GDPR compliance: the ultimate guide

GDPR compliance: the ultimate guide
As of 17 August 2026. Checklist download: GDPR compliance checklist.
The General Data Protection Regulation is Regulation (EU) 2016/679. It is the Union’s general law on the protection of natural persons in relation to the processing of personal data, and on the free movement of that data.[^1] The European Parliament and the Council adopted it on 27 April 2016. It was published in the Official Journal on 4 May 2016 (OJ L 119, p. 1). It entered into force on the twentieth day after that publication and has applied since 25 May 2018.[^2]
This guide is a working map of what the Regulation actually requires of controllers and processors. It covers who is in scope, the definitions that decide almost every later question, the Article 5 principles, the six lawful bases, consent, special-category data, children’s data, transparency, data-subject rights, controller and processor duties, records, security, breach notification, impact assessments, the data protection officer, international transfers, cookies under the ePrivacy Directive, fines and compensation, and the 2025 procedural regulation for cross-border cases. Facts below come from the Regulation, from Commission implementing decisions, from European Data Protection Board (EDPB) and Article 29 Working Party texts, and from judgments of the Court of Justice of the European Union. Citations sit at the end.
A printable checklist that tracks these duties is available as a download. Use it as an internal workplan, not as a substitute for reading the legal text that applies to a given processing operation.
The Regulation is directly applicable in the Member States.[^2] It also has EEA relevance. The EDPB treats references to Member States in its guidelines as references to EEA States, following Decision of the EEA Joint Committee No 154/2018 of 6 July 2018.[^3] Transfers from the EU to Norway, Liechtenstein and Iceland are therefore not “third-country” transfers in the sense of Chapter V.[^4]
Two related instruments sit next to the GDPR and are easy to confuse with it. Processing by competent authorities for criminal-law purposes is governed by Directive (EU) 2016/680, not by the GDPR.[^5] Processing by Union institutions, bodies, offices and agencies is now governed by Regulation (EU) 2018/1725, which replaced Regulation (EC) No 45/2001.[^6] This guide is about Regulation (EU) 2016/679.
On 19 November 2025 the Commission presented a proposal (COM(2025) 837) that would, if adopted, amend the GDPR and several other digital instruments.[^7] That text is a proposal. It is not the law. Until the European Parliament and the Council adopt a regulation, the 2016 GDPR remains the rule.
What the GDPR is
Article 1 states three things. The Regulation lays down rules on the protection of natural persons with regard to the processing of personal data, and rules on the free movement of personal data. It protects fundamental rights and freedoms of natural persons, in particular their right to the protection of personal data. The free movement of personal data within the Union must not be restricted or prohibited for reasons connected with that protection.[^8]
Recital 1 places that right in primary law. Article 8(1) of the Charter of Fundamental Rights and Article 16(1) of the Treaty on the Functioning of the European Union both provide that everyone has the right to the protection of personal data concerning him or her.[^9] Recital 4 adds that the right is not absolute. It must be considered in relation to its function in society and balanced against other fundamental rights, in accordance with proportionality.[^10]
The GDPR replaced Directive 95/46/EC. Article 94 repeals that Directive with effect from 25 May 2018. References to the repealed Directive are to be construed as references to the GDPR.[^11] Recital 9 records why the Union moved from a directive to a regulation: the 1995 Directive had not prevented fragmentation, legal uncertainty, or a public perception of significant risks, especially online. Differences in protection among Member States could obstruct economic activity and the free flow of data.[^12] Recital 13 states that a regulation was necessary to give economic operators, including micro, small and medium-sized enterprises, legal certainty and transparency, and to give natural persons the same legally enforceable rights in all Member States.[^13]
The Regulation is technologically neutral. Recital 15 says the protection of natural persons should not depend on the techniques used. It covers processing by automated means, and manual processing if the data form part of a filing system or are intended to do so. Unstructured files that are not organised according to specific criteria fall outside the Regulation.[^14]
Material and territorial scope
Material scope
Article 2(1) applies the Regulation to the processing of personal data wholly or partly by automated means, and to non-automated processing of personal data that form part of a filing system or are intended to form part of one.[^15]
Article 2(2) lists four exclusions:[^16]
- activity that falls outside the scope of Union law
- processing by Member States when carrying out activities that fall within Chapter 2 of Title V of the TEU (common foreign and security policy)
- processing by a natural person in the course of a purely personal or household activity
- processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security
Recital 18 explains the household exception. Correspondence, address books, and social networking or online activity undertaken in a purely personal or household context can fall within it. The Regulation still applies to controllers or processors that provide the means for such processing.[^17] Recital 16 confirms that activities concerning national security fall outside Union law for these purposes.[^18]
Article 2(4) leaves the e-commerce Directive’s intermediary liability rules (Articles 12 to 15 of Directive 2000/31/EC) untouched.[^19]
Territorial scope
Article 3 sets three connecting factors.[^20]
Establishment (Article 3(1)). The Regulation applies to processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing itself takes place in the Union. Recital 22 says establishment implies the effective and real exercise of activity through stable arrangements. Legal form (branch or subsidiary) is not the determining factor.[^21]
Targeting (Article 3(2)). The Regulation applies to processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing is related to:
- the offering of goods or services to such data subjects in the Union, whether or not a payment is required, or
- the monitoring of their behaviour as far as that behaviour takes place within the Union
Recital 23 says mere accessibility of a website, an email address or other contact details, or use of a language generally used in the third country, is not enough to show an intention to offer goods or services in the Union. Factors that may show such an intention include use of a language or currency generally used in one or more Member States, with the possibility of ordering in that language, or mentioning customers or users who are in the Union.[^22]
Recital 24 addresses monitoring. To decide whether behaviour is being monitored, it should be ascertained whether natural persons are tracked on the internet, including subsequent use of profiling techniques to take decisions concerning a person or to analyse or predict preferences, behaviours and attitudes.[^23]
Public international law (Article 3(3)). The Regulation also applies to a controller not established in the Union but in a place where Member State law applies by virtue of public international law, for example a Member State’s diplomatic mission or consular post (recital 25).[^24]
The EDPB’s Guidelines 3/2018 on territorial scope distinguish the “establishment” criterion in Article 3(1) from the “targeting” criterion in Article 3(2). Where either criterion is met, the relevant provisions of the GDPR apply to the processing in question.[^25] The same guidelines state that the function of an Article 27 representative in the Union is not compatible with the role of an external data protection officer, because the representative acts on the controller’s or processor’s mandate and instructions, while Article 38(3) requires that the DPO receive no instructions regarding the exercise of DPO tasks.[^25]
Non-EU controllers and processors caught by Article 3(2) must, subject to the exceptions in Article 27(2), designate in writing a representative in the Union. The representative must be established in one of the Member States where the relevant data subjects are. The representative is to be addressed, in addition to or instead of the controller or processor, by supervisory authorities and data subjects. Designation of a representative does not prevent legal action against the controller or processor themselves.[^26] The exceptions are: processing that is occasional, does not include large-scale processing of special-category or criminal-conviction data, and is unlikely to result in a risk to rights and freedoms; and public authorities or bodies.[^26]
Definitions that decide later questions
Article 4 supplies the vocabulary. Several definitions do most of the work in a compliance programme.
Personal data is any information relating to an identified or identifiable natural person (the data subject). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to physical, physiological, genetic, mental, economic, cultural or social identity.[^27]
Recital 26 adds the test of means reasonably likely to be used, by the controller or by another person, to identify the person, taking account of all objective factors such as cost and time, available technology and technological developments. Pseudonymised data that can be attributed to a person by using additional information remain personal data. The principles of data protection do not apply to anonymous information, meaning information that does not relate to an identified or identifiable natural person, or personal data rendered anonymous so that the data subject is not or no longer identifiable.[^28]
Recital 30 states that natural persons may be associated with online identifiers provided by devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. Combined with unique identifiers and other information, those traces may be used to create profiles and identify people.[^29]
Recital 14 states that the Regulation does not cover processing of data that concerns legal persons, including the name, form and contact details of a legal person.[^30] Recital 27 states that the Regulation does not apply to the personal data of deceased persons, though Member States may provide rules on that processing.[^31]
Processing is any operation or set of operations performed on personal data, whether or not by automated means. The list includes collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.[^32] Almost every handling of personal data is processing.
Controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing. Where Union or Member State law determines the purposes and means, that law may provide the controller or the criteria for nominating one.[^33]
Processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.[^34]
The EDPB’s Guidelines 07/2020 on the concepts of controller and processor state that these concepts determine who is responsible for compliance and how data subjects can exercise their rights. The guidelines replace the earlier WP29 opinion on the same concepts (WP169).[^35]
Consent is any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.[^36]
Personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.[^37]
Profiling is any form of automated processing consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.[^38]
Pseudonymisation is processing in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.[^39] Recital 28 notes that pseudonymisation can reduce risks and help controllers and processors meet their obligations. It is not the only available measure.[^40]
Special categories are defined through Article 9 rather than Article 4, with supporting definitions of genetic data, biometric data and data concerning health in Article 4(13) to (15).[^41]
Main establishment, cross-border processing and supervisory authority concerned are defined in Article 4(16), (22) and (23). They matter for the one-stop-shop in Articles 55 and 56.[^42]
The Article 5 principles and accountability
Article 5(1) sets six principles. Article 5(2) adds a seventh: the controller is responsible for, and must be able to demonstrate, compliance with paragraph 1 (accountability).[^43]
Lawfulness, fairness and transparency. Personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject.[^43] Recital 39 develops this. Processing should be lawful and fair. It should be transparent to natural persons that personal data concerning them are collected, used, consulted or otherwise processed, and to what extent. Information and communication relating to processing should be easily accessible and easy to understand, using clear and plain language.[^44]
Purpose limitation. Data must be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Further processing for archiving in the public interest, scientific or historical research, or statistical purposes is not considered incompatible if it complies with Article 89(1).[^43]
Article 6(4) supplies the compatibility test where further processing is not based on consent or on a Union or Member State law that is a necessary and proportionate measure for an Article 23(1) objective. The controller must take into account, among other things: any link between the original and new purposes; the context of collection, in particular the relationship between data subjects and the controller; the nature of the data, including whether Article 9 or 10 data are involved; possible consequences for data subjects; and the existence of appropriate safeguards, which may include encryption or pseudonymisation.[^45] Recital 50 states that where further processing is compatible, no legal basis separate from that which allowed the original collection is required.[^46]
Data minimisation. Data must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.[^43] Recital 39 says personal data should be processed only if the purpose could not reasonably be fulfilled by other means.[^44]
Accuracy. Data must be accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes of processing, are erased or rectified without delay.[^43]
Storage limitation. Data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes. Longer storage is allowed where processing is solely for archiving in the public interest, scientific or historical research, or statistical purposes in accordance with Article 89(1), subject to appropriate technical and organisational measures.[^43] Recital 39 says time limits should be established for erasure or periodic review.[^44]
Integrity and confidentiality. Data must be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.[^43]
Accountability in Article 5(2) is the spine of a compliance programme. Article 24 then requires the controller, taking into account the nature, scope, context and purposes of processing and the risks of varying likelihood and severity for the rights and freedoms of natural persons, to implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with the Regulation. Those measures must be reviewed and updated where necessary. Where proportionate, they include data protection policies. Adherence to an approved code of conduct (Article 40) or an approved certification mechanism (Article 42) may be used as an element to demonstrate compliance.[^47]
Lawful bases under Article 6
Processing is lawful only if and to the extent that at least one of the six grounds in Article 6(1) applies.[^48] Recital 40 states that processing should be lawful where it is based on the consent of the data subject or on some other legitimate basis laid down by law, either in the Regulation or in other Union or Member State law as referred to in the Regulation.[^49]
The six grounds are:
(a) Consent. The data subject has given consent to the processing of his or her personal data for one or more specific purposes.
