Brubru
EU policy intelligence
Try Brubru free
EU Canon / EU Data Protection Law

The General Data Protection Regulation

Regulation (EU) 2016/679, applying from 25 May 2018, is the EU's primary framework for protecting personal data. It replaced the 1995 Data Protection Directive, extended EU data protection rules to the whole world when EU residents are targeted, and introduced fines reaching 4% of global annual turnover.

Adopted 27 April 2016 OJ L 119, 4.5.2016, pp. 1-88 CELEX 32016R0679 Art 16 TFEU
Digital security lock and shield on a blue circuit board background representing data protection
Photo: Pixabay via Pexels | Data protection is a fundamental right under Article 8 of the EU Charter of Fundamental Rights
4%
Maximum fine (Tier 2)
Art 83(5): up to EUR 20 million or 4% of total worldwide annual turnover (whichever is higher) for infringements of the basic principles, data subject rights, and international transfer rules.
72 hours
Breach notification deadline
Art 33: a controller that becomes aware of a personal data breach must notify the competent supervisory authority within 72 hours, unless the breach is unlikely to risk individuals' rights and freedoms.
6
Legal bases for processing
Art 6: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Processing is unlawful unless at least one applies. Consent is not the only or even the most commonly used basis.
1 month
Rights request deadline
Art 12(3): controllers must respond to data subject rights requests (access, erasure, portability, etc.) within one month, extendable by a further two months for complex or numerous requests.

Overview

the EU's primary law protecting the fundamental right to personal data privacy

What the GDPR is

The General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, is the European Union's framework law governing the collection, storage, use, and transfer of personal data about natural persons. It replaces Directive 95/46/EC of 1995 and applies directly across all 27 Member States without requiring national implementing legislation.

The GDPR has two stated purposes: to protect the fundamental right of natural persons to the protection of their personal data (Article 1(2)), and to ensure that the free movement of personal data within the Union is not restricted or prohibited for data protection reasons (Article 1(3)). These twin goals reflect the GDPR's position at the intersection of fundamental rights and the internal market.

The regulation rests on Article 16 TFEU, which mandates the European Parliament and the Council to lay down rules on the protection of personal data. It is also grounded in Articles 7 and 8 of the EU Charter of Fundamental Rights, which guarantee respect for private life and the right to data protection respectively.

Why it was needed

The 1995 Data Protection Directive was adopted before the internet became a mass-market phenomenon. By the 2010s, fragmented national implementations had produced 28 different regulatory frameworks across the EU, creating legal uncertainty for businesses, inconsistent protection for individuals, and a enforcement landscape where data-intensive US tech giants could operate in the EU with little effective accountability.

The Commission's January 2012 proposal set out to fix this fragmentation. Four years of legislative process followed, driven by the European Parliament's insistence on stronger individual rights and stricter enforcement. The GDPR was formally adopted on 27 April 2016, entered into force on 24 May 2016, and applied from 25 May 2018 after a two-year implementation period. Directive 95/46/EC was simultaneously repealed.

Structure at a glance

The GDPR has 99 articles across 11 chapters, preceded by 173 recitals that explain the legislative intent and provide interpretive guidance:

  • Chapter I (Arts 1-4): Subject matter, scope and definitions
  • Chapter II (Arts 5-11): Principles and legal bases for processing
  • Chapter III (Arts 12-23): Rights of the data subject
  • Chapter IV (Arts 24-43): Controller and processor obligations
  • Chapter V (Arts 44-50): International data transfers
  • Chapter VI (Arts 51-59): Independent supervisory authorities
  • Chapter VII (Arts 60-76): Cooperation, consistency and the EDPB
  • Chapter VIII (Arts 77-84): Remedies, liability and penalties
  • Chapter IX (Arts 85-91): Specific processing situations (employment, research, freedom of expression, etc.)
  • Chapters X-XI (Arts 92-99): Delegated acts and final provisions

Who it applies to

material scope (Article 2) and territorial scope (Article 3): global reach for EU data subjects

Material scope (Article 2)

The GDPR applies to the processing of personal data wholly or partly by automated means, and to non-automated processing where the data form part of, or are intended to form part of, a filing system. This captures virtually all digital data processing, as well as structured manual records.

