Data Protection Atlas

European Union

Tier 3 Comprehensive law Supranational

Principal framework: Regulation (EU) 2016/679 (GDPR), directly applicable in all member states without national transposition. Member states legislate only in the areas the GDPR's opening clauses leave to them, which is why national implementing acts are derogations from a shared text rather than independent statutes. Enforcement is national: each state has its own supervisory authority, coordinated through the European Data Protection Board.

At a glance

Principal law
Regulation (EU) 2016/679 (GDPR)
Regulator
National supervisory authorities, coordinated by the EDPB
Breach notification
72 hours to the supervisory authority (Art 33); undue-delay notice to individuals at high risk
Maximum penalty
Up to €20m or 4% of global annual turnover
Extraterritorial reach
Yes — targeting or monitoring people in the EU (Art 3(2))

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
EU

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Regulators

  • European Data Protection Board EDPB

    Coordinates the national supervisory authorities, issues guidelines and resolves cross-border disputes. It does not supervise controllers directly — that is the national authority's job.

  • European Data Protection Supervisor EDPS

    Supervises the EU institutions and bodies themselves, under a separate regulation.

Transfers and adequacy

EU member
Yes
EEA member
Yes

Instruments

Sources

Never independently verified — seeded from the prototype.