← Framework library

EU General Data Protection Regulation

The obligations of the EU General Data Protection Regulation most often examined in a policy review or audit, expressed as controls — one per article (or tightly linked group of articles), each citing the article it derives from. UK GDPR mirrors these obligations; where the UK differs, the control says so.

European Union · Regulation (EU) 2016/679, in force since 25 May 2018 · European Union / EEA, with extraterritorial reach under Article 3; mirrored in the UK by UK GDPR · Official source

GDPR is law, not a control framework: an obligation cannot be marked 'not applicable' because it is inconvenient, only because the processing it governs does not occur (for example Article 8 if no service is offered to children, or Article 27 if the organisation is established in the EU). Requirement text is paraphrased for assessment purposes — the articles themselves are authoritative, and this tool is not legal advice. UK GDPR (the retained version, as amended by the Data (Use and Access) Act 2025) follows the same article numbering; the supervisory authority is the ICO.
39 of 39 controls
Art.5(1)(a) Lawfulness, fairness and transparency critical

Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject.

Principles lawful-basisprivacy-notice
Art.5(1)(b) Purpose limitation high

Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.

Principles data-minimisationlawful-basis
Art.5(1)(c) Data minimisation high

Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.

Principles data-minimisation
Art.5(1)(d) Accuracy medium

Personal data shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to erase or rectify inaccurate data without delay.

Principles integrity
Art.5(1)(e) Storage limitation high

Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed.

Principles data-retentiondata-deletion
Art.5(1)(f) Integrity and confidentiality critical

Personal data shall be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

Principles encryption-at-restencryption-in-transitaccess-control
Art.5(2) Accountability high

The controller shall be responsible for, and be able to demonstrate compliance with, the principles of Article 5(1).

Principles policy-governancerecords
Art.6 Lawful basis for processing critical

Processing is lawful only if at least one of the six Article 6 bases applies: consent, contract, legal obligation, vital interests, public task or legitimate interests.

Lawfulness lawful-basisconsent
Art.7 Conditions for consent high

Where processing is based on consent, the controller must be able to demonstrate that consent was freely given, specific, informed and unambiguous, and the data subject must be able to withdraw it as easily as it was given.

Lawfulness consent
Art.8 Conditions for a child's consent to online services high

Where consent is the basis for offering an information society service directly to a child, processing is lawful only if the child is at least 16 — or a lower age set by the Member State, not below 13 — or if consent is given or authorised by the holder of parental responsibility, and the controller makes reasonable efforts to verify this.

Lawfulness consentlawful-basischildren
Art.9 Special category data critical

Processing of data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation is prohibited unless an Article 9(2) condition applies.

Lawfulness data-classificationlawful-basis
Art.10 Criminal convictions and offences data high

Personal data relating to criminal convictions and offences may be processed only under the control of official authority or where authorised by Union or Member State law providing appropriate safeguards.

Lawfulness data-classificationlawful-basis
Art.12 Transparent communication and handling of rights requests high

Information and communications to data subjects must be concise, transparent, intelligible and easily accessible, in clear and plain language. Requests to exercise rights must be answered without undue delay and within one month (extendable by two further months for complex requests), free of charge, with reasonable identity verification and reasons given for any refusal.

Data subject rights privacy-noticedata-subject-rights
Art.13 Information when data is collected from the data subject high

When personal data is collected from the data subject, the controller must at that time provide its identity and contact details, the DPO's contact details, the purposes and lawful basis (including the legitimate interests pursued), recipients, any third-country transfers, the retention period, the data subject's rights including withdrawal of consent and the right to complain to a supervisory authority, and whether providing the data is a statutory or contractual requirement.

Data subject rights privacy-notice
Art.14 Information when data is not obtained from the data subject medium

Where personal data is obtained from another source, the controller must provide the Article 13 information plus the categories of data and their source, within a reasonable period and at the latest within one month — or at first communication or first disclosure to another recipient, if earlier — unless an Article 14(5) exception applies.

Data subject rights privacy-noticethird-party
Art.15 Right of access high

Data subjects have the right to obtain confirmation of whether their personal data is being processed and, where it is, a copy of that data together with prescribed supplementary information, normally within one month.

Data subject rights data-subject-rights
Art.16 Right to rectification medium

Data subjects have the right to have inaccurate personal data corrected, and incomplete data completed, without undue delay.

Data subject rights data-subject-rightsintegrity
Art.17 Right to erasure (“right to be forgotten”) high

Data subjects have the right to erasure without undue delay where an Article 17(1) ground applies — for example the data is no longer necessary, consent is withdrawn, an objection is upheld or processing is unlawful — subject to the Article 17(3) exceptions such as legal obligations to retain; where data was made public, reasonable steps must be taken to inform other controllers.

Data subject rights data-subject-rightsdata-deletion
Art.18 Right to restriction of processing medium

Data subjects may obtain restriction of processing while accuracy is contested, where processing is unlawful but erasure is opposed, where the controller no longer needs the data but the data subject needs it for legal claims, or pending verification of an objection; restricted data may then only be stored, and the data subject must be told before a restriction is lifted.