(b) Contract. Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
(c) Legal obligation. Processing is necessary for compliance with a legal obligation to which the controller is subject.
(d) Vital interests. Processing is necessary in order to protect the vital interests of the data subject or of another natural person.
(e) Public task. Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
(f) Legitimate interests. Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. Point (f) does not apply to processing carried out by public authorities in the performance of their tasks.[^48]
The basis for processing under points (c) and (e) must be laid down by Union law or Member State law to which the controller is subject. That legal basis must meet an objective of public interest and be proportionate to the legitimate aim pursued.[^50] Member States may maintain or introduce more specific provisions for points (c) and (e).[^51]
Each ground is a distinct legal basis. The EDPB’s Guidelines 05/2020 on consent state that the two lawful bases of consent and contract cannot be merged and blurred, and that if processing is in fact necessary for the performance of a contract, consent is not the appropriate lawful basis.[^3]
Contract (Article 6(1)(b))
Necessity for a contract is a strict test. In Meta Platforms and Others (C-252/21), the Court of Justice held that processing by the operator of an online social network that collects user data from other group services or from visits to third-party websites or apps, links those data with the social-network account, and uses them, can be regarded as necessary for the performance of a contract only if the processing is objectively indispensable for a purpose that is integral to the contractual obligation intended for those users, such that the main subject matter of the contract cannot be achieved if that processing does not occur.[^52]
Legal obligation and public task (Article 6(1)(c) and (e))
These grounds require a Union or Member State legal basis that meets an objective of public interest and is proportionate (Article 6(3)). In C-252/21 the Court held that off-platform collection and linking of social-network user data is justified under Article 6(1)(c) only where it is actually necessary for compliance with such a legal obligation and is carried out only in so far as is strictly necessary. Points (d) and (e) cannot, in principle and subject to verification by the referring court, justify that kind of processing by an operator whose activity is essentially economic and commercial.[^52]
Vital interests (Article 6(1)(d))
Recital 46 says this ground concerns an interest essential for the life of the data subject or of another natural person. Processing based on the vital interest of another person should in principle take place only where the processing cannot be manifestly based on another legal basis. Examples include humanitarian purposes, monitoring epidemics, and humanitarian emergencies such as natural and man-made disasters.[^53]
Legitimate interests (Article 6(1)(f))
Recital 47 states that a legitimate interest of the controller or of a third party may provide a legal basis provided that the interests or fundamental rights and freedoms of the data subject are not overriding, taking into consideration the reasonable expectations of data subjects based on their relationship with the controller. A relevant and appropriate relationship, such as where the data subject is a client or in the service of the controller, is given as an example. The existence of a legitimate interest needs careful assessment, including whether a data subject can reasonably expect, at the time and in the context of collection, that processing for that purpose may take place. The interests and fundamental rights of the data subject could in particular override the controller’s interest where data are processed in circumstances where data subjects do not reasonably expect further processing. Processing strictly necessary for preventing fraud constitutes a legitimate interest of the controller concerned. Processing for direct marketing purposes may be regarded as carried out for a legitimate interest.[^54]
Recital 48 refers to a legitimate interest in transmitting personal data within a group of undertakings for internal administrative purposes, including processing of clients’ or employees’ personal data. The general principles for transfers to an undertaking in a third country remain unaffected.[^55]
Recital 49 states that processing to the extent strictly necessary and proportionate for ensuring network and information security constitutes a legitimate interest of the controller concerned. Examples include preventing unauthorised access to electronic communications networks, malicious code distribution, and stopping denial-of-service attacks.[^56]
The EDPB’s Guidelines 1/2024 on processing based on Article 6(1)(f) set three cumulative conditions, taking into account the Court of Justice judgment of 4 October 2024 in case C-621/22:[^57]
- pursuit of a legitimate interest by the controller or by a third party
- necessity of the processing for the purposes of that interest
- the interests or fundamental rights and freedoms of individuals do not take precedence (a balancing test)
The Board states that only interests that are lawful, clearly and precisely articulated, and real and present may be considered legitimate. If there are reasonable, just as effective, but less intrusive alternatives, the processing may not be considered necessary. Necessity should also be examined with the data-minimisation principle in Article 5(1)(c). In the balancing exercise the controller must take into account the interests of the individuals, the impact of the processing, their reasonable expectations, and additional safeguards that could limit the impact.[^57]
In C-252/21 the Court held that off-platform collection and linking of social-network user data can be based on legitimate interests only if the operator has informed the users of the legitimate interest pursued, the processing is carried out only in so far as is strictly necessary for that interest, and a balancing of the opposing interests shows that the users’ interests or fundamental rights and freedoms do not override that interest.[^52]
Where processing is based on Article 6(1)(f), Articles 13 and 14 require the controller to tell the data subject the legitimate interests pursued.[^58] Article 21 gives the data subject a right to object to processing based on point (e) or (f), including profiling based on those provisions. For direct marketing, the right to object is absolute: once the data subject objects, the personal data must no longer be processed for such purposes.[^59]
Consent: Articles 4(11), 7 and 8, and EDPB Guidelines 05/2020
Consent is one lawful basis among six. It is also a condition for several other operations, including some Article 9 processing, some Article 22 automated decisions, and some Article 49 transfers.
The legal test
Article 4(11) requires a freely given, specific, informed and unambiguous indication of wishes, by a statement or a clear affirmative action.[^36]
Recital 32 states that consent should be given by a clear affirmative act. Examples include ticking a box when visiting a website, choosing technical settings for information society services, or another statement or conduct which clearly indicates acceptance. Silence, pre-ticked boxes or inactivity should not constitute consent. Consent should cover all processing activities carried out for the same purpose or purposes. When processing has multiple purposes, consent should be given for all of them. If the request is made by electronic means, it must be clear, concise and not unnecessarily disruptive to the use of the service.[^60]
Article 7 adds operational conditions:[^61]
- The controller must be able to demonstrate that the data subject consented (Article 7(1)).
- If consent is given in a written declaration that also concerns other matters, the request for consent must be clearly distinguishable, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration that infringes the Regulation is not binding (Article 7(2)).
- The data subject has the right to withdraw consent at any time. Withdrawal does not affect lawfulness of processing before withdrawal. The data subject must be informed of this before giving consent. It must be as easy to withdraw as to give consent (Article 7(3)).
- When assessing whether consent is freely given, utmost account must be taken of whether, among other things, the performance of a contract, including the provision of a service, is conditional on consent to processing that is not necessary for that contract (Article 7(4)).
