EU Regulatory Domain
Regulation (EU) 2016/679 (GDPR): directly applicable in every Member State and fully in force.
Key facts
Regulation (EU) 2016/679 has applied since 25 May 2018 and is directly applicable in every Member State.
Under Article 3, it also covers organisations outside the Union that offer goods or services to, or monitor, people in the EU.
Breaches must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours.
The most serious infringements carry fines of up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher.
The General Data Protection Regulation has applied since 25 May 2018. It governs the processing of personal data by controllers and processors established in the European Union and, under Article 3, by organisations outside the Union that offer goods or services to people in the EU or monitor their behaviour. As a regulation, it is directly applicable, although Member States complement it with national laws, such as Law 58/2019 in Portugal and Organic Law 3/2018 (LOPDGDD) in Spain.
principles and accountability: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and the duty to demonstrate compliance (Article 5);
lawful basis: every processing operation needs a legal basis (Article 6), with stricter conditions for special categories of data (Article 9);
transparency and rights: clear information to data subjects and a response to rights requests, as a rule within one month (Articles 12 to 22);
records of processing activities: a documented inventory of processing operations (Article 30);
privacy by design and security: data protection by design and by default, and appropriate technical and organisational security measures (Articles 25 and 32);
data protection impact assessment: mandatory where processing is likely to result in a high risk (Article 35);
processors and transfers: written contracts with processors (Article 28) and appropriate safeguards for transfers outside the European Economic Area (Chapter V);
personal data breaches: notification to the supervisory authority without undue delay and, where feasible, within 72 hours, and communication to data subjects when the risk is high (Articles 33 and 34).
Designating a Data Protection Officer is mandatory for public authorities and bodies, and for organisations whose core activities consist of large-scale regular and systematic monitoring or large-scale processing of special categories of data or criminal-offence data (Article 37). The DPO must be involved in all data protection issues, act independently, report to the highest management level and not be dismissed or penalised for performing their tasks (Article 38). The role may be performed by an employee or under a service contract, which is how many public bodies and SMEs meet the requirement efficiently.
Administrative fines reach EUR 20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements, and EUR 10 million or 2% for the lower tier (Article 83). Each Member State has an independent supervisory authority, such as the CNPD in Portugal and the AEPD in Spain, and the European Data Protection Board ensures consistent application.
cross-border enforcement: Regulation (EU) 2025/2518 harmonises procedures for cross-border cases and applies from 2 April 2027;
simplification proposals: targeted amendments, including lighter record-keeping for smaller organisations and the Digital Omnibus, are still in the legislative process and have not yet changed organisations' obligations.
Compliance Assessment: a GDPR gap analysis of records, legal bases, contracts and security;
Implementation Kits: policies, records, DPIA and breach-response templates;
Fractional Compliance Officer: an external DPO or DPO support on retainer;
Training & Capacity: awareness for staff and specialised training for privacy teams.
Related domains: Cybersecurity (NIS2) · Artificial Intelligence · Whistleblower Protection · Third-Party & Supply Chain
Official text: Regulation (EU) 2016/679 on EUR-Lex
General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.
Related domains
Request a free gap analysis of your records, legal bases, contracts and security.