| 1 |
General Data Protection Regulation (GDPR) |
text |
| 2 |
General Data Protection Regulation (GDPR) |
text |
| 3 |
Recitals |
text |
| 4 |
Key Issues |
text |
| 5 |
Skip to content |
text |
| 6 |
GDPR |
text |
| 7 |
Recitals |
text |
| 8 |
Key Issues |
text |
| 9 |
GDPR |
text |
| 10 |
Chapter 1 (Art. 1 – 4)General provisions |
text |
| 11 |
Art. 1Subject-matter and objectives |
text |
| 12 |
Art. 2Material scope |
text |
| 13 |
Art. 3Territorial scope |
text |
| 14 |
Art. 4Definitions |
text |
| 15 |
Chapter 2 (Art. 5 – 11)Principles |
text |
| 16 |
Art. 5Principles relating to processing of personal data |
text |
| 17 |
Art. 6Lawfulness of processing |
text |
| 18 |
Art. 7Conditions for consent |
text |
| 19 |
Art. 8Conditions applicable to child’s consent in relation to information society services |
text |
| 20 |
Art. 9Processing of special categories of personal data |
text |
| 21 |
Art. 10Processing of personal data relating to criminal convictions and offences |
text |
| 22 |
Art. 11Processing which does not require identification |
text |
| 23 |
Chapter 3 (Art. 12 – 23)Rights of the data subject |
text |
| 24 |
Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subject |
text |
| 25 |
Art. 13Information to be provided where personal data are collected from the data subject |
text |
| 26 |
Art. 14Information to be provided where personal data have not been obtained from the data subject |
text |
| 27 |
Art. 15Right of access by the data subject |
text |
| 28 |
Art. 16Right to rectification |
text |
| 29 |
Art. 17Right to erasure (‘right to be forgotten’) |
text |
| 30 |
Art. 18Right to restriction of processing |
text |
| 31 |
Art. 19Notification obligation regarding rectification or erasure of personal data or restriction of processing |
text |
| 32 |
Art. 20Right to data portability |
text |
| 33 |
Art. 21Right to object |
text |
| 34 |
Art. 22Automated individual decision-making, including profiling |
text |
| 35 |
Art. 23Restrictions |
text |
| 36 |
Chapter 4 (Art. 24 – 43)Controller and processor |
text |
| 37 |
Art. 24Responsibility of the controller |
text |
| 38 |
Art. 25Data protection by design and by default |
text |
| 39 |
Art. 26Joint controllers |
text |
| 40 |
Art. 27Representatives of controllers or processors not established in the Union |
text |
| 41 |
Art. 28Processor |
text |
| 42 |
Art. 29Processing under the authority of the controller or processor |
text |
| 43 |
Art. 30Records of processing activities |
text |
| 44 |
Art. 31Cooperation with the supervisory authority |
text |
| 45 |
Art. 32Security of processing |
text |
| 46 |
Art. 33Notification of a personal data breach to the supervisory authority |
text |
| 47 |
Art. 34Communication of a personal data breach to the data subject |
text |
| 48 |
Art. 35Data protection impact a***essment |
text |
| 49 |
Art. 36Prior consultation |
text |
| 50 |
Art. 37Designation of the data protection officer |
text |