Regulation (EU) 2016/679, applying from 25 May 2018, is the EU's primary framework for protecting personal data. It replaced the 1995 Data Protection Directive, extended EU data protection rules to the whole world when EU residents are targeted, and introduced fines reaching 4% of global annual turnover.
the EU's primary law protecting the fundamental right to personal data privacy
The General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, is the European Union's framework law governing the collection, storage, use, and transfer of personal data about natural persons. It replaces Directive 95/46/EC of 1995 and applies directly across all 27 Member States without requiring national implementing legislation.
The GDPR has two stated purposes: to protect the fundamental right of natural persons to the protection of their personal data (Article 1(2)), and to ensure that the free movement of personal data within the Union is not restricted or prohibited for data protection reasons (Article 1(3)). These twin goals reflect the GDPR's position at the intersection of fundamental rights and the internal market.
The regulation rests on Article 16 TFEU, which mandates the European Parliament and the Council to lay down rules on the protection of personal data. It is also grounded in Articles 7 and 8 of the EU Charter of Fundamental Rights, which guarantee respect for private life and the right to data protection respectively.
The 1995 Data Protection Directive was adopted before the internet became a mass-market phenomenon. By the 2010s, fragmented national implementations had produced 28 different regulatory frameworks across the EU, creating legal uncertainty for businesses, inconsistent protection for individuals, and a enforcement landscape where data-intensive US tech giants could operate in the EU with little effective accountability.
The Commission's January 2012 proposal set out to fix this fragmentation. Four years of legislative process followed, driven by the European Parliament's insistence on stronger individual rights and stricter enforcement. The GDPR was formally adopted on 27 April 2016, entered into force on 24 May 2016, and applied from 25 May 2018 after a two-year implementation period. Directive 95/46/EC was simultaneously repealed.
The GDPR has 99 articles across 11 chapters, preceded by 173 recitals that explain the legislative intent and provide interpretive guidance:
material scope (Article 2) and territorial scope (Article 3): global reach for EU data subjects
The GDPR applies to the processing of personal data wholly or partly by automated means, and to non-automated processing where the data form part of, or are intended to form part of, a filing system. This captures virtually all digital data processing, as well as structured manual records.
It does not apply to: activities outside Union law (e.g. national security); Member State CFSP activities; purely personal or household activities by natural persons; and processing by competent authorities for criminal law purposes, which falls under Directive (EU) 2016/680 instead.
A company based in California, Canada, India or Brazil that sells products or services to EU consumers, or that tracks EU users' behaviour online, is subject to the full GDPR. It must designate an EU representative (Art 27), comply with all data subject rights, and is exposed to EU supervisory authority enforcement and fines. This is why the GDPR has become a de facto global standard: multinationals find it simpler to apply GDPR rules globally than to maintain separate compliance tracks.
Article 5: the foundational requirements that govern all personal data processing
Article 5 sets out seven principles that apply to all processing of personal data. Violation of these principles attracts the highest fine tier (up to EUR 20 million or 4% of global turnover). The seventh principle, accountability, requires controllers not just to comply but to be able to prove they comply.
| Principle | What it means in practice | Key Article |
|---|---|---|
| Lawfulness, fairness and transparency | There must be a legal basis for processing (one of the six in Art 6). Processing must not be deceptive. Data subjects must be informed. | Arts 5(1)(a), 6, 13-14 |
| Purpose limitation | Data may only be collected for specified, explicit and legitimate purposes. Further processing must be compatible with those purposes. Research, archiving and statistics can be compatible by virtue of Art 89. | Art 5(1)(b) |
| Data minimisation | Only the data that is adequate, relevant and limited to what is necessary for the purposes may be processed. More data than needed may not be collected on a precautionary basis. | Art 5(1)(c) |
| Accuracy | Data must be accurate and, where necessary, kept up to date. Inaccurate data must be erased or rectified without delay, taking into account the purposes for which it is processed. | Art 5(1)(d) |
| Storage limitation | Data must be kept in a form permitting identification for no longer than necessary. Controllers must set and document retention periods. Archiving, research and statistics are exceptions subject to Art 89 safeguards. | Art 5(1)(e) |
| Integrity and confidentiality | Appropriate technical and organisational security measures must protect data against unauthorised or unlawful processing, and against accidental loss, destruction or damage. | Arts 5(1)(f), 32 |
| Accountability | The controller is responsible for and must be able to demonstrate compliance with all the principles above. Passive compliance is not enough: evidence must exist. This principle underpins the entire GDPR documentation architecture (records, DPIAs, policies, training logs). | Art 5(2), Art 24 |
Article 6: one of these six must apply before any personal data is processed
A common misconception is that consent is always required to process personal data. In fact, there are six alternative legal bases. A controller must identify the correct basis in advance and cannot switch between them after the fact. For special categories of personal data (health, genetic, biometric, racial/ethnic, political, religious, trade union, sex-life data), the additional conditions of Article 9 must also be met.
