GDPR
General Data Protection Regulation (EU) 2016/679
- I. General Data Protection Regulation (GDPR)
- Ch. I — General Provisions
- Art. 1. Subject matter and objectives (1)
- Art. 2. Material scope (4)
- Art. 3. Territorial scope (4)
- Art. 4. Definitions (4)
- Ch. II — Principles
- Art. 5. Principles relating to processing of personal data (12)
- Art. 6. Lawfulness of processing (11)
- Art. 7. Conditions for consent (7)
- Art. 8. Conditions applicable to child's consent in relation to information society services (3)
- Art. 9. Processing of special categories of personal data (13)
- Art. 10. Processing of personal data relating to criminal convictions and offences (2)
- Art. 11. Processing which does not require identification (4)
- Ch. III — Rights of the Data Subject
- Art. 12. Transparent information, communication and modalities for the exercise of the rights of the data subject (16)
- Art. 13. Information to be provided where personal data are collected from the data subject (14)
- Art. 14. Information to be provided where personal data have not been obtained from the data subject (12)
- Art. 15. Right of access by the data subject (15)
- Art. 16. Right to rectification (2)
- Art. 17. Right to erasure (‘right to be forgotten’) (4)
- Art. 18. Right to restriction of processing (6)
- Art. 19. Notification obligation regarding rectification or erasure of personal data or restriction of processing (2)
- Art. 20. Right to data portability (5)
- Art. 21. Right to object (5)
- Art. 22. making, including profiling (10)
- Art. 23. Restrictions (11)
- Ch. IV — Controller and Processor
- Art. 24. Responsibility of the controller (3)
- Art. 25. Data protection by design and by default (7)
- Art. 26. Joint controllers (5)
- Art. 27. Representatives of controllers or processors not established in the Union (3)
- Art. 28. Processor (15)
- Art. 29. Processing under the authority of the controller or processor (2)
- Art. 30. Records of processing activities (17)
- Art. 31. Cooperation with the supervisory authority (3)
- Art. 32. Security of processing (7)
- Art. 33. Notification of a personal data breach to the supervisory authority (10)
- Art. 34. Communication of a personal data breach to the data subject (7)
- Art. 35. Data protection impact assessment (17)
- Art. 36. Prior consultation (7)
- Art. 37. Designation of the data protection officer (6)
- Art. 38. Position of the data protection officer (8)
- Art. 39. Tasks of the data protection officer (6)
- Art. 40. Codes of conduct (15)
- Art. 41. Monitoring of approved codes of conduct (8)
- Art. 42. Certification (7)
- Art. 43. Certification bodies (12)
- Ch. V — Transfers of Personal Data to Third Countries or International Organisations
- Art. 44. General principle for transfers (2)
- Art. 45. Transfers on the basis of an adequacy decision (11)
- Art. 46. Transfers subject to appropriate safeguards (8)
- Art. 47. Binding corporate rules ref
- Art. 48. Transfers or disclosures not authorised by Union law (1)
- Art. 49. Derogations for specific situations (10)
- Art. 50. International cooperation for the protection of personal data (4)
- Ch. VI — Independent Supervisory Authorities
- Art. 51. Supervisory authority (6)
- Art. 52. Independence (9)
- Art. 53. General conditions for the members of the supervisory authority (4)
- Art. 54. Rules on the establishment of the supervisory authority (8)
- Art. 55. Competence (3)
- Art. 56. Competence of the lead supervisory authority (9)
- Art. 57. Tasks (26)
- Art. 58. Powers (14)
- Art. 59. Activity reports (3)
- Ch. VII — Cooperation and Consistency
- Art. 60. Cooperation between the lead supervisory authority and the other supervisory authorities concerned (21)
- Art. 61. Mutual assistance (9)
- Art. 62. Joint operations of supervisory authorities (10)
- Art. 63. Consistency mechanism (2)
- Art. 64. Opinion of the Board (9)
- Art. 65. Dispute resolution by the Board (12)
- Art. 66. Urgency procedure (5)
- Art. 67. Exchange of information (2)
- Art. 68. European Data Protection Board (3)
- Art. 69. Independence (3)
- Art. 70. Tasks of the Board ref
- Art. 71. Reports (7)
- Art. 72. Procedure (3)
- Art. 73. Chair (2)
- Art. 74. Tasks of the Chair (4)
- Art. 75. Secretariat (13)
- Art. 76. Confidentiality (2)
- Ch. VIII — Remedies, Liability and Penalties
- Art. 77. Right to lodge a complaint with a supervisory authority (2)
- Art. 78. Right to an effective judicial remedy against a supervisory authority (4)
- Art. 79. Right to an effective judicial remedy against a controller or processor (3)
- Art. 80. Representation of data subjects (3)
- Art. 81. Suspension of proceedings (3)
- Art. 82. Right to compensation and liability (6)
- Art. 83. General conditions for imposing administrative fines (8)
- Art. 84. Penalties (3)
- Ch. IX — Provisions Relating to Specific Processing Situations
- Art. 85. Processing and freedom of expression and information (4)
- Art. 86. Processing and public access to official documents (2)
- Art. 87. Processing of the national identification number (1)
- Art. 88. Processing in the context of employment (4)
- Art. 89. Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes (5)
- Art. 90. Obligations of secrecy (4)
- Art. 91. Existing data protection rules of churches and religious associations (2)
- Ch. X — Delegated Acts and Implementing Acts
- Art. 92. Exercise of the delegation (3)
- Art. 93. Committee procedure (3)
- Ch. XI — Final Provisions
- Art. 94. Repeal of Directive 95/46/EC (2)
- Art. 95. Relationship with Directive 2002/58/EC (1)
- Art. 96. Relationship with previously concluded Agreements (1)
