Digital & AI
Regulation (EU) 2016/679
GDPR
General Data Protection Regulation
Anyone using your personal data needs a lawful reason, has to be clear about it, and you can ask to see, fix, or delete much of it.
Does this hit me?
You can ask a company what they hold and tell them to stop some uses. Cookie walls are a messy side-effect, not the heart of the law. Supervisory authorities take complaints.
Check in the wizardPick a country in the header to see who enforces this at home. Union text is not the last word for directives.
How it rolls in
2016
Adopted.
May 2018
Became applicable.
Why it exists
Personal data became a business model. GDPR put rights and fines on that model so consent banners are not the whole story — though they became the visible part.
What actually changes
- Lawful basis required (consent, contract, legitimate interest, etc.).
- Rights of access, erasure, portability, and objection.
- Breach notification and DPO duties for many organisations.
- Extra rules for sensitive data and automated decisions.
How it hits you
You can ask a company what they hold and tell them to stop some uses. Cookie walls are a messy side-effect, not the heart of the law. Supervisory authorities take complaints.
For citizens
What this does to everyday life
Rights, bills, and what you can ignore. You are usually not the one who files — companies and states are.
Your data is not the company's property
A shop, app, or hospital needs a lawful reason to use your name, location, or browsing. You can ask what they hold, correct it, and in many cases delete it or take it elsewhere.
Cookie walls and tracking
Advertising trackers generally need a real choice. A banner that only says 'accept' is often worse than the law. Necessary cookies (login, basket) do not need a circus of buttons.
Work and school
Employers and schools are controllers too. Camera systems, badge logs, and exam proctoring have limits. You can raise this with a DPO or the national authority, not only with HR.
Rights you actually get
- Access — a copy of your data, in a usable form.
- Rectification and erasure in defined cases.
- Objection to some marketing and legitimate-interest uses.
- Complaint to a data protection authority, free of charge.
Costs and trade-offs
- Some free services get clunkier because ads are harder to target.
- You may be asked to identify yourself when exercising rights — that is allowed if proportionate.
What you can do
- Email the privacy contact and ask for a copy of your data. Keep the date.
- If ignored after a month (plus a possible extension), complain to your national DPA.
What you can ignore
- You are not fined as a private person for browsing the web.
- You do not have to read every 40-page policy. The short version should be true.
If something goes wrong
National data protection authority. The European Data Protection Board publishes a directory. Police-data files often sit under a sister law — still a public authority.
More citizen notes across files: For people
Heard this? Not quite.
Claim: You must tick a cookie box on every site or the site is illegal.
Consent is required for many trackers, not for every strictly necessary login cookie. The banners are often worse than the law demands.
Latest official statements
All EU NewsNo tagged Commission, Parliament or Council statement in the current feeds.
Board one-pager
Board one-pager
Who this is for: EU digital, product and data teams. Regulation (EU) 2016/679. Since 25 May 2018 — still the baseline.
Scope
- You have an EU establishment, or you offer goods/services to people in the EU, or you monitor their behaviour.
- You store names, emails, IDs, location, HR files, or device identifiers.
First 90 days
- Week 1: Write a one-page map: what data, why, where, who can see it.
- Week 2: Pick a lawful basis per purpose. Stop using consent as wallpaper.
- Week 3: Fix vendor list and transfer clauses for the tools you actually use.
- Week 4: Publish a short, true privacy notice and a working access-request path.
Penalties: Up to €20 million or 4% of worldwide annual turnover, whichever is higher, for the gravest breaches. Supervisory authorities can also order a processing stop.
For companies
How to stay on the right side of this file
Practical order of work, not a substitute for counsel. Any organisation that processes personal data of people in the EU, or that is established in the EU.
You are probably
A controller if you decide why the data is processed; a processor if you only follow a customer’s documented instructions.
Effort
A truthful SME map is days. A group with shadow IT is months, then continuous.
Budget
SME: owner time plus a processor who will sign a DPA. Large: DPO/privacy ops, transfer programme, tooling — not a one-off PDF.
Roles in this file
The same company can wear more than one hat. Classify before you buy a tool.
Controller
You set purposes and means (shop, employer, hospital, app owner).
Lawful basis per purpose, notice, RoPA, DSAR path, DPIAs, 72-hour playbook.
Processor
SaaS, payroll bureau, host acting only on instruction.
Article 28 contract, sub-processor list, no secondary use, help the controller with DSARs.
Joint controllers
Two parties jointly decide purposes (some adtech, some group HR).