It does not apply to: activities outside Union law (e.g. national security); Member State CFSP activities; purely personal or household activities by natural persons; and processing by competent authorities for criminal law purposes, which falls under Directive (EU) 2016/680 instead.

1
EU establishment test (Art 3(1))
Any controller or processor that has an establishment in the EU is subject to the GDPR for all processing carried out in the context of that establishment, regardless of whether the actual processing takes place in the EU or elsewhere.
2
Targeting test (Art 3(2)(a))
A non-EU controller or processor is subject to the GDPR if it offers goods or services to data subjects in the EU, whether or not payment is required. Indicators include EU-language websites, EU-currency pricing, or mentioning EU customers.
3
Monitoring test (Art 3(2)(b))
A non-EU controller is subject to the GDPR if it monitors the behaviour of data subjects in the EU, for example through website cookies, tracking pixels, behavioural advertising or analytics that profile EU-based users.
4
Public international law (Art 3(3))
The GDPR also applies to processing by a controller not established in the EU but in a place where a Member State's law applies by virtue of public international law, such as an EU diplomatic mission abroad.

Practical implication of the extraterritorial reach

A company based in California, Canada, India or Brazil that sells products or services to EU consumers, or that tracks EU users' behaviour online, is subject to the full GDPR. It must designate an EU representative (Art 27), comply with all data subject rights, and is exposed to EU supervisory authority enforcement and fines. This is why the GDPR has become a de facto global standard: multinationals find it simpler to apply GDPR rules globally than to maintain separate compliance tracks.


The seven principles

Article 5: the foundational requirements that govern all personal data processing

Article 5 sets out seven principles that apply to all processing of personal data. Violation of these principles attracts the highest fine tier (up to EUR 20 million or 4% of global turnover). The seventh principle, accountability, requires controllers not just to comply but to be able to prove they comply.

Principle What it means in practice Key Article
Lawfulness, fairness and transparency There must be a legal basis for processing (one of the six in Art 6). Processing must not be deceptive. Data subjects must be informed. Arts 5(1)(a), 6, 13-14
Purpose limitation Data may only be collected for specified, explicit and legitimate purposes. Further processing must be compatible with those purposes. Research, archiving and statistics can be compatible by virtue of Art 89. Art 5(1)(b)
Data minimisation Only the data that is adequate, relevant and limited to what is necessary for the purposes may be processed. More data than needed may not be collected on a precautionary basis. Art 5(1)(c)
Accuracy Data must be accurate and, where necessary, kept up to date. Inaccurate data must be erased or rectified without delay, taking into account the purposes for which it is processed. Art 5(1)(d)
Storage limitation Data must be kept in a form permitting identification for no longer than necessary. Controllers must set and document retention periods. Archiving, research and statistics are exceptions subject to Art 89 safeguards. Art 5(1)(e)
Integrity and confidentiality Appropriate technical and organisational security measures must protect data against unauthorised or unlawful processing, and against accidental loss, destruction or damage. Arts 5(1)(f), 32
Accountability The controller is responsible for and must be able to demonstrate compliance with all the principles above. Passive compliance is not enough: evidence must exist. This principle underpins the entire GDPR documentation architecture (records, DPIAs, policies, training logs). Art 5(2), Art 24


Your rights as a data subject

Chapter III, Articles 12-23: eight enforceable rights you can exercise against any data controller

The one-month rule (Article 12)

Controllers must respond to any data subject rights request within one month of receipt, free of charge. The period may be extended by two further months where requests are complex or numerous, but the controller must inform you of the extension within the first month. Where requests are manifestly unfounded or excessive, the controller may charge a reasonable fee or refuse to act, but must bear the burden of demonstrating that character. The controller must also provide a copy of personal data undergoing processing in response to an access request.

