New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
← Legislation library

European Union

GDPR

The General Data Protection Regulation governs how personal data of people in the EU is collected, processed, and protected. It sets out lawful bases, data subject rights, breach notification duties, and the accountability obligations organisations must be able to demonstrate.

20 articles

Article 5

Principles relating to processing of personal data

Personal data shall be processed lawfully, fairly and in a transparent manner.

Article 6

Lawfulness of processing

Processing of personal data shall only be lawful where one of the legal bases applies.

Article 7

Conditions for consent

Where processing is based on consent, the controller must be able to demonstrate consent was given, consent requests must be clearly distinguishable and in plain language, and withdrawal must be as easy as giving consent.

Article 13

Information to be provided where personal data are collected from the data subject

When personal data are collected from the data subject, the controller shall provide specified information.

Article 14

Information to be provided where personal data have not been obtained from the data subject

When personal data have not been obtained from the data subject, the controller shall provide specified information.

Article 15

Right of access by the data subject

The data subject has the right to confirmation of whether their personal data is being processed and, if so, access to it plus specified information (purposes, categories, recipients, retention period, source, automated decision-making).

Article 16

Right to rectification

The data subject has the right to obtain rectification of inaccurate personal data without undue delay, and to have incomplete data completed.

Article 17

Right to erasure ('right to be forgotten')

The data subject can obtain erasure of personal data without undue delay on specified grounds (no longer necessary, consent withdrawn, unlawful processing, legal obligation, etc.), subject to listed exceptions.

Article 20

Right to data portability

The data subject has the right to receive personal data they provided in a structured, commonly used, machine-readable format and to transmit it to another controller, where processing is based on consent or contract and carried out by automated means.

Article 22

Automated individual decision-making, including profiling

The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them, subject to specified exceptions and safeguards.

Article 25

Data protection by design and by default

The controller shall implement appropriate technical and organisational measures designed to implement data protection principles.

Article 28

Processor

Controllers must only use processors providing sufficient guarantees; processing must be governed by a contract covering subject-matter, duration, nature, purpose, security measures, sub-processor conditions, and audit rights.

Article 30

Records of processing activities

Controllers and processors must maintain written records of processing activities (purposes, data categories, recipients, transfers, retention, security measures); enterprises under 250 employees are exempt unless the processing is risky, non-occasional, or involves special categories.

Article 32

Security of processing

Controllers and processors must implement technical and organisational measures appropriate to the risk (pseudonymisation, encryption, resilience, ability to restore availability, regular testing), taking into account state of the art and cost.

Article 33

Notification of a personal data breach to the supervisory authority

Controllers must notify the supervisory authority of a personal data breach without undue delay, and where feasible within 72 hours, unless unlikely to result in risk; processors must notify the controller without undue delay.

Article 34

Communication of a personal data breach to the data subject

When a personal data breach is likely to result in high risk to rights and freedoms, the controller shall communicate the breach to the data subject without undue delay (Art.34).

Article 35

Data protection impact assessment

Where processing is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall carry out a data protection impact assessment.

Article 37

Designation of the data protection officer

Controllers and processors shall designate a DPO where required (public authority, large-scale systematic monitoring, or large-scale special categories); DPO contact details published and communicated to supervisory authority (Art.37).

Article 44

General principle for transfers

Any transfer of personal data to a third country or international organisation, including onward transfers, may take place only if the conditions of this Chapter are complied with, so that the level of protection guaranteed by the Regulation is not undermined.

Article 83

General conditions for imposing administrative fines

Administrative fines up to EUR 10 million/2% of global turnover for lower-tier infringements (e.g. Articles 8, 11, 25-39, 42, 43), or up to EUR 20 million/4% for higher-tier infringements (e.g. the basic processing principles, data subjects' rights, international transfers).

Turn GDPR into tracked tasks

eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.

Start free trial