GDPR applies based on where a website's visitors are, not where the business running it is registered. Serious violations carry fines of up to €20 million or 4% of the company's global annual turnover, whichever is greater — a figure deliberately set high enough that a flat cap can't become trivial for a large company. For any site that might have EU visitors, that's not a future compliance project; it's a question that belongs in scoping, before the build starts.
This is the question most likely to get skipped on international and white-label work specifically — the kind we cover in our white-label guide. An agency briefing us on a build rarely thinks to mention which countries the end client's customers are actually in, and a Malaysian studio has no instinct to assume EU law reaches a site it built. GDPR's Article 3(2) "targeting criterion" closes that gap deliberately: any organisation, anywhere, that offers goods or services to people in the EU or monitors their behaviour there is in scope, the same "where the consumer is" logic that governs the EU Accessibility Act. The two laws cover different things — this one is about personal data, not interface access — but they share the same blind spot if nobody asks the question up front.
What the build actually has to get right
Two pieces show up in almost every GDPR-covered build. The first is the cookie banner, and most of the ones we see fail the same way: non-essential cookies — analytics, ad pixels, embedded social widgets — can only be set after a real opt-in, with "Reject all" offered just as easily as "Accept all." A banner with a pre-ticked "accept" box, or one that blocks the page until the visitor agrees, isn't consent under GDPR, it's a dark pattern wearing a consent banner's clothes. The second is a working path for the two individual rights that come up in practice: a visitor asking what data is held on them, and a visitor asking for it to be deleted. Both need an actual process behind them, not just a sentence in the privacy policy promising one exists.
The 72-hour clock, and why it isn't the same 72 hours as PDPA
If a breach does happen, GDPR's Article 33 gives the controller 72 hours from becoming aware of it to notify the relevant supervisory authority — an initial notification with whatever is known so far is enough to meet the deadline; the rest can follow once the investigation catches up. Our Malaysia PDPA guide describes an identical 72-hour window, which makes the two laws easy to conflate — they're not the same law, and a site can fall under one, both, or neither depending on whose personal data it actually processes, not which country the business happens to be registered in. Checking that is a scoping question, the same way who should hold the domain and hosting is on a white-label build — easy to skip when nobody in the room is explicitly responsible for asking it.
Frequently asked questions
Does GDPR apply to a site built outside the EU?
Yes, if the site targets or monitors people in the EU. GDPR's Article 3(2) targeting criterion reaches any organisation, regardless of where it's registered or hosted, that offers goods or services to people in the EU or monitors their behaviour there. A white-label build for a client selling into Germany or France is in scope even though neither the studio nor the client's head office is in Europe — the same "where the consumer is" logic that governs the EU Accessibility Act.
What actually happens if a site gets this wrong?
GDPR fines run on two tiers. The most serious violations — unlawful processing, invalid consent, ignoring data subject rights — carry fines up to €20 million or 4% of the violating company's global annual turnover, whichever is greater. Procedural and technical failures sit on a lower tier, capped at €10 million or 2% of global turnover. The percentage basis exists specifically so a flat cap doesn't become trivial for a large company.
What does a compliant cookie banner actually have to do?
It needs a real opt-in, not an opt-out: non-essential cookies (analytics, ads, embedded social widgets) may only be set after a clear affirmative action, and the banner must offer an equally easy "Reject all" alongside "Accept all" — no pre-ticked boxes, no cookie wall that blocks the site until the visitor agrees. Cookies that are strictly necessary for the site to function don't need consent, but that exemption is narrower than most banners assume.
We already cover Malaysia's PDPA — is GDPR the same law?
No, they're separate laws that happen to share one number. Malaysia's PDPA (covered in our PDPA guide) governs personal data collected in Malaysia; GDPR governs data belonging to people in the EU, regardless of where the collecting business sits. Both set a 72-hour breach notification clock, which makes them easy to conflate, but a site can be covered by one, both, or neither depending on whose data it actually touches — that has to be checked separately, not assumed from one or the other.
Once the cookie banner and privacy policy are live, is the job done?
No. GDPR also gives individuals ongoing rights — to see what data is held on them and to have it deleted — that someone has to actually be able to fulfil, not just promise in a privacy policy. A new analytics script added six months after launch, or a marketing tool that drops its own tracking cookie, can quietly break consent coverage the same way an unreviewed access list breaks account security. It belongs on the same recurring maintenance check as the rest of this list, not a one-time task at delivery.