An arrangement that says who answers the individual. The DPA can still chase both.
Are you in scope?
Act now- You have an EU establishment, or you offer goods/services to people in the EU, or you monitor their behaviour.
- You store names, emails, IDs, location, HR files, or device identifiers.
Usually not, if
- Purely household / personal use.
- Truly anonymous data (harder than most dashboards claim).
First moves
- Week 1Write a one-page map: what data, why, where, who can see it.Ops / DPO
- Week 2Pick a lawful basis per purpose. Stop using consent as wallpaper.Legal
- Week 3Fix vendor list and transfer clauses for the tools you actually use.IT + legal
- Week 4Publish a short, true privacy notice and a working access-request path.Legal + support
- Minimise. If you do not need the field, delete the field.
- A 40-page policy copied from a bank is worse than a two-page honest one.
- Use a processor who will sign Article 28 terms. If they will not, do not use them.
If you skip this
- DSARs missed → easy DPA file.
- No RoPA → you cannot answer a buyer or a regulator with a straight face.
- US tools without SCCs + assessment → transfer findings on top of the original issue.
Done looks like
- A living record of processing that matches the systems you actually run.
- A DSAR mailbox that hits the one-month clock.
- Vendor list with roles (controller/processor) and transfer tools.
- Breach log and a named person who can call the DPA.
Keep this evidence
- Record of processing activities (even a spreadsheet, if true).
- DPIAs for high-risk processing (monitoring, special data, large-scale profiling).
- Processor contracts and transfer tools.
- Breach log and 72-hour playbook.
Ask vendors
- Are you a processor or a controller for this service?
- Where is data stored and who can access it?
- Will you sign our DPA and list sub-processors?
Where programmes usually break
- Consent banners that block the site until you accept advertising cookies.
- Calling data 'anonymous' when it is only hashed.
- No one owning DSARs, so deadlines are missed.
Call counsel when
- Special-category data, large-scale profiling, or covert monitoring.
- A cross-border complaint or a dawn-raid-style information request.
- A deal room that asks you to warrant GDPR compliance in the SPA.
Enforcement
Up to €20 million or 4% of worldwide annual turnover, whichever is higher, for the gravest breaches. Supervisory authorities can also order a processing stop.
National data protection authority (lead authority if you are cross-border). European Data Protection Board coordinates.
Need a stack, not one file? Open the company desk
Professional briefing
Legal architecture and duties
For counsel, compliance, and policy teams. Not advice. The Official Journal still wins.
- Instrument
- Regulation
- Legal basis
- Arts 16 TFEU and 8 CFR · Regulation (EU) 2016/679
- Application
- Directly applicable since 25 May 2018. National DPAs still run procedure, HR exceptions, and some public-interest bases.
The GDPR remains the base layer under later digital files. Almost every AI, platform, employment and product-data question starts here: personal data, a controller, a lawful basis, and a transfer story. Treat the AI Act and Data Act as overlays, not substitutes. Enforcement is mature; the EDPB and one-stop-shop still leave room for forum shopping and inconsistent cookie practice.
How the file is built
Material and territorial scope (Arts 2–3)
Processing of personal data wholly or partly by automated means, plus structured filing systems. Territorial reach is establishment in the Union or targeting/monitoring of people in the Union — extra-territorial by design.
Principles and lawful bases (Arts 5–11)
Lawfulness, purpose limitation, minimisation, accuracy, storage limitation, integrity, accountability. Special-category data (Art 9) is a separate gate, not a footnote to legitimate interests.
Rights and transfers (Arts 12–23, 44–49)
Access, erasure, portability, objection. Chapter V transfers need an adequacy decision, SCCs plus transfer impact assessment, or a narrow derogation. The US Data Privacy Framework is not a substitute for purpose limitation.
Operators
| Role | Who | Core duties |
|---|---|---|
| Controller | Determines purposes and means. | Lawful basis, transparency, DPIA, DPO where required, records, security, breach notification. |
| Processor | Processes on documented instructions. | Art 28 contract, no sub-processing without authorisation, assistance on rights and breaches. |
| Joint controllers | Jointly determine purposes/means. | Art 26 arrangement; data subjects may exercise rights against each. |
Scope
EU establishment, or offering goods/services to or monitoring behaviour of people in the Union. A representative (Art 27) is required for many non-EU controllers/processors.
In
- Any personal data relating to an identified or identifiable natural person.
- Employee, candidate, customer, patient, and device identifiers that can single someone out.