- Art. 97. Commission reports (6)
- Art. 98. Review of other Union legal acts on data protection (2)
- Art. 99. Entry into force and application (1)
Title I — General Data Protection Regulation (GDPR)
Chapter I — General Provisions
Chapter II — Principles
Chapter III — Rights of the Data Subject
Chapter IV — Controller and Processor
Chapter V — Transfers of Personal Data to Third Countries or International Organisations
Chapter VI — Independent Supervisory Authorities
Chapter VII — Cooperation and Consistency
Article 74. Tasks of the Chair
1 obligation
Article 75. Secretariat
13 obligations
GDPR-75-01
Requirement
European Data Protection Supervisor must provide Board secretariat
The European Data Protection Supervisor must provide a secretariat for the Board
GDPR-75-02
Requirement
Secretariat must perform tasks under Board Chair instructions
The secretariat must perform all its tasks exclusively under the instructions of the Chair of the Board
GDPR-75-03
Data Governance
Maintain separate reporting lines for Board secretariat staff
Staff of the European Data Protection Supervisor involved in Board tasks must have separate reporting lines from staff c
GDPR-75-04
Documentation
Establish Memorandum of Understanding when appropriate
The Board and the European Data Protection Supervisor must establish a Memorandum of Understanding when appropriate, det
GDPR-75-05
Transparency
Publish Memorandum of Understanding when established
When a Memorandum of Understanding is established between the Board and European Data Protection Supervisor, it must be
GDPR-75-06
Requirement
Provide analytical, administrative and logistical support
The secretariat must provide analytical, administrative and logistical support to the Board
GDPR-75-07
Requirement
Handle day-to-day business of the Board
The secretariat must be responsible for the day-to-day business of the Board
GDPR-75-08
Requirement
Facilitate communication between Board members, Chair and Commission
The secretariat must be responsible for communication between the members of the Board, its Chair and the Commission
GDPR-75-09
Requirement
Manage communication with other institutions and public
The secretariat must be responsible for communication with other institutions and the public
GDPR-75-10
Requirement
Use electronic means for internal and external communication
The secretariat must be responsible for the use of electronic means for both internal and external communication
GDPR-75-11
Requirement
Provide translation of relevant information
The secretariat must be responsible for the translation of relevant information
GDPR-75-12
Requirement
Prepare and follow-up Board meetings
The secretariat must be responsible for the preparation and follow-up of the meetings of the Board
GDPR-75-13
Requirement
Prepare, draft and publish Board outputs
The secretariat must be responsible for the preparation, drafting and publication of opinions, decisions on dispute sett
Article 76. Confidentiality
2 obligations
GDPR-76-01
Data Governance
Board confidentiality determination
The Board must determine when discussions need to be confidential in accordance with its rules of procedure and ensure s
GDPR-76-02
Transparency
Document access governance under Regulation 1049/2001
Access to documents submitted to Board members, experts and third party representatives must be governed by and comply w
Chapter VIII — Remedies, Liability and Penalties
Article 77. Right to lodge a complaint with a supervisory authority
2 obligations
GDPR-77-01
Requirement
Ensure data subjects can lodge complaints with supervisory authorities
Organizations must not interfere with or prevent data subjects from exercising their right to lodge complaints with supe
GDPR-77-02
Transparency
Inform complainants on progress and outcome of complaints
Supervisory authorities must provide updates to complainants regarding the progress and final outcome of their complaint
Article 78. Right to an effective judicial remedy against a supervisory authority
4 obligations
GDPR-78-01
Data Governance
Ensure right to effective judicial remedy against supervisory authority decisions
Must respect and not interfere with any natural or legal person's right to seek an effective judicial remedy against leg
GDPR-78-02
Data Governance
Ensure data subject judicial remedy for supervisory authority inaction
Must respect data subjects' right to effective judicial remedy when the competent supervisory authority fails to handle
GDPR-78-03
Requirement
Bring proceedings in courts of Member State where supervisory authority established
Must bring any judicial proceedings against a supervisory authority before the courts of the Member State where that sup
GDPR-78-04
Requirement
Forward Board opinion or decision to court in consistency mechanism cases
Must forward any opinion or decision of the Board from the consistency mechanism to the court when proceedings are broug
Article 79. Right to an effective judicial remedy against a controller or processor
3 obligations
GDPR-79-01
Data Governance
Ensure effective judicial remedy availability for data subjects
Controllers and processors must ensure that data subjects have access to effective judicial remedies when they consider
GDPR-79-02
Requirement
Submit to jurisdiction of courts where establishment is located
Controllers and processors must accept that proceedings against them can be brought before the courts of the Member Stat
GDPR-79-03
Requirement
Submit to jurisdiction of courts where data subject has habitual residence
Controllers and processors (except public authorities acting in exercise of public powers) must accept that proceedings