protection Officer is only mandatory under Article 37 for public authorities, organisations whose core activities involve large-scale regular and systematic monitoring of individuals, or large-scale processing of special category data. Many organisations appoint one voluntarily as good practice, but it is not a universal requirement.
No, not automatically. It depends on whether that provider has a valid international transfer mechanism in place, such as Standard Contractual Clauses backed by an adequate assessment of the risks involved. Using a US provider is not itself a violation, but it does trigger additional legal requirements that purely domestic processing does not.
Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.
About the Author
Zlatko Delev
Country Manager & Head of Commercial — GDPRLocal
Zlatko specialises in data protection compliance, ISMS strategy, and AI law. With a legal background and hands-on experience supporting organisations globally, he helps businesses navigate GDPR, the EU AI Act, and international privacy frameworks.