Archive-Opsec

Search

/ to open · ↑↓ to move · Enter to open

Indexes guides, archive entries, news, resources and sources. Nothing is sent to a third party.

Archive categories

Privacy Laws

General Data Protection Regulation (EU) 2016/679

The EU data protection regulation, its scope, and the obligations it created for organisations that process personal data.

Event date 25 May 2018 Status In force Review UNCHECKED

What the Regulation is

The GDPR is the binding text. It replaced Directive 95/46/EC, which set a floor that member states implemented with a great deal of variation, and it removed most of that variation by making the rules directly applicable.

Why it mattered

Three things changed in ways that were visible outside Europe:

  1. Territorial reach. Article 3 extends the Regulation to processing outside the EU where the processing relates to people in the EU. This is why a non-EU organisation with EU users had to read it.
  2. The fine scale. Administrative fines are expressed partly as a percentage of worldwide turnover, so enforcement is no longer limited by the size of a local operation.
  3. Enforceable individual rights. Access, rectification, erasure, portability, and objection are rights a person can exercise, not principles an organisation may consider.

What it did not do

The GDPR is a data protection instrument, not a secrecy instrument. It regulates the processing of personal data by identifiable controllers; it does not in general prohibit collection, and it says nothing about traffic analysis or metadata that does not relate to an identified person. It also has no extraterritorial application to non-personal-data surveillance, and enforcement remains national through data protection authorities.

The parts that get cited most

ProvisionSubject
Article 4Definitions, including personal data, processing, and pseudonymisation
Article 5Principles of processing
Article 6Lawful bases for processing
Article 13, 14Information to be provided to data subjects
Article 17Right to erasure
Article 20Data portability
Article 25Data protection by design and by default
Article 33, 34Breach notification to the authority and to data subjects
Article 35Data protection impact assessment
Article 44 onwardsInternational transfers
Article 83Administrative fines

Transfers

Article 44 established that personal data may leave the European Economic Area only under one of the mechanisms in Chapter V. Adequacy decisions, appropriate safeguards such as standard contractual clauses, and derogations are the three routes. The adequacy decisions have been litigated repeatedly, which is why Schrems II is tracked separately.

Sources

Claim labels

FACT

The Regulation was adopted on 27 April 2016 and became applicable from 25 May 2018.

FACT

Article 5 sets out the principles of processing, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.

FACT

Article 4(1) defines personal data as any information relating to an identified or identifiable natural person.

FACT

Article 17 establishes the right to erasure, commonly called the right to be forgotten, in enumerated circumstances.

FACT

Article 83 sets administrative fines up to EUR 20 million, or 4% of total worldwide annual turnover, whichever is higher, for the categories of infringement listed in the Article.

FACT

Article 25 requires data protection by design and by default for the processing of personal data.

SOURCE CLAIM

The European Commission has described the Regulation as making the EU the hardest jurisdiction in the world for data protection compliance. That is a characterisation by the regulator, not an independent finding.

Sources

Last link check: 2026-09-27. A link check confirms reachability, not that every claim has been independently reviewed.

  1. Regulation (EU) 2016/679 (General Data Protection Regulation) Publications Office of the European Union regulator Accessed
  2. GDPR text on EUR-Lex, all consolidated versions Publications Office of the European Union regulator Accessed
  3. Schrems II (C-311/18) and the transfer mechanism in question Court of Justice of the European Union court Accessed