Map of Regulation (EU) 2016/679 — the General Data Protection Regulation. The EU's privacy law and the global benchmark for data protection regulation. In force since 25 May 2018. Reference cluster for any work touching personal data of EU residents and for adjacent regulatory work (AI Act, NIS2, DORA) that intersects with privacy obligations.
Anchors
- position: current view, dated, revisable
- anchors: primary text, EDPB, national DPAs, enforcement actions, named voices
Provenance
- Directive 95/46/EC — predecessor. EU Data Protection Directive in force 1995-2018.
- Lisbon Treaty (2009) + Charter of Fundamental Rights Article 8 — elevated data protection to fundamental right within EU law.
- GDPR proposal — January 2012.
- Council and Parliament adoption — 2015-2016 (trilogue process).
- Final adoption — 27 April 2016.
- OJEU publication — 4 May 2016.
- Applicable — 25 May 2018 (two-year transition).
- Subsequent jurisprudence — CJEU Schrems I (2015), Schrems II (2020), Lindqvist, Google Spain (right to be forgotten), Maximillian Schrems v Facebook (various), substantial body of case law.
- EU-US Data Privacy Framework — adequacy decision, July 2023. Replaced Privacy Shield invalidated in Schrems II.
What GDPR is, in one paragraph
The GDPR is the EU's comprehensive data protection regulation. Establishes harmonized rules for processing personal data of individuals in the EU. Applies to controllers and processors of personal data — both EU-established and non-EU entities targeting EU data subjects. Built on seven principles, six lawful bases for processing, extensive data subject rights, controller and processor obligations, mandatory breach notifications, requirements for international data transfers, supervised by national data protection authorities (DPAs) coordinated through the European Data Protection Board (EDPB). Penalties up to €20M or 4% global annual turnover.
Territorial scope (Article 3)
GDPR applies to:
- Article 3(1): processing by controllers/processors established in the EU, regardless of where the processing occurs.
- Article 3(2): processing by non-EU controllers/processors where the processing relates to:
- (a) offering goods or services to EU data subjects (regardless of payment)
- (b) monitoring behavior of EU data subjects taking place in the EU.
The extraterritorial reach (Art 3(2)) is the basis for global GDPR compliance work by US, Asian, and other non-EU entities serving EU markets.
Key definitions (Article 4)
- Personal data: any information relating to an identified or identifiable natural person ("data subject").
- Processing: any operation performed on personal data — collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, alignment, restriction, erasure, destruction.
- Controller: the entity determining purposes and means of processing.
- Processor: the entity processing on behalf of the controller.
- Pseudonymization: processing personal data so it can no longer be attributed to a specific data subject without additional information.
- Special category data (Article 9): racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, genetic data, biometric data (for identification), health data, sex life, sexual orientation.
The seven principles (Article 5)
| Principle | Article 5 reference | Summary |
|---|---|---|
| Lawfulness, fairness, transparency | 5(1)(a) | Processing must be lawful, fair, transparent to the data subject |
| Purpose limitation | 5(1)(b) | Collected for specified, explicit, legitimate purposes; not further processed incompatibly |
| Data minimization | 5(1)(c) | Adequate, relevant, limited to what is necessary |
| Accuracy | 5(1)(d) | Accurate, kept up to date, inaccuracies erased or rectified |
| Storage limitation | 5(1)(e) | Kept in identifiable form only as long as necessary |
| Integrity and confidentiality | 5(1)(f) | Processed with appropriate security |
| Accountability | 5(2) | Controller responsible for and able to demonstrate compliance |
Detail in GDPR Principles.
Lawful bases for processing (Article 6)
Six exhaustive lawful bases for processing non-special-category personal data:
- Consent — explicit, informed, freely given, specific
- Contract — necessary for contract performance or pre-contract steps
- Legal obligation — necessary to comply with controller's legal obligation
- Vital interests — necessary to protect vital interests of data subject or another person
- Public task — necessary for task carried out in public interest or in exercise of official authority
- Legitimate interests — necessary for legitimate interests pursued by controller (or third party), unless overridden by data subject's interests/rights
For special category data (Art 9): processing prohibited unless one of ten exceptions applies (explicit consent, employment/social security law, vital interests, etc.).
Detail in GDPR Lawful Bases.
Data subject rights (Articles 12-23)
- Article 12: transparent information and communication.
- Articles 13-14: information to be provided when data collected from the data subject (13) or from elsewhere (14).
- Article 15: right of access.
- Article 16: right to rectification.
- Article 17: right to erasure ("right to be forgotten").
- Article 18: right to restriction of processing.
- Article 19: notification obligation regarding rectification/erasure/restriction.
- Article 20: right to data portability.
- Article 21: right to object (including against direct marketing).