Recital 42 states that consent should not be regarded as freely given if the data subject has no genuine or free choice or is unable to refuse or withdraw consent without detriment. For consent to be informed, the data subject should be aware at least of the identity of the controller and the purposes of the processing.[^62]
Recital 43 states that consent should not provide a valid legal ground where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority. Consent is presumed not to be freely given if it does not allow separate consent to different processing operations despite that being appropriate, or if the performance of a contract, including a service, is dependent on consent despite such consent not being necessary for that performance.[^63]
EDPB reading of “freely given”
Guidelines 05/2020 break “freely given” into imbalance of power, conditionality, granularity and detriment.[^3]
On public authorities, the Board points to recital 43 and considers that other lawful bases are, in principle, more appropriate for public-authority activity, without totally excluding consent in specific cases where there is a genuine choice and no loss of a core service.[^3]
On employment, the Board states that, given the dependency in the employer/employee relationship, it is unlikely that an employee can deny consent without fear or a real risk of detrimental effects. For the majority of processing at work, the lawful basis cannot and should not be the employee’s consent. Free consent is possible only in exceptional circumstances when there will be no adverse consequences whether or not the employee consents. The Board’s example is filming in part of an office, where staff who do not consent are given equivalent desks elsewhere for the duration and are not penalised.[^3]
On conditionality, the Board states that bundling consent with terms and conditions, or tying a contract or service to consent for processing that is not necessary for that contract or service, is highly undesirable. If consent is given in that situation, it is presumed not to be freely given (recital 43). Article 7(4) seeks to ensure that the purpose of processing is not disguised or bundled with a contract or service for which those data are not necessary. The processing for which consent is sought cannot become, directly or indirectly, the counter-performance of a contract.[^3] The Board also states that a controller cannot argue that a genuine choice exists merely because another controller offers an equivalent service. Access to services and functionalities must not be made conditional on consent to storing information, or gaining access to information already stored, in the user’s terminal equipment (cookie walls). In the Board’s example, a script that blocks content except for an “Accept cookies” button, with no other way to access the content, does not present a genuine choice, so consent is not freely given.[^3]
On granularity, separate consent is required for separate purposes where that is appropriate.[^3]
Court of Justice on consent
In Planet49 (C-673/17, 1 October 2019) the Court held that consent under Article 2(f) and Article 5(3) of Directive 2002/58/EC, read with Article 4(11) and Article 6(1)(a) GDPR, is not validly constituted if storage of information, or access to information already stored in a website user’s terminal equipment, is permitted by a pre-checked checkbox which the user must deselect to refuse consent. The Court also held that this interpretation does not depend on whether the information stored or accessed is personal data, and that the information the service provider must give includes the duration of the operation of the cookies and whether or not third parties may have access to those cookies.[^64]
In Meta Platforms and Others (C-252/21, 4 July 2023) the Court held that the fact that the operator of an online social network holds a dominant position on that market does not, as such, preclude users from validly consenting. It is nevertheless an important factor in determining whether consent was in fact freely given, which it is for that operator to prove. Users must be free to refuse, in the contractual process, consent to particular processing operations not necessary for the performance of the contract, without being obliged to refrain entirely from using the service, which means they are to be offered, if necessary for an appropriate fee, an equivalent alternative not accompanied by such processing.[^52]
Children’s consent for information society services
Article 8 applies where Article 6(1)(a) is used in relation to the offer of information society services directly to a child. Processing of a child’s personal data is lawful where the child is at least 16 years old. Where the child is below 16, processing is lawful only if and to the extent that consent is given or authorised by the holder of parental responsibility. Member States may provide by law for a lower age, not below 13 years. The controller must make reasonable efforts to verify that consent is given or authorised by the holder of parental responsibility, taking into consideration available technology. Article 8(1) does not affect general contract law of Member States on the validity, formation or effect of a contract in relation to a child.[^65]
Recital 38 states that children merit specific protection, as they may be less aware of the risks, consequences and safeguards and their rights. That protection should in particular apply to the use of children’s personal data for marketing or creating personality or user profiles, and to collection of children’s data when using services offered directly to a child. Consent of the holder of parental responsibility should not be necessary in the context of preventive or counselling services offered directly to a child.[^66]
Recital 171 addresses consent given under Directive 95/46/EC. It is not necessary for the data subject to give consent again if the manner in which the consent was given is in line with the conditions of the GDPR.[^67]
Special categories of data and criminal-conviction data
Article 9(1) prohibits processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.[^68]
Article 9(2) lists exceptions. The ones most often used in a commercial setting are:
- explicit consent for one or more specified purposes, except where Union or Member State law provides that the prohibition may not be lifted by the data subject (point (a))
- employment, social security and social protection law, so far as authorised by Union or Member State law or a collective agreement providing appropriate safeguards (point (b))
- vital interests where the data subject is physically or legally incapable of giving consent (point (c))
- not-for-profit bodies with a political, philosophical, religious or trade-union aim, relating solely to members, former members or persons in regular contact, with no disclosure outside the body without consent (point (d))
- data manifestly made public by the data subject (point (e))
- establishment, exercise or defence of legal claims, or courts acting in their judicial capacity (point (f))
- substantial public interest on the basis of Union or Member State law that is proportionate, respects the essence of the right to data protection, and provides suitable and specific safeguards (point (g))
- preventive or occupational medicine, working-capacity assessment, medical diagnosis, health or social care, or management of health or social care systems, on the basis of Union or Member State law or a contract with a health professional, subject to Article 9(3) professional secrecy (point (h))
- public interest in public health, on the basis of Union or Member State law with suitable and specific safeguards, in particular professional secrecy (point (i))
- archiving in the public interest, scientific or historical research, or statistical purposes in accordance with Article 89(1), on the basis of Union or Member State law with the same kinds of safeguards as point (g) (point (j))[^68]
Article 9(3) requires that processing for the medical and care purposes in point (h) be done by or under the responsibility of a professional subject to an obligation of secrecy under Union or Member State law or rules of national competent bodies.[^68] Article 9(4) allows Member States to maintain or introduce further conditions, including limitations, on genetic data, biometric data or data concerning health.[^68]
In C-252/21 the Court held that where a social-network operator collects, via interfaces, cookies or similar technologies, data from visits to websites or apps relating to Article 9 categories, links those data with the user’s account and uses them, that processing is processing of special categories of personal data where it allows information falling within one of those categories to be revealed, whether the information concerns a user of the network or any other natural person. Visiting such sites does not, by itself, mean the user has “manifestly made public” the data relating to those visits. Entering information or clicking “Like” or “Share” buttons makes data public under Article 9(2)(e) only where the user has explicitly made the choice beforehand, as the case may be on the basis of individual settings selected with full knowledge of the facts, to make the data publicly accessible to an unlimited number of persons.[^52]
Article 10 deals with personal data relating to criminal convictions and offences or related security measures. Processing based on Article 6(1) may be carried out only under the control of official authority or when authorised by Union or Member State law providing appropriate safeguards. Any comprehensive register of criminal convictions must be kept only under the control of official authority.[^69]
Transparency: Articles 12 to 14
Article 12 is the modality rule for all information and all rights. The controller must take appropriate measures to provide information under Articles 13 and 14, and any communication under Articles 15 to 22 and 34, in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for information addressed specifically to a child. Information is to be provided in writing or by other means, including electronic means where appropriate. Oral provision is possible on request if identity is proven.[^70]
The controller must facilitate the exercise of rights under Articles 15 to 22. It must provide information on action taken on a request without undue delay and in any event within one month of receipt. That period may be extended by two further months where necessary, taking into account complexity and number of requests. The controller must inform the data subject of any extension within one month, with reasons. If the request was made by electronic means, the response should be electronic where possible, unless the data subject requests otherwise.[^70]
If the controller does not take action, it must inform the data subject without delay and at the latest within one month of the reasons and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.[^70]
Information and actions under Articles 13, 14, 15 to 22 and 34 are free of charge. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may charge a reasonable fee taking into account administrative costs, or refuse to act. The controller bears the burden of demonstrating that the request is manifestly unfounded or excessive.[^70]
Where the controller has reasonable doubts concerning the identity of the person making a request under Articles 15 to 21, it may request additional information necessary to confirm identity.[^70]
Information when data are collected from the data subject (Article 13)
At the time personal data are obtained, the controller must provide:[^71]
- identity and contact details of the controller and, where applicable, of the representative
- contact details of the data protection officer, where applicable
- purposes of the processing and the legal basis
- where processing is based on Article 6(1)(f), the legitimate interests pursued
- recipients or categories of recipients, if any
- where applicable, the fact of a transfer to a third country or international organisation, the existence or absence of an adequacy decision, or, for Article 46 or 47 transfers or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means to obtain a copy of them or where they have been made available
The controller must also provide, at the time of collection, further information necessary to ensure fair and transparent processing:[^71]
- the storage period, or if that is not possible, the criteria used to determine it
- the existence of the rights of access, rectification, erasure, restriction, objection and data portability
- where processing is based on consent (Article 6(1)(a) or Article 9(2)(a)), the right to withdraw consent at any time, without affecting lawfulness before withdrawal
- the right to lodge a complaint with a supervisory authority
- whether provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, whether the data subject is obliged to provide the data, and the possible consequences of failure to provide them
- the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences
If the controller intends to further process the data for a purpose other than that for which they were collected, it must provide information on that other purpose and any relevant further information from Article 13(2) before that further processing. Paragraphs 1 to 3 do not apply where and insofar as the data subject already has the information.[^71]
Information when data have not been obtained from the data subject (Article 14)
The list is similar, with two extra items: the categories of personal data concerned, and the source of the personal data, including whether it came from publicly accessible sources.[^72]
Timing under Article 14(3) is: within a reasonable period after obtaining the data, but at the latest within one month; if the data are to be used to communicate with the data subject, at the latest at the time of the first communication; or if a disclosure to another recipient is envisaged, at the latest when the data are first disclosed.[^72]
Article 14(5) sets exceptions: the data subject already has the information; provision proves impossible or would involve a disproportionate effort (in particular for archiving, research or statistics under Article 89(1)), in which case the controller must take appropriate measures including making the information publicly available; obtaining or disclosure is expressly laid down by Union or Member State law which provides appropriate measures to protect legitimate interests; or the data must remain confidential subject to an obligation of professional secrecy regulated by Union or Member State law.[^72]
Data-subject rights
Chapter III gives data subjects a set of rights that the controller must be able to meet in practice. Response times and the free-of-charge rule sit in Article 12, described above.
