General Data Protection Regulation

Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR)

Background and Scope

The regulation sets out rules for the protection of natural persons with regard to the processing of personal data and the free movement of such data within the EU. Building on the need for a more coherent data protection framework, the GDPR replaced Directive 95/46/EC and introduced a uniform, directly applicable regime supported by consistent enforcement across all Member States.

The regulation applies to the processing of personal data wholly or partly by automated means, as well as to non-automated processing of personal data that forms part of a filing system. It covers processing carried out by controllers and processors established in the EU, regardless of where the processing takes place. Non-EU established entities fall within scope where they direct goods or services to individuals in the EU or monitor their behavior. The regulation protects natural persons regardless of nationality or place of residence and does not extend to the processing of data relating to legal persons.

At its core, the GDPR imposes obligations on controllers and processors covering, among other things, the requirement for a lawful basis for processing, transparency obligations towards data subjects, and a range of individual rights including access, rectification, and erasure. Processing activities falling outside the scope of EU law and processing by competent authorities for law enforcement purposes are excluded and regulated under separate legislation.

Key Obligations

  • Lawful basis for processing: All processing of personal data must be based on one of the six legal grounds set out in the regulation: consent, contract, legal obligation, vital interests, public interest/official authority, or legitimate interests.
  • Principles for processing: Personal data must be processed lawfully, fairly and transparently, collected for specified purposes, limited to what is necessary, and protected by appropriate technical and organisational measures.
  • Transparency and information obligations: Controllers must proactively provide data subjects with clear and accessible information about how their personal data is being processed.
  • Data subject rights: Controllers are required to facilitate individual rights including the right of access, rectification, erasure, data portability, and the right to object to processing.
  • Accountability: Controllers must not only comply with the regulation’s requirements but also be able to demonstrate that compliance is in place.
  • Personal data breach notification: In the event of a security incident involving personal data, the supervisory authority must be notified without undue delay and, where there is a high risk to individuals, those affected must also be informed.
2027 April 2, 2027

Regulation (EU) 2025/2518 applies, introducing harmonised procedural rules for the handling of cross-border complaints and investigations under the GDPR, aimed at ensuring faster and more consistent enforcement across Member States.

2016 May 25, 2016

The GDPR became applicable across all EU Member States, replacing Directive 95/46/EC.

2016 May 24, 2016

The GDPR entered into force, twenty days after publication in the Official Journal of the EU.

2016 April 27, 2016

The GDPR was adopted by the European Parliament and the Council in Brussels.