What the GDPR is
The GDPR is a regulation — not a directive — which means it applies directly and uniformly in every EU member state without needing national laws to transpose it. It was adopted on 27 April 2016 and became applicable on 25 May 2018, replacing the 1995 Data Protection Directive (95/46/EC). Because it is directly applicable, the same core articles apply whether an organisation operates in Ireland, Germany, France or any other member state. Member states may add limited national rules in specific areas the regulation leaves open (for example the age of a child’s consent), but the foundation is EU-wide.
The regulation is built around a small number of principles and a set of enforceable rights for individuals, backed by obligations on the organisations that handle their data and by supervisory authorities with the power to investigate and fine. The recitals (the numbered explanatory paragraphs before the articles) are not binding rules on their own but help interpret the articles.
Who the GDPR applies to
The GDPR applies to organisations established in the EU, and to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour (Article 3). It reaches two kinds of actor: the controller, who decides why and how personal data is processed, and the processor, who processes data on the controller’s behalf. Its territorial reach is deliberately broad: a company with no EU office still falls under the GDPR if it targets EU customers or tracks EU users online.
The regulation covers the processing of personal data wholly or partly by automated means, and the manual processing of data that forms part of a filing system. It does not apply to processing by a person for a purely personal or household activity, nor to certain areas outside EU law such as national security.
Key definitions (Article 4)
“Personal data” means any information relating to an identified or identifiable natural person. A few definitions from Article 4 do most of the work throughout the regulation:
- Personal data — any information relating to an identified or identifiable living person (the “data subject”), such as a name, an identification number, location data or an online identifier.
- Processing — virtually any operation performed on personal data: collecting, storing, using, disclosing, erasing and more.
- Controller — the body that determines the purposes and means of the processing.
- Processor — a body that processes personal data on behalf of the controller.
- Pseudonymisation — processing data so it can no longer be attributed to a person without separately kept additional information. Pseudonymised data is still personal data.
The seven principles (Article 5)
Article 5 sets out seven principles that every processing activity must satisfy. They are the backbone of the whole regulation:
- Lawfulness, fairness and transparency — process data lawfully and tell people what you do with it.
- Purpose limitation — collect data for specified, explicit and legitimate purposes, and don’t reuse it incompatibly.
- Data minimisation — only collect what is adequate, relevant and necessary.
- Accuracy — keep data accurate and up to date; correct or erase what is wrong.
- Storage limitation — keep data in identifiable form no longer than necessary.
- Integrity and confidentiality — protect data with appropriate security.
- Accountability — the controller is responsible for, and must be able to demonstrate, compliance with the other six principles.
The six lawful bases (Article 6)
Processing is lawful only if at least one of the six Article 6 bases applies. There is no ranking — you choose the one that genuinely fits the purpose:
- Consent of the data subject.
- Contract — processing necessary to perform a contract with the person (or to take steps before entering one).
- Legal obligation — processing necessary to comply with the law.
- Vital interests — processing necessary to protect someone’s life.
- Public task — processing necessary for a task in the public interest or official authority.
- Legitimate interests — pursued by the controller or a third party, unless overridden by the individual’s rights (not available to public authorities in the exercise of their tasks).
Special categories of data (Article 9)
Processing special categories of personal data is prohibited unless one of the specific exceptions in Article 9(2) applies. Special categories are data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership, and genetic data, biometric data used to uniquely identify a person, and data concerning health, sex life or sexual orientation. Exceptions include explicit consent, employment and social-security law, vital interests, and reasons of substantial public interest or public health, among others. Data on criminal convictions and offences has its own regime under Article 10.
Consent (Articles 7 and 8)
Where consent is the lawful basis, it must be freely given, specific, informed and unambiguous, and the person must be able to withdraw it as easily as they gave it (Article 7). Silence, pre-ticked boxes or inactivity do not count. The controller must be able to demonstrate that consent was given. For information-society services offered directly to children, Article 8 sets a default age of 16 for valid consent, but member states may lower this to no younger than 13.
Test yourself on these rules
Reading about the articles is one thing — recognising them under exam pressure is another. Practise with realistic multiple-choice questions across every GDPR topic.
Start free Try 30 questions free — no time limit, no credit card.Data subject rights (Articles 12–22)
The GDPR gives individuals a set of enforceable rights over their own data, and the controller must respond without undue delay and within one month (extendable by two further months for complex requests). The main rights are:
- Information (Art. 13–14) — be told who is processing your data, why, and on what basis.
- Access (Art. 15) — obtain confirmation of processing and a copy of your data.
- Rectification (Art. 16) — have inaccurate data corrected.
- Erasure (Art. 17) — the “right to be forgotten”, in defined circumstances.
- Restriction (Art. 18) — limit processing while a dispute is resolved.
- Data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller.
- Object (Art. 21) — object to processing based on legitimate interests or public task, and to direct marketing at any time.
- Not to be subject to solely automated decisions (Art. 22), including profiling, that produce legal or similarly significant effects.