Access (Article 15)
The data subject has the right to obtain confirmation as to whether personal data concerning him or her are being processed, and, where that is the case, access to the personal data and information on: purposes; categories of data; recipients or categories of recipient, in particular in third countries or international organisations; the envisaged storage period or the criteria used; the existence of the rights to rectification, erasure, restriction and objection; the right to lodge a complaint with a supervisory authority; where data were not collected from the data subject, any available information as to their source; and the existence of automated decision-making including profiling under Article 22(1) and (4), with at least in those cases meaningful information about the logic involved and the significance and envisaged consequences.[^73]
Where personal data are transferred to a third country or international organisation, the data subject has the right to be informed of the appropriate safeguards pursuant to Article 46.[^73]
The controller must provide a copy of the personal data undergoing processing. For further copies, a reasonable fee based on administrative costs may be charged. Where the request is made by electronic means, and unless otherwise requested, the information must be provided in a commonly used electronic form. The right to obtain a copy must not adversely affect the rights and freedoms of others.[^73]
Rectification (Article 16)
The data subject has the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.[^74]
Erasure, the “right to be forgotten” (Article 17)
The data subject has the right to obtain erasure without undue delay, and the controller has the obligation to erase without undue delay, where one of the following applies:[^75]
- the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed
- the data subject withdraws consent (Article 6(1)(a) or Article 9(2)(a)) and there is no other legal ground
- the data subject objects under Article 21(1) and there are no overriding legitimate grounds, or the data subject objects under Article 21(2) (direct marketing)
- the personal data have been unlawfully processed
- the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject
- the personal data have been collected in relation to the offer of information society services referred to in Article 8(1)
Where the controller has made the data public and is obliged to erase them, it must, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform other controllers processing the data that the data subject has requested erasure of any links to, or copy or replication of, those personal data.[^75]
Article 17(3) sets limits. Paragraphs 1 and 2 do not apply to the extent processing is necessary for: exercising the right of freedom of expression and information; compliance with a legal obligation, or a public-interest task or official authority; public-interest reasons in public health under Article 9(2)(h) and (i) and Article 9(3); archiving, research or statistics under Article 89(1) insofar as the right is likely to render impossible or seriously impair those objectives; or the establishment, exercise or defence of legal claims.[^75]
Restriction (Article 18)
The data subject has the right to restriction where: accuracy is contested, for a period enabling verification; processing is unlawful and the data subject opposes erasure and requests restriction instead; the controller no longer needs the data, but they are required by the data subject for legal claims; or the data subject has objected under Article 21(1) pending verification of whether the controller’s legitimate grounds override.[^76]
Where processing has been restricted, such data shall, with the exception of storage, only be processed with the data subject’s consent, or for legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or a Member State. The data subject who obtained restriction must be informed before the restriction is lifted.[^76]
Notification to recipients (Article 19)
The controller must communicate any rectification, erasure under Article 17(1), or restriction to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller must inform the data subject about those recipients if the data subject requests it.[^77]
Data portability (Article 20)
The data subject has the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format, and to transmit those data to another controller without hindrance, where processing is based on consent (Article 6(1)(a) or Article 9(2)(a)) or on a contract (Article 6(1)(b)), and the processing is carried out by automated means. Where technically feasible, the data subject has the right to have the data transmitted directly from one controller to another. The right is without prejudice to Article 17. It does not apply to processing necessary for a public-interest task or official authority. It must not adversely affect the rights and freedoms of others.[^78]
Objection (Article 21)
The data subject has the right to object, on grounds relating to his or her particular situation, at any time to processing based on Article 6(1)(e) or (f), including profiling based on those provisions. The controller must no longer process the personal data unless it demonstrates compelling legitimate grounds which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.[^59]
Where personal data are processed for direct marketing, the data subject has the right to object at any time, including to profiling related to such marketing. Where the data subject objects, the personal data shall no longer be processed for such purposes. The right in paragraphs 1 and 2 must be explicitly brought to the data subject’s attention at the latest at the time of the first communication, and presented clearly and separately from any other information.[^59]
In the context of information society services, and notwithstanding Directive 2002/58/EC, the data subject may exercise the right to object by automated means using technical specifications.[^59]
Where personal data are processed for scientific or historical research or statistical purposes pursuant to Article 89(1), the data subject, on grounds relating to his or her particular situation, has the right to object unless the processing is necessary for the performance of a task carried out for reasons of public interest.[^59]
Automated individual decision-making, including profiling (Article 22)
The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.[^79]
That right does not apply if the decision is necessary for entering into, or performance of, a contract between the data subject and a controller; is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests; or is based on the data subject’s explicit consent.[^79]
In the contract and explicit-consent cases, the controller must implement suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.[^79]
Decisions under Article 22(2) must not be based on special categories of data referred to in Article 9(1), unless Article 9(2)(a) or (g) applies and suitable measures are in place.[^79]
Restrictions (Article 23)
Union or Member State law to which the controller or processor is subject may restrict, by legislative measure, the scope of the obligations and rights in Articles 12 to 22 and Article 34, as well as Article 5 insofar as its provisions correspond to those rights and obligations, when the restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard listed objectives. Those objectives include national security, defence, public security, criminal-law purposes, other important objectives of general public interest (including important economic or financial interests, public health and social security), judicial independence, ethics of regulated professions, a connected monitoring or regulatory function, protection of the data subject or of the rights and freedoms of others, and enforcement of civil law claims. Any such measure must contain specific provisions on the matters listed in Article 23(2).[^80]
Identification (Article 11)
If the purposes of processing do not or no longer require identification of the data subject, the controller is not obliged to maintain, acquire or process additional information in order to identify the data subject for the sole purpose of complying with the Regulation. Where the controller can demonstrate that it is not in a position to identify the data subject, it must inform the data subject accordingly, if possible. Articles 15 to 20 then do not apply except where the data subject, for the purpose of exercising those rights, provides additional information enabling identification.[^81]
Controllers, processors and joint controllers
Responsibility of the controller
Article 24, described above, is the general duty to implement and demonstrate appropriate measures, reviewed and updated where necessary.[^47]
Data protection by design and by default (Article 25)
Taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity, the controller must, both at the time of determining the means for processing and at the time of the processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing.[^82]
By default, only personal data which are necessary for each specific purpose may be processed. That obligation applies to the amount of personal data collected, the extent of their processing, the period of their storage and their accessibility. In particular, such measures must ensure that by default personal data are not made accessible without the individual’s intervention to an indefinite number of natural persons.[^82] An approved certification mechanism under Article 42 may be used as an element to demonstrate compliance.[^82]
Joint controllers (Article 26)
Where two or more controllers jointly determine the purposes and means of processing, they are joint controllers. They must, in a transparent manner, determine their respective responsibilities for compliance, in particular as regards the exercise of data-subject rights and the duties to provide information under Articles 13 and 14, by means of an arrangement between them, unless Union or Member State law determines those responsibilities. The arrangement may designate a contact point for data subjects. It must duly reflect the respective roles and relationships vis-à-vis data subjects. The essence of the arrangement must be made available to the data subject. Irrespective of the terms of the arrangement, the data subject may exercise his or her rights in respect of and against each of the controllers.[^83]
Processors (Article 28)
Where processing is to be carried out on behalf of a controller, the controller must use only processors providing sufficient guarantees to implement appropriate technical and organisational measures so that processing will meet the requirements of the Regulation and ensure protection of the rights of the data subject.[^84]
The processor must not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor must inform the controller of any intended changes concerning addition or replacement of other processors, giving the controller the opportunity to object.[^84]
Processing by a processor must be governed by a contract or other legal act under Union or Member State law, binding on the processor with regard to the controller, that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller. That contract must stipulate, in particular, that the processor:[^84]
- processes the personal data only on documented instructions from the controller, including with regard to transfers to a third country or international organisation, unless required to do so by Union or Member State law to which the processor is subject (in which case the processor informs the controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest)
- ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality
- takes all measures required pursuant to Article 32
- respects the conditions in Article 28(2) and (4) for engaging another processor
- assists the controller, by appropriate technical and organisational measures insofar as this is possible, for the fulfilment of the controller’s obligation to respond to data-subject requests
- assists the controller in ensuring compliance with Articles 32 to 36, taking into account the nature of processing and the information available to the processor
- at the choice of the controller, deletes or returns all the personal data after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage
- makes available to the controller all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the controller or another auditor mandated by the controller
The processor must immediately inform the controller if, in its opinion, an instruction infringes the Regulation or other Union or Member State data protection provisions.[^84]
Where a processor engages another processor, the same data-protection obligations must be imposed on that other processor by contract or other legal act. Where that other processor fails to fulfil its obligations, the initial processor remains fully liable to the controller for the performance of that other processor’s obligations.[^84]
The contract must be in writing, including in electronic form.[^84] The Commission may lay down standard contractual clauses for these matters. It did so in Commission Implementing Decision (EU) 2021/915 of 4 June 2021 on standard contractual clauses between controllers and processors under Article 28(7) GDPR and Article 29(7) of Regulation (EU) 2018/1725. Those clauses fulfil the requirements of Article 28(3) and (4). They do not by themselves ensure compliance with Chapter V on international transfers.[^85]
If a processor infringes the Regulation by determining the purposes and means of processing, the processor is considered to be a controller in respect of that processing (Article 28(10)).[^84]
Article 29 provides that the processor and any person acting under the authority of the controller or of the processor who has access to personal data must not process those data except on instructions from the controller, unless required to do so by Union or Member State law.[^86]
The EDPB’s Guidelines 07/2020 state that elements to take into account when assessing a processor’s sufficient guarantees could include the processor’s expert knowledge (for example regarding security measures and data breaches), reliability, resources, and an approved certification mechanism.[^35]
Records of processing activities
Article 30 requires each controller, and where applicable the controller’s representative, to maintain a record of processing activities under its responsibility. The record must contain:[^87]
- the name and contact details of the controller and, where applicable, the joint controller, the representative and the data protection officer
- the purposes of the processing
- a description of the categories of data subjects and of the categories of personal data
- the categories of recipients to whom the personal data have been or will be disclosed, including recipients in third countries or international organisations
- where applicable, transfers to a third country or international organisation, including identification of that country or organisation and, in the case of transfers referred to in the second subparagraph of Article 49(1), documentation of suitable safeguards
- where possible, the envisaged time limits for erasure of the different categories of data
- where possible, a general description of the technical and organisational security measures referred to in Article 32(1)
Each processor, and where applicable the processor’s representative, must maintain a record of all categories of processing activities carried out on behalf of a controller, containing the name and contact details of the processor or processors and of each controller on whose behalf the processor is acting, and where applicable of the representative and the DPO; the categories of processing carried out on behalf of each controller; transfers as above; and where possible a general description of Article 32(1) measures.[^87]
Records must be in writing, including in electronic form, and must be made available to the supervisory authority on request.[^87]
Article 30(5) states that the obligations in paragraphs 1 and 2 do not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.[^87] Recital 13 notes that the Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping, and encourages Union institutions and bodies, Member States and supervisory authorities to take account of the specific needs of micro, small and medium-sized enterprises. The notion of those enterprises should draw from Article 2 of the Annex to Commission Recommendation 2003/361/EC.[^13]
The exemption is narrow in practice. Many organisations with fewer than 250 staff still process data that is not occasional (payroll, customer accounts, websites) or that presents a risk. The record remains the usual way to demonstrate accountability under Article 5(2) and Article 24.
Security of processing
Article 32 requires the controller and the processor, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons, to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:[^88]
- the pseudonymisation and encryption of personal data
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services
- the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
- a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing
In assessing the appropriate level of security, account must be taken in particular of the risks presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.[^88]
Adherence to an approved code of conduct or an approved certification mechanism may be used as an element to demonstrate compliance.[^88] The controller and processor must take steps to ensure that any natural person acting under their authority who has access to personal data does not process them except on instructions from the controller, unless required to do so by Union or Member State law.[^88]
Article 32 does not prescribe a named technical standard. It requires a risk-based choice of measures, documented so that it can be shown.
Personal data breaches
A personal data breach is defined in Article 4(12), quoted above. Two notification duties follow. Both sit on the controller. The processor’s duty is to notify the controller.
