EU-wide · Regulation (EU) 2016/679

The EU GDPR Explained: A Complete Guide

Grounded in the primary source (EUR-Lex) and EDPB guidance · Last reviewed 2026-07-20

The General Data Protection Regulation (GDPR) is the European Union’s data protection law — formally Regulation (EU) 2016/679. It has applied directly across the EU since 25 May 2018 (and, shortly after, across the wider EEA), and it governs how organisations collect, use and protect the personal data of people in the EU. This guide explains its scope, principles, the rights it gives individuals, and the duties it places on organisations, with every claim tied back to the regulation itself.

Key facts at a glance

Official name
Regulation (EU) 2016/679 (General Data Protection Regulation)
Adopted
27 April 2016
Applies from
25 May 2018
Replaced
Data Protection Directive 95/46/EC
Structure
99 articles, 173 recitals, 11 chapters
Territory
All EU member states, directly applicable; extended to the EEA (Norway, Iceland, Liechtenstein)
Max fine
Up to €20 million or 4% of worldwide annual turnover, whichever is higher (Art. 83)

On this page

  1. What the GDPR is
  2. Who it applies to
  3. Key definitions
  4. The seven principles
  5. Lawful bases
  6. Special categories
  7. Consent
  8. Data subject rights
  9. Controller & processor duties
  10. The Data Protection Officer
  11. Data breaches
  12. International transfers
  13. Supervisory authorities
  14. Fines & enforcement
  15. FAQ

What the GDPR is

The GDPR is a regulation — not a directive — which means it applies directly and uniformly in every EU member state without needing national laws to transpose it. It was adopted on 27 April 2016 and became applicable on 25 May 2018, replacing the 1995 Data Protection Directive (95/46/EC). Because it is directly applicable, the same core articles apply whether an organisation operates in Ireland, Germany, France or any other member state. Member states may add limited national rules in specific areas the regulation leaves open (for example the age of a child’s consent), but the foundation is EU-wide.

The regulation is built around a small number of principles and a set of enforceable rights for individuals, backed by obligations on the organisations that handle their data and by supervisory authorities with the power to investigate and fine. The recitals (the numbered explanatory paragraphs before the articles) are not binding rules on their own but help interpret the articles.

Who the GDPR applies to

The GDPR applies to organisations established in the EU, and to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour (Article 3). It reaches two kinds of actor: the controller, who decides why and how personal data is processed, and the processor, who processes data on the controller’s behalf. Its territorial reach is deliberately broad: a company with no EU office still falls under the GDPR if it targets EU customers or tracks EU users online.

The regulation covers the processing of personal data wholly or partly by automated means, and the manual processing of data that forms part of a filing system. It does not apply to processing by a person for a purely personal or household activity, nor to certain areas outside EU law such as national security.

Key definitions (Article 4)

“Personal data” means any information relating to an identified or identifiable natural person. A few definitions from Article 4 do most of the work throughout the regulation:

The seven principles (Article 5)

Article 5 sets out seven principles that every processing activity must satisfy. They are the backbone of the whole regulation:

  1. Lawfulness, fairness and transparency — process data lawfully and tell people what you do with it.
  2. Purpose limitation — collect data for specified, explicit and legitimate purposes, and don’t reuse it incompatibly.
  3. Data minimisation — only collect what is adequate, relevant and necessary.
  4. Accuracy — keep data accurate and up to date; correct or erase what is wrong.
  5. Storage limitation — keep data in identifiable form no longer than necessary.
  6. Integrity and confidentiality — protect data with appropriate security.
  7. Accountability — the controller is responsible for, and must be able to demonstrate, compliance with the other six principles.

The six lawful bases (Article 6)

Processing is lawful only if at least one of the six Article 6 bases applies. There is no ranking — you choose the one that genuinely fits the purpose:

Special categories of data (Article 9)

Processing special categories of personal data is prohibited unless one of the specific exceptions in Article 9(2) applies. Special categories are data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership, and genetic data, biometric data used to uniquely identify a person, and data concerning health, sex life or sexual orientation. Exceptions include explicit consent, employment and social-security law, vital interests, and reasons of substantial public interest or public health, among others. Data on criminal convictions and offences has its own regime under Article 10.

Where consent is the lawful basis, it must be freely given, specific, informed and unambiguous, and the person must be able to withdraw it as easily as they gave it (Article 7). Silence, pre-ticked boxes or inactivity do not count. The controller must be able to demonstrate that consent was given. For information-society services offered directly to children, Article 8 sets a default age of 16 for valid consent, but member states may lower this to no younger than 13.

