The GDPR, explained for the teams who build with personal data.
The GDPR — Regulation (EU) 2016/679 — is the EU's data protection law, applicable since 25 May 2018 and binding in its entirety in every Member State. It decides when you may process personal data at all, what the people in the data can demand from you, what you must have in place before something goes wrong, and what it costs when it does.
Who is in scope
Two scope dimensions — what the processing is, and where you or the people are — and the controller and processor roles that carry the duties.
The material test first. Article 2(1) applies the Regulation to processing of personal data wholly or partly by automated means, and to manual processing which forms part of a filing system or is intended to. The named exclusions are short: activities outside the scope of Union law, activities within the scope of Chapter 2 of Title V of the TEU, processing by a natural person in the course of a purely personal or household activity, and processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.
Then the territorial test. Article 3(1) covers processing in the context of the activities of an establishment of a controller or processor in the Union — wherever the processing itself takes place. Article 3(2) reaches controllers and processors with no Union establishment at all, where the processing relates to offering goods or services to data subjects who are in the Union, whether or not payment is required, or to monitoring their behaviour as far as it takes place within the Union. The wording matters: the trigger is people in the Union, not citizenship or residence paperwork. Article 3(3) adds a third route — a controller not established in the Union but in a place where Member State law applies by virtue of public international law. Either scope dimension alone is not enough: the processing must sit inside Article 2 and reach through one of the Article 3 routes.
The duties attach to roles that Article 4 defines. Personal data is any information relating to an identified or identifiable natural person — identifiable directly or indirectly, including by reference to an identifier such as a name, an identification number, location data or an online identifier. Processing is any operation performed on personal data, from collection and storage through disclosure to erasure. The controller determines the purposes and means of the processing, alone or jointly with others; the processor processes personal data on the controller's behalf. Which one you are is a question of fact about who decides — and Article 28(10) converts a processor that starts determining purposes and means into a controller for that processing.
Seven principles, six bases, one prohibition
Article 5 sets what all processing must look like. Article 6 decides whether it may happen at all. Article 9 closes a category of data behind stricter doors.
Article 5(1) names six principles every processing operation must satisfy: lawfulness, fairness and transparency; purpose limitation — collected for specified, explicit and legitimate purposes and not further processed incompatibly; data minimisation — adequate, relevant and limited to what is necessary; accuracy, with inaccurate data erased or rectified without delay; storage limitation — kept in identifiable form no longer than necessary; and integrity and confidentiality, processed with appropriate security. Article 5(2) adds the seventh, and it is the one audits turn on: accountability — the controller is responsible for, and must be able to demonstrate compliance with, all of the above.
Lawfulness is a closed list. Article 6(1) makes processing lawful only if at least one basis applies: consent; necessity for a contract with the data subject or pre-contractual steps at their request; necessity for compliance with a legal obligation on the controller; necessity to protect vital interests; necessity for a task in the public interest or official authority; or necessity for the legitimate interests of the controller or a third party, except where the interests or fundamental rights of the data subject override them — a basis public authorities cannot use in the performance of their tasks. Where the basis is consent, Article 7 sets the conditions: demonstrable, clearly distinguishable when bundled into a wider declaration, withdrawable at any time, and as easy to withdraw as it was to give. Article 7(4) makes conditioning a contract on unnecessary consent count against consent being freely given at all.
Article 9(1) then prohibits processing of the special categories outright: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a person, data concerning health, and data concerning sex life or sexual orientation. Article 9(2) reopens the door only through named exceptions — explicit consent, employment and social-security law, vital interests where consent is impossible, data manifestly made public by the data subject, legal claims, substantial public interest on a legal basis, health care and public health, and archiving and research under Article 89(1) safeguards among them — each exception carrying the legal-basis, necessity, proportionality and safeguard conditions its own Article 9(2) limb attaches. Article 9(4) lets Member States add further conditions for genetic, biometric and health data.
What the people in your data can demand
Chapter III gives data subjects enforceable rights against you — on a one-month information clock, free of charge in the ordinary case.
