European Law for .NET Developers: What the GDPR Means for Your Code
Hey lovely readers, The GDPR has been around since 2018, and most of us have heard of it. But when I ask developers what it actually means for the code they write, they often don't know. Usually someone mentions an annoying cookie banner and that's it. So I'm starting a small series. I'm taking three European laws that affect developers and making them as simple as I can. This first post is about…
General Data Protection Regulation (GDPR) has been in place since 2018, but many developers are unsure about what it entails for the code they write. This article aims to simplify three European laws affecting developers: GDPR, the European Accessibility Act (EAA), and the AI Act. The primary focus will be on GDPR, followed by EAA and AI Act in subsequent posts.
GDPR protects the personal data of individuals in the European Union (EU) and dictates how it can be collected, stored, and used. Personal data includes anything that can be linked to a real person, such as names, email addresses, phone numbers, home addresses, dates of birth, IP addresses, user IDs, location data, health data, sexual orientation, ethnic origin, religious or philosophical beliefs, political opinions, union membership, genetic data, and biometric data.
However, not all personal data carries the same level of risk. Some categories, known as special categories, are more sensitive and carry greater risks if leaked. These include health data, sexual orientation and sex life, ethnic origin, religious or philosophical beliefs, political opinions, union membership, genetic data, and biometric data used to identify someone, such as fingerprints. For these sensitive categories, stricter processing rules apply.
Processing special categories of data requires specific exceptions, such as explicit user consent. If a large amount of such data is processed, a data protection impact assessment (DPIA) may be necessary. Violations can result in hefty fines, up to 20 million euros or 4% of a company's global yearly revenue, whichever is higher. Nevertheless, the primary concern is maintaining user trust.
The GDPR applies to any application handling EU personal data, regardless of the developer's location. This includes webshops, contact forms, newsletter sign-ups, and even applications with internal logs containing IP addresses. Even small projects are subject to GDPR, with no minimum user count or revenue threshold.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.