European Union
GDPR
The General Data Protection Regulation governs how personal data of people in the EU is collected, processed, and protected. It sets out lawful bases, data subject rights, breach notification duties, and the accountability obligations organisations must be able to demonstrate.
20 articles
Principles relating to processing of personal data
Personal data shall be processed lawfully, fairly and in a transparent manner.
Lawfulness of processing
Processing of personal data shall only be lawful where one of the legal bases applies.
Conditions for consent
Where processing is based on consent, the controller must be able to demonstrate consent was given, consent requests must be clearly distinguishable and in plain language, and withdrawal must be as easy as giving consent.
Information to be provided where personal data are collected from the data subject
When personal data are collected from the data subject, the controller shall provide specified information.
Information to be provided where personal data have not been obtained from the data subject
When personal data have not been obtained from the data subject, the controller shall provide specified information.
Right of access by the data subject
The data subject has the right to confirmation of whether their personal data is being processed and, if so, access to it plus specified information (purposes, categories, recipients, retention period, source, automated decision-making).
Right to rectification
The data subject has the right to obtain rectification of inaccurate personal data without undue delay, and to have incomplete data completed.
Right to erasure ('right to be forgotten')
The data subject can obtain erasure of personal data without undue delay on specified grounds (no longer necessary, consent withdrawn, unlawful processing, legal obligation, etc.), subject to listed exceptions.
Right to data portability
The data subject has the right to receive personal data they provided in a structured, commonly used, machine-readable format and to transmit it to another controller, where processing is based on consent or contract and carried out by automated means.
Automated individual decision-making, including profiling
The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them, subject to specified exceptions and safeguards.
Data protection by design and by default
The controller shall implement appropriate technical and organisational measures designed to implement data protection principles.
Processor
Controllers must only use processors providing sufficient guarantees; processing must be governed by a contract covering subject-matter, duration, nature, purpose, security measures, sub-processor conditions, and audit rights.
Records of processing activities
Controllers and processors must maintain written records of processing activities (purposes, data categories, recipients, transfers, retention, security measures); enterprises under 250 employees are exempt unless the processing is risky, non-occasional, or involves special categories.
Security of processing
Controllers and processors must implement technical and organisational measures appropriate to the risk (pseudonymisation, encryption, resilience, ability to restore availability, regular testing), taking into account state of the art and cost.
Notification of a personal data breach to the supervisory authority
Controllers must notify the supervisory authority of a personal data breach without undue delay, and where feasible within 72 hours, unless unlikely to result in risk; processors must notify the controller without undue delay.
Communication of a personal data breach to the data subject
When a personal data breach is likely to result in high risk to rights and freedoms, the controller shall communicate the breach to the data subject without undue delay (Art.34).
Data protection impact assessment
Where processing is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall carry out a data protection impact assessment.
Designation of the data protection officer
Controllers and processors shall designate a DPO where required (public authority, large-scale systematic monitoring, or large-scale special categories); DPO contact details published and communicated to supervisory authority (Art.37).
General principle for transfers
Any transfer of personal data to a third country or international organisation, including onward transfers, may take place only if the conditions of this Chapter are complied with, so that the level of protection guaranteed by the Regulation is not undermined.
General conditions for imposing administrative fines
Administrative fines up to EUR 10 million/2% of global turnover for lower-tier infringements (e.g. Articles 8, 11, 25-39, 42, 43), or up to EUR 20 million/4% for higher-tier infringements (e.g. the basic processing principles, data subjects' rights, international transfers).
Turn GDPR into tracked tasks
eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.
Start free trial