Right Article What you can ask Key limitations
Right of access Art 15 Confirmation that data is processed; a copy of the data; information on purposes, recipients, retention, automated decisions, source (if indirect). Rights of others (trade secrets, third-party data) may limit the copy provided.
Right to rectification Art 16 Correction of inaccurate data; completion of incomplete data (including by supplementary statement). The controller must notify recipients of any rectification (Art 19).
Right to erasure Art 17 Erasure where: data no longer necessary; consent withdrawn and no other legal ground; data unlawfully processed; legal obligation requires erasure; data collected via online services from children. Does not apply where processing is necessary for: freedom of expression; legal obligation; public health; archiving/research/statistics; legal claims.
Right to restriction Art 18 Halt all processing (except storage) while: accuracy is contested; processing is unlawful but you prefer restriction to erasure; data is needed for your legal claims but not the controller's; you have objected and the controller is verifying its grounds. The controller must inform you before lifting a restriction.
Right to data portability Art 20 Receive data you provided in a structured, commonly used, machine-readable format. Request direct controller-to-controller transfer where technically feasible. Applies only where processing is based on consent or contract and is carried out by automated means. Does not apply to public-task or legal-obligation based processing.
Right to object Art 21 Object at any time to processing based on public task (Art 6(1)(e)) or legitimate interests (Art 6(1)(f)), including profiling. Absolute right to object to processing for direct marketing (no override possible). For non-marketing objections, the controller may continue if it can demonstrate compelling legitimate grounds overriding your interests.
Automated decision-making Art 22 Not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects or similarly significantly affects you. Right to human review, to express your view, and to contest the decision. Exceptions: necessary for contract with you; authorised by law; based on explicit consent. Special-category data requires an additional Art 9(2)(a) or (g) condition.
How to exercise your rights

You can exercise any of the above rights by contacting the data controller directly. The controller must facilitate your requests and cannot require you to use a specific format, though it may request additional information to verify your identity (Art 12(6)). Where the controller does not act on your request, you can lodge a complaint with your national Data Protection Authority or seek a judicial remedy before the courts of the Member State where the controller is established or where you reside (Art 79).


What organisations must do

Chapter IV, Articles 24-43: the compliance architecture for controllers and processors

Privacy by design and by default (Art 25)

Data protection must be embedded into systems and processes from the outset, not added as an afterthought. This means using pseudonymisation and data minimisation techniques at the design stage, and ensuring that by default only the minimum data necessary is processed. The principle applies to any new technology, service or product that involves personal data.

Records of processing activities (Art 30)

Controllers must maintain a written record of all processing activities, covering: the controller's name and contact details; the DPO's contact details; purposes; categories of data subjects and data; recipients; international transfers; retention periods; and a description of security measures. Processors must keep analogous records. Organisations with fewer than 250 employees are exempt unless the processing is not occasional, is likely to create a risk, or involves special categories.

Security (Art 32)

Controllers and processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The GDPR lists examples (encryption, pseudonymisation, resilience, backup and recovery, regular testing) but does not mandate any specific technology. The standard is risk-based: a healthcare organisation processing thousands of patient records is held to a higher standard than a small business processing only employee email addresses.

Breach notification: 72-hour rule (Arts 33-34)

When a personal data breach occurs (accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data), the controller must notify the competent supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. Where the breach is likely to cause a high risk, the affected data subjects must also be notified without undue delay. Processors must notify the controller without undue delay upon becoming aware of a breach.

Data Protection Impact Assessment (Art 35)

A DPIA is mandatory before processing that is likely to result in a high risk to individuals' rights and freedoms. The GDPR specifically requires a DPIA for: systematic and extensive profiling with significant effects; large-scale processing of special category or criminal conviction data; and systematic large-scale monitoring of publicly accessible areas (e.g. CCTV). Where the DPIA shows residual high risk that cannot be mitigated, the controller must consult the national supervisory authority before starting (Art 36).

