GDPR
General Data Protection Regulation (EU) 2016/679
- I. General Data Protection Regulation (GDPR)
- Ch. I — General Provisions
- Art. 1. Subject matter and objectives (1)
- Art. 2. Material scope (4)
- Art. 3. Territorial scope (4)
- Art. 4. Definitions (4)
- Ch. II — Principles
- Art. 5. Principles relating to processing of personal data (12)
- Art. 6. Lawfulness of processing (11)
- Art. 7. Conditions for consent (7)
- Art. 8. Conditions applicable to child's consent in relation to information society services (3)
- Art. 9. Processing of special categories of personal data (13)
- Art. 10. Processing of personal data relating to criminal convictions and offences (2)
- Art. 11. Processing which does not require identification (4)
- Ch. III — Rights of the Data Subject
- Art. 12. Transparent information, communication and modalities for the exercise of the rights of the data subject (16)
- Art. 13. Information to be provided where personal data are collected from the data subject (14)
- Art. 14. Information to be provided where personal data have not been obtained from the data subject (12)
- Art. 15. Right of access by the data subject (15)
- Art. 16. Right to rectification (2)
- Art. 17. Right to erasure (‘right to be forgotten’) (4)
- Art. 18. Right to restriction of processing (6)
- Art. 19. Notification obligation regarding rectification or erasure of personal data or restriction of processing (2)
- Art. 20. Right to data portability (5)
- Art. 21. Right to object (5)
- Art. 22. making, including profiling (10)
- Art. 23. Restrictions (11)
- Ch. IV — Controller and Processor
- Art. 24. Responsibility of the controller (3)
- Art. 25. Data protection by design and by default (7)
- Art. 26. Joint controllers (5)
- Art. 27. Representatives of controllers or processors not established in the Union (3)
- Art. 28. Processor (15)
- Art. 29. Processing under the authority of the controller or processor (2)
- Art. 30. Records of processing activities (17)
- Art. 31. Cooperation with the supervisory authority (3)
- Art. 32. Security of processing (7)
- Art. 33. Notification of a personal data breach to the supervisory authority (10)
- Art. 34. Communication of a personal data breach to the data subject (7)
- Art. 35. Data protection impact assessment (17)
- Art. 36. Prior consultation (7)
- Art. 37. Designation of the data protection officer (6)
- Art. 38. Position of the data protection officer (8)
- Art. 39. Tasks of the data protection officer (6)
- Art. 40. Codes of conduct (15)
- Art. 41. Monitoring of approved codes of conduct (8)
- Art. 42. Certification (7)
- Art. 43. Certification bodies (12)
- Ch. V — Transfers of Personal Data to Third Countries or International Organisations
- Art. 44. General principle for transfers (2)
- Art. 45. Transfers on the basis of an adequacy decision (11)
- Art. 46. Transfers subject to appropriate safeguards (8)
- Art. 47. Binding corporate rules ref
- Art. 48. Transfers or disclosures not authorised by Union law (1)
- Art. 49. Derogations for specific situations (10)
- Art. 50. International cooperation for the protection of personal data (4)
- Ch. VI — Independent Supervisory Authorities
- Art. 51. Supervisory authority (6)
- Art. 52. Independence (9)
- Art. 53. General conditions for the members of the supervisory authority (4)
- Art. 54. Rules on the establishment of the supervisory authority (8)
- Art. 55. Competence (3)
- Art. 56. Competence of the lead supervisory authority (9)
- Art. 57. Tasks (26)
- Art. 58. Powers (14)
- Art. 59. Activity reports (3)
- Ch. VII — Cooperation and Consistency
- Art. 60. Cooperation between the lead supervisory authority and the other supervisory authorities concerned (21)
- Art. 61. Mutual assistance (9)
- Art. 62. Joint operations of supervisory authorities (10)
- Art. 63. Consistency mechanism (2)
- Art. 64. Opinion of the Board (9)
- Art. 65. Dispute resolution by the Board (12)
- Art. 66. Urgency procedure (5)
- Art. 67. Exchange of information (2)
- Art. 68. European Data Protection Board (3)
- Art. 69. Independence (3)
- Art. 70. Tasks of the Board ref
- Art. 71. Reports (7)
- Art. 72. Procedure (3)
- Art. 73. Chair (2)
- Art. 74. Tasks of the Chair (4)
- Art. 75. Secretariat (13)
- Art. 76. Confidentiality (2)
- Ch. VIII — Remedies, Liability and Penalties
