November 3, 2021
The General Data Protection Regulation (EU) 2016/679 (GDPR) is a regulation in EU law on data protection and privacy in the European Union (EU) and the European Economic Area (EEA). The GDPR is an important component of EU privacy law and of human rights law, in particular Article 8(1) of the Charter of Fundamental Rights of the European Union. It also addresses the transfer of personal data outside the EU and EEA areas. The GDPR’s primary aim is to enhance individuals’ control and rights over their personal data and to simplify the regulatory environment for international business.
The GDPR was adopted on 14 April 2016 and became enforceable beginning 25 May 2018. As the GDPR is a regulation, not a directive, it is directly binding and applicable, and provides flexibility for certain aspects of the regulation to be adjusted by individual member states.
GDPR affects all companies (controllers and processors) that collect or process personal data of EU citizens, or monitor sucher persons (art. 1-3). GDPR not only covers customers but also employees.
- Art. 5-11 regulates data collection and processing, based on rightfullness, transparency, purpose, data minimizing, integrity and trust. Controllers and processors must comply to these regulations, and document their compliance.
- Art. 12-23 regulates the rights of persions affeted (“data subjects”)
- Art. 24-43 regulates responsibilities of controllers and processors.
- Art. 44-50 regulates third party data processing
- Art. 51-59 regulates the responsibilities of independent supervisory authorities
- Art. 60-76 regulates cooperation and consistency
- Art. 77-84 covers remedies, liability and penalties
- Art. 85-91 provisions specific processing situations
- Art. 92-99 cover delegated and implementing acts, as well as final provisions