Skip to main content
    Pritect

    Regulation

    GDPR
    From legal text to evidence

    The General Data Protection Regulation has applied across the EU and EEA since 25 May 2018. It governs how personal data is collected, used, shared and secured, what people can ask you to do with their data, and what has to happen when something goes wrong.

    Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)

    CELEX
    32016R0679
    Official Journal
    OJ L 119, 4.5.2016, p. 1 to 88
    Articles
    99
    Jurisdiction
    🇪🇺 Europe
    Status
    In force
    Read the text on EUR-Lex

    From the Official Journal to a tracked obligation

    Three stages, and the legal text is not rewritten at any of them.

    1. 01

      The article

      The Official Journal text, transcribed word for word and checked against a hash of the source it came from. Nothing is paraphrased, and nothing is written from memory.

    2. 02

      The clause

      Each article becomes one clause in the catalogue, carrying its official heading, its citation and any deadline the text sets. This is the layer the platform reads, and it is shared across every tenant.

    3. 03

      Your obligation

      You adopt the clauses that apply to you, and each becomes a tracked obligation of your own: an owner, an applicability decision, a review date, and the evidence that it is being met.

    Where an article sets a reporting clock, the deadline the Incident Centre counts down is computed from that clause and starts when the text says it starts, rather than from a duration typed into the product.

    Key dates

    Entry into force and the day the obligations start to bite are different dates, so each one is listed separately against the article that sets it.

    1. 27 Apr 2016

      Adopted by the Parliament and the Council

    2. 4 May 2016

      Published in the Official Journal

    3. 24 May 2016

      Entered into force

      Art. 99(1)

    4. 25 May 2018

      Applies from

      Art. 99(2)

    The articles that create work

    The obligation-bearing articles Pritect tracks, under the headings the Official Journal prints.

    99
    Articles
    45
    Tracked

    The regulation runs to 99 articles. Pritect decomposes 45 of them clause by clause into obligations you can adopt, own and evidence: the obligation-bearing articles of Chapters II to V, covering the principles, the rights of the data subject, the duties of controllers and processors including the data protection officer, codes of conduct and certification, and the rules on transfers outside the EU, together with the Chapter IX safeguards for archiving, research and statistics. The rest are deliberately not decomposed, because they are not duties you discharge. Articles 1 to 4 set the subject matter, scope and definitions, Article 23 leaves room for national law to restrict, Article 50 covers international cooperation, Articles 51 to 87 govern supervisory authorities, consistency, remedies and penalties, Article 88 addresses Member States on the employment context, and Articles 90 to 99 are the final provisions. The set grows as the catalogue is extended.

    Principles

    Chapter II, Art. 5 to 11

    • Art. 5Principles relating to processing of personal data
    • Art. 6Lawfulness of processing
    • Art. 7Conditions for consent
    • Art. 8Conditions applicable to child's consent in relation to information society services
    • Art. 9Processing of special categories of personal data
    • Art. 10Processing of personal data relating to criminal convictions and offences
    • Art. 11Processing which does not require identification

    Rights of the data subject

    Chapter III, Art. 12 to 22

    • Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subject
    • Art. 13Information to be provided where personal data are collected from the data subject
    • Art. 14Information to be provided where personal data have not been obtained from the data subject
    • Art. 15Right of access by the data subject
    • Art. 16Right to rectification
    • Art. 17Right to erasure (‘right to be forgotten’)
    • Art. 18Right to restriction of processing
    • Art. 19Notification obligation regarding rectification or erasure of personal data or restriction of processing
    • Art. 20Right to data portability
    • Art. 21Right to object
    • Art. 22Automated individual decision-making, including profiling

    Controller and processor

    Chapter IV, Art. 24 to 43

    • Art. 24Responsibility of the controller
    • Art. 25Data protection by design and by default
    • Art. 26Joint controllers
    • Art. 27Representatives of controllers or processors not established in the Union
    • Art. 28Processor
    • Art. 29Processing under the authority of the controller or processor
    • Art. 30Records of processing activities
    • Art. 31Cooperation with the supervisory authority
    • Art. 32Security of processing
    • Art. 33Notification of a personal data breach to the supervisory authority
    • Art. 34Communication of a personal data breach to the data subject
    • Art. 35Data protection impact assessment
    • Art. 36Prior consultation
    • Art. 37Designation of the data protection officer
    • Art. 38Position of the data protection officer
    • Art. 39Tasks of the data protection officer
    • Art. 40Codes of conduct
    • Art. 41Monitoring of approved codes of conduct
    • Art. 42Certification
    • Art. 43Certification bodies

    Transfers to third countries

    Chapter V, Art. 44 to 49

    • Art. 44General principle for transfers
    • Art. 45Transfers on the basis of an adequacy decision
    • Art. 46Transfers subject to appropriate safeguards
    • Art. 47Binding corporate rules
    • Art. 48Transfers or disclosures not authorised by Union law
    • Art. 49Derogations for specific situations

    Specific processing situations

    Chapter IX, Art. 89

    • Art. 89Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes

    Article headings are reproduced verbatim from the Official Journal and stay in English in every language, because a citation has to remain quotable. They are transcribed from the published text; the subject-matter review that makes them authoritative inside the product is still pending.

    Common questions

    The questions teams ask first, answered plainly.

    Who does the GDPR apply to?
    Article 3 sets the territorial scope. It covers controllers and processors established in the EU, and those established outside it that offer goods or services to people in the EU or monitor their behaviour there. Pritect records which of your processing activities fall inside that scope and why.
    Do we need a record of processing activities?
    Article 30 requires controllers and processors to maintain one. The exemption for organisations with fewer than 250 staff is narrow: it falls away where the processing is not occasional, is likely to result in a risk to rights and freedoms, or involves special categories of data or criminal convictions. Most organisations end up keeping a record.
    How long do we have to report a personal data breach?
    Article 33 requires notification to the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach, unless it is unlikely to result in a risk to rights and freedoms. Article 34 adds communication to the affected people where the risk to them is high. The clock runs from awareness, which is why Pritect starts it there rather than at the point the cause is understood.
    When is a data protection impact assessment required?
    Article 35 requires one where a type of processing is likely to result in a high risk to the rights and freedoms of individuals. Where that risk cannot be brought down, Article 36 requires prior consultation with the supervisory authority. Pritect runs the screening and keeps the assessment attached to the processing activity it belongs to.
    What do we need for transfers outside the EU?
    Chapter V allows a transfer on an adequacy decision under Article 45, on appropriate safeguards under Article 46 such as standard contractual clauses or binding corporate rules, or on a derogation under Article 49. Pritect records which route each transfer takes and the assessment that supports it.

    This page summarises publicly available legal text so you can orient yourself. It is not legal advice.

    See it against your own records

    Bring one processing activity, one supplier and one open request. We will show you where each of them lands.