Data Protection Officer (Arts 37-39)

A DPO must be designated by: all public authorities (except courts in their judicial capacity); organisations whose core activities require large-scale regular and systematic monitoring of data subjects; and those whose core activities involve large-scale processing of special categories or criminal conviction data. The DPO must be independent, cannot be dismissed for performing their role, must report to the highest management level, and must have expert knowledge of data protection law and practice. A group of companies may appoint a single DPO provided they are accessible from each establishment.

Processor contracts (Art 28)

Every engagement of a processor must be governed by a written contract that binds the processor and sets out: the subject matter and duration of processing; the nature and purpose of the processing; the type of personal data and categories of data subjects; the controller's instructions (the processor must only process data on documented instructions from the controller); security obligations; sub-processor rules; and obligations on deletion or return of data at the end of the contract. If a processor itself engages a sub-processor, the same contractual obligations must flow down.


International data transfers

Chapter V, Articles 44-50: exporting personal data outside the EU/EEA requires a valid transfer mechanism

The general principle in Article 44 is that transfers of personal data to third countries or international organisations are only permitted if the conditions of Chapter V are met. The aim is to ensure that the level of protection for individuals guaranteed by the GDPR is not undermined by an export to a less protective jurisdiction.

1
Adequacy decision (Art 45)
The European Commission has determined that the third country provides an adequate level of protection, essentially equivalent to the EU. No further authorisation from a supervisory authority is needed. Current adequacy decisions cover countries including the UK (interim), Japan, Canada (commercial organisations), Switzerland, Israel, New Zealand, South Korea, and the EU-US Data Privacy Framework for certified US organisations.
2
Standard contractual clauses (Art 46(2)(c)-(d))
Commission-adopted standard data protection clauses bind the parties contractually. Updated SCCs were adopted by the Commission on 4 June 2021 (Implementing Decision 2021/914). Following the Schrems II judgment (CJEU 16 July 2020, C-311/18), a Transfer Impact Assessment (TIA) is also required before relying on SCCs to assess whether the destination country's laws undermine the safeguards.
3
Binding corporate rules (Art 47)
Intra-group data protection policies approved by the lead supervisory authority allow a multinational group to transfer data freely between its member entities worldwide. BCRs must be legally binding, apply to all group members, and confer enforceable rights on data subjects. Approval takes one to two years.
4
Other Art 46 safeguards
Approved codes of conduct with binding commitments by the recipient; approved certification mechanisms with binding commitments; legally binding and enforceable instruments between public authorities; and, with supervisory authority authorisation, individual contractual clauses or administrative arrangements.
5
Derogations (Art 49)
In the absence of adequacy or safeguards, limited derogations permit transfers for: explicit consent (with risk disclosure); contract performance; important reasons of public interest; legal claims; vital interests; and limited public-register data. These are intended as last resorts and should not be used for systematic, repetitive transfers.

Schrems II and Transfer Impact Assessments

The CJEU's Schrems II judgment of 16 July 2020 (Case C-311/18, Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems) invalidated the EU-US Privacy Shield adequacy decision. The Court held that US surveillance law (in particular Section 702 FISA and Executive Order 12333) gave US intelligence agencies access to EU personal data in ways that did not meet EU standards. As a result, controllers relying on SCCs must carry out a case-by-case Transfer Impact Assessment to determine whether the destination country's legal framework undermines the contractual protections. The EU-US Data Privacy Framework (adopted by adequacy decision on 10 July 2023) provides a new adequacy basis for certified US organisations, but further legal challenges are anticipated.


Enforcement and fines

Chapter VI-VIII, Articles 51-84: supervisory authorities, the EDPB, and two-tier administrative fines

National supervisory authorities (Data Protection Authorities)

Each Member State must establish at least one independent national supervisory authority (Article 51). DPAs must act with complete independence and have three categories of powers under Article 58: investigative powers (access to premises, data and information); corrective powers (warnings, reprimands, orders, bans on processing, and fines); and advisory and authorisation powers (opinions, codes, BCRs, certifications).

The one-stop-shop mechanism (Articles 56, 60) means that for cross-border processing, the DPA of the Member State where the controller has its main establishment acts as the lead supervisory authority. For example, a company headquartered in Ireland deals primarily with the Irish Data Protection Commission (DPC) for cross-border processing activities.

