GDPR
General Data Protection Regulation (EU) 2016/679
- I. General Data Protection Regulation (GDPR)
- Ch. I — General Provisions
- Art. 1. Subject matter and objectives (1)
- Art. 2. Material scope (4)
- Art. 3. Territorial scope (4)
- Art. 4. Definitions (4)
- Ch. II — Principles
- Art. 5. Principles relating to processing of personal data (12)
- Art. 6. Lawfulness of processing (11)
- Art. 7. Conditions for consent (7)
- Art. 8. Conditions applicable to child's consent in relation to information society services (3)
- Art. 9. Processing of special categories of personal data (13)
- Art. 10. Processing of personal data relating to criminal convictions and offences (2)
- Art. 11. Processing which does not require identification (4)
- Ch. III — Rights of the Data Subject
- Art. 12. Transparent information, communication and modalities for the exercise of the rights of the data subject (16)
- Art. 13. Information to be provided where personal data are collected from the data subject (14)
- Art. 14. Information to be provided where personal data have not been obtained from the data subject (12)
- Art. 15. Right of access by the data subject (15)
- Art. 16. Right to rectification (2)
- Art. 17. Right to erasure (‘right to be forgotten’) (4)
- Art. 18. Right to restriction of processing (6)
- Art. 19. Notification obligation regarding rectification or erasure of personal data or restriction of processing (2)
- Art. 20. Right to data portability (5)
- Art. 21. Right to object (5)
- Art. 22. making, including profiling (10)
- Art. 23. Restrictions (11)
- Ch. IV — Controller and Processor
- Art. 24. Responsibility of the controller (3)
- Art. 25. Data protection by design and by default (7)
- Art. 26. Joint controllers (5)
- Art. 27. Representatives of controllers or processors not established in the Union (3)
- Art. 28. Processor (15)
- Art. 29. Processing under the authority of the controller or processor (2)
- Art. 30. Records of processing activities (17)
- Art. 31. Cooperation with the supervisory authority (3)
- Art. 32. Security of processing (7)
- Art. 33. Notification of a personal data breach to the supervisory authority (10)
- Art. 34. Communication of a personal data breach to the data subject (7)
- Art. 35. Data protection impact assessment (17)
- Art. 36. Prior consultation (7)
- Art. 37. Designation of the data protection officer (6)
- Art. 38. Position of the data protection officer (8)
- Art. 39. Tasks of the data protection officer (6)
- Art. 40. Codes of conduct (15)
- Art. 41. Monitoring of approved codes of conduct (8)
- Art. 42. Certification (7)
- Art. 43. Certification bodies (12)
- Ch. V — Transfers of Personal Data to Third Countries or International Organisations
- Art. 44. General principle for transfers (2)
- Art. 45. Transfers on the basis of an adequacy decision (11)
- Art. 46. Transfers subject to appropriate safeguards (8)
- Art. 47. Binding corporate rules ref
- Art. 48. Transfers or disclosures not authorised by Union law (1)
- Art. 49. Derogations for specific situations (10)
- Art. 50. International cooperation for the protection of personal data (4)
- Ch. VI — Independent Supervisory Authorities
- Art. 51. Supervisory authority (6)
- Art. 52. Independence (9)
- Art. 53. General conditions for the members of the supervisory authority (4)
- Art. 54. Rules on the establishment of the supervisory authority (8)
- Art. 55. Competence (3)
- Art. 56. Competence of the lead supervisory authority (9)
- Art. 57. Tasks (26)
- Art. 58. Powers (14)
- Art. 59. Activity reports (3)
- Ch. VII — Cooperation and Consistency
- Art. 60. Cooperation between the lead supervisory authority and the other supervisory authorities concerned (21)
- Art. 61. Mutual assistance (9)
- Art. 62. Joint operations of supervisory authorities (10)
- Art. 63. Consistency mechanism (2)
- Art. 64. Opinion of the Board (9)
- Art. 65. Dispute resolution by the Board (12)
