How GDPR works
The law governs personal data: anything that identifies a living person on its own or in combination with something else. In marketing that net is wider than most people expect, taking in email addresses and phone numbers but also IP addresses, advertising cookie identifiers and the pseudonymous IDs inside your analytics. It applies to you if you offer goods or services to people in the European Union or monitor their behaviour, whatever country your business is registered in. A consultancy in Kathmandu selling to buyers in Germany is inside its scope.
Every use of personal data needs a lawful basis. Two matter most in marketing. Consent has to be a clear affirmative act, freely given, specific, and as easy to withdraw as it was to give — silence, pre-ticked boxes and continued scrolling are none of those things. Legitimate interests is the alternative, and it is not a free pass: you have to weigh your purpose against the person’s rights and write down that you did.
Why GDPR matters
Fines are the headline, but they are rarely what bites first. The everyday consequences are duller and more expensive. Rights requests arrive and have to be answered inside a fixed window, which is painful if you cannot say where a person’s data actually lives. Advertising platforms increasingly demand documented consent signals before they will run their audience features in Europe. And a mailing list built without provable permission has to be rebuilt from scratch, which is a marketing cost, not a legal one.
Where GDPR goes wrong
The biggest error is treating it as a cookie banner. The banner is the visible part; the substance is knowing what personal data you hold, why you hold it, who else touches it and when it gets deleted. A perfect banner on top of an unmapped CRM fixes very little.
Two others come up constantly. Buying a list and mailing it, on the theory that the seller obtained consent — that consent almost never names you, so it does not transfer. And a privacy notice copied from another site, describing analytics and advertising tools the business does not use while omitting the ones it does. I have seen both directions, and an inaccurate notice is worse than a short one because it is actively misleading.
How to act on it
Start with an inventory rather than a banner. List every place personal data enters — forms, chat, phone, checkout, ad platforms — then record why you hold each item, where it is stored, who processes it for you and how long it stays. Most of what follows falls out of that list.
Then make consent real where you rely on it, keep a record of it, set retention periods that someone actually enforces, and rewrite your notice to describe your real stack. If your tags fire before anyone has chosen, that is the first technical job, and a tracking audit will show you exactly what is loading and when.