AMLEGALSDPDPAVibe Data Privacy
Jurisdiction: European Union

The Union
Codex.

Regulation (EU) 2016/679 - The General Data Protection Regulation. The gold standard of global privacy law since May 2018.

€20M
Maximum Fine
or 4% Global Turnover
72hrs
Breach Window
DPA Notification
27
Member States
Harmonized Framework
99
Articles
Plus 173 Recitals
Article 5

The 7 Principles

01

Lawfulness, Fairness, Transparency

Art. 5(1)(a)
02

Purpose Limitation

Art. 5(1)(b)
03

Data Minimization

Art. 5(1)(c)
04

Accuracy

Art. 5(1)(d)
05

Storage Limitation

Art. 5(1)(e)
06

Integrity & Confidentiality

Art. 5(1)(f)
07

Accountability

Art. 5(2)
Chapter III

Data Subject Rights

Art.15

Right to Access

Right to obtain confirmation and access to personal data

Art.16

Right to Rectification

Right to have inaccurate data corrected

Art.17

Right to Erasure

Right to be forgotten under certain conditions

Art.18

Right to Restriction

Right to restrict processing in specific scenarios

Art.20

Right to Portability

Right to receive data in machine-readable format

Art.21

Right to Object

Right to object to processing including profiling

Chapter V

Cross-Border Transfers

GDPR restricts transfers of personal data to third countries unless adequate protection is ensured. This creates the global "Brussels Effect" where non-EU entities must align with EU standards.

View Adequacy Matrix →

Adequacy Decision

Art. 45

Commission-recognized adequate protection

Standard Contractual Clauses

Art. 46(2)(c)

Commission-adopted contractual safeguards

Binding Corporate Rules

Art. 47

Intra-group transfer rules approved by SA

Derogations

Art. 49

Explicit consent, contract performance, etc.

Supervisory Authorities

Member States

🇩🇪

Germany

BfDI

Employee Data

🇫🇷

France

CNIL

Cookie Consent

🇮🇹

Italy

Garante

Marketing

🇪🇸

Spain

AEPD

Sandbox Host

🇳🇱

Netherlands

AP

Digital Services

🇮🇪

Ireland

DPC

Big Tech Hub

Explore GDPR In Depth

Access our comprehensive article-by-article analysis of Regulation (EU) 2016/679.

GDPR Deep Dive →