European Data Protection Board (Art 68)

The EDPB is an independent EU body established by the GDPR, composed of the heads of all 27 national DPAs and the European Data Protection Supervisor. It ensures the consistent application of the GDPR across the EU by issuing guidelines, opinions and binding decisions on cross-border cases where DPAs disagree. The EDPB has published extensive guidelines on topics including consent, data portability, international transfers, data breaches, DPIAs, the right of access, and many sector-specific questions. EDPB guidelines do not have the force of law but are followed closely by DPAs and courts.

Two-tier administrative fines (Article 83)

The GDPR's fine regime operates in two tiers. Both tiers use the same "whichever is higher" formula between the fixed maximum and the percentage-of-turnover maximum, ensuring that fines are meaningful even for the largest global companies.

  • Tier 1 (Art 83(4)) -- up to EUR 10 million or 2% of global annual turnover: infringements of controller/processor obligations (privacy by design, records, DPO, security, DPIA, processor contracts, certification and monitoring bodies).
  • Tier 2 (Art 83(5)) -- up to EUR 20 million or 4% of global annual turnover: infringements of the basic principles (Art 5); conditions for consent (Arts 6, 7, 9); data subject rights (Arts 12-22); international transfer rules (Arts 44-49); and non-compliance with a supervisory authority order or ban.

When deciding whether to impose a fine and the amount, DPAs must take into account: the nature, gravity and duration of the infringement; whether it was intentional or negligent; actions taken to mitigate damage; the degree of responsibility; previous infringements; cooperation with the DPA; the categories of data affected; and whether the DPA was notified voluntarily.

Major fines issued under the GDPR
Organisation DPA Year Fine Reason
Meta (Facebook) Ireland DPC 2023 EUR 1.2 billion Transfers of EU personal data to the US without adequate safeguards
Amazon Luxembourg CNPD 2021 EUR 746 million Advertising personal data processing without adequate legal basis
Meta (WhatsApp) Ireland DPC 2021 EUR 225 million Transparency and privacy information failures
Google France CNIL 2019 EUR 50 million Lack of transparency, inadequate information and absence of valid consent for personalised ads
Clearview AI Italy Garante 2022 EUR 20 million Unlawful processing of biometric data (facial images scraped from the internet)
Compensation (Article 82)

Any person who has suffered material or non-material damage as a result of a GDPR infringement has the right to receive compensation from the controller or processor. Both material damage (financial loss, identity theft costs) and non-material damage (distress, anxiety) are covered. Controllers and processors are jointly and severally liable, with rights of recourse between them. This creates a powerful private enforcement mechanism alongside public enforcement by DPAs.


Timeline

from the 1995 directive to the GDPR and beyond

24 October 1995
Directive 95/46/EC (the Data Protection Directive) adopted. The first EU-wide data protection framework, requiring Member States to enact national implementing legislation. Fragmentation began almost immediately.
25 January 2012
European Commission proposes the GDPR (COM(2012)11) alongside the Law Enforcement Directive proposal, to replace the 1995 framework with a single, directly applicable regulation.
12 March 2014
European Parliament adopts its first-reading position with significant strengthening of individual rights, consent standards and enforcement powers compared to the Commission proposal.
15 December 2015
Informal trilogue agreement between Parliament, Council and Commission reached on the final text.
27 April 2016
GDPR and Law Enforcement Directive (EU) 2016/680 formally adopted by the European Parliament and the Council of the European Union.
4 May 2016
Published in the Official Journal (OJ L 119, pp. 1-88 for the GDPR; pp. 89-131 for the LED).
24 May 2016
Entry into force. Two-year implementation period begins. Organisations have until 25 May 2018 to become compliant.
25 May 2018
GDPR starts to apply. Directive 95/46/EC simultaneously repealed. The Article 29 Working Party is replaced by the European Data Protection Board (EDPB). DPAs across the EU begin handling complaints and investigations from day one.
16 July 2020
CJEU Schrems II judgment (Case C-311/18) invalidates the EU-US Privacy Shield adequacy decision and establishes the Transfer Impact Assessment requirement for SCCs.
4 June 2021
European Commission adopts updated Standard Contractual Clauses (Implementing Decision 2021/914), replacing the 2001 and 2010 legacy SCCs. A transition period ran to 27 December 2022.
10 July 2023
Commission adopts EU-US Data Privacy Framework adequacy decision, providing a new legal basis for transfers to certified US organisations. Challenged before the CJEU in October 2023 by the same complainant as in Schrems II.

