Regulation (EU) 2016/679
Regulation (EU) 2016/679, commonly known as the General Data Protection Regulation or GDPR, is a European Union law that sets rules for how organisations handle the personal data of individuals. It was adopted by the European Parliament and the Council on 27 April 2016 and is aimed at protecting people in relation to the processing of their personal information. A separate UK version (the UK GDPR) exists following the UK's departure from the EU, so the applicable text should be confirmed for a given jurisdiction.
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 is the EU's principal data protection instrument, governing the protection of natural persons with regard to the processing of personal data and the free movement of such data. As a Regulation, it is directly applicable across EU member states, though it permits specified national derogations and implementing measures that can vary the position in individual jurisdictions. Its material scope concerns personal data of natural persons and does not extend to anonymous data or, generally, to data of deceased persons or legal entities; practitioners should note that a distinct UK GDPR regime applies in the United Kingdom and that the consolidated official text (published in OJ L 119, 4 May 2016, with corrigenda) should be verified against the current version for precise wording and article references.
Why it matters
Regulation (EU) 2016/679 is the principal data protection instrument in the European Union, setting the baseline rules that organisations must follow when processing the personal data of individuals. Because it is a Regulation rather than a Directive, it is directly applicable across EU member states, meaning organisations operating in or targeting the EU generally need to align their data handling practices with its requirements without waiting for national transposition. This gives the GDPR a broad and practical reach over how personal information is collected, used, shared, and protected.
For compliance programs, the GDPR functions as a foundational reference point around which policies, contracts, and governance structures are built. Its framework informs how legal bases for processing are selected, how individuals' rights are respected, and how accountability is demonstrated. Practitioners should note, however, that the Regulation permits specified national derogations and implementing measures, so the exact position can vary between member states and must be confirmed for the relevant jurisdiction.
Following the UK's departure from the EU, a distinct UK GDPR regime applies in the United Kingdom. This means that the phrase "GDPR" alone can be ambiguous, and the applicable text, EU GDPR or UK GDPR, should always be identified for a given matter. The consolidated official text (published in OJ L 119, 4 May 2016, with corrigenda) should be verified against the current version for precise wording and article references before it is relied upon.
Who it's relevant to
Inside GDPR
Common questions
Answers to the questions practitioners most commonly ask about GDPR.