Notification to the supervisory authority (Article 33)
In the case of a personal data breach, the controller must without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification is not made within 72 hours, it must be accompanied by reasons for the delay.[^89]
The processor must notify the controller without undue delay after becoming aware of a personal data breach.[^89]
The notification must at least: describe the nature of the breach including where possible the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; communicate the name and contact details of the DPO or other contact point; describe the likely consequences; and describe the measures taken or proposed to address the breach, including, where appropriate, measures to mitigate its possible adverse effects. Information may be provided in phases without undue further delay where it is not possible to provide it all at the same time.[^89]
The controller must document any personal data breaches, comprising the facts relating to the breach, its effects and the remedial action taken. That documentation must enable the supervisory authority to verify compliance with Article 33.[^89]
Communication to the data subject (Article 34)
When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller must communicate the breach to the data subject without undue delay. The communication must describe in clear and plain language the nature of the personal data breach and contain at least the information in Article 33(3)(b), (c) and (d).[^90]
Communication to the data subject is not required if any of the following conditions are met:[^90]
- the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected, in particular measures that render the personal data unintelligible to any person who is not authorised to access it, such as encryption
- the controller has taken subsequent measures which ensure that the high risk is no longer likely to materialise
- it would involve disproportionate effort; in that case there must instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner
If the controller has not already communicated the breach to the data subject, the supervisory authority, having considered the likelihood of a high risk, may require it to do so or may decide that any of the Article 34(3) conditions are met.[^90]
EDPB Guidelines 9/2022
The EDPB’s Guidelines 9/2022 on personal data breach notification update the earlier WP29 guidance (WP250 rev.01). For controllers not established in the EU that are subject to Article 3(2) or 3(3), the Board states that Articles 33 and 34 still apply. The mere presence of an Article 27 representative does not trigger the one-stop-shop. The breach must be notified to every supervisory authority for which affected data subjects reside in their Member State. That notification remains the responsibility of the controller. A processor subject to Article 3(2) remains bound by the duty to notify the controller under Article 33(2).[^91]
For cross-border processing by a controller established in the Union, notification is made to the lead supervisory authority in accordance with Article 56. If the controller has any doubt as to the identity of the lead authority, it should at a minimum notify the supervisory authority where the breach has taken place.[^91]
Data protection impact assessments and prior consultation
When a DPIA is required
Article 35(1) requires the controller, prior to the processing, to carry out an assessment of the impact of the envisaged processing operations on the protection of personal data where a type of processing, in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons. A single assessment may address a set of similar processing operations that present similar high risks.[^92]
The controller must seek the advice of the data protection officer, where designated, when carrying out a DPIA.[^92]
Article 35(3) states that a DPIA is in particular required in the case of:[^92]
- a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person
- processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10
- a systematic monitoring of a publicly accessible area on a large scale
Supervisory authorities must establish and make public a list of the kind of processing operations which are subject to the DPIA requirement (Article 35(4)). They may also publish a list of operations for which no DPIA is required (Article 35(5)). Lists that involve offering goods or services to data subjects or monitoring their behaviour in several Member States, or that may substantially affect the free movement of personal data, must go through the consistency mechanism before adoption.[^92]
Minimum content
The assessment must contain at least:[^92]
- a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller
- an assessment of the necessity and proportionality of the processing operations in relation to the purposes
- an assessment of the risks to the rights and freedoms of data subjects
- the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance, taking into account the rights and legitimate interests of data subjects and other persons concerned
Where appropriate, the controller must seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations.[^92] Where necessary, the controller must carry out a review to assess if processing is performed in accordance with the DPIA, at least when there is a change of the risk represented by processing operations.[^92]
WP29 nine criteria (WP248 rev.01)
The Article 29 Working Party guidelines on DPIA, endorsed by the EDPB, treat Article 35(3) as a non-exhaustive list. They set nine criteria to consider when deciding whether processing is likely to result in a high risk:[^93]
- evaluation or scoring, including profiling and predicting
- automated decision-making with legal or similar significant effect
- systematic monitoring
- sensitive data or data of a highly personal nature
- data processed on a large scale
- matching or combining datasets
- data concerning vulnerable data subjects (recital 75), which may include children, employees, patients, asylum seekers and other situations of imbalance
- innovative use or applying new technological or organisational solutions
- processing that prevents data subjects from exercising a right or using a service or a contract
In most cases, the Working Party considered that processing meeting two criteria would require a DPIA. The more criteria are met, the more likely a high risk. In some cases one criterion may suffice.[^93] For “large scale”, the Working Party recommended considering the number of data subjects (as a number or as a proportion of the relevant population), the volume of data and/or range of data items, the duration or permanence of the activity, and the geographical extent.[^93]
The obligation to carry out the DPIA sits with the controller, not the DPO. Article 35(2) requires the controller to seek the DPO’s advice. Article 39(1)(c) tasks the DPO with providing advice where requested as regards the DPIA and monitoring its performance.[^94]
Prior consultation (Article 36)
The controller must consult the supervisory authority prior to processing where a DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk.[^95]
If the supervisory authority is of the opinion that the intended processing would infringe the Regulation, in particular where the controller has insufficiently identified or mitigated the risk, it must, within a period of up to eight weeks of receipt of the request for consultation, provide written advice to the controller and, where applicable, to the processor, and may use any of its Article 58 powers. That period may be extended by six weeks, taking into account complexity. The authority must inform the controller of any extension within one month, with reasons. Periods may be suspended until the authority has obtained information it has requested.[^95]
When consulting, the controller must provide: where applicable, the respective responsibilities of the controller, joint controllers and processors; the purposes and means of the intended processing; the measures and safeguards provided to protect data subjects; where applicable, the contact details of the DPO; the DPIA; and any other information requested by the supervisory authority.[^95]
The data protection officer
When designation is mandatory
The controller and the processor must designate a data protection officer in any case where:[^96]
- the processing is carried out by a public authority or body, except for courts acting in their judicial capacity
- the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale, or
- the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10
A group of undertakings may appoint a single DPO provided that the DPO is easily accessible from each establishment. A single DPO may be designated for several public authorities or bodies, taking account of organisational structure and size. In cases other than Article 37(1), the controller or processor or associations representing them may designate a DPO, or must do so where required by Union or Member State law.[^96]
The DPO must be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks in Article 39. The DPO may be a staff member or fulfil the tasks on the basis of a service contract. The controller or processor must publish the contact details of the DPO and communicate them to the supervisory authority.[^96]
Position
The controller and processor must ensure that the DPO is involved, properly and in a timely manner, in all issues which relate to the protection of personal data. They must support the DPO by providing resources necessary to carry out the tasks and access to personal data and processing operations, and to maintain expert knowledge. The DPO must not receive any instructions regarding the exercise of those tasks, must not be dismissed or penalised for performing those tasks, and must directly report to the highest management level. Data subjects may contact the DPO with regard to all issues related to processing of their personal data and to the exercise of their rights. The DPO is bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State law. The DPO may fulfil other tasks and duties. The controller or processor must ensure that any such tasks and duties do not result in a conflict of interests.[^97]
Tasks
The DPO must have at least the following tasks:[^98]
- to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to the Regulation and to other Union or Member State data protection provisions
- to monitor compliance with the Regulation, with other Union or Member State data protection provisions and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits
- to provide advice where requested as regards the DPIA and monitor its performance pursuant to Article 35
- to cooperate with the supervisory authority
- to act as the contact point for the supervisory authority on issues relating to processing, including prior consultation under Article 36, and to consult, where appropriate, with regard to any other matter
In performing those tasks the DPO must have due regard to the risk associated with processing operations, taking into account the nature, scope, context and purposes of processing.[^98]
WP243 rev.01, endorsed by the EDPB, states that it is the controller’s task, not the DPO’s, to carry out a DPIA when necessary, and that the DPO’s advice should be sought on whether to carry out a DPIA, what methodology to follow, whether to do it in-house or outsource it, what safeguards to apply, and whether the DPIA has been correctly carried out and its conclusions comply with the GDPR.[^94]
International transfers
Chapter V applies to any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation. Transfers, including onward transfers, may take place only if the conditions in Chapter V are complied with. All provisions in the Chapter must be applied so that the level of protection of natural persons guaranteed by the Regulation is not undermined.[^99]
Recital 101 states that when personal data are transferred from the Union to controllers, processors or other recipients in third countries or to international organisations, the level of protection of natural persons ensured in the Union by the Regulation should not be undermined, including in cases of onward transfers.[^100]
The structure is a cascade: adequacy decision (Article 45); failing that, appropriate safeguards with enforceable rights and effective legal remedies (Article 46, including binding corporate rules under Article 47); failing that, derogations for specific situations (Article 49). Article 48 adds that a judgment of a court or tribunal or a decision of an administrative authority of a third country requiring a controller or processor to transfer or disclose personal data may only be recognised or enforceable if based on an international agreement, such as a mutual legal assistance treaty, in force between the requesting third country and the Union or a Member State, without prejudice to other grounds for transfer pursuant to Chapter V.[^101]
Adequacy decisions (Article 45)
A transfer may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question, ensures an adequate level of protection. Such a transfer shall not require any specific authorisation.[^102]
When assessing adequacy the Commission must take account of, in particular: the rule of law, respect for human rights and fundamental freedoms, relevant legislation including concerning public security, defence, national security and criminal law and the access of public authorities to personal data, implementation of such legislation, data protection rules, professional rules and security measures including rules for onward transfers, case-law, and effective and enforceable data-subject rights and effective administrative and judicial redress; the existence and effective functioning of one or more independent supervisory authorities; and international commitments.[^102]
An implementing act providing for adequacy must provide for a mechanism for periodic review, at least every four years. The Commission must, on an ongoing basis, monitor developments that could affect the functioning of adequacy decisions. It may repeal, amend or suspend a decision without retroactive effect where the third country, territory, sector or organisation no longer ensures an adequate level of protection.[^102]
The Commission’s public list of adequacy decisions, as of 17 August 2026, records recognition of: Andorra; Argentina; Brazil; Canada (commercial organisations); Faroe Islands; Guernsey; Israel; Isle of Man; Japan; Jersey; New Zealand; Republic of Korea; Switzerland; the United Kingdom under the GDPR and the Law Enforcement Directive, as amended in December 2025 through one renewal decision under the GDPR and one renewal decision under the LED; the United States (commercial organisations participating in the EU-US Data Privacy Framework); Uruguay; and the European Patent Organisation.[^4] With the exception of the United Kingdom, these adequacy decisions do not cover data exchanges in the law enforcement sector governed by Article 36 of Directive (EU) 2016/680.[^4] The Commission states that the effect of an adequacy decision is that personal data can flow from the EU (and Norway, Liechtenstein and Iceland) to that third country without any further safeguard being necessary, and that transfers are assimilated to intra-EU transmissions of data.[^4]
The Commission adopted an adequacy decision for Brazil on 26 January 2026 (C(2026) 373). In that decision the Commission recalls that the standard is a level of protection “essentially equivalent” to that ensured in the Union, as clarified by the Court of Justice, and that the test does not require a point-to-point replication of Union rules.[^103]
On 23 July 2026 the Commission concluded its first review of the 2021 adequacy decision for the Republic of Korea and found that the Republic of Korea continues to provide an adequate level of protection.[^4]
EU-US Data Privacy Framework
Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 provides that the United States ensures an adequate level of protection for personal data transferred under the EU-US Data Privacy Framework from a controller or a processor in the Union to certified organisations in the United States.[^104] The framework is based on certification: US organisations commit to the EU-US Data Privacy Framework Principles issued by the US Department of Commerce. To be eligible, an organisation must be subject to the investigatory and enforcement powers of the Federal Trade Commission or the US Department of Transportation. Certified organisations must recertify annually.[^104] The decision followed Executive Order 14086 of 7 October 2022, “Enhancing Safeguards for US Signals Intelligence Activities,” complemented by a US Attorney General regulation on the Data Protection Review Court.[^104]
The EDPB’s information note of July 2023 states that, as of 10 July 2023, transfers from the EEA to organisations in the US that are included in the Data Privacy Framework List maintained by the US Department of Commerce may be based on the adequacy decision, without the need to rely on Article 46 transfer tools.[^105] Transfers to US organisations that are not on that list still require Article 46 safeguards or an Article 49 derogation.