- Art. 77. Right to lodge a complaint with a supervisory authority (2)
- Art. 78. Right to an effective judicial remedy against a supervisory authority (4)
- Art. 79. Right to an effective judicial remedy against a controller or processor (3)
- Art. 80. Representation of data subjects (3)
- Art. 81. Suspension of proceedings (3)
- Art. 82. Right to compensation and liability (6)
- Art. 83. General conditions for imposing administrative fines (8)
- Art. 84. Penalties (3)
- Ch. IX — Provisions Relating to Specific Processing Situations
- Art. 85. Processing and freedom of expression and information (4)
- Art. 86. Processing and public access to official documents (2)
- Art. 87. Processing of the national identification number (1)
- Art. 88. Processing in the context of employment (4)
- Art. 89. Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes (5)
- Art. 90. Obligations of secrecy (4)
- Art. 91. Existing data protection rules of churches and religious associations (2)
- Ch. X — Delegated Acts and Implementing Acts
- Art. 92. Exercise of the delegation (3)
- Art. 93. Committee procedure (3)
- Ch. XI — Final Provisions
- Art. 94. Repeal of Directive 95/46/EC (2)
- Art. 95. Relationship with Directive 2002/58/EC (1)
- Art. 96. Relationship with previously concluded Agreements (1)
- Art. 97. Commission reports (6)
- Art. 98. Review of other Union legal acts on data protection (2)
- Art. 99. Entry into force and application (1)
Data Governance Obligations
64Title I — General Data Protection Regulation (GDPR)
Chapter I — General Provisions
Article 4. Definitions
1 obligation
Chapter II — Principles
Article 5. Principles relating to processing of personal data
1 obligation
Chapter III — Rights of the Data Subject
Article 14. Information to be provided where personal data have not been obtained from the data subject
1 obligation
Article 15. Right of access by the data subject
2 obligations
GDPR-15-13
Data Governance
Charge reasonable fees for additional copies
Controllers may charge a reasonable fee based on administrative costs for any additional copies of personal data request
GDPR-15-15
Data Governance
Protect rights and freedoms of others when providing data copies
Controllers must ensure that providing copies of personal data to data subjects does not adversely affect the rights and
Article 22. making, including profiling
3 obligations
GDPR-22-02
Data Governance
Contract Necessity Exception Compliance
When automated decision-making is necessary for entering into or performing a contract with the data subject, data contr
GDPR-22-04
Data Governance
Explicit Consent Exception Compliance
When automated decision-making is based on the data subject's explicit consent, data controllers must obtain and documen
GDPR-22-10
Data Governance
Special Safeguards for Special Category Data in Automated Decisions
When automated decisions involve special categories of personal data under Article 9(2)(a) or 9(2)(g) exceptions, data c
Chapter IV — Controller and Processor
Article 24. Responsibility of the controller
1 obligation
Article 25. Data protection by design and by default
4 obligations
GDPR-25-03
Data Governance
Apply default protection to data collection amount
The data protection by default obligation specifically applies to limiting the amount of personal data collected to what
GDPR-25-04
Data Governance
Apply default protection to processing extent
The data protection by default obligation specifically applies to limiting the extent of personal data processing to wha
GDPR-25-05
Data Governance
Apply default protection to storage period
The data protection by default obligation specifically applies to limiting the period of personal data storage to what i
GDPR-25-06
Data Governance
Apply default protection to data accessibility
The data protection by default obligation specifically applies to limiting the accessibility of personal data to what is
Article 26. Joint controllers
2 obligations
GDPR-26-01
Data Governance
Determine joint controllership transparently
When two or more controllers jointly determine the purposes and means of processing, they must transparently determine t
GDPR-26-02
Data Governance
Designate contact point for data subjects (optional)