The data subject has given freely given, specific, informed and unambiguous consent. It must be as easy to withdraw as to give. Pre-ticked boxes, silence and inactivity do not constitute consent. Children under 16 (or a lower age down to 13 set by Member State law) require parental consent for online services.
Arts 6(1)(a), 7, 8
Processing is necessary for the performance of a contract with the data subject or for pre-contractual steps at the data subject's request. For example, a delivery company processing a customer's address to fulfil an order.
Art 6(1)(b)
Processing is necessary for compliance with a legal obligation to which the controller is subject. For example, an employer processing payroll data to comply with tax law, or a bank retaining transaction records under anti-money laundering rules.
Art 6(1)(c)
Processing is necessary to protect the vital interests of the data subject or another person, such as in emergency medical situations. This basis applies only where the data subject is physically or legally incapable of giving consent and no other legal basis is available.
Art 6(1)(d)
Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. This is the primary legal basis for processing by government bodies, regulators, courts and public services.
Art 6(1)(e)
Processing is necessary for the legitimate interests of the controller or a third party, provided those interests are not overridden by the data subject's interests, rights and freedoms. Not available to public authorities acting in their public tasks. Requires a three-part balancing test: purpose test, necessity test, balancing test.
Art 6(1)(f)
For personal data that is particularly sensitive by nature, such as health data, genetic data, biometric data used for unique identification, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or data about sex life or sexual orientation, there is a general prohibition on processing. To lift that prohibition, not only must a legal basis in Article 6 apply, but one of the ten specific conditions listed in Article 9(2) must also be met. The most common in practice are explicit consent (Art 9(2)(a)), employment and social security law (Art 9(2)(b)), vital interests where the subject cannot consent (Art 9(2)(c)), and preventive medicine or occupational health (Art 9(2)(h)).
Chapter III, Articles 12-23: eight enforceable rights you can exercise against any data controller
Controllers must respond to any data subject rights request within one month of receipt, free of charge. The period may be extended by two further months where requests are complex or numerous, but the controller must inform you of the extension within the first month. Where requests are manifestly unfounded or excessive, the controller may charge a reasonable fee or refuse to act, but must bear the burden of demonstrating that character. The controller must also provide a copy of personal data undergoing processing in response to an access request.
| Right | Article | What you can ask | Key limitations |
|---|---|---|---|
| Right of access | Art 15 | Confirmation that data is processed; a copy of the data; information on purposes, recipients, retention, automated decisions, source (if indirect). | Rights of others (trade secrets, third-party data) may limit the copy provided. |
| Right to rectification | Art 16 | Correction of inaccurate data; completion of incomplete data (including by supplementary statement). | The controller must notify recipients of any rectification (Art 19). |
| Right to erasure | Art 17 | Erasure where: data no longer necessary; consent withdrawn and no other legal ground; data unlawfully processed; legal obligation requires erasure; data collected via online services from children. | Does not apply where processing is necessary for: freedom of expression; legal obligation; public health; archiving/research/statistics; legal claims. |
| Right to restriction | Art 18 | Halt all processing (except storage) while: accuracy is contested; processing is unlawful but you prefer restriction to erasure; data is needed for your legal claims but not the controller's; you have objected and the controller is verifying its grounds. | The controller must inform you before lifting a restriction. |
| Right to data portability | Art 20 | Receive data you provided in a structured, commonly used, machine-readable format. Request direct controller-to-controller transfer where technically feasible. | Applies only where processing is based on consent or contract and is carried out by automated means. Does not apply to public-task or legal-obligation based processing. |
| Right to object | Art 21 | Object at any time to processing based on public task (Art 6(1)(e)) or legitimate interests (Art 6(1)(f)), including profiling. Absolute right to object to processing for direct marketing (no override possible). | For non-marketing objections, the controller may continue if it can demonstrate compelling legitimate grounds overriding your interests. |
| Automated decision-making | Art 22 | Not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects or similarly significantly affects you. Right to human review, to express your view, and to contest the decision. | Exceptions: necessary for contract with you; authorised by law; based on explicit consent. Special-category data requires an additional Art 9(2)(a) or (g) condition. |
You can exercise any of the above rights by contacting the data controller directly. The controller must facilitate your requests and cannot require you to use a specific format, though it may request additional information to verify your identity (Art 12(6)). Where the controller does not act on your request, you can lodge a complaint with your national Data Protection Authority or seek a judicial remedy before the courts of the Member State where the controller is established or where you reside (Art 79).
Chapter IV, Articles 24-43: the compliance architecture for controllers and processors
Data protection must be embedded into systems and processes from the outset, not added as an afterthought. This means using pseudonymisation and data minimisation techniques at the design stage, and ensuring that by default only the minimum data necessary is processed. The principle applies to any new technology, service or product that involves personal data.