Schrems II and “essential equivalence”
In Data Protection Commissioner v Facebook Ireland and Schrems (C-311/18, 16 July 2020) the Court of Justice held that:[^106]
- the GDPR applies to the transfer of personal data for commercial purposes by an economic operator established in a Member State to another economic operator established in a third country, irrespective of whether, at the time of that transfer or thereafter, that data is liable to be processed by the authorities of the third country for public security, defence and State security
- the appropriate safeguards, enforceable rights and effective legal remedies required by Article 46(1) and Article 46(2)(c) must ensure that data subjects whose personal data are transferred pursuant to standard data protection clauses are afforded a level of protection essentially equivalent to that guaranteed within the Union by the GDPR, read in the light of the Charter. The assessment must take into consideration both the contractual clauses and, as regards any access by the public authorities of that third country, the relevant aspects of the legal system of that third country, in particular those set out in Article 45(2)
- unless there is a valid Commission adequacy decision, the competent supervisory authority is required to suspend or prohibit a transfer pursuant to standard data protection clauses if, in the view of that authority and in the light of all the circumstances of that transfer, those clauses are not or cannot be complied with in that third country and the protection of the data transferred that is required by EU law cannot be ensured by other means, where the controller or a processor has not itself suspended or put an end to the transfer
- examination of Commission Decision 2010/87/EU on standard contractual clauses disclosed nothing to affect the validity of that decision
- Commission Implementing Decision (EU) 2016/1250 on the EU-US Privacy Shield is invalid
The Privacy Shield is therefore not a lawful basis for transfers. The 2023 Data Privacy Framework decision is a later adequacy decision. It can be reviewed by the Court in the same way as its predecessors.
Appropriate safeguards (Article 46)
In the absence of an adequacy decision, a controller or processor may transfer personal data only if it has provided appropriate safeguards, and on condition that enforceable data-subject rights and effective legal remedies are available.[^107]
Appropriate safeguards may be provided, without requiring specific authorisation from a supervisory authority, by:[^107]
- a legally binding and enforceable instrument between public authorities or bodies
- binding corporate rules in accordance with Article 47
- standard data protection clauses adopted by the Commission
- standard data protection clauses adopted by a supervisory authority and approved by the Commission
- an approved code of conduct pursuant to Article 40 together with binding and enforceable commitments of the controller or processor in the third country
- an approved certification mechanism pursuant to Article 42 together with such commitments
Subject to authorisation from the competent supervisory authority, appropriate safeguards may also be provided by contractual clauses between the controller or processor and the recipient, or by provisions inserted into administrative arrangements between public authorities or bodies which include enforceable and effective data-subject rights.[^107]
Standard contractual clauses (2021)
Commission Implementing Decision (EU) 2021/914 of 4 June 2021 adopts standard contractual clauses for the transfer of personal data to third countries pursuant to Article 46(2)(c). Recital 2 of that Decision recalls that, pursuant to Article 46(1), in the absence of an adequacy decision a controller or processor may transfer personal data to a third country only if it has provided appropriate safeguards, and on condition that enforceable rights and effective legal remedies for data subjects are available.[^108]
The Decision recites that the role of the clauses is limited to ensuring appropriate data-protection safeguards for international transfers. The exporter and importer are free to include the clauses in a wider contract and to add other clauses or additional safeguards, provided that they do not contradict, directly or indirectly, the standard contractual clauses or prejudice the fundamental rights or freedoms of data subjects. Controllers and processors are encouraged to provide additional safeguards by means of contractual commitments that supplement the clauses.[^108]
Decision 2001/497/EC and Decision 2010/87/EU were repealed with effect from 27 September 2021. Contracts concluded before 27 September 2021 on the basis of those earlier decisions were deemed to provide appropriate safeguards until 27 December 2022, provided the processing operations that were the subject matter of the contract remained unchanged and reliance on those clauses ensured that the transfer of personal data was subject to appropriate safeguards.[^108]
The 2021 clauses are modular. They cover controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller transfers.
Supplementary measures
EDPB Recommendations 01/2020 (version 2.0) address measures that supplement transfer tools to ensure compliance with the EU level of protection after Schrems II. Article 46 transfer tools (SCCs, binding corporate rules, codes of conduct, certification mechanisms, ad hoc contractual clauses) must, overall, mean that the transferred personal data will benefit from an essentially equivalent level of protection. Where the legal situation in the third country may still require it, the exporter must supplement those tools with additional measures.[^109]
When supplementary measures are added to SCCs, no authorisation from the competent supervisory authority is needed as long as the identified measures do not contradict, directly or indirectly, the SCCs and are sufficient to ensure that the level of protection guaranteed by the GDPR is not undermined. Where the exporter intends to modify the standard clauses themselves, or where the supplementary measures contradict the SCCs, the exporter is no longer deemed to be relying on standard contractual clauses and must seek authorisation under Article 46(3)(a).[^109]
Binding corporate rules (Article 47)
The competent supervisory authority must approve binding corporate rules in accordance with the consistency mechanism, provided that they are legally binding and apply to and are enforced by every member concerned of the group of undertakings, or group of enterprises engaged in a joint economic activity, including their employees; expressly confer enforceable rights on data subjects; and fulfil the content requirements in Article 47(2). Those requirements include structure and contact details of the group; the transfers; legally binding nature internally and externally; application of the general data-protection principles; data-subject rights and means to exercise them; acceptance of liability by the controller or processor established in a Member State for breaches by any member not established in the Union (with an exemption only if it proves that that member is not responsible for the event giving rise to the damage); information to data subjects; DPO or other monitoring function; complaint procedures; verification mechanisms including audits; reporting of changes; cooperation with the supervisory authority; reporting of third-country legal requirements likely to have a substantial adverse effect on the guarantees; and appropriate training for personnel with permanent or regular access to personal data.[^110]
Derogations (Article 49)
In the absence of an adequacy decision or of appropriate safeguards, a transfer or set of transfers may take place only on one of the conditions in Article 49(1):[^111]
- the data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks of such transfers due to the absence of an adequacy decision and appropriate safeguards
- the transfer is necessary for the performance of a contract between the data subject and the controller or the implementation of pre-contractual measures taken at the data subject’s request
- the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject between the controller and another natural or legal person
- the transfer is necessary for important reasons of public interest
- the transfer is necessary for the establishment, exercise or defence of legal claims
- the transfer is necessary in order to protect the vital interests of the data subject or of other persons, where the data subject is physically or legally incapable of giving consent
- the transfer is made from a register which according to Union or Member State law is intended to provide information to the public and which is open to consultation either by the public in general or by any person who can demonstrate a legitimate interest, but only to the extent that the conditions laid down by Union or Member State law for consultation are fulfilled in the particular case
A residual derogation in the second subparagraph of Article 49(1) allows a transfer that is not repetitive, concerns only a limited number of data subjects, is necessary for the purposes of compelling legitimate interests pursued by the controller which are not overridden by the interests or rights and freedoms of the data subject, where the controller has assessed all the circumstances surrounding the data transfer and has on the basis of that assessment provided suitable safeguards. The controller must inform the supervisory authority of the transfer and must inform the data subject of the transfer and of the compelling legitimate interests pursued. That assessment and those safeguards must be documented in the Article 30 records.[^111]
Points (a), (b) and (c) of the first subparagraph, and the second subparagraph, do not apply to activities carried out by public authorities in the exercise of their public powers. The public interest in point (d) must be recognised in Union law or in the law of the Member State to which the controller is subject.[^111]
The EDPB’s Guidelines 2/2018 on Article 49 state that the derogations must be applied so that the level of protection of natural persons guaranteed by the GDPR is not undermined, and that recourse to the derogations should never lead to a situation where fundamental rights might be breached. The Board also recalls WP29’s earlier view that consent for transfers that occur periodically or on an ongoing basis is inappropriate.[^112]
Cookies, terminal equipment and the ePrivacy Directive
Article 95 GDPR provides that the Regulation shall not impose additional obligations on natural or legal persons in relation to processing in connection with the provision of publicly available electronic communications services in public communication networks in the Union in relation to matters for which they are subject to specific obligations with the same objective set out in Directive 2002/58/EC.[^113]
Storage of information, or access to information already stored, in a user’s terminal equipment is governed first by Article 5(3) of Directive 2002/58/EC, as replaced by Directive 2009/136/EC. Member States must ensure that such storage or access is only allowed on condition that the subscriber or user has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC (now to be read, by virtue of GDPR Article 94(2), as a reference to the GDPR), inter alia about the purposes of the processing. This does not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.[^114]
Planet49 confirms that GDPR-standard consent applies to that cookie consent, including the ban on pre-ticked boxes, and that the information given must include duration of the cookies and whether third parties may have access to them.[^64] The EDPB’s cookie-wall position is quoted above: access to services and functionalities must not be made conditional on consent to storing or accessing information in terminal equipment.[^3]
Where the information stored or accessed is personal data, the GDPR applies in parallel: a lawful basis under Article 6, transparency under Articles 13 or 14, and the rest of the controller’s duties. Recital 30 already treats cookie identifiers as online identifiers that may identify a natural person.[^29]
The Commission’s Digital Omnibus proposal of 19 November 2025 would, if adopted, change the relationship between cookie rules and the GDPR.[^7] Until a regulation is adopted, Article 5(3) of the ePrivacy Directive, as amended in 2009, remains the specific rule on storing or accessing information in terminal equipment.