- Article 22: rights related to automated individual decision-making, including profiling.
- Article 23: restrictions (member state law can restrict rights in limited circumstances).
Detail in GDPR Data Subject Rights.
Controller and processor obligations (Articles 24-43)
- Article 24: controller's general responsibility.
- Article 25: data protection by design and by default.
- Article 26: joint controllers.
- Article 27: representatives of non-EU controllers/processors.
- Article 28: processor obligations + DPA (data processing agreement) requirements.
- Article 29: processing under controller's authority.
- Article 30: records of processing activities.
- Article 31: cooperation with supervisory authority.
- Article 32: security of processing (technical and organizational measures).
- Articles 33-34: breach notification (33 to supervisory authority within 72 hours; 34 to data subjects without undue delay if high risk).
- Article 35: data protection impact assessment (DPIA) for high-risk processing.
- Article 36: prior consultation with supervisory authority.
- Articles 37-39: data protection officer (DPO) — appointment criteria, position, tasks.
- Articles 40-43: codes of conduct, certification.
Detail in GDPR Controller and Processor.
Cross-border transfers (Chapter V, Articles 44-50)
Transfers to third countries (outside EU/EEA) only with appropriate safeguards:
- Article 45: transfers based on adequacy decision (Commission decision that third country provides adequate protection).
- Article 46: transfers subject to appropriate safeguards — Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), approved codes of conduct, approved certification.
- Article 47: BCRs in detail.
- Article 48: transfers not authorized by Union law.
- Article 49: derogations for specific situations.
Detail in GDPR Cross-Border Transfers.
Enforcement (Chapters VI-VIII)
- Chapter VI: independent supervisory authorities (DPAs). One per member state.
- Chapter VII: cooperation and consistency. EDPB (European Data Protection Board). One-stop-shop mechanism.
- Chapter VIII: remedies, liability, penalties.
Penalties (Article 83):
- Tier 1: up to €10M or 2% global annual turnover (whichever higher) for certain violations (records, processor obligations, transparency).
- Tier 2: up to €20M or 4% global annual turnover (whichever higher) for most substantive violations (principles, lawful bases, data subject rights, transfers, supervisory authority orders).
Notable fines (illustrative):
- Meta €1.2B (May 2023) — Schrems II SCCs violation
- Amazon €746M (2021)
- TikTok €345M (September 2023) — children's data
- WhatsApp €225M (September 2021)
- Google €90M, €60M, repeated tier-1 fines for cookie consent issues
- Uber €290M (August 2024) — international transfers
Detail in GDPR Enforcement and DPAs.
Why this matters for SRE and AI-agent work
- Personal data is everywhere in AI work. Training data, prompts, retrieval corpora, agent outputs, audit logs, user telemetry. GDPR applies broadly.
- Cross-border transfer compliance is load-bearing. Model providers (Anthropic, OpenAI, Google) are US-based; sending EU personal data requires Article 46 safeguards.
- Data subject rights apply. Right to erasure (Art 17), right of access (Art 15), automated decision-making rights (Art 22) all have AI implications.
- DPIA likely required for AI features. Article 35 high-risk processing typically applies to AI systems processing personal data.
- Article 22 automated decision-making — substantive rights for individuals subject to AI decision-making with significant effect.
- AI Act and GDPR coexist. AI Act does not replace GDPR; both apply.
- DPO role for orgs processing personal data at scale.
Stefan-context relevance
Stefan does SRE / staff-engineer-track work touching:
- AI-agent operations that may consume / produce personal data
- Vault content containing some personal data (whiteout-kb classification)
- Client engagements where customer data flows through AI features
- Cross-border vendor relationships (model providers in US)
- German Mittelstand customers with established GDPR programs
Cluster atoms should:
- Stay regulation-grounded with article citations
- Bridge GDPR obligations to AI / agent work specifics
- Surface controller vs processor distinctions where they matter
- Cover transfer mechanisms relevant to model-vendor relationships
- Track notable enforcement for buyer-signal calibration
Related clusters and atoms
- ISO 27001 — InfoSec management; A.5.34 PII and adjacent controls
- ISO 42001 — AI management; data protection module
- EU AI Act — co-applies with GDPR
- TISAX — Data Protection module aligns with GDPR
- ITIL — service management with personal data implications
Conventions for this cluster
- Atoms named
GDPR <Topic>.mdwith consistent structure - Article references cited explicitly (e.g., "Article 6(1)(f)" for legitimate interests)
- Recital references where load-bearing
- Cross-link to ISO 27001 / ISO 42001 / EU AI Act where regulations overlap
- All atoms cite the relevant article number
See also
GDPR Cluster (pillars MOC) · position · anchors · ISO 27001 Cluster · ISO 42001 Cluster · EU AI Act Cluster