GDPR — Regulation (EU) 2016/679
Protection of personal data and free movement of such data.
What we read it for
The act our reading of public sources is measured against: lawful basis, purpose limitation and the rights of the person a page mentions.
Identity
| Type | Regulation |
| Identifier | EU 2016/679 |
| CELEX | 32016R0679 |
| Adopted | 2016-04-27 |
| In force | 2016-05-24 |
| Applies from | 2018-05-25 |
99 articles in the base act
Structure
| Chapter | Act | Articles |
|---|---|---|
| I | General provisions | 1–4 |
| II | Principles | 5–11 |
| III | Rights of the data subject | 12–23 |
| IV | Controller and processor | 24–43 |
| V | Transfers of personal data to third countries or international organisations | 44–50 |
| VI | Independent supervisory authorities | 51–59 |
| VII | Cooperation and consistency | 60–76 |
| VIII | Remedies, liability and penalties | 77–84 |
| IX | Provisions relating to specific processing situations | 85–91 |
| X | Delegated acts and implementing acts | 92–93 |
| XI | Final provisions | 94–99 |
Articles
99 articles are read into the register, one address each.
- 1 · Subject-matter and objectives
- 2 · Material scope
- 3 · Territorial scope
- 4 · Definitions
- 5 · Principles relating to processing of personal data
- 6 · Lawfulness of processing
- 7 · Conditions for consent
- 8 · Conditions applicable to child's consent in relation to information society services
- 9 · Processing of special categories of personal data
- 10 · Processing of personal data relating to criminal convictions and offences
- 11 · Processing which does not require identification
- 12 · Transparent information, communication and modalities for the exercise of the rights of the data subject
- 13 · Information to be provided where personal data are collected from the data subject
- 14 · Information to be provided where personal data have not been obtained from the data subject
- 15 · Right of access by the data subject
- 16 · Right to rectification
- 17 · Right to erasure (‘right to be forgotten’)
- 18 · Right to restriction of processing
- 19 · Notification obligation regarding rectification or erasure of personal data or restriction of processing
- 20 · Right to data portability
- 21 · Right to object
- 22 · Automated individual decision-making, including profiling
- 23 · Restrictions
- 24 · Responsibility of the controller
- 25 · Data protection by design and by default
- 26 · Joint controllers
- 27 · Representatives of controllers or processors not established in the Union
- 28 · Processor
- 29 · Processing under the authority of the controller or processor
- 30 · Records of processing activities
- 31 · Cooperation with the supervisory authority
- 32 · Security of processing
- 33 · Notification of a personal data breach to the supervisory authority
- 34 · Communication of a personal data breach to the data subject
- 35 · Data protection impact assessment
- 36 · Prior consultation
- 37 · Designation of the data protection officer
- 38 · Position of the data protection officer
- 39 · Tasks of the data protection officer
- 40 · Codes of conduct
- 41 · Monitoring of approved codes of conduct
- 42 · Certification
- 43 · Certification bodies
- 44 · General principle for transfers
- 45 · Transfers on the basis of an adequacy decision
- 46 · Transfers subject to appropriate safeguards
- 47 · Binding corporate rules
- 48 · Transfers or disclosures not authorised by Union law
- 49 · Derogations for specific situations
- 50 · International cooperation for the protection of personal data
- 51 · Supervisory authority
- 52 · Independence
- 53 · General conditions for the members of the supervisory authority
- 54 · Rules on the establishment of the supervisory authority
- 55 · Competence
- 56 · Competence of the lead supervisory authority
- 57 · Tasks
- 58 · Powers
- 59 · Activity reports
- 60 · Cooperation between the lead supervisory authority and the other supervisory authorities concerned
- 61 · Mutual assistance
- 62 · Joint operations of supervisory authorities
- 63 · Consistency mechanism
- 64 · Opinion of the Board
- 65 · Dispute resolution by the Board
- 66 · Urgency procedure
- 67 · Exchange of information
- 68 · European Data Protection Board
- 69 · Independence
- 70 · Tasks of the Board
- 71 · Reports
- 72 · Procedure
- 73 · Chair
- 74 · Tasks of the Chair
- 75 · Secretariat
- 76 · Confidentiality
- 77 · Right to lodge a complaint with a supervisory authority
- 78 · Right to an effective judicial remedy against a supervisory authority
- 79 · Right to an effective judicial remedy against a controller or processor
- 80 · Representation of data subjects
- 81 · Suspension of proceedings
- 82 · Right to compensation and liability
- 83 · General conditions for imposing administrative fines
- 84 · Penalties
- 85 · Processing and freedom of expression and information
- 86 · Processing and public access to official documents
- 87 · Processing of the national identification number
- 88 · Processing in the context of employment
- 89 · Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes
- 90 · Obligations of secrecy
- 91 · Existing data protection rules of churches and religious associations
- 92 · Exercise of the delegation
- 93 · Committee procedure
- 94 · Repeal of Directive 95/46/EC
- 95 · Relationship with Directive 2002/58/EC
- 96 · Relationship with previously concluded Agreements
- 97 · Commission reports
- 98 · Review of other Union legal acts on data protection
- 99 · Entry into force and application
Language versions
EUR-Lex publishes the act in every official language. These are the direct addresses for the languages this site is written in.
Norwegian is not an official EU language. Norwegian readers use the national register.
National law
One line per country. A line exists only when a primary source has been read; otherwise the national register is linked instead.
| National law | Identifier | Official text |
|---|---|---|
| Sweden: Lag med kompletterande bestämmelser till EU:s dataskyddsförordning | SFS 2018:218 | Official text |
| Norway: Lov om behandling av personopplysninger (personopplysningsloven) | LOV-2018-06-15-38 | Official text |
| Denmark: Lov om supplerende bestemmelser til forordning om beskyttelse af fysiske personer (databeskyttelsesloven) | LOV nr 502 af 23/05/2018 | Official text |
| Finland: Tietosuojalaki | 1050/2018 | Official text |
| Germany: Bundesdatenschutzgesetz | BDSG | Official text |
| United Kingdom: Data Protection Act 2018 | 2018 c. 12 | Official text |
National implementing measures on EUR-Lex
Supervision
Official text
EU acts, read down to the national law
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.