GDPR

Regulation (EU) 2016/679

General Data Protection Regulation

In force since May 25, 2018

Who it applies to

  • Controllers and processors established in the EU, wherever the processing takes place
  • Controllers and processors outside the EU that offer goods or services to people in the EU
  • Controllers and processors outside the EU that monitor the behaviour of people in the EU
  • No revenue or headcount threshold: a sole trader processing one person's data is in scope

Consumer rights

  • Access / know — grantedObtain the personal data held about you, and the categories, sources and purposes behind it.
  • Correction — grantedRequire inaccurate personal data to be fixed.
  • Deletion / erasure — grantedRequire deletion of personal data, subject to the statute's retention exceptions.
  • Portability — grantedReceive your data in a portable, machine-readable form, or have it transmitted onward.
  • Opt out of sale / sharing — not granted
  • Opt out of targeted advertising — not granted
  • Opt out of profiling — grantedStop automated profiling that produces legal or similarly significant effects.
  • Limit sensitive data use — grantedRestrict use of sensitive categories to what is necessary to deliver the service.
  • Human review of automated decisions — grantedObtain meaningful human involvement in a significant automated decision.
  • Non-discrimination — not granted
  • Appeal a refusal — grantedHave a denied request reconsidered through a stated appeals process.
  • Private right of action — grantedSue directly, rather than relying on a regulator to enforce on your behalf.

Obligations

Consent model
Opt-in
Universal opt-out signal
Not required
Risk assessments
Required for higher-risk processing
Data protection officer
Required
Records of processing
Required
Processor contract
Required
Right to cure
None — enforcement may follow immediately
Data broker registration
Not required
Minors
Information-society services offered directly to a child require parental consent below the national age of digital consent, which member states set between 13 and 16.
Automated decisions
Article 22 gives a right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects, with rights to human intervention and to contest the decision.

Breach notification

To individuals
To affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms
To the regulator
To the supervisory authority within 72 hours of becoming aware
What triggers it
A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data

Penalties

Headline
Up to €20 million or 4% of total worldwide annual turnover, whichever is higher
Private right of action
Yes — individuals can sue directly
Notes
A lower tier of €10 million or 2% applies to administrative and record-keeping failures. Article 82 gives a direct right to compensation for material or non-material damage, enforced in national courts.

Exemptions

Entities

  • Purely personal or household activity
  • Law-enforcement processing, which falls under the separate Law Enforcement Directive

Data

  • Anonymous data that cannot be attributed to an identifiable person

Sources