Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation)
Overview
The General Data Protection Regulation (GDPR) is the cornerstone of EU data protection law. It strengthens individuals’ control over their personal data, harmonizes data protection rules across the EU, and imposes significant obligations on data controllers and processors. Key principles include lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and accountability. The GDPR grants individuals rights including access, rectification, erasure (right to be forgotten), restriction of processing, data portability, and objection. It requires valid consent, establishes data breach notification obligations, and mandates data protection impact assessments for high-risk processing. Regulation (EU) 2016/679 applies from 25 May 2018.
This eu regulation (32016R0679) is part of the EU’s legal framework governing data protection. EU data protection law governs the processing of personal data by public and private actors, establishing principles, rights, and obligations that balance privacy protection with the free flow of data within the internal market.
Type: EU Regulation
CELEX Number: 32016R0679
Date of Effect: See the official publication in the Official Journal of the European Union.
Key Provisions
Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) establishes the core legal framework in this field. For specific provisions, articles, and implementing measures, consult the full text on EUR-Lex.
Significance
This legislation represents a key component of EU law in the area of data protection. It reflects the EU’s approach to harmonization and regulatory policy within the internal market framework.