> regulation_(eu)_2016/679
Regulation (EU) 2016/679
General Data Protection Regulation (GDPR)
Regulation (EU) 2016/679 (GDPR) imposes strict statutory obligations on data controllers and processors regarding personal data processing, transparency, security, cross-border transfers, and individual privacy rights. It codifies principles of purpose limitation, data minimization, accuracy, storage limitation, and accountability, backed by severe non-compliance penalties.
Scope & Applicability
Applies to all organizations processing personal data of individuals residing in the EU, regardless of the organization's physical headquarters.
Non-Coverage Boundaries
Does not apply to purely personal or household activities, or anonymous data rendered irrevocably non-identifiable.
Key Clauses & Control Requirements
Right to Erasure ('Right to be Forgotten')
Obligation to delete personal data without undue delay upon data subject request, subject to statutory retention exceptions.
Data Protection by Design and by Default
Engineering technical measures (such as pseudonymization and least-privilege schemas) directly into system architectures.
72-Hour Data Breach Notification
Mandatory notification of personal data breaches to supervisory authorities within 72 hours of becoming aware.
Required Regulatory & Audit Evidence Artifacts
- [✓]Article 30 Record of Processing Activities
- [✓]Data Processing Agreements (DPAs) with standard contractual clauses (SCC)
- [✓]Automated user data deletion and export execution logs
“GDPR is not a privacy policy page on your website. It is a backend architecture mandate: soft-deletes must become hard cryptographic shredding when an account is expunged.”
Cross-Surface Ecosystem Relationships
Frequently Asked Questions
What is the maximum penalty for a severe GDPR violation?
Up to €20 million or 4% of the enterprise's total global annual turnover of the preceding financial year, whichever is higher.
