Lesson 83 of 2244
GDPR Basics: The Regulation That Changed Data
Europe's General Data Protection Regulation (2018) reshaped how the world handles personal data. Understanding its core concepts is now essential. In 2023, Italy briefly banned ChatGPT over GDPR concerns.
Adults & Professionals · AI Foundations · ~19 min read
The World's De Facto Privacy Law
GDPR took effect May 25, 2018, regulating personal data of EU residents regardless of where a company is based. Because few large companies can afford to carve out Europe, GDPR effectively became a global standard. California's CCPA, Brazil's LGPD, and India's DPDP Act are all heavily GDPR-inspired.
The six core principles
- 1Lawfulness, fairness, transparency — you need a lawful basis to process data
- 2Purpose limitation — collect for a specific purpose, do not quietly repurpose
- 3Data minimization — only what you need
- 4Accuracy — keep data correct and up to date
- 5Storage limitation — delete data when no longer needed
- 6Integrity and confidentiality — secure the data
What counts as personal data?
Individual rights
- Right to access — see what data is held about you
- Right to rectification — correct wrong data
- Right to erasure (right to be forgotten) — delete your data
- Right to data portability — get your data in a portable format
- Right to object to processing (including automated decision-making)
- Right to withdraw consent
GDPR and AI training
A person can theoretically request deletion of their data from a trained model. Models, however, do not store individual training examples cleanly, making true deletion hard. In 2023, Italy briefly banned ChatGPT over GDPR concerns. OpenAI responded with data controls and opt-outs. This remains a live legal tension.
Practical compliance steps
- 1Maintain a record of processing activities (Article 30)
- 2Establish a lawful basis before collecting data
- 3Write clear privacy notices
- 4Implement processes for data-subject rights requests
- 5Conduct a Data Protection Impact Assessment (DPIA) for high-risk use
- 6Report breaches within 72 hours
Key terms in this lesson
The big idea: GDPR made privacy a user right rather than a corporate favor. AI builders must design with these rights from the start, not bolt them on later.
End-of-lesson quiz
Check what stuck
14 questions · Score saves to your progress.
Tutor
Curious about “GDPR Basics: The Regulation That Changed Data”?
Ask anything about this lesson. I’ll answer using just what you’re reading — short, friendly, grounded.
Progress saved locally in this browser. Sign in to sync across devices.
Related lessons
Keep going
Adults & Professionals · 35 min
Audit Methodology: How to Check a Dataset
A data audit is a structured process to find bias, errors, and ethical issues before a model goes live. Every creator should know how.
Adults & Professionals · 28 min
Opt-Out Mechanisms: The Real State of Consent
Many AI companies now offer opt-outs from training. But how well do they actually work, and what are the catches?
Builders · 28 min
NotebookLM: Turning Your Notes Into a Study Buddy
Google's NotebookLM lets you upload textbooks, lectures, and notes, then chat with them. This is the most underrated study tool of 2026.