Test yourself on these rules

Reading about the articles is one thing — recognising them under exam pressure is another. Practise with realistic multiple-choice questions across every GDPR topic.

Start free Try 30 questions free — no time limit, no credit card.

Data subject rights (Articles 12–22)

The GDPR gives individuals a set of enforceable rights over their own data, and the controller must respond without undue delay and within one month (extendable by two further months for complex requests). The main rights are:

Controller and processor duties (Articles 24–36)

Controllers must build data protection into their operations and be able to demonstrate compliance; processors carry their own direct obligations. Key duties include:

The Data Protection Officer (Articles 37–39)

A DPO must be designated where processing is carried out by a public authority, where the core activities require regular and systematic monitoring of individuals on a large scale, or where they involve large-scale processing of special categories or criminal-offence data (Article 37). The DPO must be involved in all data protection matters, report to the highest management level, and cannot be penalised for doing the job (Article 38). Their tasks (Article 39) include informing and advising the organisation, monitoring compliance, advising on DPIAs, and acting as the contact point for the supervisory authority and for data subjects. Member-state law can require a DPO in further cases beyond the EU-wide triggers above.

Personal data breaches (Articles 33 and 34)

A controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it — unless the breach is unlikely to result in a risk to individuals (Article 33). If notification is later than 72 hours, the delay must be explained. Where the breach is likely to result in a high risk to individuals, the affected people must also be told without undue delay (Article 34). Processors must notify their controller without undue delay after becoming aware of a breach.

International data transfers (Articles 44–50)

Personal data may only be transferred outside the EU/EEA if the destination ensures an adequate level of protection or appropriate safeguards are in place. The main routes are an adequacy decision by the European Commission (Art. 45), appropriate safeguards such as standard contractual clauses or binding corporate rules (Art. 46–47), or, failing those, the specific derogations in Article 49 (for example explicit consent or contractual necessity).

Supervisory authorities and the EDPB (Articles 51–76)

Each member state has one or more independent supervisory authorities that enforce the GDPR, and they coordinate through a “one-stop-shop” and the European Data Protection Board. For cross-border processing, a single lead supervisory authority takes the main role (Art. 56), while other concerned authorities cooperate. The consistency mechanism and the European Data Protection Board (EDPB) (Art. 68) keep interpretation and enforcement aligned across the EU, including by issuing binding decisions in disputes and publishing guidance.

Fines and enforcement (Articles 77–84)

Article 83 sets two tiers of administrative fines, and individuals also have their own remedies.

Fines must be effective, proportionate and dissuasive, and authorities weigh factors such as the nature and gravity of the infringement, whether it was intentional, and steps taken to mitigate harm. Alongside fines, individuals can lodge a complaint with a supervisory authority (Art. 77), seek a judicial remedy (Art. 79), and claim compensation for material or non-material damage (Art. 82).

Preparing for a DPO / GDPR certification exam?

GDPR Exam Trainer turns this material into hundreds of practice questions, chapter training and a timed exam simulation, with AI explanations for every answer.

Create your free account No in-person course required · Cancel anytime.

Frequently asked questions

What does GDPR stand for?

GDPR stands for the General Data Protection Regulation — formally Regulation (EU) 2016/679. It is the European Union’s data protection law and has applied directly across the EU since 25 May 2018 (and across the wider EEA shortly after).

Who has to comply with the GDPR?

The GDPR applies to any controller or processor established in the EU, and to organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour (Art. 3). It protects the personal data of people who are in the EU, regardless of the organisation’s location.

What are the six lawful bases for processing?

Article 6 lists six lawful bases: consent, performance of a contract, a legal obligation, protection of vital interests, a task carried out in the public interest or official authority, and legitimate interests. At least one basis must apply before any personal data is processed.

How much can a company be fined under the GDPR?

Article 83 sets two tiers of administrative fines. Lesser infringements can be fined up to €10 million or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. Serious infringements can be fined up to €20 million or 4% of worldwide annual turnover, whichever is higher.

When must a personal data breach be reported?

Under Article 33, a controller must notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of a breach — unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. Where the risk is high, affected individuals must also be informed (Article 34).

When must an organisation appoint a Data Protection Officer (DPO)?

Article 37 requires a DPO where processing is done by a public authority, where core activities involve regular and systematic monitoring of people on a large scale, or where core activities involve large-scale processing of special categories of data or criminal-offence data. Many organisations also appoint one voluntarily.

Primary sources

This guide summarises the GDPR for study and general information. It is not legal advice, and article numbers and thresholds are simplified for clarity. For a binding interpretation always consult the official text on EUR-Lex, your competent supervisory authority, or a qualified data protection lawyer.