Privacy Laws
General Data Protection Regulation (EU) 2016/679
The EU data protection regulation, its scope, and the obligations it created for organisations that process personal data.
What the Regulation is
The GDPR is the binding text. It replaced Directive 95/46/EC, which set a floor that member states implemented with a great deal of variation, and it removed most of that variation by making the rules directly applicable.
Why it mattered
Three things changed in ways that were visible outside Europe:
- Territorial reach. Article 3 extends the Regulation to processing outside the EU where the processing relates to people in the EU. This is why a non-EU organisation with EU users had to read it.
- The fine scale. Administrative fines are expressed partly as a percentage of worldwide turnover, so enforcement is no longer limited by the size of a local operation.
- Enforceable individual rights. Access, rectification, erasure, portability, and objection are rights a person can exercise, not principles an organisation may consider.
What it did not do
The GDPR is a data protection instrument, not a secrecy instrument. It regulates the processing of personal data by identifiable controllers; it does not in general prohibit collection, and it says nothing about traffic analysis or metadata that does not relate to an identified person. It also has no extraterritorial application to non-personal-data surveillance, and enforcement remains national through data protection authorities.
The parts that get cited most
| Provision | Subject |
|---|---|
| Article 4 | Definitions, including personal data, processing, and pseudonymisation |
| Article 5 | Principles of processing |
| Article 6 | Lawful bases for processing |
| Article 13, 14 | Information to be provided to data subjects |
| Article 17 | Right to erasure |
| Article 20 | Data portability |
| Article 25 | Data protection by design and by default |
| Article 33, 34 | Breach notification to the authority and to data subjects |
| Article 35 | Data protection impact assessment |
| Article 44 onwards | International transfers |
| Article 83 | Administrative fines |
Transfers
Article 44 established that personal data may leave the European Economic Area only under one of the mechanisms in Chapter V. Adequacy decisions, appropriate safeguards such as standard contractual clauses, and derogations are the three routes. The adequacy decisions have been litigated repeatedly, which is why Schrems II is tracked separately.
Sources
- Regulation (EU) 2016/679 on EUR-Lex — the authoritative text. Article numbers cited above refer to this text.
- CELEX 32016R0679 — the same instrument with its consolidated versions, useful for amendments and corrigenda.
- CJEU case list for C-311/18 — the judgment that reshaped the transfer regime.
Claim labels
FACT
The Regulation was adopted on 27 April 2016 and became applicable from 25 May 2018.
FACT
Article 5 sets out the principles of processing, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.
FACT
Article 4(1) defines personal data as any information relating to an identified or identifiable natural person.
FACT
Article 17 establishes the right to erasure, commonly called the right to be forgotten, in enumerated circumstances.
FACT
Article 83 sets administrative fines up to EUR 20 million, or 4% of total worldwide annual turnover, whichever is higher, for the categories of infringement listed in the Article.
FACT
Article 25 requires data protection by design and by default for the processing of personal data.
SOURCE CLAIM
The European Commission has described the Regulation as making the EU the hardest jurisdiction in the world for data protection compliance. That is a characterisation by the regulator, not an independent finding.
Sources
Last link check: 2026-09-27. A link check confirms reachability, not that every claim has been independently reviewed.