Controller and processor duties (Articles 24–36)
Controllers must build data protection into their operations and be able to demonstrate compliance; processors carry their own direct obligations. Key duties include:
- Data protection by design and by default (Art. 25) — embed safeguards from the outset and process only the data needed for each purpose.
- Processor contracts (Art. 28) — use of a processor must be governed by a written contract with the mandatory terms listed in Article 28(3).
- Records of processing activities (Art. 30) — keep a register of processing; smaller organisations are partly exempt unless processing is risky, regular or involves special categories.
- Security of processing (Art. 32) — apply appropriate technical and organisational measures, considering risk; pseudonymisation and encryption are named examples.
- Data protection impact assessment (Art. 35) — run a DPIA before processing likely to result in a high risk, and consult the supervisory authority first where high residual risk remains (Art. 36).
The Data Protection Officer (Articles 37–39)
A DPO must be designated where processing is carried out by a public authority, where the core activities require regular and systematic monitoring of individuals on a large scale, or where they involve large-scale processing of special categories or criminal-offence data (Article 37). The DPO must be involved in all data protection matters, report to the highest management level, and cannot be penalised for doing the job (Article 38). Their tasks (Article 39) include informing and advising the organisation, monitoring compliance, advising on DPIAs, and acting as the contact point for the supervisory authority and for data subjects. Member-state law can require a DPO in further cases beyond the EU-wide triggers above.
Personal data breaches (Articles 33 and 34)
A controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it — unless the breach is unlikely to result in a risk to individuals (Article 33). If notification is later than 72 hours, the delay must be explained. Where the breach is likely to result in a high risk to individuals, the affected people must also be told without undue delay (Article 34). Processors must notify their controller without undue delay after becoming aware of a breach.
International data transfers (Articles 44–50)
Personal data may only be transferred outside the EU/EEA if the destination ensures an adequate level of protection or appropriate safeguards are in place. The main routes are an adequacy decision by the European Commission (Art. 45), appropriate safeguards such as standard contractual clauses or binding corporate rules (Art. 46–47), or, failing those, the specific derogations in Article 49 (for example explicit consent or contractual necessity).
Supervisory authorities and the EDPB (Articles 51–76)
Each member state has one or more independent supervisory authorities that enforce the GDPR, and they coordinate through a “one-stop-shop” and the European Data Protection Board. For cross-border processing, a single lead supervisory authority takes the main role (Art. 56), while other concerned authorities cooperate. The consistency mechanism and the European Data Protection Board (EDPB) (Art. 68) keep interpretation and enforcement aligned across the EU, including by issuing binding decisions in disputes and publishing guidance.
Fines and enforcement (Articles 77–84)
Article 83 sets two tiers of administrative fines, and individuals also have their own remedies.
- Lower tier — up to €10 million or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher (e.g. breaches of controller/processor or certification-body obligations).
- Upper tier — up to €20 million or 4% of total worldwide annual turnover, whichever is higher (e.g. breaches of the basic principles, lawful bases, data subject rights, or transfer rules).
Fines must be effective, proportionate and dissuasive, and authorities weigh factors such as the nature and gravity of the infringement, whether it was intentional, and steps taken to mitigate harm. Alongside fines, individuals can lodge a complaint with a supervisory authority (Art. 77), seek a judicial remedy (Art. 79), and claim compensation for material or non-material damage (Art. 82).
Preparing for a DPO / GDPR certification exam?
GDPR Exam Trainer turns this material into hundreds of practice questions, chapter training and a timed exam simulation, with AI explanations for every answer.
Create your free account No in-person course required · Cancel anytime.Frequently asked questions
What does GDPR stand for?
GDPR stands for the General Data Protection Regulation — formally Regulation (EU) 2016/679. It is the European Union’s data protection law and has applied directly across the EU since 25 May 2018 (and across the wider EEA shortly after).
Who has to comply with the GDPR?
The GDPR applies to any controller or processor established in the EU, and to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour (Art. 3). It protects the personal data of people who are in the EU, regardless of the organisation’s location.
What are the six lawful bases for processing?
Article 6 lists six lawful bases: consent, performance of a contract, a legal obligation, protection of vital interests, a task carried out in the public interest or official authority, and legitimate interests. At least one basis must apply before any personal data is processed.
How much can a company be fined under the GDPR?
Article 83 sets two tiers of administrative fines. Lesser infringements can be fined up to €10 million or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. Serious infringements can be fined up to €20 million or 4% of worldwide annual turnover, whichever is higher.
When must a personal data breach be reported?
Under Article 33, a controller must notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of a breach — unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. Where the risk is high, affected individuals must also be informed (Article 34).
When must an organisation appoint a Data Protection Officer (DPO)?
Article 37 requires a DPO where processing is done by a public authority, where core activities involve regular and systematic monitoring of people on a large scale, or where core activities involve large-scale processing of special categories of data or criminal-offence data. Many organisations also appoint one voluntarily.