Guides / Concepts explained

What Is GDPR? A Plain-English Guide for App Builders

GDPR is the EU's main data protection law. What counts as personal data, who it applies to, users' rights, and what to ask your AI builder. Not legal advice.

Mythex Team · 2026-09-29 · 7 min read

The GDPR (General Data Protection Regulation) is the European Union's main data protection law. It sets rules for how organisations collect, use, store and share personal data — any information about an identifiable living person — and gives people rights over their own data, such as seeing it or having it deleted. It has applied since 25 May 2018, and it can apply to businesses outside the EU if they serve people in it.

Not legal advice. This guide is a general explanation to help you understand the basics and ask better questions. It isn't a substitute for advice about your situation. For authoritative detail, see the European Commission's data protection pages and the European Data Protection Board's guide for small businesses.

Why it matters when you build with AI

AI builders make it easy to collect data. One prompt gives you a sign-up form, a contact form, analytics, file uploads and an admin dashboard listing every user. Each of those collects personal data, and the GDPR cares about all of it.

The good news is that most of what the GDPR asks for is also good product practice:

  • Collect only what you actually need.
  • Tell people what you do with it.
  • Keep it secure.
  • Delete it when you no longer need it.
  • Let people see, correct or remove their data.

These are much easier to design in from the start than to bolt on after launch. Asking your AI builder the right questions early saves a painful rebuild later.

An everyday analogy

Think of personal data as belongings people leave with you — like a coat check, but for information. The GDPR is the house rules for the coat check:

  • Only take what the person agreed to leave, for a reason they understand.
  • Don't rummage through the pockets for other uses.
  • Keep the room locked.
  • Give things back, or throw them away, when asked or when you no longer need them.
  • If something is stolen, tell the right people promptly.

You're responsible for the coats while they're in your care, even if you hired someone else to run the room.

The core ideas

What counts as personal data

The European Commission defines personal data as any information that relates to an identified or identifiable living individual. That's broad. It includes names, email addresses, home addresses, IP addresses, cookie IDs and photos. Data that has been "pseudonymised" — say, names replaced with codes — can still be personal data if it can be linked back to someone.

Some categories get extra protection, including health data, biometric data, racial or ethnic origin, and political opinions.

Who it applies to

According to the Commission, the GDPR applies to organisations established in the EU, and to organisations outside the EU that offer goods or services to people in the EU (paid or free) or monitor their behaviour. A US or UAE startup with European customers may well be covered. The UK has its own version, the UK GDPR, which is closely based on it.

The principles

The GDPR is built on a short list of principles. In plain terms:

PrincipleWhat it means for your app
Lawfulness, fairness, transparencyHave a valid reason for processing, and tell people clearly what you do.
Purpose limitationUse data for the reasons you collected it, not surprise new ones.
Data minimisationDon't collect fields you don't need.
AccuracyKeep data correct and let people fix it.
Storage limitationDon't keep data forever; delete it when it's no longer needed.
Integrity and confidentialityKeep it secure against leaks and unauthorised access.
AccountabilityBe able to show how you comply.

Lawful bases

You need a legal reason — a "lawful basis" — for each way you use personal data. The GDPR lists six: consent, performance of a contract, legal obligation, vital interests, public task, and legitimate interests. Consent is only one of them. Processing an order to deliver it, for example, is usually about the contract, not consent. Which basis fits is a judgement to check against official guidance.

People's rights

The Commission lists these rights for individuals:

  • To be informed about how their data is used
  • To access their data
  • To have it corrected
  • To have it erased
  • To restrict processing
  • To data portability (get it in a usable format)
  • To object
  • Rights related to automated decision-making and profiling

Data breaches

If personal data leaks and the breach is likely to put people's rights and freedoms at risk, the organisation generally has to notify its data protection authority without undue delay and, where feasible, within 72 hours of becoming aware of it. In some cases, the affected people must be told too.

A worked example: a yoga studio booking app

Say you're building a booking app for a yoga studio with customers in Germany. Here's how the GDPR shapes it.

Collect less. The sign-up form asks for name, email and an optional phone number. The first draft also asked for date of birth and home address — nothing in the app uses them, so they're removed.

Health data needs care. The studio wants to ask about injuries. That's health data, a special category with stricter rules. The studio decides to handle it in person instead, so the app doesn't collect it.

Be transparent. A privacy policy explains what's collected, why, how long it's kept, who else processes it (the hosting provider, the email service, the payment provider) and how to contact the studio.

Marketing is separate. Booking a class doesn't sign anyone up for the newsletter. There's a separate, unticked checkbox for that.

Rights in the product. Customers can view and edit their profile, download their booking history, and request deletion from their account page.

Retention. Inactive accounts are flagged after a set period and removed if the customer doesn't respond. The studio chooses the period.

