What it is
The General Data Protection Regulation, Regulation (EU) 2016/679, is the European Union's comprehensive data protection law. It applied from 25 May 2018, replacing the 1995 Data Protection Directive, and sets a single, directly applicable standard across all EU and EEA member states. It is widely treated as the global benchmark for privacy law.
Who it applies to
The GDPR governs the processing of the personal data of people in the EU and EEA. Its reach is extraterritorial: it covers organizations established in the EU, and organizations outside the EU that offer goods or services to, or monitor the behaviour of, people in the EU. It distinguishes a "controller" (who decides why and how data is processed) from a "processor" (who processes on a controller's behalf).
Core principles
Processing must follow seven principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality (security); and accountability, meaning you must be able to demonstrate compliance, not just claim it.
Legal bases
Every processing activity needs a lawful basis: consent, performance of a contract, a legal obligation, protection of vital interests, a public task, or legitimate interests. Special category data, such as health, biometrics or data revealing beliefs, needs an additional condition on top of a lawful basis.
Individual rights
Data subjects have the rights to be informed, of access, to rectification, to erasure (the "right to be forgotten"), to restrict processing, to data portability, to object, and rights in relation to automated decision-making and profiling.
Key obligations
Controllers and processors must apply appropriate security, keep records of processing activities, build in privacy by design and by default, run a Data Protection Impact Assessment (DPIA) for high-risk processing, appoint a Data Protection Officer (DPO) in defined cases, and put written data processing agreements in place with their processors.
Data breaches
A personal data breach must be notified to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Individuals must be told directly when a breach is likely to result in a high risk to their rights and freedoms.
International transfers
Sending personal data outside the EU and EEA needs a transfer safeguard: an adequacy decision for the destination country, Standard Contractual Clauses (SCCs), Binding Corporate Rules, or another approved mechanism, often supported by a transfer impact assessment.
Enforcement and penalties
Independent supervisory authorities in each member state enforce the GDPR, with cross-border cases coordinated through the European Data Protection Board (EDPB). Fines reach up to the higher of 20 million euros or 4% of total worldwide annual turnover for the most serious infringements.
The official text
The authoritative version is Regulation (EU) 2016/679, published in all official EU languages on EUR-Lex. Use that text, not this summary, for anything that matters.
Below is the source we understand to be the official text (English, official). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:
Go to the source →