The procedure wraps every right. Article 12 requires the information and communications to be concise, transparent, intelligible and in clear and plain language; obliges the controller to “facilitate the exercise of data subject rights”; and starts a clock — information on action taken, without undue delay and in any event within one month of receipt, extendable by two further months where necessary for the complexity and number of the requests, if you explain the extension within the first month. Handling is free of charge unless a request is manifestly unfounded or excessive, and the controller carries the burden of demonstrating that. Article 13 front-loads transparency: at collection — except to the extent the data subject already has it — the data subject receives the controller's identity, the purposes and legal basis, the legitimate interests where that is the basis, recipients, any third-country transfer and its safeguards where applicable, the storage period, the list of rights, and more.
| Right | What it obliges you to do |
|---|---|
| Access — Art. 15 | Confirm whether you process data about the person and give access to it plus the purposes, categories, recipients, storage period, source where not collected from them, and the existence of automated decision-making with meaningful information about the logic. Provide a copy — electronically, if asked electronically. |
| Rectification — Art. 16 | Correct inaccurate data without undue delay and complete incomplete data, including by a supplementary statement. |
| Erasure — Art. 17 | Erase without undue delay on the listed grounds — data no longer necessary, consent withdrawn with no other basis, a successful objection, unlawful processing among them. Article 17(3) lists the exceptions — freedom of expression, legal obligations, public health, archiving and research, legal claims — each in the circumstances and on the conditions that paragraph attaches. If you made the data public, take reasonable steps to tell other controllers the person asked for links and copies to go. |
| Restriction — Art. 18 | Freeze processing while accuracy is contested, where processing is unlawful but the person prefers restriction to erasure, where they need the data for legal claims, or while an objection is being verified. Restricted data may still be stored — and otherwise processed only with the person's consent, for legal claims, to protect another person's rights, or for important public interests of the Union or a Member State. |
| Portability — Art. 20 | Hand over the data the person provided to you in a structured, commonly used and machine-readable format — and transmit it directly to another controller where technically feasible. Applies where the basis is consent or contract and the processing is automated; it does not apply to public-interest or official-authority processing, and it must not adversely affect the rights and freedoms of others. |
| Objection — Art. 21 | When the person objects on grounds relating to their particular situation, stop processing based on public-interest or legitimate-interest grounds unless you demonstrate compelling legitimate grounds that override the person's, or the processing serves legal claims. For direct marketing the objection is absolute: once made, the data are no longer processed for that purpose. The right must be brought to the person's attention explicitly, at the latest at first communication, separately from other information. |
| Automated decisions — Art. 22 | Respect the person's right not to be subject to a decision based solely on automated processing, profiling included, that produces legal effects or similarly significantly affects them — a right that does not apply where the decision is necessary for a contract, authorised by law with safeguards, or based on explicit consent. In the contract and consent cases, guarantee at least human intervention, the right to express a view and the right to contest. |
What you must have in place
The accountability duties run before, during and after the processing — and two of them come with clocks.
Build it in — Article 25
Article 25 obliges the controller to implement appropriate technical and organisational measures — pseudonymisation is the named example — both when determining the means of processing and during the processing itself, designed to implement the data-protection principles effectively. By default, only the personal data necessary for each specific purpose may be processed, and that default governs the amount collected, the extent of processing, the storage period and the accessibility — including that data are not made accessible to an indefinite number of people without the individual's intervention.
Contract your processors — Article 28
Article 28 allows only processors providing sufficient guarantees, bound by a contract that stipulates, among the listed terms: processing only on documented controller instructions, transfers included; confidentiality commitments; the Article 32 security measures; no sub-processor without prior written authorisation, with the same obligations flowing down and the initial processor remaining fully liable to the controller for the sub-processor's performance; assistance with data subject requests and with the controller's security, breach, impact-assessment and consultation duties; deletion or return of the data at the end of the engagement; and audits, inspections included. The processor must immediately flag an instruction it considers infringing.