Cookies. The login cookie is necessary. Analytics only loads after the visitor accepts it. See what cookies are.

Security. Passwords are hashed, the admin area requires two-factor authentication, and only the owner can export customer lists.

Common terms explained

TermWhat it means
Personal dataAny information about an identified or identifiable living person.
ProcessingAnything done with personal data: collecting, storing, using, sharing, deleting.
Data subjectThe person the data is about.
ControllerThe organisation that decides why and how data is processed — usually you, the app owner.
ProcessorA company that processes data on the controller's behalf, such as a hosting or email provider.
Data Processing Agreement (DPA)A contract between controller and processor setting out how data is handled.
Lawful basisThe legal reason for processing, such as consent or contract.
ConsentA freely given, specific, informed and clear "yes"; pre-ticked boxes don't count.
Special category dataSensitive data like health or biometrics, with stricter rules.
Supervisory authorityA country's data protection regulator.

Common mistakes and misconceptions

  • "We're not in the EU, so it doesn't apply." It can apply based on where your users are.
  • "GDPR means consent for everything." Consent is one of six lawful bases, and often not the right one.
  • "A cookie banner makes us compliant." Cookies are one small part. Data collection, security, rights and retention matter more.
  • "Our host is GDPR-compliant, so we are." Providers help, but you decide what your app collects and does.
  • Collecting "just in case". Every extra field is more to protect, explain and delete.
  • Copying another site's privacy policy. It has to describe what your app actually does.
  • Making deletion impossible. If nobody can delete a user without a developer, rights requests become emergencies.

What to ask your AI builder for

  • "List every piece of personal data this app collects, where it's stored, and why it's needed."
  • "Remove any form fields we don't use."
  • "Add an account page where users can view, edit and download their data, and request deletion."
  • "Build an admin action that fully deletes a user and their related records, or anonymises records we must keep."
  • "Keep marketing sign-up as a separate, unticked checkbox."
  • "Don't load analytics or marketing scripts before consent."
  • "List every third-party service that receives user data, so I can add them to the privacy policy."
  • "Restrict admin exports to the owner role and log who exported what."

Then read how to write terms of service and a privacy policy and how to add cookie consent.

GDPR and Mythex

Mythex gives you the building blocks, not a compliance certificate. Your app's data lives in its own project database and file storage when you enable them, you own the code, and on Pro you can export the project if you need to move it. What your app collects, how long it keeps it, and how people exercise their rights are decisions you make — and ask the agent to build. The docs page on data ownership explains what Mythex hosts, and security for apps you build warns against claiming compliance you don't have. If you need specifics such as where data is hosted or a data processing agreement, ask Mythex support before you launch.

Questions

What is GDPR in simple terms?

The General Data Protection Regulation (GDPR) is the European Union's main data protection law. It sets rules for how organisations collect, use, store and share information about people, and gives those people rights over their data. It has applied since 25 May 2018.

Does GDPR apply to businesses outside the EU?

It can. According to the European Commission, it applies to organisations outside the EU that offer goods or services to people in the EU, even for free, or that monitor their behaviour. Where you are based is not the only question; who your users are matters too.

Is an email address personal data?

Yes. Personal data is any information that relates to an identified or identifiable living person. Names, email addresses, IP addresses and cookie IDs can all count.

Does using a GDPR-compliant host make my app compliant?

No. A host can support compliance, but you decide what data your app collects, why, how long it is kept and who sees it. Those choices are yours to get right.

Is this guide legal advice?

No. It is a general explanation to help you ask better questions. For your specific situation, check the official guidance from the EU or your national data protection authority, or speak to a qualified adviser.

Keep reading

  • Frontend vs Backend: What's the Difference? — The frontend is what users see in the browser; the backend runs on a server and handles data, logic and security. How the two fit together, with an example.
  • How Domains and DNS Work: A Guide for Non-Developers — How domain names and DNS connect example.com to your app: registrars, nameservers, A, CNAME, MX and TXT records, propagation, and connecting a custom domain.
  • How to Add Cookie Consent to Your Website — Add a cookie banner that actually blocks scripts until people agree: what needs consent, CMP vs custom, Google consent mode and a checklist. Not legal advice.
  • How to Use LLM APIs: Tokens, Costs, Keys and Your First AI Feature — What an LLM API is, how tokens, context windows and per-token pricing work, how to keep your API key safe, and how to add a first AI feature to your app.
  • How to Write Terms of Service and a Privacy Policy for Your App — What terms of service and a privacy policy for your app usually contain, why each section matters, how to prepare a draft, and when to involve a lawyer.
  • Native Apps vs Progressive Web Apps: Which Do You Need? — Native apps vs progressive web apps (PWAs): what each can do, iPhone limits as of September 2026, costs, and how to choose for your first version.

Start building free · Templates · Docs