Data Protection Atlas

Regulation (EU) 2016/679

Tier 1 In force

The GDPR is the EU's general-purpose regime for the processing of personal data of natural persons; it directly binds controllers and processors across the EU/EEA and, via Article 3, reaches organisations established outside the EU that offer goods or services to, or monitor, people in the Union. The single most commonly misunderstood point is that the GDPR itself creates no criminal offences and sets no criminal penalties: Article 84 delegates "other penalties" (including criminal ones) to member state law, so the administrative-fine track (regulator versus organisation) and any criminal track (prosecutor versus defendant, often an individual, under national law) are separate. It also does not occupy the whole field: law enforcement processing (Directive 2016/680), EU-institution processing (Regulation 2018/1725) and national security sit outside it, and the ePrivacy Directive prevails as lex specialis for electronic communications.

Identity

Citation
Regulation (EU) 2016/679 (General Data Protection Regulation)
Jurisdiction
European Union
Type
comprehensive
Structure
11 Chapters, 99 Articles, 173 Recitals
Royal assent
27 April 2016
Main commencement
25 May 2018

Adopted 27 April 2016, published in OJ L 119 on 4 May 2016, entered into force on the twentieth day after publication (24 May 2016), but applied only from 25 May 2018 (Article 99) — a two-year transition. Article 94 repealed Directive 95/46/EC with effect from the same date, 25 May 2018. Note a date distinction some summaries collapse: 14 April 2016 was the European Parliament's final plenary vote; 27 April 2016 is the date the instrument itself bears.

Amended by: The GDPR has not been substantively amended since it applied in 2018. It was supplemented, not amended, by Regulation (EU) 2025/2518 (the GDPR Procedural Regulation), done at Strasbourg on 26 November 2025, published in OJ L 2025/2518 on 12 December 2025 and entering into force on 1 January 2026, with its dispute-resolution and urgency provisions (Arts 65 and 66 GDPR cases) applying after 2 April 2027; it lays down additional procedural rules for cross-border enforcement without changing substantive obligations. The European Commission's Digital Omnibus proposal (COM(2025) 837, published 19 November 2025) would amend several GDPR articles but, as of July 2026, remains a proposal under negotiation and is not in force (see liveIssues).

← European Union overview

Reads together with

  • Directive 2002/58/EC (ePrivacy Directive)

    Lex specialis for electronic communications. Article 95 GDPR provides the GDPR imposes no additional obligations where matters are already subject to specific ePrivacy obligations with the same objective; the ePrivacy Directive prevails on, for example, cookie/terminal-equipment consent (Art 5(3)) and confidentiality of communications, while the GDPR fills the gaps (such as the definition of valid consent).

  • Directive (EU) 2016/680 (Law Enforcement Directive)

    Governs processing by competent authorities for prevention, investigation, detection or prosecution of criminal offences; GDPR Article 2(2)(d) and Recital 19 exclude this from GDPR scope. The two are complementary, not overlapping.

  • Regulation (EU) 2018/1725 (EUDPR)

    Governs processing by EU institutions, bodies, offices and agencies; materially equivalent to the GDPR. GDPR Article 2(3) directs EU-institution processing to this regime (the article as enacted names the predecessor Regulation (EC) 45/2001, since replaced by 2018/1725).

  • National implementing and derogating law

    The GDPR contains numerous "opening clauses" (for example Arts 6(2)-(3), 8, 9(4), 23, 85-90) that require or permit member state law. For several questions the accurate answer is "left to national law".

Asymmetry checklist

All ten points answered explicitly. "None found — checked" is a recorded answer, not a gap.