- Profiling and automated decision-making with legal or similarly significant effects (Art 22).
Out, or narrower than assumed
- Purely personal or household activity.
- Competent authorities for criminal law (LED 2016/680) and common foreign and security policy processing.
- Anonymous data that cannot reasonably be re-identified — a high bar, not a hashing trick.
Operative provisions
| Anchor | Rule | What it does in practice |
|---|---|---|
| Art 6 | Six lawful bases; consent must be specific and withdrawable. | Cookie walls and bundled ‘accept all’ remain the usual DPA target. |
| Art 30 / 35 | Records of processing; DPIA for high-risk processing. | HR monitoring, large-scale special-category, and systematic profiling almost always trigger a DPIA. |
| Art 33–34 | Breach notification to DPA (72h) and, if high risk, to people. | Incident playbooks must include legal characterisation, not only IT restore. |
| Art 83 | Administrative fines up to €20m or 4% of worldwide turnover. | Turnover is group turnover where the undertaking concept applies. |
Secondary law and guidance
- EDPB guidelines (consent, targeting, legitimate interests, transfer tools).
- Standard contractual clauses 2021/914.
- National DPA guidance — not always aligned on cookies or employment monitoring.
National layer. Member States legislate for employment, journalism, research, and public-interest bases. Works-council and labour-law overlays often bite harder than the DPA in HR files.
How it sits with other files
High-risk AI that processes personal data still needs a GDPR lawful basis and often a DPIA; FRIA under the AI Act does not replace it.
User access to product data is additional; if the telemetry is personal, GDPR continues to govern sharing with third parties.
Platform moderation and ads transparency sit beside, not instead of, GDPR targeting rules.
Enforcement and private rights
Who
Lead supervisory authority of the main establishment, with EDPB consistency. Commission does not fine under GDPR.
Tools
Orders, bans, audits, administrative fines. Schrems-style litigation and representative actions (Directive 2020/1828) add private pressure.
Private rights
Compensation (Art 82) without needing a DPA decision first. NGOs can be mandated in some States.
Risk register
| Risk | Signal | Control |
|---|---|---|
| Unlawful international transfers | US SaaS in HR or support with no TIA | Inventory tools; SCCs + assessment or switch region. |
| Dark-pattern consent | Reject harder than accept | Equal-effort consent UI; actual choice of non-essential cookies. |
| Shadow processing | Marketing pixels not in RoPA | Tag governance tied to Art 30 records. |
Open issues
- Cookie-banner enforcement remains fragmented despite EDPB work.
- AI training on personal data: legitimate interests vs consent is litigated, not settled.
- The ‘undertaking’ concept for fines after CJEU case law on parental liability.
Primary sources
This is the base layer under almost every later digital file. Get the map wrong here and AI, HR tools, and cookies fail on a 2018 rule, not a 2026 one.
You feel it now
Already in force. Complaints and DSARs are live in every Member State.
Next
AI Act, DSA and Data Act sit on top. They do not replace GDPR.
Where it lands
| Channel | People | Companies |
|---|---|---|
| Rights and complaints | Access, deletion, and a free complaint to the national DPA. The clock on an access request is one month, not ‘when support gets to it’. | DSAR volume, complaint letters, and tenders that ask for a record of processing. The DPA talks to the controller, not the marketing intern. |
| Price and product | Some free services get clumsier because ads are harder to target. That is a trade-off, not a fine on you. | Cookie walls that force ads, shadow SaaS, and US tools without a transfer story leak into lost deals and blocked analytics. |
| Work | Badge logs, cameras, and exam proctoring have limits. You raise it with the DPO or the DPA, not only HR. | Employee monitoring and recruitment tools need a lawful basis and often a DPIA before an AI-Act file is even opened. |
| Incidents | You may get a breach letter. That is the company duty, not yours. | 72-hour notice to the DPA, customer notice when risk is high. Downtime and trust usually cost more than the fine. |
Who gains
People who can get a copy of their file; buyers who demand a real RoPA in due diligence.
Who pays
Controllers who treated the privacy policy as the programme.
Files this pulls with it
- AI Act — High-risk HR and credit AI still need a GDPR lawful basis and DPIA.
- Data Act — IoT access rights sit beside, not instead of, personal-data rules.
- Digital Services Act — Ads and recommender transparency on platforms still start with GDPR if personal data is in the mix.
Who pays
Controllers and processors of personal data.
Who benefits
Individuals in the EU (and often anyone whose data is processed in the EU model).
Read the official text