- Art. 66. Urgency procedure (5)
- Art. 67. Exchange of information (2)
- Art. 68. European Data Protection Board (3)
- Art. 69. Independence (3)
- Art. 70. Tasks of the Board ref
- Art. 71. Reports (7)
- Art. 72. Procedure (3)
- Art. 73. Chair (2)
- Art. 74. Tasks of the Chair (4)
- Art. 75. Secretariat (13)
- Art. 76. Confidentiality (2)
- Ch. VIII — Remedies, Liability and Penalties
- Art. 77. Right to lodge a complaint with a supervisory authority (2)
- Art. 78. Right to an effective judicial remedy against a supervisory authority (4)
- Art. 79. Right to an effective judicial remedy against a controller or processor (3)
- Art. 80. Representation of data subjects (3)
- Art. 81. Suspension of proceedings (3)
- Art. 82. Right to compensation and liability (6)
- Art. 83. General conditions for imposing administrative fines (8)
- Art. 84. Penalties (3)
- Ch. IX — Provisions Relating to Specific Processing Situations
- Art. 85. Processing and freedom of expression and information (4)
- Art. 86. Processing and public access to official documents (2)
- Art. 87. Processing of the national identification number (1)
- Art. 88. Processing in the context of employment (4)
- Art. 89. Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes (5)
- Art. 90. Obligations of secrecy (4)
- Art. 91. Existing data protection rules of churches and religious associations (2)
- Ch. X — Delegated Acts and Implementing Acts
- Art. 92. Exercise of the delegation (3)
- Art. 93. Committee procedure (3)
- Ch. XI — Final Provisions
- Art. 94. Repeal of Directive 95/46/EC (2)
- Art. 95. Relationship with Directive 2002/58/EC (1)
- Art. 96. Relationship with previously concluded Agreements (1)
- Art. 97. Commission reports (6)
- Art. 98. Review of other Union legal acts on data protection (2)
- Art. 99. Entry into force and application (1)
Reporting Obligations
40Title I — General Data Protection Regulation (GDPR)
Chapter I — General Provisions
Chapter II — Principles
Chapter III — Rights of the Data Subject
Chapter IV — Controller and Processor
Article 30. Records of processing activities
1 obligation
Article 33. Notification of a personal data breach to the supervisory authority
3 obligations
GDPR-33-01
Reporting
Notify supervisory authority of personal data breach within 72 hours
Controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feas
GDPR-33-03
Reporting
Processor must notify controller of personal data breach
The processor must notify the controller without undue delay after becoming aware of a personal data breach.
GDPR-33-08
Reporting
Provide breach information in phases if necessary
Where it is not possible to provide all required breach notification information at the same time, the information may b
Article 34. Communication of a personal data breach to the data subject
1 obligation
Article 35. Data protection impact assessment
2 obligations
GDPR-35-07
Reporting
Communicate DPIA-required list to Board
The supervisory authority must communicate the list of processing operations requiring DPIA to the Board.
GDPR-35-09
Reporting
Communicate DPIA-exempt list to Board
The supervisory authority must communicate the list of processing operations exempt from DPIA to the Board.
Article 41. Monitoring of approved codes of conduct
1 obligation
Article 43. Certification bodies
3 obligations
GDPR-43-01
Reporting
Inform supervisory authority before issuing/renewing certification
Certification bodies must inform the supervisory authority before issuing and renewing certification to allow the superv
GDPR-43-09
Reporting
Provide reasons for certification decisions to supervisory authorities
Certification bodies must provide the competent supervisory authorities with the reasons for granting or withdrawing the
GDPR-43-11
Reporting
Transmit requirements and criteria to the Board
Supervisory authorities must transmit the requirements and criteria to the Board.
