Regulations › European Union

GDPR

General Data Protection Regulation (EU) 2016/679

In force privacy consumer rights transfers breach notification
WhenIn effect since 25 May 2018
Who enforces itNational data protection authorities, coordinated by the European Data Protection Board
Who it applies toOrganizations established in the EU, and organizations outside it that offer goods or services to people in the EU or monitor their behavior.

The global reference point for privacy law: lawful bases, principles, rights, accountability, breach notice within 72 hours, transfer rules and fines up to 4 percent of worldwide turnover.

The law in brief

The GDPR is the European Union's main data protection law. It sets the rules for collecting, using, sharing and keeping personal data about people in the EU, and it gives those people rights they can enforce. It reaches organizations inside the EU and many outside it.

Most of its duties fall on the controller, the organization that decides why and how personal data is used. Processors, which handle data on a controller's behalf, carry their own narrower duties and can be fined directly.

Who it applies to

  • Organizations established in the EU, for processing in the context of that establishment, wherever the processing itself happens.
  • Organizations outside the EU that offer goods or services to people in the EU, paid or free, or monitor their behavior in the EU (Art. 3(2)). They usually need a representative in the EU (Art. 27).
  • It covers personal data: any information about an identified or identifiable living person. Purely personal or household activity is outside it (Art. 2).
  • Size is no exemption. The one relief for smaller organizations concerns records of processing, and it is narrow (see Records of processing below).

Where it reaches

An EU establishment brings its processing under the GDPR even when the servers, staff or vendors doing the work are outside the EU.

What it requires

A lawful basis for every use

Each purpose needs one of six bases: consent, contract, legal obligation, vital interests, public task or legitimate interests. Choose and record it before you start; it decides which rights apply later.

The principles, and proving you follow them

Use data fairly and openly, only for stated purposes, no more than you need, accurate, kept no longer than necessary and secure. You must be able to show compliance, not just achieve it.

Sensitive data

Health, genetic and biometric data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and sex life or sexual orientation are off limits unless one of the specific conditions in Article 9(2) applies.

Tell people what you do

When you collect data, tell people who you are, why you use it, on what basis, who receives it, how long you keep it and what rights they have, in clear and plain language.

Answer rights requests within a month

Act on a request without undue delay and within one month. For complex or numerous requests you can extend by two more months, if you tell the person within the first month. Requests are free unless manifestly unfounded or excessive.

Processors under a written contract

Use only processors that give sufficient guarantees, and bind each one by contract: documented instructions, confidentiality, security, sub-processor approval, help with rights and breaches, deletion or return at the end, and audits.

Records of processing

Keep a written record of your processing: purposes, categories of people and data, recipients, transfers, retention and security measures. Organizations with fewer than 250 employees are exempt only when processing is occasional, unlikely to result in a risk and involves no sensitive or criminal-offense data, which is rare in practice.

Security appropriate to the risk

Put technical and organizational measures in place that match the risk, such as encryption or pseudonymization, resilience, the ability to restore access after an incident, and regular testing.

Report breaches to the authority within 72 hours

Notify the supervisory authority without undue delay, unless the breach is unlikely to result in a risk to people. A late notice must give reasons, and information can follow in phases. Processors must tell their controller without undue delay. Document every breach, notified or not.

Tell people about high-risk breaches

When a breach is likely to result in a high risk to people, tell them directly and without undue delay, in plain language, unless a listed exception applies, such as strong encryption.

Impact assessments before high-risk processing

Assess the impact before you start processing that is likely to be high risk. It is required in particular for automated decisions with legal or similar effects, large-scale sensitive or criminal-offense data, and large-scale monitoring of public areas.

A data protection officer, where required

Public authorities must appoint one, as must organizations whose core activities involve large-scale regular and systematic monitoring of people, or large-scale sensitive or criminal-offense data.

Transfers out of the EU

Personal data can leave the EU only on a recognized basis: an adequacy decision, appropriate safeguards such as standard contractual clauses or binding corporate rules, or a narrow derogation.

