Updated: September 3, 2026 · Docs · Law · Clothoff AI Editorial Team

What is the GDPR?

The EU data-protection regulation, why it reaches US websites and apps that serve Europeans, and which rights an EU visitor can exercise here.

General information about EU and US law for readers of tool reviews, not legal advice. Questions: editorial@clothoff.ai.

The GDPR is Regulation (EU) 2016/679, the General Data Protection Regulation, applicable since May 25, 2018. It governs processing of personal data about people in the European Union, including by companies outside the EU that offer them services, and grants rights of access, erasure and complaint backed by fines of up to €20 million or 4% of turnover.

Key provisions at a glance

Checked against the linked sources on September 3, 2026; no editor scores here (how we rate).

LawEffective dateWhat it coversPenaltySource
Art. 3(2) — territorial scopeMay 25, 2018Non-EU controllers offering goods or services to people in the UnionUp to €20 million or 4% of turnoverEUR-Lex
Art. 15 and 17 — access and erasureMay 25, 2018Copy of one’s data; deletion without undue delayUp to €20 million or 4%EUR-Lex
Art. 12(3) — response deadlineMay 25, 2018Reply within one month, extendable by two monthsUp to €20 million or 4%EUR-Lex
Art. 27 and 44 — representative, transfersMay 25, 2018EU representative for non-EU controllers; Chapter V transfer safeguardsUp to €10 million or 2%; transfers up to €20 million or 4%EUR-Lex
Art. 77 — complaintMay 25, 2018Complaint to a supervisory authorityOrders to limit or ban processingEUR-Lex

Who does the GDPR apply to?

Article 3 has two arms. Any organization established in the EU is covered for all of its processing. Any organization outside the EU is covered when it offers goods or services to people in the Union — payment or not — or monitors their behavior online. A US website with analytics cookies and EU visitors, or a US app selling credits to Europeans, meets that test.

Non-EU controllers in scope must name a representative under Article 27 and may transfer data out of the EU only under Chapter V safeguards. The rules protect natural persons only.

What rights does an EU visitor have?

Articles 15 to 22 grant access, rectification, erasure, restriction, portability and objection. Article 12(3) sets the clock: a reply within one month, extendable by two further months for complex requests. Article 77 adds the right to complain to a supervisory authority and Article 82 the right to compensation.

The closest US analogue is the CCPA/CPRA, which grants access, deletion and opt-out rights to California residents. The GDPR requires a lawful basis for every processing operation; the CCPA mostly regulates disclosure and sale.

What does the GDPR mean for undress apps?

A photograph of an identifiable person is personal data, and a generated intimate image of a real person is data too. An app that stores uploads or keeps outputs needs a lawful basis for each step, must honor erasure requests and must explain retention plainly. Data revealing sexual life is a special category under Article 9 and needs explicit consent of the person depicted — consent a third party uploading someone else’s photo cannot give.

Reviews on this site record retention periods and deletion controls for every tool; see data retention compared. The consent rule of the Responsible AI policy — own photos or consenting adults only — is the practical GDPR floor.

How does this site handle EU visitors?

Clothoff AI stores no images and runs no accounts; it processes analytics, cookie preferences and reader messages. EU visitors exercise Articles 15 to 17 through the privacy rights request form or privacy@clothoff.ai; the privacy policy lists categories, retention and the one-month response target. California residents use the same form. This page is general information, not legal advice.

Questions about GDPR

Frequently asked questions

Does the GDPR apply to a US website with no EU office?

Yes, when the site offers goods or services to people in the EU or monitors their behavior, for example through analytics cookies. Article 3(2) makes payment irrelevant. Such a controller must also appoint an EU representative under Article 27 unless the processing is occasional and low-risk.

How fast must a company answer an access or deletion request?

Article 12(3) requires a reply without undue delay and at the latest within one month of receipt. The period may be extended by two further months for complex or numerous requests, but the person must be told of the extension and the reasons within the first month.

Is a photo personal data under the GDPR?

Yes, when a person can be identified from it. An intimate image of a real person also falls under Article 9 as data concerning sex life, which requires a stricter legal basis such as explicit consent of the person depicted. Uploading another person’s photo without that consent has no lawful basis.

What are the maximum GDPR fines?

Article 83 sets two tiers: up to €10 million or 2% of worldwide annual turnover for duties such as security and representatives, and up to €20 million or 4% for breaches of principles, data-subject rights and international transfers. The higher of the fixed sum and the percentage applies.

How is the GDPR different from the CCPA?

The GDPR requires a lawful basis for every processing activity and applies to all people in the EU. The CCPA/CPRA applies to California residents and larger businesses, focuses on disclosure, deletion and the right to opt out of sale or sharing, and is enforced by the California Privacy Protection Agency.

How can an EU visitor exercise GDPR rights on this site?

Send a request through the privacy rights request form or to privacy@clothoff.ai. The site holds no images or accounts, so most requests concern analytics identifiers and correspondence. Replies follow the one-month standard of Article 12(3), and a complaint may be lodged under Article 77.