EU Regulatory Domain

Data Protection

Regulation (EU) 2016/679 (GDPR): directly applicable in every Member State and fully in force.

Key facts

The GDPR at a glance

In force since 2018

Regulation (EU) 2016/679 has applied since 25 May 2018 and is directly applicable in every Member State.

Reach beyond the EU

Under Article 3, it also covers organisations outside the Union that offer goods or services to, or monitor, people in the EU.

72-hour breach notification

Breaches must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours.

Fines up to 4%

The most serious infringements carry fines of up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher.

Overview

The General Data Protection Regulation has applied since 25 May 2018. It governs the processing of personal data by controllers and processors established in the European Union and, under Article 3, by organisations outside the Union that offer goods or services to people in the EU or monitor their behaviour. As a regulation, it is directly applicable, although Member States complement it with national laws, such as Law 58/2019 in Portugal and Organic Law 3/2018 (LOPDGDD) in Spain.

Core obligations

  • principles and accountability: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and the duty to demonstrate compliance (Article 5);

  • lawful basis: every processing operation needs a legal basis (Article 6), with stricter conditions for special categories of data (Article 9);

  • transparency and rights: clear information to data subjects and a response to rights requests, as a rule within one month (Articles 12 to 22);

  • records of processing activities: a documented inventory of processing operations (Article 30);

  • privacy by design and security: data protection by design and by default, and appropriate technical and organisational security measures (Articles 25 and 32);

  • data protection impact assessment: mandatory where processing is likely to result in a high risk (Article 35);

  • processors and transfers: written contracts with processors (Article 28) and appropriate safeguards for transfers outside the European Economic Area (Chapter V);

  • personal data breaches: notification to the supervisory authority without undue delay and, where feasible, within 72 hours, and communication to data subjects when the risk is high (Articles 33 and 34).

The Data Protection Officer

Designating a Data Protection Officer is mandatory for public authorities and bodies, and for organisations whose core activities consist of large-scale regular and systematic monitoring or large-scale processing of special categories of data or criminal-offence data (Article 37). The DPO must be involved in all data protection issues, act independently, report to the highest management level and not be dismissed or penalised for performing their tasks (Article 38). The role may be performed by an employee or under a service contract, which is how many public bodies and SMEs meet the requirement efficiently.

Enforcement

Administrative fines reach EUR 20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements, and EUR 10 million or 2% for the lower tier (Article 83). Each Member State has an independent supervisory authority, such as the CNPD in Portugal and the AEPD in Spain, and the European Data Protection Board ensures consistent application.

What is changing

  • cross-border enforcement: Regulation (EU) 2025/2518 harmonises procedures for cross-border cases and applies from 2 April 2027;

  • simplification proposals: targeted amendments, including lighter record-keeping for smaller organisations and the Digital Omnibus, are still in the legislative process and have not yet changed organisations' obligations.

How we can help

Related domains: Cybersecurity (NIS2) · Artificial Intelligence · Whistleblower Protection · Third-Party & Supply Chain

Official text: Regulation (EU) 2016/679 on EUR-Lex

General information as of October 2026; it does not constitute legal advice. Confirm the applicable requirements with the competent authorities.

Related domains

Where the GDPR meets other rules

Cybersecurity (NIS2)

Cybersecurity risk management and incident reporting under NIS2

Artificial Intelligence

AI Act obligations alongside personal data processing

Third-Party & Supply Chain

Processor contracts and transfer safeguards in one due-diligence lifecycle

Find out where your GDPR compliance stands

Request a free gap analysis of your records, legal bases, contracts and security.