People's rights

People can ask a controller to:

  • see their data and how it is used (access, Art. 15);
  • correct it (Art. 16), or erase it in the cases the law sets out (Art. 17);
  • restrict its use, for example while a dispute is resolved (Art. 18);
  • receive it in a machine-readable format to take elsewhere, where processing is automated and based on consent or a contract (portability, Art. 20);
  • object to processing, with an absolute right to stop direct marketing (Art. 21);
  • not be subject to decisions based solely on automated processing that have legal or similarly significant effects, subject to limited exceptions (Art. 22).

They can also complain to a supervisory authority (Art. 77) and claim compensation for material or non-material damage (Art. 82).

Enforcement and penalties

Two tiers of fines. Up to €10 million or 2% of worldwide annual turnover, whichever is higher, for controller and processor duties such as security, records, impact assessments and breach notice (Art. 83(4)). Up to €20 million or 4%, whichever is higher, for the principles, legal bases, people's rights and transfer rules, and for ignoring an authority's order (Art. 83(5) and (6)). Authorities can also order processing to stop (Art. 58), and people can sue for damages (Art. 82).

The higher tier of fines

Up to €20 million or 4% of worldwide annual turnover, whichever is higher, for breaching the principles, legal bases, people's rights or transfer rules.

What's changing

Proposed, not law. The European Commission's Digital Omnibus proposal (COM(2025) 837, November 2025) would notify authorities only of breaches likely to result in a high risk, extend the deadline from 72 to 96 hours, and add a single EU reporting point. In late August 2026 it was still before the Parliament and Council. Keep your 72-hour process until it is adopted; Regulatory Watch will report the outcome.

What to do first

  1. Map your personal data: what you hold, why, where it goes and how long you keep it. The map becomes your record of processing.
  2. Give each purpose a lawful basis, and write it down.
  3. Rewrite your privacy notices so they match the map.
  4. Set up a rights-request process that verifies identity and answers within a month.
  5. Review processor contracts against Article 28(3) and close the gaps.
  6. Rehearse a breach: who decides, who notifies, and how you meet 72 hours.
  7. List every transfer out of the EU and the mechanism each one relies on.
  8. Run an impact assessment for anything high-risk, before it goes live.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

  • 9 Oct 2026 Fine in effect Moderate 59 EU-IT Garante – Italian Data Protection Authority

    Italian DPA fines security firm €39,000 for employee data violations

    The enforcement highlights the GDPR’s strict requirements for employee data access and transparent processing of location data. The Italian Data Protection Authority (Garante) imposed a total administrative fine of EUR 39,000 on La Patria S.p.A. for failing to respond to employee access requests and for inadequate information about GPS‑derived geolocation data. The fine was split into EUR 22,000 for access‑right infringements and EUR 17,000 for information‑provision breaches.

    Effective: 6 August 2026. Penalty: total administrative fine of EUR 39 000.

    Source: European Data Protection Board news. GDPR in the regulations library.

  • 9 Oct 2026 Dpa Action decided High 72 EU-IT Italian Data Protection Authority

    Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data

    The fine highlights enforcement of GDPR obligations for health data controllers and underscores the need for proper legal bases, transparency, and impact assessments. The Italian Data Protection Authority imposed an administrative fine of EUR 7,000,000 on IQVIA Solutions Italy S.r.l. for processing health data without a legal basis, inadequate information to patients, and missing DPIA and retention measures. The decision, dated 23 September 2026, requires IQVIA to achieve GDPR compliance within 120 days or have anonymisation carried out by the general practitioners.

    Effective: 23 September 2026. Penalty: EUR 7 000 000.

    Source: European Data Protection Board news. GDPR in the regulations library.

