European Union
Tier 3 Comprehensive law SupranationalPrincipal framework: Regulation (EU) 2016/679 (GDPR), directly applicable in all member states without national transposition. Member states legislate only in the areas the GDPR's opening clauses leave to them, which is why national implementing acts are derogations from a shared text rather than independent statutes. Enforcement is national: each state has its own supervisory authority, coordinated through the European Data Protection Board.
At a glance
- Principal law
- Regulation (EU) 2016/679 (GDPR)
- Regulator
- National supervisory authorities, coordinated by the EDPB
- Breach notification
- 72 hours to the supervisory authority (Art 33); undue-delay notice to individuals at high risk
- Maximum penalty
- Up to €20m or 4% of global annual turnover
- Extraterritorial reach
- Yes — targeting or monitoring people in the EU (Art 3(2))
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- EU
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Regulators
- European Data Protection Board EDPB
Coordinates the national supervisory authorities, issues guidelines and resolves cross-border disputes. It does not supervise controllers directly — that is the national authority's job.
- European Data Protection Supervisor EDPS
Supervises the EU institutions and bodies themselves, under a separate regulation.
Transfers and adequacy
- EU member
- Yes
- EEA member
- Yes
Instruments
Sources
- Primary Regulation (EU) 2016/679 (GDPR) EUR-Lex
- Regulator European Data Protection Board EDPB
Never independently verified — seeded from the prototype.