Skip to main content
Category: Legal Framework & Instruments

Regulation (EU) 2016/679

Also known as: GDPR, General Data Protection Regulation, EU GDPR
Simply put

Regulation (EU) 2016/679, commonly known as the General Data Protection Regulation or GDPR, is a European Union law that sets rules for how organisations handle the personal data of individuals. It was adopted by the European Parliament and the Council on 27 April 2016 and is aimed at protecting people in relation to the processing of their personal information. A separate UK version (the UK GDPR) exists following the UK's departure from the EU, so the applicable text should be confirmed for a given jurisdiction.

Formal definition

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 is the EU's principal data protection instrument, governing the protection of natural persons with regard to the processing of personal data and the free movement of such data. As a Regulation, it is directly applicable across EU member states, though it permits specified national derogations and implementing measures that can vary the position in individual jurisdictions. Its material scope concerns personal data of natural persons and does not extend to anonymous data or, generally, to data of deceased persons or legal entities; practitioners should note that a distinct UK GDPR regime applies in the United Kingdom and that the consolidated official text (published in OJ L 119, 4 May 2016, with corrigenda) should be verified against the current version for precise wording and article references.

Why it matters

Regulation (EU) 2016/679 is the principal data protection instrument in the European Union, setting the baseline rules that organisations must follow when processing the personal data of individuals. Because it is a Regulation rather than a Directive, it is directly applicable across EU member states, meaning organisations operating in or targeting the EU generally need to align their data handling practices with its requirements without waiting for national transposition. This gives the GDPR a broad and practical reach over how personal information is collected, used, shared, and protected.

For compliance programs, the GDPR functions as a foundational reference point around which policies, contracts, and governance structures are built. Its framework informs how legal bases for processing are selected, how individuals' rights are respected, and how accountability is demonstrated. Practitioners should note, however, that the Regulation permits specified national derogations and implementing measures, so the exact position can vary between member states and must be confirmed for the relevant jurisdiction.

Following the UK's departure from the EU, a distinct UK GDPR regime applies in the United Kingdom. This means that the phrase "GDPR" alone can be ambiguous, and the applicable text, EU GDPR or UK GDPR, should always be identified for a given matter. The consolidated official text (published in OJ L 119, 4 May 2016, with corrigenda) should be verified against the current version for precise wording and article references before it is relied upon.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads rely on the Regulation as the reference framework for building and maintaining a compliance program, including selecting the correct legal basis for processing and demonstrating accountability. They should confirm which jurisdiction's version applies and account for potential national derogations.
Privacy and Data Protection Lawyers
Lawyers advising on data protection matters use Regulation (EU) 2016/679 as a primary source and must be careful to distinguish the EU GDPR from the UK GDPR and from national implementing law. They should verify wording and article references against the current consolidated official text before citing it.
Engineers and Product Teams
Engineers and product teams handling personal data of individuals need to understand that the Regulation governs how such data is processed, while noting that anonymous data generally falls outside its material scope. Confirming whether data qualifies as personal data is an important scoping step subject to assessment.
Organisations Operating Across the EU and UK
Businesses processing personal data in or targeting the EU are subject to the directly applicable EU GDPR, while those operating in the United Kingdom must consider the separate UK GDPR regime. The applicable text should be confirmed for each jurisdiction, as national measures and the two regimes can diverge.

Inside GDPR

General Data Protection Regulation (GDPR)
The common name for Regulation (EU) 2016/679, the principal EU legal instrument governing the processing of personal data of individuals. As a Regulation, it is directly applicable across EU member states, though it contains numerous provisions permitting national derogations and implementing measures, so the precise position can vary by member state.
Material and territorial scope
The Regulation applies to the processing of personal data relating to identified or identifiable living individuals. It generally does not govern anonymous data, and does not, as a rule, cover the data of deceased persons or legal entities, though member state law may address some of these areas differently. Its territorial reach extends beyond the EU in certain circumstances, subject to assessment of the specific processing.
Data protection principles
Core requirements such as lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. These principles underpin the operative obligations throughout the Regulation and inform how specific provisions are interpreted.
Legal bases for processing (Article 6)
Six distinct bases: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a public task, and legitimate interests. These are alternatives; consent is one option among several and is not a universal requirement. The appropriate basis depends on the context of the processing.
Special category data (Article 9)
Certain sensitive categories of personal data attract heightened protection. Processing such data generally requires both an Article 6 legal basis and a separate Article 9 condition. Member state law may add further conditions or restrictions in some cases.
Roles: controller and processor
The Regulation distinguishes the controller, which determines the purposes and means of processing, from the processor, which processes on the controller's behalf. These roles carry different obligations and should not be conflated when allocating responsibility.
Accountability instruments
Tools including Data Processing Agreements between controllers and processors (Article 28), Data Protection Impact Assessments for higher-risk processing (Article 35), and records of processing activities. These instruments serve distinct functions and are not interchangeable.
Data subject rights
Rights afforded to individuals, which may include access, rectification, erasure, restriction, portability, and objection, subject to conditions and exemptions. The availability and scope of a given right depends on the processing context and applicable derogations.
International transfer mechanisms
Mechanisms enabling transfers of personal data outside the EU, including adequacy decisions, Standard Contractual Clauses, and Binding Corporate Rules, sometimes accompanied by supplementary measures. These are distinct tools; their availability and requirements evolve over time and should be verified against current guidance and the official text.

