Regulation (EU) 2018/1725 — data protection for EU institutions
The rules the European Data Protection Supervisor enforces.
What we read it for
The act that governs the EU bodies we read from, so a reader can see which rules the source itself works under.
Identity
| Type | Regulation |
| Identifier | EU 2018/1725 |
| CELEX | 32018R1725 |
| Adopted | 2018-10-23 |
| In force | 2018-12-11 |
| Applies from | 2018-12-11 |
99 articles in the base act
Structure
The chapter structure of this act is not read into the register yet. The official text carries it.
Articles
101 articles are read into the register, one address each.
- 1 · Subject matter and objectives
- 2 · Scope
- 3 · Definitions
- 4 · Principles relating to processing of personal data
- 5 · Lawfulness of processing
- 6 · Processing for another compatible purpose
- 7 · Conditions for consent
- 8 · Conditions applicable to a child’s consent in relation to information society services
- 9 · Transmissions of personal data to recipients established in the Union other than Union institutions and bodies
- 10 · Processing of special categories of personal data
- 11 · Processing of personal data relating to criminal convictions and offences
- 12 · Processing which does not require identification
- 13 · Safeguards relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes
- 14 · Transparent information, communication and modalities for the exercise of the rights of the data subject
- 15 · Information to be provided where personal data are collected from the data subject
- 16 · Information to be provided where personal data have not been obtained from the data subject
- 17 · Right of access by the data subject
- 18 · Right to rectification
- 19 · Right to erasure (‘right to be forgotten’)
- 20 · Right to restriction of processing
- 21 · Notification obligation regarding rectification or erasure of personal data or restriction of processing
- 22 · Right to data portability
- 23 · Right to object
- 24 · Automated individual decision-making, including profiling
- 25 · Restrictions
- 26 · Responsibility of the controller
- 27 · Data protection by design and by default
- 28 · Joint controllers
- 29 · Processor
- 30 · Processing under the authority of the controller or processor
- 31 · Records of processing activities
- 32 · Cooperation with the European Data Protection Supervisor
- 33 · Security of processing
- 34 · Notification of a personal data breach to the European Data Protection Supervisor
- 35 · Communication of a personal data breach to the data subject
- 36 · Confidentiality of electronic communications
- 37 · Protection of information transmitted to, stored in, related to, processed by and collected from users’ terminal equipment
- 38 · Directories of users
- 39 · Data protection impact assessment
- 40 · Prior consultation
- 41 · Information and consultation
- 42 · Legislative consultation
- 43 · Designation of the data protection officer
- 44 · Position of the data protection officer
- 45 · Tasks of the data protection officer
- 46 · General principle for transfers
- 47 · Transfers on the basis of an adequacy decision
- 48 · Transfers subject to appropriate safeguards
- 49 · Transfers or disclosures not authorised by Union law
- 50 · Derogations for specific situations
- 51 · International cooperation for the protection of personal data
- 52 · European Data Protection Supervisor
- 53 · Appointment of the European Data Protection Supervisor
- 54 · Regulations and general conditions governing the performance of the European Data Protection Supervisor’s duties, staff and financial resources
- 55 · Independence
- 56 · Professional secrecy
- 57 · Tasks
- 58 · Powers
- 59 · Obligation of controllers and processors to react to allegations
- 60 · Activities report
- 61 · Cooperation between the European Data Protection Supervisor and national supervisory authorities
- 62 · Coordinated supervision by the European Data Protection Supervisor and national supervisory authorities
- 63 · Right to lodge a complaint with the European Data Protection Supervisor
- 64 · Right to an effective judicial remedy
- 65 · Right to compensation
- 66 · Administrative fines
- 67 · Representation of data subjects
- 68 · Complaints by Union staff
- 69 · Sanctions
- 70 · Scope of the Chapter
- 71 · Principles relating to processing of operational personal data
- 72 · Lawfulness of processing of operational personal data
- 73 · Distinction between different categories of data subjects
- 74 · Distinction between operational personal data and verification of the quality of operational personal data
- 75 · Specific processing conditions
- 76 · Processing of special categories of operational personal data
- 77 · Automated individual decision-making, including profiling
- 78 · Communication and modalities for exercising the rights of the data subject
- 79 · Information to be made available or given to the data subject
- 80 · Right of access by the data subject
- 81 · Limitations to the right of access
- 82 · Right to rectification or erasure of operational personal data and restriction of processing
- 83 · Right of access in criminal investigations and proceedings
- 84 · Exercise of rights by the data subject and verification by the European Data Protection Supervisor
- 85 · Data protection by design and by default
- 86 · Joint controllers
- 87 · Processor
- 88 · Logging
- 89 · Data protection impact assessment
- 90 · Prior consultation of the European Data Protection Supervisor
- 91 · Security of processing of operational personal data
- 92 · Notification of a personal data breach to the European Data Protection Supervisor
- 93 · Communication of a personal data breach to the data subject
- 94 · Transfer of operational personal data to third countries and international organisations
- 95 · Secrecy of judicial inquiries and criminal proceedings
- 96 · Committee procedure
- 97 · Review clause
- 98 · Review of Union legal acts
- 99 · Repeal of Regulation (EC) No 45/2001 and of Decision No 1247/2002/EC
- 100 · Transitional measures
- 101 · Entry into force and application
Language versions
EUR-Lex publishes the act in every official language. These are the direct addresses for the languages this site is written in.
Norwegian is not an official EU language. Norwegian readers use the national register.
National law
One line per country. A line exists only when a primary source has been read; otherwise the national register is linked instead.
| National law | Identifier | Official text |
|---|---|---|
| Sweden: Outside this jurisdiction | — | National register |
| Norway: Outside this jurisdiction | — | National register |
| Denmark: Outside this jurisdiction | — | National register |
| Finland: Outside this jurisdiction | — | National register |
| Germany: Outside this jurisdiction | — | National register |
| United Kingdom: Outside this jurisdiction | — | National register |
National implementing measures on EUR-Lex
Supervision
Official text
EU acts, read down to the national law
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.