Write it down — Article 30
Article 30 requires the controller to keep a record of its processing activities — purposes, categories of data subjects and data, recipients, transfers, envisaged erasure time limits, a general description of the security measures — and the processor to keep a record of the categories of processing it carries out on behalf of each controller. Both are kept in writing and made available to the supervisory authority on request. The Article 30(5) derogation for organisations under 250 persons applies only where the processing is unlikely to pose a risk, is occasional, and touches no special categories and no criminal-convictions data — three conditions that must all hold at once.
Secure it — Article 32
Article 32 requires the controller and the processor to implement measures appropriate to the risk, naming as candidates: pseudonymisation and encryption; the ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems; the ability to restore availability and access in a timely manner after an incident; and a process for regularly testing, assessing and evaluating the effectiveness of the measures. The risk assessment behind the choice looks in particular at accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Report the breach — Articles 33 and 34
| Supervisory authority — Art. 33 | Data subjects — Art. 34 | |
|---|---|---|
| Trigger | Every personal data breach, unless it is unlikely to result in a risk to the rights and freedoms of natural persons. | A breach likely to result in a high risk to the rights and freedoms of natural persons. |
| Clock | Without undue delay and, where feasible, within 72 hours of becoming aware; later notification carries reasons for the delay. Information may follow in phases, without undue further delay. The processor notifies the controller without undue delay. | Without undue delay, in clear and plain language, with at least the contact point, likely consequences and measures taken or proposed. |
| Way out | None for notifiable breaches — and Article 33(5) requires documenting every breach, notifiable or not, so the authority can verify compliance. | Not required where the affected data were made unintelligible to unauthorised persons — encryption is the named example — where later measures removed the high risk, or where individual notice takes disproportionate effort and a public communication informs people equally effectively. |
Assess it first, and appoint where required — Articles 35 and 37
Article 35 requires a data protection impact assessment before processing likely to result in a high risk — in particular systematic and extensive evaluation of personal aspects, based on automated processing, feeding decisions with legal or similar effects; large-scale processing of special categories or criminal-convictions data; and large-scale systematic monitoring of publicly accessible areas — with the DPO's advice sought where one is designated. Article 37 makes a data protection officer mandatory for public authorities and bodies (courts acting in their judicial capacity excepted) and for organisations whose core activities involve regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories and criminal-convictions data.
The Chapter V ladder
Adequacy first, safeguards second, derogations last — and the rule at the top governs onward transfers too.
Article 44 states the general principle: transfers to third countries or international organisations happen only under Chapter V's conditions — onward transfers from the destination included — so that the level of protection the Regulation guarantees is not undermined. The first rung is an Article 45 adequacy decision: the Commission has decided the third country, a territory or sector within it, or the organisation ensures an adequate level of protection, the transfer needs no specific authorisation, the Commission publishes the list in the Official Journal and reviews each decision at least every four years.
Absent adequacy, Article 46 requires appropriate safeguards plus enforceable data subject rights and effective remedies. The instruments that work without a supervisory authority's specific authorisation include the Commission's standard data protection clauses, binding corporate rules under Article 47, approved codes of conduct and approved certification mechanisms with binding commitments from the receiving side. Ad-hoc contractual clauses are possible with the competent authority's authorisation.
The last rung is Article 49: derogations for specific situations — explicit consent given after being informed of the risks, contract necessity, important reasons of public interest, legal claims, vital interests, and transfers from public registers on that limb's own conditions. Failing all of those, a transfer may still happen only if it is not repetitive, concerns a limited number of data subjects, is necessary for compelling legitimate interests not overridden by the data subject's, and rests on a documented assessment with suitable safeguards — with the supervisory authority and the data subject both informed, and the assessment kept in the Article 30 records.
