Skip to content
atlas

GDPR

Also known as: General Data Protection Regulation, Regulation (EU) 2016/679

The EU law that protects personal data and gives people rights over how it is used.

Draft - this entry has not been reviewed yet.

Read the full article →

Formal

Regulation (EU) 2016/679, applying directly in every member state since 25 May 2018, which sets principles, legal grounds, rights and security duties for processing data about identifiable people, with fines of up to 20 million euro or 4% of global turnover.

In plain English

Information about you is treated as yours - others may borrow it only for a fair reason, must look after it and must tell you what they do with it.

In practice

When a laptop holding customer lists is stolen from the owner's car, a Danish web shop has 72 hours to report the breach to Datatilsynet and must decide whether the customers themselves need to be told.

Why it matters

Before it, data protection rules differed from country to country and were weakly enforced; GDPR gave people the same rights across the EU and made breaking them costly.

Technical deep dive

Regulation (EU) 2016/679 has 99 articles and 173 recitals; it entered into force on 24 May 2016 and has applied since 25 May 2018, replacing Directive 95/46/EC. Its material scope (Art. 2) is the processing of personal data wholly or partly by automated means, or in a filing system, excluding purely household activity and law-enforcement processing, which falls under the separate Directive (EU) 2016/680. Territorial scope (Art. 3) follows either an establishment in the EU or, for non-EU organisations, the targeting of goods or services at people in the EU or the monitoring of their behaviour. Personal data (Art. 4(1)) covers any information relating to an identified or identifiable natural person, including online identifiers; pseudonymised data remains personal data (recital 26), while only truly anonymised data falls outside the regulation, a distinction regularly misapplied to hashed identifiers and device IDs.

The regulation is principle-driven. Art. 5(1) sets the six processing principles and Art. 5(2) adds accountability, which is operationalised through records of processing (Art. 30), data protection by design and by default (Art. 25), security of processing (Art. 32), DPIAs (Art. 35) and, where Art. 37 applies, a data protection officer. Every processing operation needs one of the six legal bases in Art. 6(1); consent is neither preferred nor usually appropriate for employers or public authorities because of the power imbalance. Special categories under Art. 9, such as health, biometric data used for identification and trade-union membership, are prohibited by default and need an Art. 9(2) exception in addition to an Art. 6 basis.

Enforcement is decentralised but coordinated. Each member state has an independent supervisory authority; for cross-border processing the one-stop-shop mechanism (Art. 56 and Art. 60) makes the authority of the main establishment lead, and disagreements go to the European Data Protection Board under the consistency mechanism (Arts. 63-65). Chapter V restricts transfers to third countries: adequacy decisions (Art. 45), appropriate safeguards such as standard contractual clauses (Art. 46), or narrow derogations (Art. 49). After the CJEU invalidated Privacy Shield in Schrems II (C-311/18, July 2020), transfers to the US have relied on SCCs with transfer impact assessments or, since the adequacy decision of 10 July 2023, on the EU-US Data Privacy Framework for certified recipients.

Denmark supplements the regulation with databeskyttelsesloven (lov nr. 502 af 23. maj 2018), which uses the opening clauses, for example setting the age for consent to information society services at 13 and regulating CPR numbers. Because Danish law does not allow administrative fines against private companies, Art. 83(9) applies: Datatilsynet reports cases to the police and the courts impose fines. Data subjects can also claim compensation for material or non-material damage under Art. 82. In security practice, GDPR does not prescribe specific controls; Art. 32 is risk-based and technology-neutral, so frameworks such as ISO 27001 or the CIS Controls are used to demonstrate that measures are appropriate.

What to learn first

Everything this builds on, foundations first.

  1. Confidentiality
  2. →Personal data
  3. →GDPR

Relationships

A kind of
EU regulation

Sources & further reading

Standards & official texts

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.