Privacy & Data Protection · European Union / EEA
General Data Protection Regulation
The EU's foundational data protection law, giving individuals rights over their personal data and requiring organisations to have a lawful basis for processing it. It applies extraterritorially to any organisation handling the data of EU or EEA residents, regardless of where that organisation is based.
REGULATOREuropean Data Protection Board (EDPB) & national DPAs
REGIONEuropean Union / EEA
EFFECTIVE25 May 2018
Who it applies to
- Any organisation processing personal data of people in the EU/EEA
- Both data controllers and data processors
- Public authorities and private businesses of any size
Key requirements
- A documented lawful basis for every processing activity
- Data Protection Officer where processing meets Article 37 thresholds
- 72-hour breach notification to the supervisory authority
- Data Protection Impact Assessments for high-risk processing
- Data subject rights: access, rectification, erasure, portability
Maximum penaltyUp to €20 million or 4% of global annual turnover, whichever is higher
Go to the source
Official resources
Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.
Start your compliance journey
See how Praeferre automates GDPR compliance
Continuous monitoring, evidence and reporting for GDPR — alongside every other framework you need to satisfy.