Two fine tiers, plus the claims you owe individuals
Article 83 prices infringements by what was infringed. Articles 77 and 82 give individuals their own routes.
| Ceiling | What falls under it |
|---|---|
| EUR 10 000 000 or 2% — Art. 83(4) | The controller and processor obligations Article 83(4) enumerates — data protection by design and by default, processor contracts, records, security, breach notification, impact assessments and the DPO among them. For an undertaking, the ceiling is the higher of the euro figure and 2% of total worldwide annual turnover of the preceding financial year. |
| EUR 20 000 000 or 4% — Art. 83(5) | The provisions Article 83(5) enumerates — the basic principles including conditions for consent, the data subjects' rights, third-country transfers, obligations under Member State law adopted under Chapter IX, and non-compliance with a supervisory authority's order or limitation. Same higher-of construction for undertakings. |
| The factors — Art. 83(2) | Nature, gravity and duration; intentional or negligent character; mitigation; the degree of responsibility given the Article 25 and 32 measures; previous infringements; cooperation; the data categories affected; the manner in which the infringement became known — in particular whether, and to what extent, you notified it yourself; adherence to codes and certifications; and financial benefits gained or losses avoided. For linked infringements, the total stays within the ceiling for the gravest one. |
The fine is not the only exposure. Article 77 gives every data subject who considers that processing of their data infringes the Regulation the right to lodge a complaint with a supervisory authority — in the Member State of their habitual residence, place of work or the place of the alleged infringement, without prejudice to any other remedy. Article 82 gives any person who suffered material or non-material damage from an infringement the right to compensation from the controller or processor, with joint and several liability where several actors share responsibility, so each can be held liable for the entire damage.
Data law, next to the cyber laws
The GDPR protects the people in the data. The EU's cyber laws regulate entities and products. Treat overlapping duties as parallel, not interchangeable.
Article 1 states the subject-matter: rules relating to the protection of natural persons with regard to the processing of personal data, and to the free movement of personal data — a fundamental-rights law with no company-size threshold anywhere in its scope rules, which turn on the Article 2 and 3 tests, not on sector or size. Our NIS2, DORA and CRA explainers cover the laws whose triggers are being a regulated entity or placing a product on the market — each cited to its own text.
Treat the overlap as parallel duties, not substitutes. The Article 32 security duty stands on its own terms, and so does the breach duty: a personal data breach — unless it is unlikely to result in a risk to people's rights and freedoms — starts the Article 33 notification to the data protection authority, without undue delay and, where feasible, within 72 hours. The Article 33 text carries no carve-out for notifications made under other regimes, so the safe operating assumption is to map each duty to its own regime, addressee and threshold rather than assuming one notification covers all.
The date question that dominates the other pages barely exists here: Article 99 put the Regulation into application on 25 May 2018, binding in its entirety and directly applicable in all Member States. For GDPR work the moving parts are not commencement dates but the things that keep changing around a stable text — adequacy decisions under Article 45 with their four-yearly reviews, supervisory authority DPIA lists under Article 35(4), and Member State law in the areas the Regulation leaves open.
From article text to a cited gap analysis or DPIA
Every answer grounded in the regulation, in the AI client your team already uses.
The fastest way to see where you stand: a GDPR gap analysis and a DPIA are both workflow types on the Free tier — one run a month on a system you describe, reported as a watermarked document with every finding cited to the article it comes from. The sample gap analysis shows the deliverable shape end to end, and the sample DPIA shows the Article 35 deliverable specifically.
Two duties reward starting early: Article 30 records and Article 32 security measures are both lists you can start writing today, and both feed breach readiness — an Article 33 notification describes, where possible, the categories and approximate numbers of data subjects and records concerned, and the Article 30 record is where the categories already live. Threat modeling that doubles as compliance evidence — mapping each threat to the measure it satisfies — is covered in this walkthrough.
Questions teams ask about the GDPR
If your question is not here, email us — every message gets a human answer.
Does the GDPR apply to my company?
Two questions decide it: is the processing within the material scope of Article 2 — personal data processed wholly or partly by automated means, plus manual processing that forms or is intended to form part of a filing system — and is there a territorial hook under Article 3. Any one territorial route is enough: an establishment in the Union whose activities the processing relates to (Article 3(1)); with no Union establishment at all, offering goods or services to people who are in the Union, paid or not, or monitoring their behaviour there (Article 3(2)); or a place where Member State law applies by virtue of public international law (Article 3(3)). The trigger is people in the Union, not citizenship. Processing by a natural person in the course of a purely personal or household activity is excluded.