Joint controllers may designate a contact point for data subjects in their arrangement to facilitate communication and e
Article 27. Representatives of controllers or processors not established in the Union
1 obligation
Article 28. Processor
1 obligation
Article 32. Security of processing
1 obligation
Article 34. Communication of a personal data breach to the data subject
1 obligation
Article 35. Data protection impact assessment
1 obligation
Article 37. Designation of the data protection officer
5 obligations
GDPR-37-01
Data Governance
Designate DPO for public authorities
Controllers and processors that are public authorities or bodies (except courts in judicial capacity) must designate a d
GDPR-37-02
Data Governance
Designate DPO for large-scale systematic monitoring
Controllers and processors whose core activities involve regular and systematic monitoring of data subjects on a large s
GDPR-37-03
Data Governance
Designate DPO for large-scale special category data processing
Controllers and processors whose core activities involve large-scale processing of special categories of data or persona
GDPR-37-04
Data Governance
Ensure DPO accessibility for group companies
When a group of undertakings appoints a single data protection officer, they must ensure the DPO is easily accessible fr
GDPR-37-05
Data Governance
Designate DPO based on professional qualifications
The data protection officer must be designated based on professional qualities, particularly expert knowledge of data pr
Article 38. Position of the data protection officer
1 obligation
Article 39. Tasks of the data protection officer
4 obligations
GDPR-39-01
Data Governance
DPO must inform and advise on data protection obligations
The data protection officer must inform and advise the controller or processor and employees who carry out processing of
GDPR-39-03
Data Governance
DPO must provide advice on data protection impact assessments
The data protection officer must provide advice when requested regarding data protection impact assessments and monitor
GDPR-39-04
Data Governance
DPO must cooperate with supervisory authority
The data protection officer must cooperate with the supervisory authority in the performance of their duties.
GDPR-39-05
Data Governance
DPO must act as contact point for supervisory authority
The data protection officer must act as the contact point for the supervisory authority on processing issues, including
Chapter V — Transfers of Personal Data to Third Countries or International Organisations
Article 44. General principle for transfers
1 obligation
Chapter VI — Independent Supervisory Authorities
Article 56. Competence of the lead supervisory authority
2 obligations
GDPR-56-01
Data Governance
Act as lead supervisory authority for cross-border processing
The supervisory authority of the main establishment or single establishment of the controller or processor must act as l
GDPR-56-09
Data Governance
Serve as sole interlocutor for cross-border processing
The lead supervisory authority must be the sole interlocutor of the controller or processor for the cross-border process
Article 57. Tasks
5 obligations
GDPR-57-07
Data Governance
Cooperate with other supervisory authorities
Supervisory authorities must cooperate with other supervisory authorities, including sharing information and providing m
GDPR-57-10
Data Governance
Adopt standard contractual clauses
Supervisory authorities must adopt standard contractual clauses as referred to in specific GDPR provisions
GDPR-57-20
Data Governance
Contribute to Board activities
Supervisory authorities must contribute to the activities of the European Data Protection Board
GDPR-57-22
Data Governance
Fulfill other personal data protection tasks
Supervisory authorities must fulfill any other tasks related to the protection of personal data
GDPR-57-25
Data Governance
Apply reasonable fees for manifestly unfounded/excessive requests
Supervisory authorities may charge a reasonable fee based on administrative costs or refuse to act on requests that are
Chapter VII — Cooperation and Consistency
Article 66. Urgency procedure
4 obligations
GDPR-66-01
Data Governance
Adopt provisional measures in urgent circumstances
In exceptional circumstances where there is an urgent need to protect data subject rights, a supervisory authority may i
GDPR-66-03
Data Governance
