Regulation (EU) 2016/679 has applied since 25 May 2018. Its reach is set by Article 3 rather than by where a company is registered: it covers processing in the context of an EU establishment, and processing by organisations outside the EU where they offer goods or services to people in the Union or monitor their behaviour. A company with no European entity can therefore be fully in scope.
Every processing operation must satisfy two separate tests. It must respect the principles in Article 5 — lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality — and it must rest on one of the six legal bases in Article 6. Choosing a basis is not a formality: consent can be withdrawn, legitimate interests require a documented balancing test, and the basis determines which rights the individual can exercise.
Obligations follow the role. A controller decides why and how data is processed; a processor acts on documented instructions under Article 28; joint controllers under Article 26 must agree and publish how responsibilities are divided. Getting the role wrong is structural, not clerical: the wrong party ends up carrying — or failing to carry — the Article 5(2) accountability duty.
Enforcement runs through national supervisory authorities, in Poland the President of the Personal Data Protection Office, coordinated through the one-stop-shop mechanism and the European Data Protection Board. Article 83(2) sets eleven criteria that determine any fine, including the gravity and duration of the infringement, whether it was intentional, and how far the organisation cooperated. That is why documented decisions matter even when something has gone wrong.