GDPR
Regulation (EU) 2016/679General Data Protection Regulation
In force since May 25, 2018
Who it applies to
- Controllers and processors established in the EU, wherever the processing takes place
- Controllers and processors outside the EU that offer goods or services to people in the EU
- Controllers and processors outside the EU that monitor the behaviour of people in the EU
- No revenue or headcount threshold: a sole trader processing one person's data is in scope
Consumer rights
- Access / know — grantedObtain the personal data held about you, and the categories, sources and purposes behind it.
- Correction — grantedRequire inaccurate personal data to be fixed.
- Deletion / erasure — grantedRequire deletion of personal data, subject to the statute's retention exceptions.
- Portability — grantedReceive your data in a portable, machine-readable form, or have it transmitted onward.
- Opt out of sale / sharing — not granted
- Opt out of targeted advertising — not granted
- Opt out of profiling — grantedStop automated profiling that produces legal or similarly significant effects.
- Limit sensitive data use — grantedRestrict use of sensitive categories to what is necessary to deliver the service.
- Human review of automated decisions — grantedObtain meaningful human involvement in a significant automated decision.
- Non-discrimination — not granted
- Appeal a refusal — grantedHave a denied request reconsidered through a stated appeals process.
- Private right of action — grantedSue directly, rather than relying on a regulator to enforce on your behalf.
Obligations
- Consent model
- Opt-in
- Universal opt-out signal
- Not required
- Risk assessments
- Required for higher-risk processing
- Data protection officer
- Required
- Records of processing
- Required
- Processor contract
- Required
- Right to cure
- None — enforcement may follow immediately
- Data broker registration
- Not required
- Minors
- Information-society services offered directly to a child require parental consent below the national age of digital consent, which member states set between 13 and 16.
- Automated decisions
- Article 22 gives a right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects, with rights to human intervention and to contest the decision.
Breach notification
- To individuals
- To affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms
- To the regulator
- To the supervisory authority within 72 hours of becoming aware
- What triggers it
- A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data
Penalties
- Headline
- Up to €20 million or 4% of total worldwide annual turnover, whichever is higher
- Private right of action
- Yes — individuals can sue directly
- Notes
- A lower tier of €10 million or 2% applies to administrative and record-keeping failures. Article 82 gives a direct right to compensation for material or non-material damage, enforced in national courts.
Exemptions
Entities
- Purely personal or household activity
- Law-enforcement processing, which falls under the separate Law Enforcement Directive
Data
- Anonymous data that cannot be attributed to an identifiable person
Sources
- PrimaryRegulationRegulation (EU) 2016/679 — consolidated text on EUR-Lex
- OfficialGuidanceEuropean Data Protection Board — guidelines and decisions