What are the GDPR fines?
Article 83 sets two ceilings. The lower tier, Article 83(4): up to EUR 10 000 000 or, for an undertaking, up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher — for the controller and processor obligations (records, security, breach notification, impact assessments and the DPO among them). The upper tier, Article 83(5): up to EUR 20 000 000 or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher — for the basic principles including consent, the data subjects' rights and third-country transfers. Article 82 adds private compensation claims, including for non-material damage.
What is the deadline for reporting a data breach?
The controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware — unless the breach is unlikely to result in a risk to people's rights and freedoms (Article 33). A later notification carries reasons for the delay, and information may follow in phases without undue further delay. A processor notifies the controller without undue delay. When the breach is likely to result in a high risk, Article 34 adds a second duty: tell the affected people without undue delay — not required where the data were made unintelligible to unauthorised persons (encryption is the named example), where the risk has since been removed, or where individual notice would involve disproportionate effort, in which case a public communication that informs people in an equally effective manner takes its place.
What counts as valid consent?
Freely given, specific, informed and unambiguous, given by a statement or a clear affirmative action (Article 4(11)). Article 7 adds the operating conditions: you must be able to demonstrate it; a consent request bundled into a wider declaration must be clearly distinguishable and in plain language; withdrawal must be possible at any time and as easy as giving consent was; and making a contract conditional on consent to unnecessary processing counts against the consent being freely given. Where special-category data under Article 9 rely on consent, it must be explicit.
When is a data protection impact assessment required?
Before any processing likely to result in a high risk to people's rights and freedoms, in particular with new technologies — the assessment comes prior to the processing (Article 35(1)). Article 35(3) names three cases in particular: systematic and extensive automated evaluation of personal aspects feeding decisions with legal or similarly significant effects; large-scale processing of special categories or criminal-convictions data; and large-scale systematic monitoring of publicly accessible areas. Your supervisory authority also publishes its own list of processing kinds that trigger the duty.
Do we need a data protection officer?
Article 37(1) makes designation mandatory in three cases: you are a public authority or body (courts acting in their judicial capacity excepted); your core activities require regular and systematic monitoring of data subjects on a large scale; or your core activities consist of large-scale processing of the Article 9 special categories and of criminal-convictions data. Otherwise designation is voluntary unless Union or Member State law requires it. A group of undertakings may appoint a single DPO, provided the DPO is easily accessible from each establishment.
Do small companies have to keep records of processing?
Often yes. Article 30(5) lifts the record-keeping duty below 250 employees only where the processing is not likely to pose a risk, is only occasional, and includes no special categories and no criminal-convictions data — all three at once. As a practical reading (the Regulation does not define occasional), processing that is a regular part of how the business runs is unlikely to qualify. For a controller the record is the Article 30(1) list — purposes, categories, recipients, transfers, erasure time limits, security measures; a processor keeps the narrower Article 30(2) record of the categories of processing it runs for each controller. Both are kept in writing and shown to the supervisory authority on request.
How do we transfer personal data outside the EU?
Chapter V is a ladder, and Article 44 makes it govern onward transfers too. First rung: an Article 45 adequacy decision — the Commission has decided the destination ensures adequate protection, and the transfer needs no specific authorisation. Second, absent adequacy: Article 46 appropriate safeguards with enforceable rights and remedies — the Commission's standard data protection clauses, binding corporate rules, or approved codes of conduct and certification mechanisms together with binding and enforceable commitments from the receiving side. Last rung: the Article 49 derogations for specific situations, explicit consent after being informed of the risks and contract necessity among them, with a tightly conditioned, documented one-off route at the very bottom.
See where you stand on the GDPR
A free-tier run produces a cited GDPR gap analysis or DPIA of a system you describe — one row per requirement, each anchored to its article. Start there, then bring your own documents on a paid plan.