General Data Protection Regulation (GDPR)

Complete Reference Guide & Download Resources — Regulation (EU) 2016/679.
Effective: May 25, 2018Jurisdiction: EU & EEACurrent as of January 202699 Articles · 173 Recitals

Official GDPR Download Sources

The primary official source is EUR-Lex (European Union Official Journal). The full text is available in all 24 EU languages: English, German, French, Spanish, Italian, Dutch, Polish, Romanian, Greek, Hungarian, Swedish, Portuguese, Czech, Bulgarian, Danish, Finnish, Slovak, Lithuanian, Latvian, Slovenian, Estonian, Irish, Croatian, and Maltese.

1. GDPR Overview

The General Data Protection Regulation (GDPR) is the European Union’s comprehensive data protection law that harmonizes data privacy laws across all EU member states and protects EU citizens’ personal data rights.

Full official title: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.

Key facts

  • Adopted: April 27, 2016
  • Came into force: May 24, 2016
  • Became applicable: May 25, 2018
  • Replaces: Data Protection Directive 95/46/EC
  • Total: 99 Articles + 173 Recitals, organized into 11 Chapters
  • Why GDPR matters

    Global impact: GDPR applies to any organization worldwide that processes EU residents’ personal data — regardless of where the business is located. It sets the gold standard for privacy protection globally and has influenced privacy laws worldwide, including California’s CCPA.

    Fundamental rights protection: privacy is a fundamental human right in the EU, and data protection is a constitutional right. GDPR empowers individuals with control over their data.

    Business implications: significant compliance requirements, substantial penalties for violations (up to €20 million or 4% of global revenue), requirements for data protection by design and default, and mandatory breach notifications.

    2. Key Definitions

    Personal Data (Article 4(1))
    Any information relating to an identified or identifiable natural person ("data subject"). An identifiable person can be identified directly or indirectly by reference to a name, identification number, location data, an online identifier, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity. Examples include name, email address, ID card number, IP address, cookie identifiers, location data, biometric data, genetic data, health information, sexual orientation, and political opinions.
    Special Categories of Personal Data (Article 9)
    Higher protection is required for: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data (for unique identification), health data, and data concerning sex life or sexual orientation. Processing is prohibited by default unless specific conditions are met.
    Processing (Article 4(2))
    Any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, making available, alignment or combination, restriction, erasure, or destruction. Almost anything you do with personal data is processing.
    Controller (Article 4(7))
    The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing personal data. The controller is the primary responsible party under GDPR: it must ensure compliance, is liable for violations, and must implement appropriate technical and organizational measures.
    Processor (Article 4(8))
    A natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller, under a binding contract (Article 28) that restricts its use of the data.
    Consent (Article 4(11))
    A freely given, specific, informed, and unambiguous indication of the data subject's wishes by a statement or clear affirmative action. Consent must be as easy to withdraw as to give.

    3. Scope & Applicability

    Territorial scope (Article 3)

  • Establishment in the EU: applies to processing in the context of activities of an establishment of a controller or processor in the EU, regardless of where the processing takes place.
  • Offering goods or services: applies to controllers or processors outside the EU that offer goods or services (paid or free) to data subjects in the EU.
  • Monitoring behavior: applies to organizations outside the EU that monitor the behavior of data subjects in the EU (e.g., profiling, tracking).
  • Material scope (Article 2)

    GDPR applies to the processing of personal data wholly or partly by automated means, and to non-automated processing that forms part of a filing system. It does not apply to purely personal or household activity, processing by EU institutions (covered by separate rules), or processing for law-enforcement purposes (covered by the Law Enforcement Directive).

    4. Core Principles (Article 5)

    Lawfulness, Fairness & Transparency

    Personal data must be processed lawfully, fairly, and in a transparent manner in relation to the data subject.

    Purpose Limitation

    Data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.

    Data Minimization

    Data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.

    Accuracy

    Data must be accurate and, where necessary, kept up to date; inaccurate data must be erased or rectified without delay.

    Storage Limitation

    Data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes of processing.

    Integrity & Confidentiality

    Data must be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

    Accountability

    The controller is responsible for, and must be able to demonstrate, compliance with all of the above principles.

