General Data Protection Regulation (GDPR)
Official GDPR Download Sources
Table of Contents
1. GDPR Overview
Full official title: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
Key facts
Why GDPR matters
Global impact: GDPR applies to any organization worldwide that processes EU residents’ personal data — regardless of where the business is located. It sets the gold standard for privacy protection globally and has influenced privacy laws worldwide, including California’s CCPA.
Fundamental rights protection: privacy is a fundamental human right in the EU, and data protection is a constitutional right. GDPR empowers individuals with control over their data.
Business implications: significant compliance requirements, substantial penalties for violations (up to €20 million or 4% of global revenue), requirements for data protection by design and default, and mandatory breach notifications.
2. Key Definitions
- Personal Data (Article 4(1))
- Any information relating to an identified or identifiable natural person ("data subject"). An identifiable person can be identified directly or indirectly by reference to a name, identification number, location data, an online identifier, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity. Examples include name, email address, ID card number, IP address, cookie identifiers, location data, biometric data, genetic data, health information, sexual orientation, and political opinions.
- Special Categories of Personal Data (Article 9)
- Higher protection is required for: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data (for unique identification), health data, and data concerning sex life or sexual orientation. Processing is prohibited by default unless specific conditions are met.
- Processing (Article 4(2))
- Any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, making available, alignment or combination, restriction, erasure, or destruction. Almost anything you do with personal data is processing.
- Controller (Article 4(7))
- The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing personal data. The controller is the primary responsible party under GDPR: it must ensure compliance, is liable for violations, and must implement appropriate technical and organizational measures.
- Processor (Article 4(8))
- A natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller, under a binding contract (Article 28) that restricts its use of the data.
- Consent (Article 4(11))
- A freely given, specific, informed, and unambiguous indication of the data subject's wishes by a statement or clear affirmative action. Consent must be as easy to withdraw as to give.
3. Scope & Applicability
Territorial scope (Article 3)
Material scope (Article 2)
4. Core Principles (Article 5)
Lawfulness, Fairness & Transparency
Personal data must be processed lawfully, fairly, and in a transparent manner in relation to the data subject.
Purpose Limitation
Data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
Data Minimization
Data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
Accuracy
Data must be accurate and, where necessary, kept up to date; inaccurate data must be erased or rectified without delay.
Storage Limitation
Data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes of processing.
Integrity & Confidentiality
Data must be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
Accountability
The controller is responsible for, and must be able to demonstrate, compliance with all of the above principles.
5. Legal Basis for Processing (Article 6)
- Consent (Art. 6(1)(a))
- The data subject has given clear, affirmative consent for one or more specific purposes.
- Contract (Art. 6(1)(b))
- Processing is necessary to perform a contract with the data subject or to take pre-contractual steps at their request.
- Legal Obligation (Art. 6(1)(c))
- Processing is necessary to comply with a legal obligation to which the controller is subject.
- Vital Interests (Art. 6(1)(d))
- Processing is necessary to protect the vital interests of the data subject or another natural person.
- Public Task (Art. 6(1)(e))
- Processing is necessary for a task carried out in the public interest or in the exercise of official authority.
- Legitimate Interests (Art. 6(1)(f))
- Processing is necessary for the legitimate interests of the controller or a third party, except where overridden by the data subject's interests or fundamental rights.
6. Data Subject Rights
Right to be Informed (Art. 13–14)
Data subjects must be told who is processing their data, why, the legal basis, retention periods, recipients, and their rights — at the point of collection or within a reasonable period.
Right of Access (Art. 15)
Data subjects can obtain confirmation of whether their data is being processed and receive a copy of it, along with information about the processing.
Right to Rectification (Art. 16)
Data subjects can have inaccurate personal data corrected and incomplete data completed without undue delay.
Right to Erasure — 'Right to be Forgotten' (Art. 17)
Data subjects can request deletion of their data when it is no longer necessary, consent is withdrawn, processing is unlawful, or other grounds apply — subject to exceptions.
Right to Restriction of Processing (Art. 18)
Data subjects can restrict processing where accuracy is contested, processing is unlawful, or they need the data for legal claims.