Controllers must maintain a written record of all processing activities, covering: the controller's name and contact details; the DPO's contact details; purposes; categories of data subjects and data; recipients; international transfers; retention periods; and a description of security measures. Processors must keep analogous records. Organisations with fewer than 250 employees are exempt unless the processing is not occasional, is likely to create a risk, or involves special categories.
Controllers and processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The GDPR lists examples (encryption, pseudonymisation, resilience, backup and recovery, regular testing) but does not mandate any specific technology. The standard is risk-based: a healthcare organisation processing thousands of patient records is held to a higher standard than a small business processing only employee email addresses.
When a personal data breach occurs (accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data), the controller must notify the competent supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. Where the breach is likely to cause a high risk, the affected data subjects must also be notified without undue delay. Processors must notify the controller without undue delay upon becoming aware of a breach.
A DPIA is mandatory before processing that is likely to result in a high risk to individuals' rights and freedoms. The GDPR specifically requires a DPIA for: systematic and extensive profiling with significant effects; large-scale processing of special category or criminal conviction data; and systematic large-scale monitoring of publicly accessible areas (e.g. CCTV). Where the DPIA shows residual high risk that cannot be mitigated, the controller must consult the national supervisory authority before starting (Art 36).
A DPO must be designated by: all public authorities (except courts in their judicial capacity); organisations whose core activities require large-scale regular and systematic monitoring of data subjects; and those whose core activities involve large-scale processing of special categories or criminal conviction data. The DPO must be independent, cannot be dismissed for performing their role, must report to the highest management level, and must have expert knowledge of data protection law and practice. A group of companies may appoint a single DPO provided they are accessible from each establishment.
Every engagement of a processor must be governed by a written contract that binds the processor and sets out: the subject matter and duration of processing; the nature and purpose of the processing; the type of personal data and categories of data subjects; the controller's instructions (the processor must only process data on documented instructions from the controller); security obligations; sub-processor rules; and obligations on deletion or return of data at the end of the contract. If a processor itself engages a sub-processor, the same contractual obligations must flow down.
Chapter V, Articles 44-50: exporting personal data outside the EU/EEA requires a valid transfer mechanism
The general principle in Article 44 is that transfers of personal data to third countries or international organisations are only permitted if the conditions of Chapter V are met. The aim is to ensure that the level of protection for individuals guaranteed by the GDPR is not undermined by an export to a less protective jurisdiction.
The CJEU's Schrems II judgment of 16 July 2020 (Case C-311/18, Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems) invalidated the EU-US Privacy Shield adequacy decision. The Court held that US surveillance law (in particular Section 702 FISA and Executive Order 12333) gave US intelligence agencies access to EU personal data in ways that did not meet EU standards. As a result, controllers relying on SCCs must carry out a case-by-case Transfer Impact Assessment to determine whether the destination country's legal framework undermines the contractual protections. The EU-US Data Privacy Framework (adopted by adequacy decision on 10 July 2023) provides a new adequacy basis for certified US organisations, but further legal challenges are anticipated.
Chapter VI-VIII, Articles 51-84: supervisory authorities, the EDPB, and two-tier administrative fines
Each Member State must establish at least one independent national supervisory authority (Article 51). DPAs must act with complete independence and have three categories of powers under Article 58: investigative powers (access to premises, data and information); corrective powers (warnings, reprimands, orders, bans on processing, and fines); and advisory and authorisation powers (opinions, codes, BCRs, certifications).
The one-stop-shop mechanism (Articles 56, 60) means that for cross-border processing, the DPA of the Member State where the controller has its main establishment acts as the lead supervisory authority. For example, a company headquartered in Ireland deals primarily with the Irish Data Protection Commission (DPC) for cross-border processing activities.
The EDPB is an independent EU body established by the GDPR, composed of the heads of all 27 national DPAs and the European Data Protection Supervisor. It ensures the consistent application of the GDPR across the EU by issuing guidelines, opinions and binding decisions on cross-border cases where DPAs disagree. The EDPB has published extensive guidelines on topics including consent, data portability, international transfers, data breaches, DPIAs, the right of access, and many sector-specific questions. EDPB guidelines do not have the force of law but are followed closely by DPAs and courts.
The GDPR's fine regime operates in two tiers. Both tiers use the same "whichever is higher" formula between the fixed maximum and the percentage-of-turnover maximum, ensuring that fines are meaningful even for the largest global companies.
