GDPR sets the ground rules for lawful, fair and transparent processing of personal data, and grants individuals a set of enforceable rights.
It applies to any organisation processing personal data of people in the EU/EEA, regardless of where the organisation is located.
Supervision and enforcement are carried out by national Data Protection Authorities, coordinated by the European Data Protection Board (EDPB).
Controllers and processors of personal data of EU/EEA data subjects.
Non-EU organisations offering goods/services to, or monitoring, EU/EEA individuals.
Lawful basis, purpose limitation, data minimisation, accuracy, storage limitation, integrity & confidentiality, accountability.
Data subject rights (access, rectification, erasure, restriction, portability, objection).
Records of processing, DPIAs for high-risk processing, DPO where required.
Personal data breach notification to the DPA within 72h; notification to individuals when high risk.
International transfer safeguards (adequacy, SCCs, BCRs, derogations).
- 2016-04-27Regulation (EU) 2016/679 adopted
- 2016-05-24Entry into force (20 days after OJ publication of 4 May 2016)
- 2018-05-25Full application across the EU/EEA
- 2020-07-16CJEU Schrems II judgment (Case C-311/18)
- 2021-06-04New Standard Contractual Clauses adopted by the Commission
- 2023-07-10EU–US Data Privacy Framework adequacy decision
License · EU legislative texts are reusable under the EUR-Lex reuse policy (© European Union).