  • 9 Oct 2026 Fine decided High 66 EU-IT Italian Data Protection Authority

    Italian DPA fines Emirates €180,000 for health data infringements

    The enforcement highlights GDPR obligations for clear information and proportionate retention of health data in the aviation sector. The Italian Data Protection Authority imposed an administrative fine of EUR 180,000 on Emirates for violations of GDPR transparency and retention requirements concerning passengers' health data. Emirates was ordered to clarify which passengers must complete the MEDIF form, specify necessary fields, and reduce the seven‑year data retention period. The decision was issued on 14 May 2026.

    Penalty: administrative fine of EUR 180 000.

    Source: European Data Protection Board news. GDPR in the regulations library.

  • 9 Oct 2026 Fine in effect High 63 EU-IT Italian Data Protection Authority

    Italian DPA fines BBVA €5.508 million for ignoring customer objection to direct marketing

    The fine underscores the obligation of controllers to promptly respect data subject objections and implement effective technical measures. The Italian Data Protection Authority issued an administrative fine of €5,508,000 against BBVA's Italian branch for failing to honor a customer's right to object to direct marketing. The violation lasted seven months, during which the customer received at least ten unsolicited notifications despite having objected via the bank's app and customer service.

    Effective: 3 July 2026. Penalty: administrative fine of EUR 5 508 000.

    Source: European Data Protection Board news. GDPR in the regulations library.

  • 8 Oct 2026 Fine published High 72 EU-NL Autoriteit Persoonsgegevens

    Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making

    The fine demonstrates robust GDPR enforcement on automated decision‑making in the gig‑economy. The Autoriteit Persoonsgegevens imposed an administrative fine of €824,990,000 on Uber for violating GDPR Article 22 by automatically deactivating drivers’ accounts and for failing to provide sufficient information under Article 13. The violations concerned incidents between 2018 and 2022 and Uber has since stopped the practices.

    Penalty: EUR 824 990 000.

    Source: European Data Protection Board news. GDPR in the regulations library.

  • 8 Oct 2026 Fine decided Moderate 57 EU-SE Swedish Data Protection Authority (IMY)

    Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures

    The fine underscores the enforcement of GDPR security obligations for data processors handling large volumes of personal and sensitive data. The Swedish Data Protection Authority (IMY) imposed an administrative fine of SEK 1,800,000 (≈ EUR 160,000) on IT service provider Miljödata i Karlskrona for violating Article 32(1) GDPR. The authority found the company lacked adequate technical and organisational safeguards, including real‑time intrusion monitoring, after a cyberattack exposed data of 2.2 million individuals.

    Penalty: administrative fine of SEK 1 800 000 (approximately EUR 160 000).

    Source: European Data Protection Board news. GDPR in the regulations library.

  • 8 Oct 2026 Dpa Action decided High 62 EU-GR Hellenic Data Protection Authority

    Hellenic DPA fines Ministry and EETAA for data breach

    The enforcement action highlights the liability of both controllers and processors for inadequate security and non‑compliant processing agreements under the GDPR. The Hellenic Data Protection Authority issued a final decision on 28/07/2026 imposing administrative fines of EUR 200,000 on the Ministry of Social Cohesion and Family Affairs and EUR 150,000 on E.E.T.A.A. S.A. for security deficiencies. The DPA also ordered both parties to conclude a GDPR‑compliant data processing agreement and to fully implement security upgrades.

    Penalty: The Hellenic DPA imposed administrative fines of EUR 200 000 on the Ministry of Social Cohesion and Family Affairs and EUR 150 000 on E.E.T.A.A..

    Source: European Data Protection Board news. GDPR in the regulations library.

  • 2 Oct 2026 Regulatory Guidance published Low 40 EU European Data Protection Board

    EDPB adopts Guidelines 04/2026 on GDPR fines and corrective powers for public consultation

    The guidance clarifies how EU data protection authorities may impose fines and corrective measures, impacting GDPR enforcement. The European Data Protection Board adopted Guidelines 04/2026 on the application of administrative fines and other corrective powers under the EU GDPR. The guidelines were released on September 17, 2026 for public consultation.

    Source: Hunton Privacy & Cybersecurity Law Blog. GDPR in the regulations library.

Sources