Enforcement, fines and compensation
Supervisory authorities and the one-stop-shop
Each Member State must provide for one or more independent public authorities to monitor the application of the Regulation (Article 51). Each supervisory authority must act with complete independence (Article 52).[^115]
Article 55 gives each supervisory authority competence for processing in the territory of its own Member State. Article 56 assigns a lead supervisory authority, for cross-border processing, to the supervisory authority of the main establishment or of the single establishment of the controller or processor. Other concerned authorities participate through the cooperation procedure in Article 60. Where they cannot reach consensus, Article 65 provides for dispute resolution by the EDPB.[^116]
Article 58 sets investigative, corrective and authorisation powers. Corrective powers include warnings, reprimands, orders to comply, orders to communicate a personal data breach to the data subject, a ban on processing, and administrative fines under Article 83.[^117]
Complaints and judicial remedies
Every data subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement (Article 77). Each natural or legal person has the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning them (Article 78). Each data subject has the right to an effective judicial remedy where he or she considers that his or her rights have been infringed as a result of processing of his or her personal data in non-compliance with the Regulation (Article 79). Proceedings against a controller or processor may be brought before the courts of the Member State where the controller or processor has an establishment, or, alternatively, where the data subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.[^118]
Article 80 allows the data subject to mandate a not-for-profit body that meets stated conditions to lodge a complaint and exercise Articles 77, 78 and 79 on his or her behalf, and to exercise the right to compensation under Article 82 where provided for by Member State law. Member States may also provide that such a body can lodge a complaint independently of a data subject’s mandate.[^119]
Compensation (Article 82)
Any person who has suffered material or non-material damage as a result of an infringement of the Regulation has the right to receive compensation from the controller or processor for the damage suffered.[^120] Recital 146 states that the concept of damage should be broadly interpreted in the light of the case-law of the Court of Justice in a manner which fully reflects the objectives of the Regulation, and that data subjects should receive full and effective compensation.[^121]
Any controller involved in processing is liable for the damage caused by processing which infringes the Regulation. A processor is liable only where it has not complied with obligations of the Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller. A controller or processor is exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage. Where more than one controller or processor, or both a controller and a processor, are involved in the same processing and are responsible, each is held liable for the entire damage in order to ensure effective compensation of the data subject, with a right to claim back from the others the part corresponding to their responsibility.[^120]
Administrative fines (Article 83)
Each supervisory authority must ensure that the imposition of administrative fines in respect of infringements referred to in Article 83(4), (5) and (6) is, in each individual case, effective, proportionate and dissuasive.[^122]
Fines may be imposed in addition to, or instead of, the corrective measures in Article 58(2)(a) to (h) and (j). When deciding whether to impose a fine and deciding on the amount, due regard must be given to the factors in Article 83(2), including: nature, gravity and duration of the infringement, taking into account the nature, scope or purpose of the processing as well as the number of data subjects affected and the level of damage suffered; the intentional or negligent character of the infringement; any action taken to mitigate damage; the degree of responsibility taking into account technical and organisational measures implemented pursuant to Articles 25 and 32; any relevant previous infringements; the degree of cooperation with the supervisory authority; the categories of personal data affected; the manner in which the infringement became known to the authority, in particular whether, and if so to what extent, the controller or processor notified the infringement; compliance with previous Article 58(2) measures regarding the same subject-matter; adherence to approved codes of conduct or certification mechanisms; and any other aggravating or mitigating factor, such as financial benefits gained or losses avoided from the infringement.[^122]
If a controller or processor intentionally or negligently, for the same or linked processing operations, infringes several provisions, the total amount of the administrative fine must not exceed the amount specified for the gravest infringement (Article 83(3)).[^122]
Article 83(4) sets a maximum of EUR 10 000 000, or in the case of an undertaking up to 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher, for infringements of the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39, 42 and 43, and of certain obligations of certification and monitoring bodies.[^122]
Article 83(5) sets a maximum of EUR 20 000 000, or in the case of an undertaking up to 4% of total worldwide annual turnover of the preceding financial year, whichever is higher, for infringements of: the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9; the data subjects’ rights pursuant to Articles 12 to 22; transfers pursuant to Articles 44 to 49; any obligations pursuant to Member State law adopted under Chapter IX; and non-compliance with an order or a temporary or definitive limitation on processing or the suspension of data flows by the supervisory authority pursuant to Article 58(2), or failure to provide access in violation of Article 58(1).[^122]
Non-compliance with an order under Article 58(2) is also subject to the Article 83(6) maximum of EUR 20 000 000 or 4% of worldwide annual turnover, whichever is higher.[^122]
Member States may lay down whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State (Article 83(7)). Recital 148 states that in a case of a minor infringement or if the fine likely to be imposed would constitute a disproportionate burden to a natural person, a reprimand may be issued instead of a fine.[^123]
The EDPB’s Guidelines 04/2022 set a five-step methodology for calculating fines, complementary to the earlier WP253 guidelines on when to impose a fine: identify the processing operations and evaluate Article 83(3); find the starting point based on the Article 83(4) to (6) classification, seriousness, and turnover of the undertaking; evaluate aggravating and mitigating circumstances; identify the legal maximums, which increases applied in previous steps cannot exceed; and analyse whether the final amount meets effectiveness, dissuasiveness and proportionality under Article 83(1).[^124]
Article 84 requires Member States to lay down rules on other penalties applicable to infringements, in particular for infringements which are not subject to administrative fines pursuant to Article 83. Those penalties must be effective, proportionate and dissuasive.[^125]
Cross-border procedure: Regulation (EU) 2025/2518
Regulation (EU) 2025/2518 of the European Parliament and of the Council of 26 November 2025 lays down additional procedural rules on the enforcement of Regulation (EU) 2016/679 in cases concerning cross-border processing. It was published in the Official Journal on 12 December 2025. It enters into force on the twentieth day following that publication. It applies from 2 April 2027.[^126]
Article 1 states that the Regulation lays down procedural rules for the handling of complaints and the conduct of investigations in complaint-based and ex officio cases by supervisory authorities in the enforcement of the GDPR where those cases concern cross-border processing, including the determination of whether a case concerns cross-border processing.[^126]
Article 3 requires supervisory authorities to conduct those proceedings in an expedient and efficient manner and to cooperate with each other in a sincere and effective manner. A complainant must have the possibility to communicate exclusively with the supervisory authority with which the complaint was lodged pursuant to Article 77 GDPR. The handling of a complaint must always lead to a decision that is subject to an effective judicial remedy within the meaning of Article 78 GDPR.[^126]
Article 36 sets transitional rules. Chapters III and IV of Regulation 2025/2518 apply to ex officio investigations opened after 2 April 2027 and to complaint-based investigations where the complaint was lodged after 2 April 2027. Chapters V and VI apply to all cases referred to dispute resolution under Article 65 GDPR and the urgency procedure under Article 66(2) and (3) GDPR after 2 April 2027.[^126]
The Commission’s EUR-Lex summary of the GDPR, last updated 24 March 2026, states that Regulation 2025/2518 is intended to improve efficiency and legal certainty in cross-border GDPR enforcement while supporting smoother coordination between regulators, and that it does not change the GDPR’s substantive data-protection rights.[^6]
Until 2 April 2027, cross-border cases continue under Articles 56 and 60 to 66 of the GDPR alone.
Related Union instruments
Several neighbouring instruments are often relevant to the same processing.
Directive (EU) 2016/680 (the Law Enforcement Directive) governs processing by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security. Recital 19 and Article 2(2)(d) GDPR exclude that processing from the GDPR.[^5]
Regulation (EU) 2018/1725 governs processing by Union institutions, bodies, offices and agencies. Article 2(3) GDPR still refers to Regulation (EC) No 45/2001, which Article 98 contemplated would be adapted. Regulation 2018/1725 is the adapted instrument.[^6]
Directive 2002/58/EC, as amended by Directive 2009/136/EC, remains the specific law on confidentiality of electronic communications and on storing or accessing information in terminal equipment, as described above.[^114]
Codes of conduct and certification (Articles 40 to 43) are voluntary tools. Adherence may be used as an element to demonstrate compliance with several GDPR duties, including Articles 24, 25, 28, 32 and 46.[^127]
Member State specifications. Recital 8 and Recital 10, and Chapter IX, leave room for Member State law in defined areas: employment (Article 88), freedom of expression and information including journalism (Article 85), public access to official documents (Article 86), national identification numbers (Article 87), archiving, research and statistics (Article 89), secrecy obligations (Article 90), and churches and religious associations (Article 91).[^128] A compliance programme that operates in more than one Member State needs to map those national provisions, not only the GDPR text.
The Digital Omnibus proposal is not the GDPR
On 19 November 2025 the Commission presented COM(2025) 837, a proposal for a regulation amending, among other acts, Regulations (EU) 2016/679, 2018/1724, 2018/1725 and 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557, as regards simplification of the digital legislative framework (Digital Omnibus).[^7]
The Commission’s accompanying news item of 19 November 2025 states that targeted amendments to the GDPR will, in the Commission’s words, harmonise, clarify and simplify certain rules, without lowering data protection standards, and that modernised cookie rules will improve users’ experience online. The proposals were submitted to the European Parliament and the Council for adoption.[^129]
The proposal’s explanatory memorandum records that stakeholders have in general found the GDPR balanced and sound and continuing to be fit for purpose, while some entities, especially smaller companies and associations with a low number of data-intensive, often low-risk processing operations, expressed concerns regarding the application of some GDPR rules.[^7]
Until that proposal is adopted and applies, controllers and processors remain bound by Regulation (EU) 2016/679 as it stands, by Regulation (EU) 2025/2518 from 2 April 2027 for the procedural rules it contains, and by the ePrivacy Directive as amended in 2009.
Building a compliance programme that matches the text
The Regulation does not prescribe a named “GDPR programme.” It does prescribe outcomes that a programme has to produce.
Start with inventory. Article 30 records, even where the small-organisation exemption might apply, are the practical way to list purposes, categories of data subjects and data, recipients, transfers, retention and security measures. Without that list, Articles 13 and 14 notices, Article 6 lawful-basis choices, Article 9 analysis, and Article 15 responses cannot be shown to match the processing that actually occurs.
Assign roles. For each processing activity, identify the controller, any joint controllers, and each processor. Put Article 26 arrangements and Article 28 contracts in writing. If Article 3(2) applies and no Article 27(2) exception is available, designate a Union representative.
Choose a lawful basis per purpose, before the processing starts. Document why that basis fits. For Article 6(1)(f), keep the three-step assessment the EDPB describes. For consent, keep evidence that it was freely given, specific, informed and unambiguous, that withdrawal is as easy as giving consent, and that the Article 7(4) conditionality test was considered. Do not use consent where a contract actually requires the processing, or where an imbalance of power makes free consent unlikely.
Write notices that contain every Article 13 or 14 item that applies. Meet the Article 12 language and timing rules. Build a process that can meet the one-month (extendable to three months) deadline in Article 12(3) for rights requests, including identity checks under Article 12(6).
Implement Article 25 defaults: collect only what is needed, keep it only as long as needed, and do not make it publicly accessible by default. Implement Article 32 security that is appropriate to the risk, with a process for regular testing.
Write a breach procedure that can decide, within hours not days, whether Article 33 notification is required, whether Article 34 communication is required, and how the Article 33(5) internal record will be kept. Processors need a contractual path to notify the controller without undue delay.
