Law / European Union

General Data Protection Regulation (GDPR), Comprehensive Regime

Regulation (EU) 2016/679

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

A comprehensive regime rule binding public and private bodies.

As of 23 August 2026.

What it requires

  • Establish and document a lawful basis under Article 6 before processing any personal data of a person in the EU.
  • Allocate and document controller and processor responsibilities in a written agreement wherever a third party processes personal data on your behalf, and appoint a Data Protection Officer where your core activities involve large scale monitoring or large scale special category processing.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

Article 83(5) sets the higher administrative-fine tier, up to EUR 20,000,000 or 4 percent of total worldwide annual turnover of the preceding financial year, whichever is higher, for infringements of the basic principles for processing (Articles 5, 6, 7 and 9), the data subjects' rights (Articles 12 to 22), cross-border transfer conditions (Articles 44 to 49), Member State law obligations under Chapter IX, and non-compliance with a supervisory authority order under Article 58. A separate, lower tier under Article 83(4) caps the controller and processor obligations in Articles 8, 11, 25 to 39, 42 and 43 (which include the Article 33 and 34 breach notification duties) at EUR 10,000,000 or 2 percent of worldwide annual turnover, whichever is higher; that lower tier is recorded on the instrument covering Articles 33 and 34.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

The data protection supervisory authority designated by each EU Member State under Article 51, coordinated on cross-border cases through the one stop shop mechanism and the European Data Protection Board (Articles 68-76).

Enforcement record

CMS GDPR Enforcement Tracker Report, 7th edition (cut-off 1 March 2026, published 21 May 2026): 2,685 fines with complete amount, date and controller information recorded across the EU/EEA since the GDPR became applicable on 25 May 2018 (3,062 including cases with incomplete information), totalling approximately EUR 6.11 billion, the first time the tracker's cumulative total crossed EUR 6 billion. actions_per_year (440) and fines_per_year (approximately EUR 487.6 million) are the report's own comparison against its prior, 2025 edition (roughly a one-year interval between editions), not a fixed calendar year; trend is recorded as rising on that reported increase. Counts DPA-imposed administrative fines only; the report does not separately track private civil claims under Article 82. This is the Regulation's enforcement record as a whole.

As of
2 September 2026
Trend
Rising
Currency
EUR
Source link
https://cms.law/en/int/publication/GDPR-Enforcement-Tracker-Report/numbers-and-figures
Total fines
6,110,000,000
Fines per year
487,600,000
Actions per year
440

What it reaches

Obligation class

Consent, Disclosure, DPIA, Data subject rights, Transfer, Breach notice, Security, Governance

Also on the record

EEA status

Annex
XI
Status
Incorporated
Force date
20 July 2018
Joint committee decision number
154/2018
Source link
https://www.efta.int/eea-lex/32016r0679
Decision date
6 July 2018

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Establishes the lawful basis, purpose limitation, and controller and processor accountability framework for processing personal data of people in the EU. Article 6(1) requires one of six lawful bases for any processing, Articles 24-28 allocate duties between controllers, joint controllers and processors, and the Regulation applies extraterritorially to any controller or processor offering goods or services to, or monitoring, people in the EU (Article 3).

It binds public authorities as well as private sector controllers, though Article 83(7) lets Member States decide whether administrative fines apply to their own public bodies.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app