What is the GDPR?

The GDPR is the European regulation on personal data protection, adopted in 2016 and enforced since May 2018. It gives everyone concrete rights: access your data, obtain a copy, demand erasure. Any organization processing the data of European residents must comply with it.

Information verified on July 13, 2026

The European regulation that governs what companies do with your personal data. Adopted in 2016 and enforced since May 2018, it applies to any organization processing the data of a European resident, whether it is based in Paris or California.

In practice, it gives you rights you can use today: know what a company holds about you, get a copy of it in a usable format, demand erasure. This is the text that forces Google to let you leave with your emails, your photos and your contacts under your arm. Without it, exporting your data would be a commercial gesture, revocable overnight.

Its limit? It binds companies, not the laws of other countries. The American Cloud Act, for instance, can compel a US company to hand your data to its authorities, even when it is stored in Europe. The GDPR gives you rights; it does not move the servers.

Where it plays out: these rights stay theoretical as long as you do not use them. The book turns them into an action plan, the leaving Gmail guide shows one very concrete use, and personal digital sovereignty puts it all into a bigger picture.

Want the complete guide?

“Vivre sans Google” (in French) covers the full journey, service by service, with step-by-step migration guides.

Forthcoming 22/10/2026 from Éditions Eyrolles

Discover the book
Share: Email LinkedIn

Where do you stand?

24 questions to measure how much you depend on Google services. Free, no sign-up.

Take the diagnostic

Tech jargon, translated

Every week in The Spark, I break down one tech story through the privacy lens. And what you can do about it, concretely.

Join 400+ readers. Unsubscribe in one click. Your data will never be shared.