AIWiki
Malaysia
Back to all articles
Ethics & Policygdprdata-protectionprivacy

GDPR

4 min readUpdated September 2026
General Data Protection Regulation
Type
Data protection regulation
Jurisdiction
European Union and EEA
Adopted
27 April 2016
In force
25 May 2018
Key obligations
Lawful basis, data subject rights, breach notification, data protection officers
Maximum penalty
€20 million or 4% of global annual turnover
Related
EU AI Act, PDPA AI Compliance, AI and Copyright
General Data Protection Regulation (GDPR) is the European Union's flagship data protection law, formally Regulation (EU) 2016/679, which replaced the bloc's 1995 data protection directive and has applied since 25 May 2018. Its distinguishing feature is extraterritorial reach: it covers any organisation that processes the personal data of people in the European Union, wherever that organisation is based. For artificial intelligence, the GDPR supplies much of the law governing training data, automated decisions and cross-border data flows, and it operates alongside the newer EU AI Act.[1][2]

Background

The regulation was developed from a 2012 European Commission proposal and adopted in April 2016, with a two-year transition period before it took effect. It established a single set of rules across the EU, a "one-stop-shop" enforcement model in which a lead supervisory authority handles cross-border cases, and the European Data Protection Board to coordinate national regulators. Penalties reach €20 million or 4 per cent of a company's global annual turnover, whichever is higher — levels that produced record fines, including a €1.2 billion penalty against Meta in 2023 over transfers of European user data to the United States.[1][5]

International transfers have been the regulation's most contested frontier. The Court of Justice's Schrems II ruling in 2020 invalidated the EU-United States Privacy Shield framework, forcing companies to rely on alternative safeguards, and a new EU-US Data Privacy Framework agreed in 2023 restored a pathway for transatlantic data flows. For multinationals — including the many European firms operating in Malaysia — transfer compliance has become a routine feature of IT architecture.[2]

GDPR and artificial intelligence

AI systems interact with the GDPR at several points. Models trained on personal data require a lawful basis for that processing; the principles of data minimisation and purpose limitation challenge bulk data collection; and Article 22 gives individuals rights over purely automated decisions that significantly affect them. Transparency obligations, records of processing and data protection impact assessments apply to higher-risk uses such as profiling, and data subjects retain rights of access, correction and erasure whose application to trained models remains actively debated.[1][6]

European regulators have translated those rules into enforcement. Italy's data protection authority, the Garante, briefly blocked ChatGPT in 2023 and fined OpenAI €15 million in December 2024 over its handling of personal data — a penalty an Italian court annulled in March 2026 — while the European Data Protection Board issued a 2024 opinion on the lawful use of personal data in developing AI models. The EU AI Act, in force since 2024, does not replace the GDPR: the two regimes apply in parallel, with the GDPR governing the processing of personal data and the AI Act regulating AI systems according to risk.[3][4][6]

>See Also

🇲🇾Malaysian Context

Malaysia's own Personal Data Protection Act 2010 drew on earlier European frameworks, and amendments passed in 2024 and phased into force during 2025 moved the country closer to GDPR-style expectations: mandatory notification of personal data breaches to the Commissioner within 72 hours, the appointment of data protection officers by qualifying organisations, and updated cross-border transfer guidelines. For companies working across both jurisdictions the obligations increasingly overlap — a Kuala Lumpur firm handling personal data for European clients must satisfy GDPR requirements through its contracts, while the same data remains governed at home by the PDPA.[7][8]

The practical stakes are highest for Malaysia's shared-services and outsourcing sector, technology exporters and the electrical-and-electronics supply chain, all of which routinely process European personal data; universities collaborating with EU partners face similar questions. Guidance from legal practitioners converges on the same points: map where data flows, document legal bases, and treat privacy impact assessments as part of AI project design rather than a compliance afterthought. As Malaysia builds out national AI governance through the National AI Office and related frameworks, alignment with international regimes such as the GDPR is regularly cited as a factor in cross-border trust.[7][8]

References

  1. ↑EUR-Lex. Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation). https://eur-lex.europa.eu/eli/reg/2016/679/oj
  2. ↑European Commission. Data protection in the EU. https://commission.europa.eu/law/law-topic/data-protection_en
  3. ↑Reuters. (2024). Italy fines OpenAI 15 million euros over privacy rules breach. https://www.reuters.com/technology/italy-fines-openai-15-million-euros-over-privacy-rules-breach-2024-12-20/
  4. ↑Reuters. (2026). Italian court scraps 15-million-euro privacy watchdog fine on ChatGPT maker OpenAI. https://www.reuters.com/technology/italian-court-scraps-15-million-euro-privacy-watchdog-fine-chatgpt-maker-openai-2026-03-19/
  5. ↑The Guardian. (2023). Facebook owner Meta fined €1.2bn for mishandling user information. https://www.theguardian.com/technology/2023/may/22/facebook-fined-mishandling-user-information-ireland-eu-meta
  6. ↑European Data Protection Board. (2024). Opinion on AI models and GDPR principles. https://www.edpb.europa.eu/news/news/2024/edpb-opinion-ai-models-gdpr-principles-support-responsible-ai_en
  7. ↑DLA Piper. (2025). Malaysia: guidelines issued on data breach notification and data protection officer appointment. https://privacymatters.dlapiper.com/2025/03/malaysia-guidelines-issued-on-data-breach-notification-and-data-protection-officer-appointment/
  8. ↑Mayer Brown. (2025). From legislative reform to practical guidance: key amendments to Malaysia's PDPA and the launch of cross-border transfer guidelines. https://www.mayerbrown.com/en/insights/publications/2025/07/from-legislative-reform-to-practical-guidance-key-amendments-to-malaysias-pdpa-and-the-launch-of-cross-border-transfer-guidelines