    5. Legal Basis for Processing (Article 6)

    Processing is lawful only if at least one of the following six legal bases applies:
    Consent (Art. 6(1)(a))
    The data subject has given clear, affirmative consent for one or more specific purposes.
    Contract (Art. 6(1)(b))
    Processing is necessary to perform a contract with the data subject or to take pre-contractual steps at their request.
    Legal Obligation (Art. 6(1)(c))
    Processing is necessary to comply with a legal obligation to which the controller is subject.
    Vital Interests (Art. 6(1)(d))
    Processing is necessary to protect the vital interests of the data subject or another natural person.
    Public Task (Art. 6(1)(e))
    Processing is necessary for a task carried out in the public interest or in the exercise of official authority.
    Legitimate Interests (Art. 6(1)(f))
    Processing is necessary for the legitimate interests of the controller or a third party, except where overridden by the data subject's interests or fundamental rights.

    6. Data Subject Rights

    Right to be Informed (Art. 13–14)

    Data subjects must be told who is processing their data, why, the legal basis, retention periods, recipients, and their rights — at the point of collection or within a reasonable period.

    Right of Access (Art. 15)

    Data subjects can obtain confirmation of whether their data is being processed and receive a copy of it, along with information about the processing.

    Right to Rectification (Art. 16)

    Data subjects can have inaccurate personal data corrected and incomplete data completed without undue delay.

    Right to Erasure — 'Right to be Forgotten' (Art. 17)

    Data subjects can request deletion of their data when it is no longer necessary, consent is withdrawn, processing is unlawful, or other grounds apply — subject to exceptions.

    Right to Restriction of Processing (Art. 18)

    Data subjects can restrict processing where accuracy is contested, processing is unlawful, or they need the data for legal claims.

    Right to Data Portability (Art. 20)

    Data subjects can receive their data in a structured, commonly used, machine-readable format and transmit it to another controller.

    Right to Object (Art. 21)

    Data subjects can object to processing based on legitimate interests, public tasks, or direct marketing (where objection is absolute).

    Rights re: Automated Decision-Making (Art. 22)

    Data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects.

    Controllers must respond to requests without undue delay and within one month, extendable by two further months for complex or numerous requests (Article 12(3)).

    7. Controller & Processor Obligations

    Implement data protection by design and by default (Art. 25).
    Maintain records of processing activities (Art. 30).
    Implement appropriate technical and organizational security measures (Art. 32).
    Notify the supervisory authority of personal data breaches within 72 hours where feasible (Art. 33); notify affected data subjects without undue delay when the breach is likely to result in a high risk (Art. 34).
    Conduct Data Protection Impact Assessments (DPIAs) for high-risk processing (Art. 35).
    Consult the supervisory authority prior to processing where a DPIA indicates high risk (Art. 36).
    Designate a Data Protection Officer where required (Art. 37–39).
    Use processors only under binding contracts meeting Article 28 requirements.
    Cooperate with supervisory authorities and demonstrate accountability.
    Appoint an EU representative if established outside the EU but subject to GDPR (Art. 27).

    8. Data Protection Officer (Articles 37–39)

    A Data Protection Officer (DPO) must be designated where:
  • Processing is carried out by a public authority or body;
  • Core activities require regular and systematic monitoring of data subjects on a large scale; or
  • Core activities consist of large-scale processing of special categories of data or data relating to criminal convictions and offences.
  • The DPO must have expert knowledge of data protection law, operate independently, report to the highest management level, and may not be penalized for performing their duties. Tasks include informing and advising on GDPR obligations, monitoring compliance, advising on DPIAs, and acting as the contact point for the supervisory authority.

    9. International Data Transfers (Chapter V)

    Personal data may only be transferred outside the EU/EEA under one of the following mechanisms:
  • Adequacy decision (Art. 45): the European Commission has decided that the destination country ensures an adequate level of protection.
  • Appropriate safeguards (Art. 46): Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), approved codes of conduct, or certification mechanisms.
  • Derogations (Art. 49): explicit consent, contract necessity, important public interest, legal claims, or vital interests — for occasional, non-repetitive transfers.
  • Following the Schrems II judgment, transfers based on safeguards also require a transfer impact assessment to verify that the destination country’s laws do not undermine the protection provided.