Screen processing against Article 35(3) and the WP29 nine criteria. Carry out DPIAs before high-risk processing starts. Seek the DPO’s advice where a DPO is designated. Consult the supervisory authority under Article 36 where residual high risk remains.
Map every flow of personal data out of the EEA. If the recipient is in a country, territory, sector or organisation covered by a current adequacy decision, record that decision and its limits (for example, US transfers only to organisations on the Data Privacy Framework List). Otherwise put in place an Article 46 tool, complete a transfer assessment of the kind Schrems II and Recommendations 01/2020 require, and add supplementary measures where needed. Treat Article 49 as exceptional.
Treat cookies and similar technologies under Article 5(3) of Directive 2002/58/EC first, then under the GDPR if personal data are involved. Do not use pre-ticked boxes. Do not make access to the service conditional on consent to unnecessary storage or access in terminal equipment.
Designate a DPO where Article 37(1) requires it. Even where designation is not mandatory, someone still has to do the work that Articles 5(2) and 24 describe.
Review. Article 24 requires measures to be reviewed and updated where necessary. Article 35(11) requires a DPIA review when the risk changes. Adequacy decisions are reviewed at least every four years.[^102] Consent can be withdrawn at any time.[^61] A static policy document is not, by itself, compliance.
How to use the checklist
The downloadable checklist restates the duties above as yes/no items, each tied to an article of the GDPR or to a named official text. Work through it against a real inventory of processing, not against an abstract description of the organisation. Mark items that do not apply, and record why. Keep the completed checklist with the Article 30 records.
Print it, or open it in a browser and use the browser’s print function to save a PDF.
Download the GDPR compliance checklist
This article describes the law as published on 17 August 2026. It is not legal advice. Supervisory authorities and courts apply the Regulation to facts. Member State law under Chapter IX and under Articles 6(2), 9(4) and 88 can add conditions that this Union-level guide does not list.
Notes and references
[^1]: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1). EUR-Lex, CELEX 32016R0679.
[^2]: GDPR, Article 99.
[^3]: European Data Protection Board, Guidelines 05/2020 on consent under Regulation 2016/679, Version 1.1, adopted 4 May 2020. The guidelines refer to Decision of the EEA Joint Committee No 154/2018 of 6 July 2018. PDF.
[^4]: European Commission, “Data protection adequacy for non-EU countries,” page as retrieved 17 August 2026. Commission page.
[^5]: GDPR, Article 2(2)(d) and recital 19; Directive (EU) 2016/680 (OJ L 119, 4.5.2016, p. 89).
[^6]: GDPR, Article 2(3) and recital 17; EUR-Lex summary of Regulation (EU) 2016/679, last update 24 March 2026, referring also to Regulation (EU) 2018/1725 and Regulation (EU) 2025/2518. EUR-Lex LSU.
[^7]: European Commission, Proposal for a Regulation of the European Parliament and of the Council amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus), COM(2025) 837 final, Brussels, 19.11.2025. EUR-Lex 52025PC0837.
[^8]: GDPR, Article 1.
[^9]: GDPR, recital 1; Charter of Fundamental Rights of the European Union, Article 8(1); Treaty on the Functioning of the European Union, Article 16(1).
[^10]: GDPR, recital 4.
[^11]: GDPR, Article 94.
[^12]: GDPR, recital 9.
[^13]: GDPR, recital 13.
[^14]: GDPR, recital 15.
[^15]: GDPR, Article 2(1).
[^16]: GDPR, Article 2(2).
[^17]: GDPR, recital 18.
[^18]: GDPR, recital 16.
[^19]: GDPR, Article 2(4).
[^20]: GDPR, Article 3.
[^21]: GDPR, recital 22.
[^22]: GDPR, recital 23.
[^23]: GDPR, recital 24.
[^24]: GDPR, Article 3(3) and recital 25.
[^25]: European Data Protection Board, Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), after public consultation. PDF.
[^26]: GDPR, Article 27.
[^27]: GDPR, Article 4(1).
[^28]: GDPR, recital 26.
[^29]: GDPR, recital 30.
[^30]: GDPR, recital 14.
[^31]: GDPR, recital 27.
[^32]: GDPR, Article 4(2).
[^33]: GDPR, Article 4(7).
[^34]: GDPR, Article 4(8).
[^35]: European Data Protection Board, Guidelines 07/2020 on the concepts of controller and processor in the GDPR. PDF.
[^36]: GDPR, Article 4(11).
[^37]: GDPR, Article 4(12).
[^38]: GDPR, Article 4(4).
[^39]: GDPR, Article 4(5).
[^40]: GDPR, recital 28.
[^41]: GDPR, Article 4(13) to (15) and Article 9(1).
[^42]: GDPR, Article 4(16), (22), (23); Articles 55 and 56.
[^43]: GDPR, Article 5.
[^44]: GDPR, recital 39.
[^45]: GDPR, Article 6(4).
[^46]: GDPR, recital 50.
[^47]: GDPR, Article 24.
[^48]: GDPR, Article 6(1).
[^49]: GDPR, recital 40.
[^50]: GDPR, Article 6(3).
[^51]: GDPR, Article 6(2).
[^52]: Judgment of the Court (Grand Chamber) of 4 July 2023, Meta Platforms and Others, C-252/21, EU:C:2023:537. EUR-Lex 62021CJ0252.
[^53]: GDPR, recital 46.
[^54]: GDPR, recital 47.
[^55]: GDPR, recital 48.
[^56]: GDPR, recital 49.
[^57]: European Data Protection Board, Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR, adopted 8 October 2024; EDPB news of that adoption. PDF. News item.
[^58]: GDPR, Articles 13(1)(d) and 14(2)(b).
[^59]: GDPR, Article 21.
[^60]: GDPR, recital 32.
[^61]: GDPR, Article 7.
[^62]: GDPR, recital 42.
[^63]: GDPR, recital 43.
[^64]: Judgment of the Court (Grand Chamber) of 1 October 2019, Planet49, C-673/17, EU:C:2019:801. EUR-Lex 62017CJ0673.
[^65]: GDPR, Article 8.
[^66]: GDPR, recital 38.
[^67]: GDPR, recital 171.
[^68]: GDPR, Article 9.
[^69]: GDPR, Article 10.
[^70]: GDPR, Article 12.
[^71]: GDPR, Article 13.
[^72]: GDPR, Article 14.
[^73]: GDPR, Article 15.
[^74]: GDPR, Article 16.
[^75]: GDPR, Article 17.
[^76]: GDPR, Article 18.
[^77]: GDPR, Article 19.
[^78]: GDPR, Article 20.
[^79]: GDPR, Article 22.
[^80]: GDPR, Article 23.
[^81]: GDPR, Article 11.
[^82]: GDPR, Article 25.
[^83]: GDPR, Article 26.
[^84]: GDPR, Article 28.
[^85]: Commission Implementing Decision (EU) 2021/915 of 4 June 2021 on standard contractual clauses between controllers and processors under Article 28(7) of Regulation (EU) 2016/679 and Article 29(7) of Regulation (EU) 2018/1725. The Decision states that the clauses in the Annex fulfil Article 28(3) and (4) GDPR. EUR-Lex.
[^86]: GDPR, Article 29.
[^87]: GDPR, Article 30.
[^88]: GDPR, Article 32.
[^89]: GDPR, Article 33.
[^90]: GDPR, Article 34.
[^91]: European Data Protection Board, Guidelines 9/2022 on personal data breach notification under GDPR, version 2.0. PDF.
[^92]: GDPR, Article 35.
[^93]: Article 29 Data Protection Working Party, Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is “likely to result in a high risk” for the purposes of Regulation 2016/679, WP248 rev.01, adopted 4 April 2017, last revised and adopted 4 October 2017, endorsed by the EDPB. Listed at EDPB endorsed WP29 guidelines.
[^94]: Article 29 Data Protection Working Party, Guidelines on Data Protection Officers (‘DPOs’), WP243 rev.01, endorsed by the EDPB.
[^95]: GDPR, Article 36.
[^96]: GDPR, Article 37.
[^97]: GDPR, Article 38.
[^98]: GDPR, Article 39.
[^99]: GDPR, Article 44.
[^100]: GDPR, recital 101.
[^101]: GDPR, Article 48.
[^102]: GDPR, Article 45.
[^103]: Commission Implementing Decision of 26.1.2026 pursuant to Regulation (EU) 2016/679 on the adequate level of protection of personal data by Brazil, C(2026) 373 final. Linked from the Commission adequacy page.
[^104]: Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 pursuant to Regulation (EU) 2016/679 on the adequate level of protection of personal data under the EU-US Data Privacy Framework. EUR-Lex.
[^105]: European Data Protection Board, Information note on data transfers under the GDPR to the United States after the adoption of the adequacy decision on 10 July 2023. PDF.
[^106]: Judgment of the Court (Grand Chamber) of 16 July 2020, Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems, C-311/18, EU:C:2020:559. EUR-Lex 62018CJ0311.
[^107]: GDPR, Article 46.
[^108]: Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679. EUR-Lex.
[^109]: European Data Protection Board, Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data, Version 2.0. PDF.
[^110]: GDPR, Article 47.
[^111]: GDPR, Article 49.
[^112]: European Data Protection Board, Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679. PDF.
[^113]: GDPR, Article 95.
[^114]: Directive 2002/58/EC, Article 5(3), as replaced by Directive 2009/136/EC of the European Parliament and of the Council of 25 November 2009 (OJ L 337, 18.12.2009, p. 11), Article 2(5). EUR-Lex 32009L0136.
[^115]: GDPR, Articles 51 and 52.
[^116]: GDPR, Articles 55, 56, 60 and 65.
[^117]: GDPR, Article 58.
[^118]: GDPR, Articles 77, 78 and 79.
[^119]: GDPR, Article 80.
[^120]: GDPR, Article 82.
[^121]: GDPR, recital 146.
[^122]: GDPR, Article 83.
[^123]: GDPR, recital 148.
[^124]: European Data Protection Board, Guidelines 04/2022 on the calculation of administrative fines under the GDPR. PDF.
[^125]: GDPR, Article 84.
[^126]: Regulation (EU) 2025/2518 of the European Parliament and of the Council of 26 November 2025 laying down additional procedural rules on the enforcement of Regulation (EU) 2016/679 (OJ L, 2025/2518, 12.12.2025). EUR-Lex.
[^127]: GDPR, Articles 40 to 43, and the demonstration clauses in Articles 24(3), 25(3), 28(5), 32(3) and 46(2)(e) and (f).
[^128]: GDPR, recitals 8 and 10; Chapter IX, Articles 85 to 91.
[^129]: European Commission, “Simpler digital rules to help EU businesses grow,” 19 November 2025, Directorate-General for Communication. Commission news.