What is the GDPR?
The EU data-protection regulation, why it reaches US websites and apps that serve Europeans, and which rights an EU visitor can exercise here.
General information about EU and US law for readers of tool reviews, not legal advice. Questions: editorial@clothoff.ai.
The GDPR is Regulation (EU) 2016/679, the General Data Protection Regulation, applicable since May 25, 2018. It governs processing of personal data about people in the European Union, including by companies outside the EU that offer them services, and grants rights of access, erasure and complaint backed by fines of up to €20 million or 4% of turnover.
Key provisions at a glance
Checked against the linked sources on September 3, 2026; no editor scores here (how we rate).
| Law | Effective date | What it covers | Penalty | Source |
|---|---|---|---|---|
| Art. 3(2) — territorial scope | May 25, 2018 | Non-EU controllers offering goods or services to people in the Union | Up to €20 million or 4% of turnover | EUR-Lex |
| Art. 15 and 17 — access and erasure | May 25, 2018 | Copy of one’s data; deletion without undue delay | Up to €20 million or 4% | EUR-Lex |
| Art. 12(3) — response deadline | May 25, 2018 | Reply within one month, extendable by two months | Up to €20 million or 4% | EUR-Lex |
| Art. 27 and 44 — representative, transfers | May 25, 2018 | EU representative for non-EU controllers; Chapter V transfer safeguards | Up to €10 million or 2%; transfers up to €20 million or 4% | EUR-Lex |
| Art. 77 — complaint | May 25, 2018 | Complaint to a supervisory authority | Orders to limit or ban processing | EUR-Lex |
Who does the GDPR apply to?
Article 3 has two arms. Any organization established in the EU is covered for all of its processing. Any organization outside the EU is covered when it offers goods or services to people in the Union — payment or not — or monitors their behavior online. A US website with analytics cookies and EU visitors, or a US app selling credits to Europeans, meets that test.
Non-EU controllers in scope must name a representative under Article 27 and may transfer data out of the EU only under Chapter V safeguards. The rules protect natural persons only.
What rights does an EU visitor have?
Articles 15 to 22 grant access, rectification, erasure, restriction, portability and objection. Article 12(3) sets the clock: a reply within one month, extendable by two further months for complex requests. Article 77 adds the right to complain to a supervisory authority and Article 82 the right to compensation.
The closest US analogue is the CCPA/CPRA, which grants access, deletion and opt-out rights to California residents. The GDPR requires a lawful basis for every processing operation; the CCPA mostly regulates disclosure and sale.
What does the GDPR mean for undress apps?
A photograph of an identifiable person is personal data, and a generated intimate image of a real person is data too. An app that stores uploads or keeps outputs needs a lawful basis for each step, must honor erasure requests and must explain retention plainly. Data revealing sexual life is a special category under Article 9 and needs explicit consent of the person depicted — consent a third party uploading someone else’s photo cannot give.
Reviews on this site record retention periods and deletion controls for every tool; see data retention compared. The consent rule of the Responsible AI policy — own photos or consenting adults only — is the practical GDPR floor.
How does this site handle EU visitors?
Clothoff AI stores no images and runs no accounts; it processes analytics, cookie preferences and reader messages. EU visitors exercise Articles 15 to 17 through the privacy rights request form or privacy@clothoff.ai; the privacy policy lists categories, retention and the one-month response target. California residents use the same form. This page is general information, not legal advice.
Sources
All sources accessed September 3, 2026.
- Regulation (EU) 2016/679, Articles 3, 9, 12, 15, 17, 27, 44, 77, 83 — EUR-Lex
- Regulation (EU) 2024/1689 (AI Act), Article 50(3) — EUR-Lex
- Regulation (EU) 2022/2065 (Digital Services Act) — EUR-Lex
- California Consumer Privacy Act — California Attorney General
- California Privacy Protection Agency
- Privacy and security guidance — Federal Trade Commission
Corrections: editorial@clothoff.ai · Editorial policy
Frequently asked questions
Does the GDPR apply to a US website with no EU office?
Yes, when the site offers goods or services to people in the EU or monitors their behavior, for example through analytics cookies. Article 3(2) makes payment irrelevant. Such a controller must also appoint an EU representative under Article 27 unless the processing is occasional and low-risk.
How fast must a company answer an access or deletion request?
Article 12(3) requires a reply without undue delay and at the latest within one month of receipt. The period may be extended by two further months for complex or numerous requests, but the person must be told of the extension and the reasons within the first month.
Is a photo personal data under the GDPR?
Yes, when a person can be identified from it. An intimate image of a real person also falls under Article 9 as data concerning sex life, which requires a stricter legal basis such as explicit consent of the person depicted. Uploading another person’s photo without that consent has no lawful basis.
What are the maximum GDPR fines?
Article 83 sets two tiers: up to €10 million or 2% of worldwide annual turnover for duties such as security and representatives, and up to €20 million or 4% for breaches of principles, data-subject rights and international transfers. The higher of the fixed sum and the percentage applies.
How is the GDPR different from the CCPA?
The GDPR requires a lawful basis for every processing activity and applies to all people in the EU. The CCPA/CPRA applies to California residents and larger businesses, focuses on disclosure, deletion and the right to opt out of sale or sharing, and is enforced by the California Privacy Protection Agency.
How can an EU visitor exercise GDPR rights on this site?
Send a request through the privacy rights request form or to privacy@clothoff.ai. The site holds no images or accounts, so most requests concern analytics identifiers and correspondence. Replies follow the one-month standard of Article 12(3), and a complaint may be lodged under Article 77.