# Point Finding Notes
1 Territorial extent Asymmetry found The GDPR applies uniformly across the 27 EU member states and, through the EEA Agreement, in Norway, Iceland and Liechtenstein (30 states in total). It does not apply of its own force in the UK post-Brexit, which retains a separate domestic "UK GDPR". Article 3 gives it extraterritorial reach over non-EU establishments that target or monitor people in the Union. The asymmetry is not an internal regional carve-out but the mix of EEA extension, extraterritorial reach and the extensive space left to member state law under the opening clauses, which produces genuine variation in application across territories.
2 Commencement Asymmetry found Adopted 27 April 2016, in force 24 May 2016, but applicable only from 25 May 2018 — a deliberate two-year gap to let controllers and member states prepare and adopt implementing legislation. The substantive obligations came fully into effect on 25 May 2018 and nothing in the GDPR itself is still phased or pending. Cross-border enforcement procedure was later supplemented by the GDPR Procedural Regulation (EU) 2025/2518, whose dispute-resolution provisions apply after 2 April 2027.
3 Sunset / mandatory review Asymmetry found There is no sunset or expiry. Article 97 imposes a mandatory review cycle: the Commission must submit an evaluation and review report by 25 May 2020 and every four years thereafter, examining in particular Chapter V (international transfers) and Chapter VII (cooperation and consistency). The first report was adopted on 24 June 2020; the second report on the application of the GDPR was adopted on 25 July 2024 (COM(2024) 357). Article 97(5) allows the Commission to propose amendments where necessary.
4 Criminal liability Asymmetry found This is the point most summaries get wrong. The GDPR itself creates no criminal offences. Article 84 requires member states to lay down "the rules on other penalties" for infringements not subject to Article 83 administrative fines, and Recital 149 confirms member states "should be able to lay down the rules on criminal penalties". Whether custody is available, for what conduct, and against whom is therefore a matter of national law and varies. Recital 149 also flags the ne bis in idem constraint where administrative and criminal penalties overlap.
5 Civil liability Asymmetry found Article 82 gives any person who has suffered material or non-material damage a direct right to compensation from the controller or processor, in national courts, independent of any regulator action. The CJEU has confirmed there is no de minimis or seriousness threshold for non-material damage (C-300/21 Osterreichische Post; reaffirmed C-687/21, C-741/21 juris, and C-655/23 Quirin Privatbank, 4 September 2025), but the claimant must still prove actual damage and a causal link — mere infringement is not enough. Article 80 provides for representation by non-profit bodies; Directive (EU) 2020/1828 (Collective Redress) lists the GDPR in its Annex I.
6 Regulatory enforcement toolkit Asymmetry found Under Article 58(2) a supervisory authority can issue warnings and reprimands; order compliance with data subject requests; order processing brought into compliance; order breach communication to data subjects; impose a temporary or definitive ban on processing; order rectification/erasure; withdraw certifications; suspend data flows to third countries; and impose administrative fines under Article 83. Fines are two-tier (see the enforcement block). Enforcement is national, through independent supervisory authorities, coordinated for cross-border cases by the one-stop-shop (Arts 56/60) and the consistency mechanism/EDPB (Arts 63-65).
7 Personal / director liability Asymmetry found The GDPR's administrative fines and Article 82 damages target the controller or processor (the organisation), not individual officers. Personal liability of a director or officer arises, if at all, under national law — including any criminal penalties enacted under Article 84 and general company/labour law. The DPO has protected status under Article 38(3): they cannot be dismissed or penalised for performing their tasks and report to the highest management level; Article 29 Working Party guidance states DPOs are not personally liable for the organisation's GDPR compliance.
8 Public vs private sector split Asymmetry found The GDPR applies to both public and private sector controllers under one regime, though it allows member states to tailor rules for the public sector (for example Art 6(2)-(3)) and to set differentiated fine rules for public authorities (Art 83(7)). Sitting entirely outside the GDPR: law enforcement processing by competent authorities (Directive 2016/680), processing by EU institutions and bodies (Regulation 2018/1725), and activities outside Union law including national security (Art 2(2)(a)).
9 Legal-person coverage Asymmetry found The GDPR protects natural persons only. Recital 14 states protection applies to natural persons and that "This Regulation does not cover the processing of personal data which concerns legal persons ... including the name and the form of the legal person and the contact details". Data about a company can nonetheless be personal data of a natural person (for example a sole trader or named employee) and then falls within scope.
10 Exemptions — with conditions Asymmetry found The exemption regime is not a set of blanket carve-outs. Article 23 permits member states to restrict specified rights and obligations only where necessary and proportionate to safeguard listed objectives (a necessity-and-proportionality test set nationally). Article 85 requires member states to reconcile data protection with freedom of expression/journalism. Article 89 permits derogations for research/archiving/statistics subject to safeguards. Article 2(2)(c) exempts purely personal or household activity (read narrowly per Ryneš). Article 2(2)(a) and (d) exclude activities outside Union law/national security and law enforcement. Detail is in the exemptions block.

Civil liability

Article 82 gives data subjects a directly enforceable right to compensation from a controller or processor for material or non-material damage caused by processing that infringed the GDPR, pursued in national courts independently of any regulatory action. A controller/processor escapes liability only by proving it was "not in any way responsible" for the event giving rise to the damage (Art 82(3)). The CJEU has rejected any minimum seriousness threshold for non-material damage but requires proof of actual damage and causation.