When deciding whether to impose a fine and the amount, DPAs must take into account: the nature, gravity and duration of the infringement; whether it was intentional or negligent; actions taken to mitigate damage; the degree of responsibility; previous infringements; cooperation with the DPA; the categories of data affected; and whether the DPA was notified voluntarily.
| Organisation | DPA | Year | Fine | Reason |
|---|---|---|---|---|
| Meta (Facebook) | Ireland DPC | 2023 | EUR 1.2 billion | Transfers of EU personal data to the US without adequate safeguards |
| Amazon | Luxembourg CNPD | 2021 | EUR 746 million | Advertising personal data processing without adequate legal basis |
| Meta (WhatsApp) | Ireland DPC | 2021 | EUR 225 million | Transparency and privacy information failures |
| France CNIL | 2019 | EUR 50 million | Lack of transparency, inadequate information and absence of valid consent for personalised ads | |
| Clearview AI | Italy Garante | 2022 | EUR 20 million | Unlawful processing of biometric data (facial images scraped from the internet) |
Any person who has suffered material or non-material damage as a result of a GDPR infringement has the right to receive compensation from the controller or processor. Both material damage (financial loss, identity theft costs) and non-material damage (distress, anxiety) are covered. Controllers and processors are jointly and severally liable, with rights of recourse between them. This creates a powerful private enforcement mechanism alongside public enforcement by DPAs.
from the 1995 directive to the GDPR and beyond
common questions on GDPR scope, consent, fines and the rights framework
Yes, if you offer goods or services to people in the EU (whether free or paid) or if you monitor the behaviour of people in the EU (for example, through website analytics, cookies or behavioural advertising targeting EU users), the GDPR applies to you under Article 3(2). You must also appoint a written EU representative (Article 27), unless your processing is occasional, does not involve large-scale special-category data, and is unlikely to result in a risk to individuals' rights.
No. Consent is one of six legal bases in Article 6. In many situations, another legal basis is more appropriate: processing for contract performance (Art 6(1)(b)), compliance with a legal obligation (Art 6(1)(c)), or legitimate interests (Art 6(1)(f)) may provide a more stable and appropriate foundation. Choosing consent when another legal basis applies creates problems: if the individual withdraws consent, you must stop processing even if you have a legitimate business need. Controllers should identify the correct legal basis before starting to process data.
Under Article 4(12), a personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. This covers not only cyberattacks and hacking but also accidentally sending an email containing personal data to the wrong recipient, losing an unencrypted USB drive, or a misconfigured database becoming publicly accessible. Not every breach requires notification to the supervisory authority: notification is only required if the breach is likely to result in a risk to the rights and freedoms of natural persons (Art 33(1)).
No. A DPO is mandatory only for: (a) public authorities and bodies (except courts acting in their judicial capacity); (b) organisations whose core activities require regular and systematic monitoring of data subjects on a large scale; and (c) organisations whose core activities involve large-scale processing of special categories or criminal conviction data (Art 37(1)). An individual doctor, lawyer or small business is not required to appoint a DPO. However, any organisation may voluntarily designate a DPO (Art 37(4)), and the EDPB encourages this as good practice.
DPAs must assess fines on a case-by-case basis, taking into account the factors listed in Article 83(2): the nature, gravity and duration of the infringement; whether it was intentional or negligent; the number of data subjects affected; the level of damage; previous infringements; cooperation with the authority; the categories of data affected; and how the infringement became known. The two-tier maximum (EUR 10 million / 2% or EUR 20 million / 4%) acts as a ceiling, not a standard or expected amount. For large multinationals, the 4% of global turnover calculation is the binding limit, as it will exceed EUR 20 million.
A controller (Art 4(7)) is the natural or legal person, public authority, agency or body that determines the purposes and means of the processing of personal data. A processor (Art 4(8)) is the entity that processes personal data on behalf of the controller, following the controller's documented instructions. The same entity can be a controller for some processing and a processor for other processing. Controllers bear the primary compliance obligations under the GDPR. Processors have directly applicable obligations too (security, breach notification to the controller, sub-processor authorisation, records), and they are directly liable if they exceed the controller's instructions or act unlawfully.
key definitions from Article 4 and the GDPR framework
primary legislative and regulatory references for the GDPR
The official consolidated text of Regulation (EU) 2016/679 is available on EUR-Lex in all EU official languages.
Open on EUR-LexThe EDPB publishes binding decisions, guidelines, recommendations and consistency opinions on GDPR interpretation. Essential reading for compliance professionals.
EDPB documentsEach EU Member State has its own data protection supervisory authority. The EDPB maintains a full directory. Your national DPA is the primary contact for complaints and guidance in your jurisdiction.
DPA directoryThe original Official Journal publication of the GDPR. Pages 1-88 contain the Regulation; pages 88-102 contain the Law Enforcement Directive (2016/680) in the same issue.
OJ L 119AI-powered tools to go deeper on GDPR compliance, amendments and policy analysis
Brubru gives EU policy professionals AI-powered tools to navigate the full EU legal corpus: chat, compliance checks, amendment drafting and legislative monitoring across all 27 Member States.