GDPR
General Data Protection Regulation (EU) 2016/679
- I. General Data Protection Regulation (GDPR)
- Ch. I — General Provisions
- Art. 1. Subject matter and objectives (1)
- Art. 2. Material scope (4)
- Art. 3. Territorial scope (4)
- Art. 4. Definitions (4)
- Ch. II — Principles
- Art. 5. Principles relating to processing of personal data (12)
- Art. 6. Lawfulness of processing (11)
- Art. 7. Conditions for consent (7)
- Art. 8. Conditions applicable to child's consent in relation to information society services (3)
- Art. 9. Processing of special categories of personal data (13)
- Art. 10. Processing of personal data relating to criminal convictions and offences (2)
- Art. 11. Processing which does not require identification (4)
- Ch. III — Rights of the Data Subject
- Art. 12. Transparent information, communication and modalities for the exercise of the rights of the data subject (16)
- Art. 13. Information to be provided where personal data are collected from the data subject (14)
- Art. 14. Information to be provided where personal data have not been obtained from the data subject (12)
- Art. 15. Right of access by the data subject (15)
- Art. 16. Right to rectification (2)
- Art. 17. Right to erasure (‘right to be forgotten’) (4)
- Art. 18. Right to restriction of processing (6)
- Art. 19. Notification obligation regarding rectification or erasure of personal data or restriction of processing (2)
- Art. 20. Right to data portability (5)
- Art. 21. Right to object (5)
- Art. 22. making, including profiling (10)
- Art. 23. Restrictions (11)
- Ch. IV — Controller and Processor
- Art. 24. Responsibility of the controller (3)
- Art. 25. Data protection by design and by default (7)
- Art. 26. Joint controllers (5)
- Art. 27. Representatives of controllers or processors not established in the Union (3)
- Art. 28. Processor (15)
- Art. 29. Processing under the authority of the controller or processor (2)
- Art. 30. Records of processing activities (17)
- Art. 31. Cooperation with the supervisory authority (3)
- Art. 32. Security of processing (7)
- Art. 33. Notification of a personal data breach to the supervisory authority (10)
- Art. 34. Communication of a personal data breach to the data subject (7)
- Art. 35. Data protection impact assessment (17)
- Art. 36. Prior consultation (7)
- Art. 37. Designation of the data protection officer (6)
- Art. 38. Position of the data protection officer (8)
- Art. 39. Tasks of the data protection officer (6)
- Art. 40. Codes of conduct (15)
- Art. 41. Monitoring of approved codes of conduct (8)
- Art. 42. Certification (7)
- Art. 43. Certification bodies (12)
- Ch. V — Transfers of Personal Data to Third Countries or International Organisations
- Art. 44. General principle for transfers (2)
- Art. 45. Transfers on the basis of an adequacy decision (11)
- Art. 46. Transfers subject to appropriate safeguards (8)
- Art. 47. Binding corporate rules ref
- Art. 48. Transfers or disclosures not authorised by Union law (1)
- Art. 49. Derogations for specific situations (10)
- Art. 50. International cooperation for the protection of personal data (4)
- Ch. VI — Independent Supervisory Authorities
- Art. 51. Supervisory authority (6)
- Art. 52. Independence (9)
- Art. 53. General conditions for the members of the supervisory authority (4)
- Art. 54. Rules on the establishment of the supervisory authority (8)
- Art. 55. Competence (3)
- Art. 56. Competence of the lead supervisory authority (9)
- Art. 57. Tasks (26)
- Art. 58. Powers (14)
- Art. 59. Activity reports (3)
- Ch. VII — Cooperation and Consistency
- Art. 60. Cooperation between the lead supervisory authority and the other supervisory authorities concerned (21)
- Art. 61. Mutual assistance (9)
- Art. 62. Joint operations of supervisory authorities (10)
- Art. 63. Consistency mechanism (2)
- Art. 64. Opinion of the Board (9)
- Art. 65. Dispute resolution by the Board (12)
- Art. 66. Urgency procedure (5)
- Art. 67. Exchange of information (2)
- Art. 68. European Data Protection Board (3)
- Art. 69. Independence (3)
- Art. 70. Tasks of the Board ref
- Art. 71. Reports (7)
- Art. 72. Procedure (3)
- Art. 73. Chair (2)
- Art. 74. Tasks of the Chair (4)
- Art. 75. Secretariat (13)
- Art. 76. Confidentiality (2)
- Ch. VIII — Remedies, Liability and Penalties
- Art. 77. Right to lodge a complaint with a supervisory authority (2)
- Art. 78. Right to an effective judicial remedy against a supervisory authority (4)
- Art. 79. Right to an effective judicial remedy against a controller or processor (3)
- Art. 80. Representation of data subjects (3)
- Art. 81. Suspension of proceedings (3)
- Art. 82. Right to compensation and liability (6)
- Art. 83. General conditions for imposing administrative fines (8)
- Art. 84. Penalties (3)
- Ch. IX — Provisions Relating to Specific Processing Situations
- Art. 85. Processing and freedom of expression and information (4)
- Art. 86. Processing and public access to official documents (2)
- Art. 87. Processing of the national identification number (1)
- Art. 88. Processing in the context of employment (4)
- Art. 89. Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes (5)
- Art. 90. Obligations of secrecy (4)
- Art. 91. Existing data protection rules of churches and religious associations (2)
- Ch. X — Delegated Acts and Implementing Acts
- Art. 92. Exercise of the delegation (3)
- Art. 93. Committee procedure (3)
- Ch. XI — Final Provisions
- Art. 94. Repeal of Directive 95/46/EC (2)
- Art. 95. Relationship with Directive 2002/58/EC (1)
- Art. 96. Relationship with previously concluded Agreements (1)
- Art. 97. Commission reports (6)
- Art. 98. Review of other Union legal acts on data protection (2)
- Art. 99. Entry into force and application (1)
Title I — General Data Protection Regulation (GDPR)
Chapter I — General Provisions
Chapter II — Principles
Chapter III — Rights of the Data Subject
Chapter IV — Controller and Processor
Chapter V — Transfers of Personal Data to Third Countries or International Organisations
Chapter VI — Independent Supervisory Authorities
Chapter VII — Cooperation and Consistency
Article 64. Opinion of the Board
3 obligations
GDPR-64-07
Prohibition
Supervisory Authority Prohibited from Adopting Draft Decision During Opinion Period
The competent supervisory authority must not adopt its draft decision within the period referred to in paragraph 3 (the
GDPR-64-08
Requirement
Supervisory Authority Must Take Utmost Account of Board Opinion
The competent supervisory authority must take utmost account of the opinion of the Board when making its final decision.