  • Article 82

    National courts of the member state (per Art 79(2): where the controller/processor has an establishment, or where the data subject is resident) · Material and non-material damage (including distress, loss of control, well-founded fear of misuse); no de minimis threshold but damage must be proven — Joint controllers and controllers/processors involved in the same processing can be held jointly and severally liable (Art 82(4)).

  • Article 80 / Directive (EU) 2020/1828

    National courts, via qualified non-profit entities · Representative/collective redress for GDPR (and ePrivacy) infringements; opt-in or, where member states allow (Art 80(2)), broader — Article 80(1) mandate-based representation is available EU-wide; Article 80(2) mandate-free/collective action is left to member state choice. The GDPR is listed in Annex I of the Collective Redress Directive.

Regulatory enforcement

Penalty ceiling
Two tiers. Lower tier (Article 83(4)): up to EUR 10,000,000 or, for an undertaking, up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher — for infringements of controller/processor obligations (Arts 8, 11, 25-39, 42, 43) and certification/monitoring body duties. Higher tier (Article 83(5)): up to EUR 20,000,000 or up to 4% of total worldwide annual turnover, whichever is higher — for infringements of the basic principles and consent (Arts 5, 6, 7, 9), data subject rights (Arts 12-22), international transfer rules (Arts 44-49), and non-compliance with an SA order (also Art 83(6)). The EDPB Guidelines 04/2022 set a harmonised methodology. The largest single fine to date is the EUR 1.2 billion imposed on Meta by Ireland's Data Protection Commission in 2023 for unlawful transfers, illustrating that for large undertakings the percentage cap far exceeds the fixed euro amount.
  • Warning Art 58(2)(a)

    Formal warning that intended processing is likely to infringe

  • Reprimand Art 58(2)(b)

    Censure for processing that has infringed

  • Compliance / bring-into-compliance order Art 58(2)(c)-(d)

    Order to satisfy data subject requests or bring processing into line, within a set period

  • Ban / limitation on processing Art 58(2)(f)

    Temporary or definitive limitation, including a ban

  • Erasure / rectification order Art 58(2)(g)

    Order rectification, erasure or restriction and notify recipients

  • Suspension of data flows Art 58(2)(j)

    Order suspension of data transfers to a third country recipient

  • Administrative fine Art 58(2)(i) / Art 83

    Two-tier fines (see penaltyCeiling)

Enforcement is national; each SA acts on its own territory, with cross-border cases coordinated through the one-stop-shop and EDPB consistency mechanism. These regulatory powers are separate from any national criminal track under Article 84 and from Article 82 civil claims: the same incident can attract a regulatory fine against the organisation, a criminal prosecution of an individual under national law, and a private damages claim, in three different forums.

Personal / director liability

Available
No
Basis
GDPR targets controllers/processors; individual liability arises only under national law (including Art 84 penalties). DPO protected by Art 38(3).

The GDPR does not itself make company directors, officers or DPOs personally liable; its fines and Article 82 damages run against the organisation. Personal liability of individuals — criminal or otherwise — is a matter of national law, including any criminal offences a member state enacts under Article 84. The DPO enjoys protected status under Article 38(3) (no dismissal or penalty for performing their tasks; direct reporting line) and, per Article 29 Working Party guidance, is not personally liable for the organisation's compliance.

Legal-person coverage

Covers legal persons
No — natural persons only

Recital 14: protection applies to natural persons and "This Regulation does not cover the processing of personal data which concerns legal persons ... including the name and the form of the legal person and the contact details of the legal person." Company data can still be personal data of an associated natural person and then falls within scope.

Public / private sector split

Separate regimes
No — one statute

One GDPR regime covers both public and private sector controllers, with limited member-state tailoring for the public sector. The genuine "split" is what falls outside the GDPR entirely and is governed by sister instruments.

  • GDPR (Regulation 2016/679)

    General public and private sector processing of personal data

  • Law Enforcement Directive (2016/680)

    Processing by competent authorities for criminal law enforcement purposes (excluded by Art 2(2)(d))

  • EUDPR (Regulation 2018/1725)

    Processing by EU institutions, bodies, offices and agencies

  • Outside Union law / national security

    Excluded by Art 2(2)(a); governed, if at all, by national law

Exemptions

Recorded with their trigger conditions, not as bare names — most are conditional tests applied case by case rather than blanket carve-outs.