Right to Data Portability (Art. 20)
Data subjects can receive their data in a structured, commonly used, machine-readable format and transmit it to another controller.
Right to Object (Art. 21)
Data subjects can object to processing based on legitimate interests, public tasks, or direct marketing (where objection is absolute).
Rights re: Automated Decision-Making (Art. 22)
Data subjects have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects.
7. Controller & Processor Obligations
8. Data Protection Officer (Articles 37–39)
9. International Data Transfers (Chapter V)
10. Enforcement & Penalties
€20M / 4%
Maximum fine for the most serious infringements (e.g., violating core principles or data subject rights) — €20 million or 4% of total worldwide annual turnover, whichever is higher (Art. 83(5)).
€10M / 2%
For other infringements (e.g., controller/processor obligations, certification bodies) — €10 million or 2% of worldwide annual turnover (Art. 83(4)).
72 hrs
Deadline to notify the supervisory authority of a personal data breach, where feasible (Art. 33).
11. Complete Article Structure
| Chapter | Title | Articles | Covers |
|---|---|---|---|
| Chapter I | General Provisions | Art. 1–4 | Subject matter, scope, definitions |
| Chapter II | Principles | Art. 5–11 | Processing principles, lawfulness, consent, special categories |
| Chapter III | Rights of the Data Subject | Art. 12–23 | Transparency, access, rectification, erasure, portability, objection |
| Chapter IV | Controller and Processor | Art. 24–43 | Obligations, security, breach notification, DPIAs, DPOs, codes of conduct |
| Chapter V | Transfers to Third Countries | Art. 44–50 | Adequacy, safeguards, derogations |
| Chapter VI | Supervisory Authorities | Art. 51–59 | Independence, competence, powers |
| Chapter VII | Cooperation and Consistency | Art. 60–76 | One-stop-shop, EDPB, consistency mechanism |
| Chapter VIII | Remedies, Liability and Penalties | Art. 77–84 | Complaints, judicial remedies, compensation, fines |
| Chapter IX | Specific Processing Situations | Art. 85–91 | Freedom of expression, employment, research, archiving |
| Chapter X | Delegated and Implementing Acts | Art. 92–93 | Commission powers |
| Chapter XI | Final Provisions | Art. 94–99 | Repeal of Directive 95/46/EC, entry into force |
12. Quick Reference Tables
For Individuals
- You have 8 core rights: information, access, rectification, erasure, restriction, portability, objection, and protection from solely automated decisions.
- Controllers must respond to your request within one month (extendable by two).
- Consent must be as easy to withdraw as to give.
- Complaints go to your national supervisory authority.
For Organizations
- Applies worldwide if you offer goods/services to, or monitor, people in the EU.
- Every processing activity needs one of six legal bases.
- Breach notification to the authority within 72 hours.
- Fines up to €20M or 4% of global turnover.
FAQs
Does GDPR apply to companies outside the EU?
Yes. GDPR has extraterritorial reach: it applies to any organization that offers goods or services to people in the EU or monitors their behavior, regardless of where the organization is based.
What is the difference between a controller and a processor?
The controller determines the purposes and means of processing and bears primary responsibility for compliance. The processor processes data on the controller's behalf under a binding contract.
When is a Data Protection Officer required?
When processing is by a public authority, when core activities require large-scale regular and systematic monitoring, or when core activities involve large-scale processing of special categories of data.
How fast must a breach be reported?
To the supervisory authority within 72 hours of becoming aware, where feasible. Affected individuals must be notified without undue delay when the breach is likely to result in a high risk to their rights and freedoms.
How does GDPR relate to StewardIQ?
StewardIQ's governance platform helps operationalize GDPR compliance — data mapping, lineage, consent and request workflows, retention policies, and audit-ready evidence. To exercise your rights with respect to StewardIQ, contact privacy@stewardiq.com.
Disclaimer
This guide is provided for informational purposes only and does not constitute legal advice. Consult qualified counsel for advice on your specific obligations. See also our Privacy Policy, CCPA Guide, and Terms of Service.
Operationalize GDPR compliance with StewardIQ