GDPR-64-09
Requirement
Supervisory Authority Must Communicate Decision Status Within Two Weeks
The supervisory authority must communicate to the Chair of the Board within two weeks after receiving the opinion whethe
Article 65. Dispute resolution by the Board
12 obligations
GDPR-65-01
Requirement
Board must adopt binding decisions in specified dispute cases
The Board shall adopt a binding decision in cases where: (a) a supervisory authority has raised a relevant and reasoned
GDPR-65-02
Requirement
Board must adopt decisions within one month by two-thirds majority
The Board must adopt binding decisions within one month from referral by a two-thirds majority of members, with the peri
GDPR-65-03
Transparency
Board decisions must be reasoned and addressed to relevant authorities
Board decisions must be reasoned and addressed to the lead supervisory authority and all supervisory authorities concern
GDPR-65-04
Requirement
Board must adopt decision by simple majority if unable to meet deadline
If the Board cannot adopt a decision within the specified periods, it must adopt its decision within two weeks following
GDPR-65-05
Prohibition
Supervisory authorities prohibited from deciding during Board consideration
Supervisory authorities concerned shall not adopt a decision on the subject matter submitted to the Board during the per
GDPR-65-06
Requirement
Board Chair must notify decision to supervisory authorities without undue delay
The Chair of the Board must notify the Board's decision to the supervisory authorities concerned without undue delay.
GDPR-65-07
Reporting
Board Chair must inform Commission of decision
The Chair of the Board must inform the Commission of the Board's decision.
GDPR-65-08
Transparency
Board must publish decision on website without delay
The Board must publish its decision on its website without delay after the supervisory authority has notified the final
GDPR-65-09
Requirement
Lead/complaint supervisory authority must adopt final decision based on Board decision
The lead supervisory authority or the supervisory authority with which the complaint was lodged must adopt its final dec
GDPR-65-10
Reporting
Supervisory authority must inform Board of final decision notification date
The lead supervisory authority or complaint supervisory authority must inform the Board of the date when its final decis
GDPR-65-11
Transparency
Final decision must refer to Board decision and specify publication
The final decision must refer to the Board's decision and specify that the Board's decision will be published on the Boa
GDPR-65-12
Transparency
Final decision must attach Board decision
The supervisory authority's final decision must attach the Board's decision as an appendix.
Article 66. Urgency procedure
5 obligations
GDPR-66-01
Data Governance
Adopt provisional measures in urgent circumstances
In exceptional circumstances where there is an urgent need to protect data subject rights, a supervisory authority may i
GDPR-66-02
Reporting
Communicate provisional measures without delay
The supervisory authority must immediately communicate adopted provisional measures and the reasons for adopting them to
GDPR-66-03
Data Governance
Request urgent opinion or binding decision from Board
Where a supervisory authority has taken provisional measures and considers final measures need urgent adoption, it may r
GDPR-66-04
Data Governance
Request urgent Board decision for inadequate supervisory action
Any supervisory authority may request an urgent opinion or binding decision from the Board where a competent supervisory
GDPR-66-05
Data Governance
Adopt urgent decisions within two weeks by simple majority
The Board must adopt urgent opinions or binding decisions referred to in paragraphs 2 and 3 within two weeks by simple m
Article 67. Exchange of information
2 obligations
GDPR-67-01
Data Governance
Commission may adopt implementing acts for information exchange arrangements
The European Commission is authorized to adopt implementing acts of general scope to specify arrangements for electronic
GDPR-67-02
Conformity
Commission must follow examination procedure for implementing acts
When adopting implementing acts for information exchange arrangements, the European Commission must follow the examinati
Article 68. European Data Protection Board
3 obligations
GDPR-68-01
Data Governance
Appoint joint representative for multiple supervisory authorities
Where in a Member State more than one supervisory authority is responsible for monitoring the application of the provisi
GDPR-68-02
Requirement
Commission designate representative to Board
The Commission shall designate a representative to participate in the activities and meetings of the Board.
GDPR-68-03
Reporting
Board Chair communicate activities to Commission
The Chair of the Board shall communicate to the Commission the activities of the Board.