Article 23 — Member state restrictions on rights and obligations

Trigger

A member state (or Union) legislative measure may restrict the scope of specified obligations and rights (Arts 12-22, 34, and corresponding principles in Art 5) only when the restriction "respects the essence" of fundamental rights and is "a necessary and proportionate measure in a democratic society" to safeguard one of the listed objectives (national security, defence, public security, prevention/investigation of criminal offences, other important public interests, judicial independence, regulatory functions, protection of the data subject or others' rights, enforcement of civil claims). It is a necessity-and-proportionality test applied by the legislator, not a blanket carve-out, and must contain the specific safeguards listed in Art 23(2).

Disapplies

  • Transparency and information rights (Arts 12-14)
  • Right of access (Art 15)
  • Rectification, erasure, restriction, portability, objection (Arts 16-21)
  • Breach communication to data subject (Art 34)
  • Principles in Art 5 to the extent they correspond

National implementations vary widely; a "crime and taxation" style restriction is lawful only to the extent the necessity/proportionality test is met on the facts — a case-by-case prejudice assessment, not an automatic carve-out. This is where "left to member state law" is the accurate answer.

Article 85 — Journalism and academic, artistic or literary expression

Trigger

Member states "shall by law reconcile" the right to data protection with freedom of expression and information; they must provide exemptions or derogations from most of the GDPR (Chapters II-VII and IX) for processing carried out for journalistic purposes or academic, artistic or literary expression where necessary to reconcile the two rights. The balance is struck by national law and applied case by case by courts/SAs; it is not a self-executing GDPR exemption.

Disapplies

  • As determined by national law: principles, lawfulness, transparency, data subject rights, transfers, cooperation, and specific processing situations, to the extent necessary for expression

The "journalistic purposes" concept is read broadly by the CJEU (for example Buivids, Satakunnan Markkinaporssi) but the reconciliation and its limits are national.

Article 89 — Research, archiving and statistics safeguards and derogations

Trigger

Processing for archiving in the public interest, scientific or historical research, or statistical purposes is permitted subject to "appropriate safeguards" (in particular data minimisation and, where possible, pseudonymisation). On that condition, member state or Union law may derogate from certain data subject rights (Arts 15, 16, 18, 21) so far as those rights would render impossible or seriously impair the research/archiving objectives. Conditional on safeguards, not automatic.

Disapplies

  • Right of access (Art 15)
  • Right to rectification (Art 16)
  • Right to restriction (Art 18)
  • Right to object (Art 21) — for research/statistics and archiving as provided by national/Union law

The derogations must be enabled by Union or member state law and depend on the safeguards actually being in place; the Digital Omnibus proposals (see liveIssues) would touch this area.

Article 2(2)(c) — Purely personal or household activity

Trigger

The GDPR does not apply to processing by a natural person "in the course of a purely personal or household activity" with no connection to a professional or commercial activity. Read narrowly by the CJEU: in Ryneš (C-212/13) home CCTV that captured a public space fell outside the exemption. It is an activity-based test decided case by case; monetisation or outward-facing/public reach defeats it.

Disapplies

  • The entire GDPR, where the exemption applies

Recital 18 gives correspondence, address books and social networking/online activity for personal purposes as examples, but sharing beyond a limited private circle or any economic purpose can bring the processing back into scope.

Article 2(2)(a) and (d) — Scope exclusions — outside Union law, national security, law enforcement Territorial limit

Trigger

Automatic subject-matter exclusions, not conditional derogations. Art 2(2)(a) excludes processing "in the course of an activity which falls outside the scope of Union law" (national security is a member-state responsibility per Art 4(2) TEU). Art 2(2)(d) excludes processing by competent authorities for criminal law enforcement purposes, which is instead governed by Directive 2016/680.

Disapplies

  • The entire GDPR for the excluded activity

Territorial limit

National security remains a member-state responsibility, but the CJEU (for example La Quadrature du Net, Privacy International) has held that obligations imposed on private electronic communications providers can still fall within Union law even when the ultimate purpose is national security.

The law-enforcement exclusion is limited to competent authorities acting for those purposes; a private company's processing does not become exempt merely because data may later be used by police.

Interactions and conflicts

The cross-instrument texture that profiling an Act in isolation misses — including where the real answer to a question about this Act is found in a different one.