Frequently asked questions

common questions on GDPR scope, consent, fines and the rights framework

Does the GDPR apply to my business even if I am based outside the EU?

Yes, if you offer goods or services to people in the EU (whether free or paid) or if you monitor the behaviour of people in the EU (for example, through website analytics, cookies or behavioural advertising targeting EU users), the GDPR applies to you under Article 3(2). You must also appoint a written EU representative (Article 27), unless your processing is occasional, does not involve large-scale special-category data, and is unlikely to result in a risk to individuals' rights.

Do I always need consent to process personal data?

No. Consent is one of six legal bases in Article 6. In many situations, another legal basis is more appropriate: processing for contract performance (Art 6(1)(b)), compliance with a legal obligation (Art 6(1)(c)), or legitimate interests (Art 6(1)(f)) may provide a more stable and appropriate foundation. Choosing consent when another legal basis applies creates problems: if the individual withdraws consent, you must stop processing even if you have a legitimate business need. Controllers should identify the correct legal basis before starting to process data.

What counts as a personal data breach?

Under Article 4(12), a personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. This covers not only cyberattacks and hacking but also accidentally sending an email containing personal data to the wrong recipient, losing an unencrypted USB drive, or a misconfigured database becoming publicly accessible. Not every breach requires notification to the supervisory authority: notification is only required if the breach is likely to result in a risk to the rights and freedoms of natural persons (Art 33(1)).

Is a Data Protection Officer mandatory for every business?

No. A DPO is mandatory only for: (a) public authorities and bodies (except courts acting in their judicial capacity); (b) organisations whose core activities require regular and systematic monitoring of data subjects on a large scale; and (c) organisations whose core activities involve large-scale processing of special categories or criminal conviction data (Art 37(1)). An individual doctor, lawyer or small business is not required to appoint a DPO. However, any organisation may voluntarily designate a DPO (Art 37(4)), and the EDPB encourages this as good practice.

How are fines calculated?

DPAs must assess fines on a case-by-case basis, taking into account the factors listed in Article 83(2): the nature, gravity and duration of the infringement; whether it was intentional or negligent; the number of data subjects affected; the level of damage; previous infringements; cooperation with the authority; the categories of data affected; and how the infringement became known. The two-tier maximum (EUR 10 million / 2% or EUR 20 million / 4%) acts as a ceiling, not a standard or expected amount. For large multinationals, the 4% of global turnover calculation is the binding limit, as it will exceed EUR 20 million.

What is the difference between a controller and a processor?

A controller (Art 4(7)) is the natural or legal person, public authority, agency or body that determines the purposes and means of the processing of personal data. A processor (Art 4(8)) is the entity that processes personal data on behalf of the controller, following the controller's documented instructions. The same entity can be a controller for some processing and a processor for other processing. Controllers bear the primary compliance obligations under the GDPR. Processors have directly applicable obligations too (security, breach notification to the controller, sub-processor authorisation, records), and they are directly liable if they exceed the controller's instructions or act unlawfully.