Data subject rights data-subject-rights
Art.19 Notifying recipients of rectification, erasure or restriction medium

The controller shall communicate any rectification, erasure or restriction to each recipient to whom the data was disclosed, unless this proves impossible or involves disproportionate effort, and shall tell the data subject about those recipients if they ask.

Data subject rights data-subject-rightsthird-party
Art.20 Right to data portability medium

Where processing is based on consent or contract and carried out by automated means, the data subject has the right to receive their data in a structured, commonly used and machine-readable format and to transmit it to another controller.

Data subject rights data-subject-rights
Art.21 Right to object, including to direct marketing high

Data subjects may object to processing based on public task or legitimate interests, which must then stop unless compelling legitimate grounds override; objection to direct marketing (including related profiling) is absolute. The right must be explicitly brought to the data subject's attention, at the latest at the first communication.

Data subject rights data-subject-rightsconsent
Art.22 Automated decision-making and profiling medium

Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, unless it is necessary for a contract, authorised by law or based on explicit consent — and then with safeguards including the right to human intervention, to express their view and to contest the decision.

Data subject rights data-subject-rights
Art.24 Responsibility of the controller high

Taking into account the nature, scope, context, purposes and risks of processing, the controller shall implement appropriate technical and organisational measures — including, where proportionate, data protection policies — to ensure and be able to demonstrate compliance, and review and update them where necessary.

Controller obligations policy-governance
Art.25 Data protection by design and by default high

The controller shall implement data protection principles, such as data minimisation and pseudonymisation, both when determining the means of processing and at the time of processing (by design), and ensure that by default only the personal data necessary for each purpose is processed and not made accessible to an indefinite number of people (by default).

Controller obligations sdlcdata-minimisation
Art.26 Joint controllers medium

Where two or more controllers jointly determine the purposes and means of processing, they must set out their respective responsibilities — in particular for data subject rights and transparency — in an arrangement whose essence is made available to data subjects.

Controller obligations vendor-managementroles-responsibilities
Art.27 EU representative for non-EU organisations high

A controller or processor not established in the EU that offers goods or services to, or monitors the behaviour of, people in the EU (Article 3(2)) must designate in writing a representative in a Member State where those people are, unless processing is occasional, not large-scale special-category or criminal data, and unlikely to result in a risk.

Controller obligations roles-responsibilitiescross-border-transfer
Art.28 Processors and processing agreements critical

Processing by a processor shall be governed by a contract setting out the subject matter, duration, nature and purpose of processing, the obligations in Article 28(3), and the requirement for prior authorisation of sub-processors.

Controller obligations vendor-managementthird-party
Art.29 Processing under the authority of the controller low

A processor, and any person acting under the authority of the controller or processor who has access to personal data, may process that data only on instructions from the controller, unless required to do so by law.

Controller obligations roles-responsibilitiesaccess-control
Art.30 Records of processing activities high

Controllers and processors shall maintain a record of processing activities including purposes, categories of data subjects and data, recipients, third-country transfers, retention periods and security measures.

Controller obligations recordsinventory
Art.31 Cooperation with the supervisory authority low

The controller and processor, and where applicable their representatives, shall cooperate on request with the supervisory authority in the performance of its tasks.

Accountability policy-governance
Art.32 Security of processing critical

The controller and processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including pseudonymisation and encryption, resilience, restoration of availability, and a process for regularly testing the effectiveness of measures.

Security encryption-at-restencryption-in-transitaccess-controlbackup
Art.33 Notification of a breach to the supervisory authority critical

In the case of a personal data breach, the controller shall notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to individuals.

Security breach-notificationincident-response
Art.34 Communication of a breach to data subjects high

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate it to the data subjects without undue delay.

Security breach-notification
Art.35 Data protection impact assessment high

Where processing is likely to result in a high risk to the rights and freedoms of natural persons, in particular using new technologies, the controller shall carry out a data protection impact assessment prior to the processing.

Accountability dpiarisk-assessment
Art.36 Prior consultation with the supervisory authority medium

Where a data protection impact assessment indicates that processing would result in a high risk in the absence of measures taken by the controller to mitigate it, the controller shall consult the supervisory authority before starting the processing.

Accountability dpiarisk-assessment
Art.37 Designation of a data protection officer medium

A controller or processor must designate a DPO if it is a public authority, or if its core activities involve large-scale regular and systematic monitoring of individuals or large-scale processing of special-category or criminal data; the DPO's contact details must be published and communicated to the supervisory authority. Others should record why no DPO is required.

Accountability dporoles-responsibilities
Art.38-39 Position and tasks of the data protection officer medium

The DPO must be involved properly and in a timely manner in all data protection issues, be given the resources needed, report directly to the highest management level, not receive instructions on the exercise of their tasks or be penalised for performing them, and have no conflicting duties. Their tasks include informing and advising, monitoring compliance, advising on DPIAs and acting as contact point for the supervisory authority.

Accountability dporoles-responsibilities
Art.44-49 Transfers of personal data to third countries critical

Transfers of personal data outside the EEA require an adequacy decision, appropriate safeguards such as standard contractual clauses or binding corporate rules, or a derogation, together with a transfer impact assessment where safeguards are relied upon.

Transfers cross-border-transfervendor-management