EU General Data Protection Regulation
The obligations of the EU General Data Protection Regulation most often examined in a policy review or audit, expressed as controls — one per article (or tightly linked group of articles), each citing the article it derives from. UK GDPR mirrors these obligations; where the UK differs, the control says so.
European Union · Regulation (EU) 2016/679, in force since 25 May 2018 · European Union / EEA, with extraterritorial reach under Article 3; mirrored in the UK by UK GDPR · Official source
Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject.
Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes.
Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
Personal data shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to erase or rectify inaccurate data without delay.
Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed.
Personal data shall be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
The controller shall be responsible for, and be able to demonstrate compliance with, the principles of Article 5(1).
Processing is lawful only if at least one of the six Article 6 bases applies: consent, contract, legal obligation, vital interests, public task or legitimate interests.
Where processing is based on consent, the controller must be able to demonstrate that consent was freely given, specific, informed and unambiguous, and the data subject must be able to withdraw it as easily as it was given.
Where consent is the basis for offering an information society service directly to a child, processing is lawful only if the child is at least 16 — or a lower age set by the Member State, not below 13 — or if consent is given or authorised by the holder of parental responsibility, and the controller makes reasonable efforts to verify this.
Processing of data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation is prohibited unless an Article 9(2) condition applies.
Personal data relating to criminal convictions and offences may be processed only under the control of official authority or where authorised by Union or Member State law providing appropriate safeguards.
Information and communications to data subjects must be concise, transparent, intelligible and easily accessible, in clear and plain language. Requests to exercise rights must be answered without undue delay and within one month (extendable by two further months for complex requests), free of charge, with reasonable identity verification and reasons given for any refusal.
When personal data is collected from the data subject, the controller must at that time provide its identity and contact details, the DPO's contact details, the purposes and lawful basis (including the legitimate interests pursued), recipients, any third-country transfers, the retention period, the data subject's rights including withdrawal of consent and the right to complain to a supervisory authority, and whether providing the data is a statutory or contractual requirement.
Where personal data is obtained from another source, the controller must provide the Article 13 information plus the categories of data and their source, within a reasonable period and at the latest within one month — or at first communication or first disclosure to another recipient, if earlier — unless an Article 14(5) exception applies.
Data subjects have the right to obtain confirmation of whether their personal data is being processed and, where it is, a copy of that data together with prescribed supplementary information, normally within one month.
Data subjects have the right to have inaccurate personal data corrected, and incomplete data completed, without undue delay.
Data subjects have the right to erasure without undue delay where an Article 17(1) ground applies — for example the data is no longer necessary, consent is withdrawn, an objection is upheld or processing is unlawful — subject to the Article 17(3) exceptions such as legal obligations to retain; where data was made public, reasonable steps must be taken to inform other controllers.
Data subjects may obtain restriction of processing while accuracy is contested, where processing is unlawful but erasure is opposed, where the controller no longer needs the data but the data subject needs it for legal claims, or pending verification of an objection; restricted data may then only be stored, and the data subject must be told before a restriction is lifted.
The controller shall communicate any rectification, erasure or restriction to each recipient to whom the data was disclosed, unless this proves impossible or involves disproportionate effort, and shall tell the data subject about those recipients if they ask.
Where processing is based on consent or contract and carried out by automated means, the data subject has the right to receive their data in a structured, commonly used and machine-readable format and to transmit it to another controller.
Data subjects may object to processing based on public task or legitimate interests, which must then stop unless compelling legitimate grounds override; objection to direct marketing (including related profiling) is absolute. The right must be explicitly brought to the data subject's attention, at the latest at the first communication.
Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, unless it is necessary for a contract, authorised by law or based on explicit consent — and then with safeguards including the right to human intervention, to express their view and to contest the decision.
Taking into account the nature, scope, context, purposes and risks of processing, the controller shall implement appropriate technical and organisational measures — including, where proportionate, data protection policies — to ensure and be able to demonstrate compliance, and review and update them where necessary.
The controller shall implement data protection principles, such as data minimisation and pseudonymisation, both when determining the means of processing and at the time of processing (by design), and ensure that by default only the personal data necessary for each purpose is processed and not made accessible to an indefinite number of people (by default).
Where two or more controllers jointly determine the purposes and means of processing, they must set out their respective responsibilities — in particular for data subject rights and transparency — in an arrangement whose essence is made available to data subjects.
A controller or processor not established in the EU that offers goods or services to, or monitors the behaviour of, people in the EU (Article 3(2)) must designate in writing a representative in a Member State where those people are, unless processing is occasional, not large-scale special-category or criminal data, and unlikely to result in a risk.
Processing by a processor shall be governed by a contract setting out the subject matter, duration, nature and purpose of processing, the obligations in Article 28(3), and the requirement for prior authorisation of sub-processors.
A processor, and any person acting under the authority of the controller or processor who has access to personal data, may process that data only on instructions from the controller, unless required to do so by law.
Controllers and processors shall maintain a record of processing activities including purposes, categories of data subjects and data, recipients, third-country transfers, retention periods and security measures.
The controller and processor, and where applicable their representatives, shall cooperate on request with the supervisory authority in the performance of its tasks.
The controller and processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including pseudonymisation and encryption, resilience, restoration of availability, and a process for regularly testing the effectiveness of measures.
In the case of a personal data breach, the controller shall notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to individuals.
Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate it to the data subjects without undue delay.
Where processing is likely to result in a high risk to the rights and freedoms of natural persons, in particular using new technologies, the controller shall carry out a data protection impact assessment prior to the processing.
Where a data protection impact assessment indicates that processing would result in a high risk in the absence of measures taken by the controller to mitigate it, the controller shall consult the supervisory authority before starting the processing.
A controller or processor must designate a DPO if it is a public authority, or if its core activities involve large-scale regular and systematic monitoring of individuals or large-scale processing of special-category or criminal data; the DPO's contact details must be published and communicated to the supervisory authority. Others should record why no DPO is required.
The DPO must be involved properly and in a timely manner in all data protection issues, be given the resources needed, report directly to the highest management level, not receive instructions on the exercise of their tasks or be penalised for performing them, and have no conflicting duties. Their tasks include informing and advising, monitoring compliance, advising on DPIAs and acting as contact point for the supervisory authority.
Transfers of personal data outside the EEA require an adequacy decision, appropriate safeguards such as standard contractual clauses or binding corporate rules, or a derogation, together with a transfer impact assessment where safeguards are relied upon.