GDPR — General Data Protection Regulation
The General Data Protection Regulation (GDPR) is a comprehensive data privacy law enacted by the European Union (EU) and in force since May 25, 2018. It is designed to protect the personal data and privacy of individuals within the EU and the European Economic Area (EEA), and also addresses the export of personal data outside these areas.
By complying with the GDPR, organizations demonstrate their commitment to privacy, build trust with customers and partners, and meet legal and regulatory requirements across the EU.
Table Of Contents
Chapter I
Article 1+
Chapter II
Article 5+
- Article 5Principles relating to processing of personal data
- Article 6Lawfulness of processing
- Article 7Conditions for consent
- Article 8Conditions applicable to child's consent in relation to information society services
- Article 9Processing of special categories of personal data
- Article 10Processing of personal data relating to criminal convictions and offences
- Article 11Processing which does not require identification
Chapter III
Article 12+
- Article 12Transparent information, communication and modalities for the exercise of the rights of the data subject
- Article 13Information to be provided where personal data are collected from the data subject
- Article 14Information to be provided where personal data have not been obtained from the data subject
- Article 15Right of access by the data subject
- Article 16Right to rectification
- Article 17Right to erasure ('right to be forgotten')
- Article 18Right to restriction of processing
- Article 19Notification obligation regarding rectification or erasure of personal data or restriction of processing
- Article 20Right to data portability
- Article 21Right to object
- Article 22Automated individual decision-making, including profiling
- Article 23Restrictions
Chapter IV
Article 24+
- Article 24Responsibility of the controller
- Article 25Data protection by design and by default
- Article 26Joint controllers
- Article 27Representatives of controllers or processors not established in the Union
- Article 28Processor
- Article 29Processing under the authority of the controller or processor
- Article 30Records of processing activities
- Article 31Cooperation with the supervisory authority
- Article 32Security of processing
- Article 33Notification of a personal data breach to the supervisory authority
- Article 34Communication of a personal data breach to the data subject
- Article 35Data protection impact assessment
- Article 36Prior consultation
- Article 37Designation of the data protection officer
- Article 38Position of the data protection officer
- Article 39Tasks of the data protection officer
- Article 40Codes of conduct
- Article 41Monitoring of approved codes of conduct
- Article 42Certification
- Article 43Certification bodies
Chapter V
Article 44+
- Article 44General principle for transfers
- Article 45Transfers on the basis of an adequacy decision
- Article 46Transfers subject to appropriate safeguards
- Article 47Binding corporate rules
- Article 48Transfers or disclosures not authorised by Union law
- Article 49Derogations for specific situations
- Article 50International cooperation for the protection of personal data
Chapter VI
Article 51+
- Article 51Supervisory authority
- Article 52Independence
- Article 53General conditions for the members of the supervisory authority
- Article 54Rules on the establishment of the supervisory authority
- Article 55Competence
- Article 56Competence of the lead supervisory authority
- Article 57Tasks
- Article 58Powers
- Article 59Activity reports
Chapter VII
Article 60+
- Article 60Cooperation between the lead supervisory authority and the other supervisory authorities concerned
- Article 61Mutual assistance
- Article 62Joint operations of supervisory authorities
- Article 63Consistency mechanism
- Article 64Opinion of the Board
- Article 65Dispute resolution by the Board
- Article 66Urgency procedure
- Article 67Exchange of information
- Article 68European Data Protection Board
- Article 69Independence
- Article 70Tasks of the Board
- Article 71Reports
- Article 72Procedure
- Article 73Chair
- Article 74Tasks of the Chair
- Article 75Secretariat
- Article 76Confidentiality
Chapter VIII
Article 77+
- Article 77Right to lodge a complaint with a supervisory authority
- Article 78Right to an effective judicial remedy against a supervisory authority
- Article 79Right to an effective judicial remedy against a controller or processor
- Article 80Representation of data subjects
- Article 81Suspension of proceedings
- Article 82Right to compensation and liability
- Article 83General conditions for imposing administrative fines
- Article 84Penalties
Chapter IX
Article 85+
- Article 85Processing and freedom of expression and information
- Article 86Processing and public access to official documents
- Article 87Processing of the national identification number
- Article 88Processing in the context of employment
- Article 89Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes
- Article 90Obligations of secrecy
- Article 91Existing data protection rules of churches and religious associations
Chapter X
Article 92+