    10. Enforcement & Penalties

    €20M / 4%

    Maximum fine for the most serious infringements (e.g., violating core principles or data subject rights) — €20 million or 4% of total worldwide annual turnover, whichever is higher (Art. 83(5)).

    €10M / 2%

    For other infringements (e.g., controller/processor obligations, certification bodies) — €10 million or 2% of worldwide annual turnover (Art. 83(4)).

    72 hrs

    Deadline to notify the supervisory authority of a personal data breach, where feasible (Art. 33).

    Enforcement is carried out by national supervisory authorities in each member state, coordinated through the European Data Protection Board (EDPB). Data subjects also have the right to lodge a complaint (Art. 77), seek judicial remedy (Art. 78–79), and receive compensation for material or non-material damage (Art. 82).

    11. Complete Article Structure

    ChapterTitleArticlesCovers
    Chapter IGeneral ProvisionsArt. 1–4Subject matter, scope, definitions
    Chapter IIPrinciplesArt. 5–11Processing principles, lawfulness, consent, special categories
    Chapter IIIRights of the Data SubjectArt. 12–23Transparency, access, rectification, erasure, portability, objection
    Chapter IVController and ProcessorArt. 24–43Obligations, security, breach notification, DPIAs, DPOs, codes of conduct
    Chapter VTransfers to Third CountriesArt. 44–50Adequacy, safeguards, derogations
    Chapter VISupervisory AuthoritiesArt. 51–59Independence, competence, powers
    Chapter VIICooperation and ConsistencyArt. 60–76One-stop-shop, EDPB, consistency mechanism
    Chapter VIIIRemedies, Liability and PenaltiesArt. 77–84Complaints, judicial remedies, compensation, fines
    Chapter IXSpecific Processing SituationsArt. 85–91Freedom of expression, employment, research, archiving
    Chapter XDelegated and Implementing ActsArt. 92–93Commission powers
    Chapter XIFinal ProvisionsArt. 94–99Repeal of Directive 95/46/EC, entry into force

    12. Quick Reference Tables

    For Individuals

    • You have 8 core rights: information, access, rectification, erasure, restriction, portability, objection, and protection from solely automated decisions.
    • Controllers must respond to your request within one month (extendable by two).
    • Consent must be as easy to withdraw as to give.
    • Complaints go to your national supervisory authority.

    For Organizations

    • Applies worldwide if you offer goods/services to, or monitor, people in the EU.
    • Every processing activity needs one of six legal bases.
    • Breach notification to the authority within 72 hours.
    • Fines up to €20M or 4% of global turnover.

    FAQs

    Does GDPR apply to companies outside the EU?

    Yes. GDPR has extraterritorial reach: it applies to any organization that offers goods or services to people in the EU or monitors their behavior, regardless of where the organization is based.

    What is the difference between a controller and a processor?

    The controller determines the purposes and means of processing and bears primary responsibility for compliance. The processor processes data on the controller's behalf under a binding contract.

    When is a Data Protection Officer required?

    When processing is by a public authority, when core activities require large-scale regular and systematic monitoring, or when core activities involve large-scale processing of special categories of data.

    How fast must a breach be reported?

    To the supervisory authority within 72 hours of becoming aware, where feasible. Affected individuals must be notified without undue delay when the breach is likely to result in a high risk to their rights and freedoms.

    How does GDPR relate to StewardIQ?

    StewardIQ's governance platform helps operationalize GDPR compliance — data mapping, lineage, consent and request workflows, retention policies, and audit-ready evidence. To exercise your rights with respect to StewardIQ, contact privacy@stewardiq.com.

    Disclaimer

    This guide is provided for informational purposes only and does not constitute legal advice. Consult qualified counsel for advice on your specific obligations. See also our Privacy Policy, CCPA Guide, and Terms of Service.

    Operationalize GDPR compliance with StewardIQ

    Map data, manage data subject requests, and keep audit-ready evidence — all in one governed platform.
    Data access governance illustration