Chapter V — Transfers of Personal Data to Third Countries or International Organisations
Article 49. Derogations for specific situations
2 obligations
GDPR-49-07
Reporting
Inform supervisory authority of exceptional transfers
Controllers must inform the supervisory authority when making transfers based on compelling legitimate interests under t
GDPR-49-10
Reporting
Notify Commission of transfer limitations for public interest reasons
Member States must notify the Commission of any provisions that set limits to the transfer of specific categories of per
Chapter VI — Independent Supervisory Authorities
Article 51. Supervisory authority
1 obligation
Article 56. Competence of the lead supervisory authority
1 obligation
Article 58. Powers
1 obligation
Article 59. Activity reports
2 obligations
GDPR-59-01
Reporting
Draw up annual activity report
Each supervisory authority must prepare an annual report documenting its activities, which may include a list of types o
GDPR-59-02
Reporting
Transmit reports to national authorities
Supervisory authorities must transmit their annual activity reports to the national parliament, the government and other
Chapter VII — Cooperation and Consistency
Article 60. Cooperation between the lead supervisory authority and the other supervisory authorities concerned
1 obligation
Article 61. Mutual assistance
1 obligation
Article 65. Dispute resolution by the Board
2 obligations
GDPR-65-07
Reporting
Board Chair must inform Commission of decision
The Chair of the Board must inform the Commission of the Board's decision.
GDPR-65-10
Reporting
Supervisory authority must inform Board of final decision notification date
The lead supervisory authority or complaint supervisory authority must inform the Board of the date when its final decis
Article 66. Urgency procedure
1 obligation
Article 68. European Data Protection Board
1 obligation
Article 71. Reports
6 obligations
GDPR-71-01
Reporting
Draw up annual report on data protection
The Board must prepare an annual report regarding the protection of natural persons with regard to processing in the Uni
GDPR-71-03
Reporting
Transmit annual report to European Parliament
The Board must transmit the annual report to the European Parliament.
GDPR-71-04
Reporting
Transmit annual report to the Council
The Board must transmit the annual report to the Council.
GDPR-71-05
Reporting
Transmit annual report to the Commission
The Board must transmit the annual report to the Commission.
GDPR-71-06
Reporting
Include review of guidelines, recommendations and best practices in annual report
The annual report must include a review of the practical application of the guidelines, recommendations and best practic
GDPR-71-07
Reporting
Include review of binding decisions in annual report
The annual report must include a review of the binding decisions (referenced but not fully specified in the article text
Chapter VIII — Remedies, Liability and Penalties
Article 83. General conditions for imposing administrative fines
1 obligation
Article 84. Penalties
1 obligation
Chapter IX — Provisions Relating to Specific Processing Situations
Article 85. Processing and freedom of expression and information
2 obligations
GDPR-85-03
Reporting
Notify Commission of adopted provisions
Each Member State must notify the European Commission of the provisions of national law adopted pursuant to paragraph 2
GDPR-85-04
Reporting
Notify Commission of subsequent amendments without delay
Each Member State must notify the European Commission without delay of any subsequent amendment to the law or amendments
Article 88. Processing in the context of employment
2 obligations
GDPR-88-03
Reporting
Notify Commission of employment data protection laws by deadline
Each Member State must notify the Commission of the provisions of its law adopted pursuant to paragraph 1 by 25 May 2018
GDPR-88-04
Reporting
Report amendments to employment data protection laws without delay
Each Member State must notify the Commission without delay of any subsequent amendments to the employment data protectio
Article 90. Obligations of secrecy
2 obligations
GDPR-90-03
Reporting
Member States must notify Commission of adopted secrecy rules by 25 May 2018
Each Member State shall notify to the Commission the rules adopted pursuant to paragraph 1, by 25 May 2018 and, without
GDPR-90-04
Reporting
Member States must notify Commission of subsequent amendments without delay
Each Member State must notify the Commission without delay of any subsequent amendments to rules adopted pursuant to par
Chapter X — Delegated Acts and Implementing Acts
Article 92. Exercise of the delegation
1 obligation
Chapter XI — Final Provisions
Article 97. Commission reports
1 obligation