European Union
GDPR
The General Data Protection Regulation governs how personal data of people in the EU is collected, processed, and protected. It sets out lawful bases, data subject rights, breach notification duties, and the accountability obligations organisations must be able to demonstrate.
8 articles
Principles relating to processing of personal data
Personal data shall be processed lawfully, fairly and in a transparent manner.
Lawfulness of processing
Processing of personal data shall only be lawful where one of the legal bases applies.
Information to be provided where personal data are collected from the data subject
When personal data are collected from the data subject, the controller shall provide specified information.
Information to be provided where personal data have not been obtained from the data subject
When personal data have not been obtained from the data subject, the controller shall provide specified information.
Automated individual decision-making, including profiling
The data subject shall have the right not to be subject to a decision based solely on automated processing.
Data protection by design and by default
The controller shall implement appropriate technical and organisational measures designed to implement data protection principles.
Data protection impact assessment
Where processing is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall carry out a data protection impact assessment.
General conditions for imposing administrative fines
Administrative fines up to EUR 20 million or 4% of global annual turnover.
Turn GDPR into tracked tasks
eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.
Start free trial