Request urgent opinion or binding decision from Board
Where a supervisory authority has taken provisional measures and considers final measures need urgent adoption, it may r
GDPR-66-04
Data Governance
Request urgent Board decision for inadequate supervisory action
Any supervisory authority may request an urgent opinion or binding decision from the Board where a competent supervisory
GDPR-66-05
Data Governance
Adopt urgent decisions within two weeks by simple majority
The Board must adopt urgent opinions or binding decisions referred to in paragraphs 2 and 3 within two weeks by simple m
Article 67. Exchange of information
1 obligation
Article 68. European Data Protection Board
1 obligation
Article 72. Procedure
3 obligations
GDPR-72-01
Data Governance
Board Decision-Making by Simple Majority
The European Data Protection Board must make decisions using a simple majority vote of its members, unless this Regulati
GDPR-72-02
Data Governance
Board Rules of Procedure Adoption
The European Data Protection Board must adopt its own rules of procedure, requiring a two-thirds majority vote of its me
GDPR-72-03
Data Governance
Board Operational Arrangements Organization
The European Data Protection Board must organize its own operational arrangements to facilitate its functioning and oper
Article 75. Secretariat
1 obligation
Article 76. Confidentiality
1 obligation
Chapter VIII — Remedies, Liability and Penalties
Article 78. Right to an effective judicial remedy against a supervisory authority
2 obligations
GDPR-78-01
Data Governance
Ensure right to effective judicial remedy against supervisory authority decisions
Must respect and not interfere with any natural or legal person's right to seek an effective judicial remedy against leg
GDPR-78-02
Data Governance
Ensure data subject judicial remedy for supervisory authority inaction
Must respect data subjects' right to effective judicial remedy when the competent supervisory authority fails to handle
Article 79. Right to an effective judicial remedy against a controller or processor
1 obligation
Article 80. Representation of data subjects
3 obligations
GDPR-80-01
Data Governance
Recognize data subject right to mandate not-for-profit representative
Data controllers and processors must recognize and respect the data subject's right to mandate a qualifying not-for-prof
GDPR-80-02
Data Governance
Allow Member States to provide independent complaint rights to qualifying bodies
Member States may establish legal frameworks allowing qualifying not-for-profit bodies to lodge complaints with supervis
GDPR-80-03
Data Governance
Accept complaints from independent qualifying representative bodies
Where Member State law provides for it, supervisory authorities must accept and process complaints lodged by qualifying
Chapter IX — Provisions Relating to Specific Processing Situations
Article 86. Processing and public access to official documents
2 obligations
GDPR-86-01
Data Governance
Comply with applicable law when disclosing personal data in official documents
When disclosing personal data contained in official documents to reconcile public access rights with data protection rig
GDPR-86-02
Data Governance
Balance public access rights with data protection rights in disclosure decisions
When handling requests for access to official documents containing personal data, authorities and bodies must reconcile
Article 87. Processing of the national identification number
1 obligation
Article 89. Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes
2 obligations
GDPR-89-01
Data Governance
Implement appropriate safeguards for special purpose processing
Organizations must implement appropriate safeguards in accordance with GDPR for the rights and freedoms of data subjects
GDPR-89-03
Data Governance
Use pseudonymisation where purposes can be fulfilled
Organizations may implement pseudonymisation as a safeguard measure provided that the archiving, research or statistical
Article 90. Obligations of secrecy
1 obligation
Article 91. Existing data protection rules of churches and religious associations
1 obligation
Chapter X — Delegated Acts and Implementing Acts
Article 93. Committee procedure
1 obligation
Chapter XI — Final Provisions
Article 96. Relationship with previously concluded Agreements
1 obligation