Skip to content

What is GDPR?

GDPR — TAP-ONE Glossary

A European Union data protection law setting strict rules on how personal data is collected and used.

Last updated: 8 August 2026

GDPR (General Data Protection Regulation) is a European Union law governing how organizations, including SaaS providers like Salesforce (opens in new tab), collect, store, and use personal data of EU residents. Even businesses outside the EU may need to comply if they serve EU customers, and it has influenced data protection laws in other countries, including India’s DPDP Act.

Why It Matters Beyond Just the EU

GDPR effectively set the template that many other countries’ data protection laws, including India’s own DPDP Act, have since drawn from, so understanding its core principles, consent, transparency, the right to have data deleted, is useful even for a business that never directly deals with EU customers.

Penalties for serious violations can be substantial, which is one reason larger platforms and payment providers take these principles seriously even for smaller merchants using their systems.

A simple, honest privacy policy and a clear, unforced way for customers to opt out of marketing messages cover most of what these principles actually require in practice for a small local business.

People also ask

Does GDPR apply to Indian businesses?

It applies if an Indian business processes personal data of EU residents, even without a physical EU presence. Purely domestic Indian businesses are instead primarily governed by India’s own DPDP Act.

See also

How TAP-ONE helps

A fast, secure site that brings in leads while you focus on running the business.

Explore Get a Website

More in Security & Privacy

Back to glossary