Glossary

key definitions from Article 4 and the GDPR framework

Personal data
Any information relating to an identified or identifiable natural person (Art 4(1)). Includes names, email addresses, IP addresses, location data, cookie identifiers, and any combination of data that allows identification of an individual.
Processing
Any operation performed on personal data, whether automated or not: collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, erasure, destruction (Art 4(2)). Almost any interaction with personal data is "processing".
Controller
The natural or legal person, public authority, agency or body that determines the purposes and means of processing (Art 4(7)). Bears primary responsibility for GDPR compliance.
Processor
A person or body that processes personal data on behalf of the controller, following the controller's documented instructions (Art 4(8)). Cloud providers, payroll companies and email marketing platforms are typically processors.
Consent
Freely given, specific, informed and unambiguous indication of the data subject's wishes by a clear affirmative action (Art 4(11)). Pre-ticked boxes, silence and inactivity do not constitute valid consent.
Pseudonymisation
Processing personal data such that it can no longer be attributed to a specific data subject without additional separately-kept information (Art 4(5)). Pseudonymised data is still personal data under the GDPR; anonymised data (irreversibly de-identified) is not.
Special categories
Personal data that is particularly sensitive by nature and receives heightened protection under Art 9: racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, genetic data, biometric data (for unique ID), health data, sex life or sexual orientation.
Profiling
Automated processing of personal data to evaluate personal aspects about a natural person, in particular to analyse or predict performance at work, economic situation, health, preferences, interests, behaviour, location or movements (Art 4(4)).
Personal data breach
A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data (Art 4(12)). Includes cyberattacks, accidental disclosures, and loss of devices containing data.
DPO
Data Protection Officer. An independent expert in data protection law and practices who informs, advises, monitors compliance, and cooperates with the supervisory authority. Mandatory for public authorities and certain large-scale processors (Arts 37-39).
DPIA
Data Protection Impact Assessment. A systematic assessment of the risks of a high-risk processing operation, required before starting that processing (Art 35). Must include measures to mitigate the identified risks.
EDPB
European Data Protection Board. The independent EU body composed of the heads of all national DPAs and the EDPS, established by Art 68 of the GDPR to ensure consistent application of data protection rules across the Union.

Official sources

primary legislative and regulatory references for the GDPR

Regulation text on EUR-Lex

The official consolidated text of Regulation (EU) 2016/679 is available on EUR-Lex in all EU official languages.

Open on EUR-Lex
EDPB: European Data Protection Board

The EDPB publishes binding decisions, guidelines, recommendations and consistency opinions on GDPR interpretation. Essential reading for compliance professionals.

EDPB documents
National supervisory authorities

Each EU Member State has its own data protection supervisory authority. The EDPB maintains a full directory. Your national DPA is the primary contact for complaints and guidance in your jurisdiction.

DPA directory
OJ L 119, 4 May 2016

The original Official Journal publication of the GDPR. Pages 1-88 contain the Regulation; pages 88-102 contain the Law Enforcement Directive (2016/680) in the same issue.

OJ L 119


Explore with Brubru

AI-powered tools to go deeper on GDPR compliance, amendments and policy analysis

Brubru Chat
Ask any question about GDPR: legal bases, consent conditions, breach notification timelines, the one-stop-shop mechanism, EDPB guidelines. Backed by the full GDPR knowledge guide and EDPB guidance corpus.
Chat now
Amendator
Draft, compare and track amendments to GDPR articles in Akoma Ntoso XML. Essential when working on the ePrivacy Regulation, national implementation acts or sector-specific data law proposals that reference the GDPR.
Open Amendator
My EU Bubble
Track GDPR enforcement news, EDPB decision feeds, MEP positions on data legislation, and upcoming committee hearings on digital regulation in one personalised dashboard.
Open Bubble
EU Law Comply
Run a GDPR compliance gap analysis against your organisation's processing activities. Checks 16 key obligations from lawful basis documentation to DPO appointment, breach response procedures and international transfer mechanisms.
Check compliance
Canon Library
Browse the full EU Canon: plain-language deep-dives on binding EU law spanning digital, environment, finance, health, food safety, transport and more, in six languages.
Browse Canon
Brubru API
Integrate EU legislative data directly into your own tools. The Brubru Public Data API provides structured access to EU law content, news feeds, parliamentary questions, council register items and more.
API docs
GDPR Intelligence

All the EU, with AI.

Brubru gives EU policy professionals AI-powered tools to navigate the full EU legal corpus: chat, compliance checks, amendment drafting and legislative monitoring across all 27 Member States.