Common questions

Answers to the questions practitioners most commonly ask about GDPR.

Does the GDPR require consent for all processing of personal data?
No. Consent is only one of six lawful bases set out in Article 6 (the others being contract, legal obligation, vital interests, public task, and legitimate interests). Controllers should select the basis most appropriate to the processing rather than defaulting to consent. Note that processing special category data under Article 9 generally requires an additional condition on top of an Article 6 basis. The correct approach is context and purpose dependent.
Does the GDPR protect the data of companies and deceased individuals?
Generally no. The Regulation applies to personal data relating to identified or identifiable living individuals (data subjects) and does not, as a rule, govern the data of legal entities or, in most cases, deceased persons. However, member state implementing law can vary the position on deceased persons, so the national context should be checked. Anonymous data also falls outside the Regulation's scope.
How should an organisation identify which lawful basis under Article 6 applies to a given processing activity?
In most cases the assessment starts by defining the specific purpose of the processing, then matching it to the most appropriate of the six Article 6 bases. The basis chosen affects the applicable data subject rights and the documentation required, so it should generally be determined before processing begins and recorded. Where special category data under Article 9 is involved, an additional condition must also be identified. This is a case-by-case assessment and readers should verify against the current official text and relevant regulatory guidance.
What is the difference between a Data Processing Agreement and a Data Protection Impact Assessment?
These are distinct instruments. A Data Processing Agreement is a contract required under Article 28 governing the controller-processor relationship and setting out processing terms. A Data Protection Impact Assessment under Article 35 is an internal risk assessment carried out, typically where processing is likely to result in a high risk to individuals, before that processing begins. One is a contractual instrument; the other is an accountability and risk tool. They are not interchangeable.
How does an organisation determine whether it acts as a controller or a processor?
The distinction turns on who determines the purposes and means of the processing. A controller decides why and how personal data is processed; a processor acts on the controller's documented instructions. The characterisation is factual rather than merely a matter of labels in a contract, and an entity may be a controller for some activities and a processor for others. Because the roles carry different obligations, the analysis should be conducted per processing activity, and regulatory guidance may assist in borderline cases.
What should organisations consider when transferring personal data outside the EU under the GDPR?
International transfers generally require an appropriate mechanism, which may include reliance on an adequacy decision, or transfer tools such as Standard Contractual Clauses or Binding Corporate Rules, potentially combined with supplementary measures following a transfer assessment. These mechanisms and the adequacy landscape evolve over time, and divergence can exist between EU GDPR and UK GDPR positions. Any given arrangement should be verified against the current official text and applicable regulatory guidance rather than treated as permanently settled.

Common misconceptions

The GDPR always requires consent before processing personal data.
Consent is only one of the six legal bases under Article 6. In many cases another basis, such as contract, legal obligation, or legitimate interests, is more appropriate. The correct basis depends on the context, and special category data generally requires an additional Article 9 condition on top of an Article 6 basis.
A Data Processing Agreement and a Data Protection Impact Assessment are the same document or serve the same purpose.
They are distinct instruments. A Data Processing Agreement (Article 28) governs the controller-processor relationship contractually, whereas a Data Protection Impact Assessment (Article 35) is a risk assessment carried out for certain higher-risk processing. One does not substitute for the other.
The GDPR governs all data, including anonymous data and information about companies.
The Regulation applies to personal data of identified or identifiable living individuals. Genuinely anonymous data generally falls outside its scope, and it does not, as a rule, govern the data of legal entities or deceased persons, though member state law may vary the position for some of these categories.

Best practices

Identify and document the specific Article 6 legal basis for each processing activity before starting, and confirm an additional Article 9 condition where special category data is involved rather than defaulting to consent.
Clearly determine and record whether your organisation acts as a controller or a processor for each processing activity, since the applicable obligations differ, and put in place the correct instrument (for example, an Article 28 Data Processing Agreement) for the relationship.
Assess whether a Data Protection Impact Assessment (Article 35) is required for higher-risk processing, and keep it distinct from and additional to any contractual arrangements.
Check whether member state derogations or, where relevant, the UK GDPR and national implementing law alter the position for your processing, and do not assume the EU baseline applies uniformly.
Before relying on an international transfer mechanism such as an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules, verify its current status and consider whether supplementary measures are needed, treating this as an evolving area.
Verify article numbers, dates, and any figures against the current official text and up-to-date regulator guidance, and note where regulators may diverge or guidance is pending rather than presenting a snapshot as settled.