Instrument Relationship Note
Directive 2002/58/EC (ePrivacy Directive) Reads with Lex specialis for electronic communications. Article 95 GDPR means the GDPR adds no obligations where the ePrivacy Directive already imposes specific ones with the same objective; ePrivacy prevails on cookie/terminal-equipment consent (Art 5(3)) and confidentiality of communications. GDPR fills the gaps (for example defining valid consent).
Directive (EU) 2016/680 (Law Enforcement Directive) Lex specialis Governs processing by competent authorities for criminal law enforcement; GDPR Art 2(2)(d) and Recital 19 carve this out of GDPR scope. The LED prevails for in-scope law enforcement processing; the GDPR applies to the same body's non-law-enforcement processing.
Regulation (EU) 2018/1725 (EUDPR) Lex specialis Governs processing by EU institutions and bodies; materially equivalent to the GDPR but the applicable instrument for those controllers. GDPR Art 2(3) directs EU-institution processing to this regime.
Regulation (EU) 2024/1689 (AI Act) Cross-reference AI Act Article 2(7) states it "shall not affect" the GDPR (or EUDPR, ePrivacy, LED); the GDPR continues to apply and prevails on personal-data protection, save two narrow AI Act processing conditions for special-category data (Art 10(5) bias detection, Art 59 sandboxes).
Regulation (EU) 2023/2854 (Data Act) Cross-reference Data Act Article 1(5): without prejudice to the GDPR, and in the event of conflict the data-protection law "shall prevail"; the Data Act creates no new legal basis for processing personal data.
Regulation (EU) 2022/868 (Data Governance Act) Cross-reference DGA Article 1(3): without prejudice to the GDPR; on conflict, data-protection law prevails; creates no new processing bases.
Directive (EU) 2022/2555 (NIS2) Overlapping oversight Real, not theoretical, overlap. A single incident can trigger both NIS2 Art 23 incident reporting (to the CSIRT/competent cybersecurity authority, 24h/72h/1-month) and GDPR Art 33 personal-data-breach notification (to the DPA within 72h). Different regulators, different portals, no single-notification deconfliction between NIS2 and GDPR. Triggers do not always coincide.
Regulation (EU) 2025/2518 (GDPR Procedural Regulation) Cross-reference Supplements the GDPR's cross-border enforcement (Arts 60-66) with harmonised procedure, complaint requirements and defence rights; dispute-resolution provisions apply after 2 April 2027. Does not change substantive GDPR obligations.

Live issues

Sources

  • Primary Regulation (EU) 2016/679 (General Data Protection Regulation), consolidated text EUR-Lex, Publications Office of the European Union

    Primary source for all article and recital text (Arts 2, 3, 23, 58, 80, 82, 83, 84, 85, 89, 94, 95, 97, 99; Recitals 14, 18, 19, 149).

  • Primary Second report on the application of the GDPR (COM(2024) 357) European Commission (EUR-Lex CELEX 52024DC0357) no verified URL yet

    Adopted 25 July 2024 under Article 97; the first report was adopted 24 June 2020. URL not confirmed — verify on EUR-Lex before publishing.

  • Case law Judgment in Case T-553/23 Latombe v Commission (EU-US Data Privacy Framework) General Court of the European Union (curia.europa.eu) no verified URL yet

    3 September 2025; DPF adequacy upheld. Appeal pending as C-703/25 P. URL not confirmed — verify on curia.europa.eu before publishing.

  • Case law Judgment in Case C-413/23 P EDPS v SRB (concept of personal data) Court of Justice of the European Union (curia.europa.eu)

    4 September 2025 press release; pseudonymised data as a relative concept.

  • Regulator Opinion 08/2024 on valid consent in the context of consent or pay models European Data Protection Board

    Non-binding; adopted 17 April 2024.

  • Primary Regulation (EU) 2025/2518 (GDPR Procedural Regulation) EUR-Lex / Official Journal L 2025/2518, 12 December 2025 no verified URL yet

    Done 26 November 2025; in force 1 January 2026; dispute-resolution provisions apply after 2 April 2027. URL not confirmed — verify on EUR-Lex.

  • Primary Digital Omnibus proposal COM(2025) 837 and legislative tracker European Commission / European Parliament no verified URL yet

    Proposal of 19 November 2025; in negotiation as of July 2026. URL not confirmed — verify on EUR-Lex/OEIL.

  • Secondary GDPR Article 83 fines methodology (Guidelines 04/2022) and Article 82 case law digests EDPB; law-firm analyses (A&O Shearman, White & Case, Bird & Bird) no verified URL yet

    Used to corroborate the two-tier fine ceilings, the EUR 1.2 billion Meta fine and the non-material damages case law.

Never independently verified — seeded from the prototype.