GDPR (General Data Protection Regulation)
The full value of a customer contract over its entire term, including all fees and commitments.
What Is GDPR?
GDPR is the European Union regulation, in force since 25 May 2018, that governs how organizations collect, use, store, and share the personal data of people in the EU and EEA. It applies to any company anywhere that targets or monitors those people, and it carries fines reaching 4 percent of global annual turnover.
How GDPR Works
GDPR assigns every party a role. The controller decides why and how personal data is processed. The data processor acts only on the controller's documented instructions. A B2B software vendor is almost always a processor for its customers' data and a controller for its own employee and prospect records, and the two roles carry different obligations.
Processing is legal only when it rests on one of six lawful bases, when it satisfies the principles of purpose limitation, data minimization, accuracy, storage limitation, and security, and when the organization can prove all of that on demand. Accountability is the operative word: a company that cannot produce records of processing activities under Article 30 has a compliance problem even if nothing was ever misused.
Two deadlines matter operationally. A reportable personal data breach must reach the relevant supervisory authority within 72 hours of the controller becoming aware of it. A data subject request must be answered within one month, extendable by two further months for genuinely complex cases.
GDPR in Plain English
GDPR treats personal data as something the person keeps a claim on rather than something a company owns once collected. You need a specific reason to hold it, you can only use it for that reason, you must tell people plainly what you are doing, you must secure it, and you must give it back or delete it when they ask. Everything else in the regulation is machinery built to enforce those five ideas.
Lawful Basis and Consent Under GDPR
The six lawful bases are consent, performance of a contract, legal obligation, vital interests, public task, and legitimate interests. Consent gets the most attention and is the weakest option for most B2B work: it must be freely given, specific, informed, unambiguous, and as easy to withdraw as to give, which means pre-ticked boxes and bundled terms do not qualify.
Legitimate interests is the workhorse basis for B2B prospecting, fraud prevention, and product analytics, but it requires a documented balancing test showing the interest does not override the individual's rights. Choosing a basis is not a formality. You cannot switch bases mid-stream when the first one becomes inconvenient.
Data Subject Rights and the Right to Erasure
GDPR gives individuals enforceable rights: access to their data, rectification of errors, erasure, restriction of processing, portability in a machine readable format, objection to processing, and protection against solely automated decisions with legal or similarly significant effects.
The right to erasure is not absolute. It yields where data is still needed for the contract, for a legal obligation such as tax or anti money laundering record keeping, or for the establishment or defense of legal claims. In practice the hard part is not the policy but the architecture: deleting a person from a production database means little if copies persist in backups, logs, a warehouse, a CRM, and three analytics tools nobody documented.
GDPR and Cross-Border Data Transfers
Moving personal data outside the EEA requires a transfer mechanism. The cleanest is an adequacy decision, where the Commission has judged a country's regime equivalent. Where none exists, most companies rely on standard contractual clauses, the SCCs, in their modular 2021 form, paired with a transfer impact assessment that evaluates whether local surveillance law would undermine the clauses in practice. Transfers to the United States can also use the EU to US Data Privacy Framework where the importer is certified. A data processing agreement, or DPA, sits underneath all of this and is the contract that binds a processor to Article 28 terms and lists approved sub-processors.
GDPR and the Closing Motion
GDPR shapes the close long before anyone reads a contract. In the Propose stage a buyer's security review arrives with a questionnaire, a DPA to negotiate, a sub-processor list to approve, and questions about where data lives. Weak answers add weeks; clean answers, a signed DPA, and current SCCs remove an entire workstream from procurement diligence. That matters because the Closing Motion depends on removing friction between yes and cash. Ratio operates on the same principle for the financial side of the close, running proposals, buyer underwriting, and payments on rails a security team can actually approve. Trust is what lets Propose move to Close without a detour through legal.
Common Questions About GDPR
Does GDPR apply to a US company with no EU office?
Yes, if it offers goods or services to people in the EU or monitors their behavior, which includes most self serve software and most web tracking. Article 3 ties the regulation to where the individual is, not where the company is incorporated.
What is the difference between a controller and a data processor?
The controller determines the purposes and means of processing and carries primary accountability. The processor acts only on documented instructions and must be bound by a DPA. Vendors that quietly decide to reuse customer data for their own purposes become controllers for that use, with all the obligations attached.
How large are GDPR fines in practice?
The two tiers cap at 10 million euros or 2 percent of global annual turnover, and 20 million euros or 4 percent, whichever is greater. Regulators have issued penalties in the hundreds of millions against large platforms, though most enforcement against smaller companies ends in orders and corrective measures rather than maximum fines.
Key Takeaways
- GDPR governs personal data of people in the EU and EEA and applies extraterritorially to any company that targets or monitors them.
- Every processing activity needs one of six lawful bases, and consent is often the weakest choice for B2B use cases.
- Data subject rights include access, rectification, erasure, portability, and objection, with a one month response clock.
- Cross-border transfers need an adequacy decision, SCCs plus a transfer impact assessment, or a certified framework.
- GDPR readiness, especially a clean DPA and sub-processor list, directly shortens enterprise security review.
↗
The Closing Motion Platform
Sellers on Ratio see up to 30% higher close rates and 25% higher ACV.