Nix2
Back to Nix2
Regulation·European Union / EEA (directly applicable, extraterritorial)

GDPR

GDPR — General Data Protection Regulation

EU regulation governing the processing of personal data of individuals in the EU/EEA.

Official sources ↓
Applicable since 25 May 2018
Scroll
Overview

GDPR sets the ground rules for lawful, fair and transparent processing of personal data, and grants individuals a set of enforceable rights.

It applies to any organisation processing personal data of people in the EU/EEA, regardless of where the organisation is located.

Supervision and enforcement are carried out by national Data Protection Authorities, coordinated by the European Data Protection Board (EDPB).

Who it applies to
01

Controllers and processors of personal data of EU/EEA data subjects.

02

Non-EU organisations offering goods/services to, or monitoring, EU/EEA individuals.

Core obligations
Duty · 01

Lawful basis, purpose limitation, data minimisation, accuracy, storage limitation, integrity & confidentiality, accountability.

Duty · 02

Data subject rights (access, rectification, erasure, restriction, portability, objection).

Duty · 03

Records of processing, DPIAs for high-risk processing, DPO where required.

Duty · 04

Personal data breach notification to the DPA within 72h; notification to individuals when high risk.

Duty · 05

International transfer safeguards (adequacy, SCCs, BCRs, derogations).

Timeline
  1. 2016-04-27
    Regulation (EU) 2016/679 adopted
  2. 2016-05-24
    Entry into force (20 days after OJ publication of 4 May 2016)
  3. 2018-05-25
    Full application across the EU/EEA
  4. 2020-07-16
    CJEU Schrems II judgment (Case C-311/18)
  5. 2021-06-04
    New Standard Contractual Clauses adopted by the Commission
  6. 2023-07-10
    EU–US Data Privacy Framework adequacy decision
Official sources

License · EU legislative texts are reusable under the EUR-Lex reuse policy (© European Union).

Explore other frameworks