Regulation (EU) 2016/679 · Last verified

GDPR

GDPR is Regulation (EU) 2016/679, applicable from 25 May 2018 — its territorial scope and fine ceilings are reproduced verbatim on this page. Adopted 27 April 2016, it is reproduced here in its own wording, with article numbers and a link to the official text — this page does not interpret it or assess whether it applies to any organisation.

Citation
Regulation (EU) 2016/679
Jurisdiction
EU
Last verified

What it is

Adopted 27 April 2016, it is reproduced here in its own wording, with article numbers and a link to the official text — this page does not interpret it or assess whether it applies to any organisation.

REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) ↗

Key dates

  • Adopted: — "Done at Brussels, 27 April 2016."
  • Applies from: — "It shall apply from 25 May 2018."

Entry into force: "This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union."

Scope

Article 3 — Territorial scope

1. This Regulation applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not.

2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.

3. This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.

EUR-Lex — Regulation (EU) 2016/679 (Official Journal text) ↗

Penalties

Article 83(4)

Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher

Article 83(5)

Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher

Certification mechanisms

Article 42(1)

The Member States, the supervisory authorities, the Board and the Commission shall encourage, in particular at Union level, the establishment of data protection certification mechanisms and of data protection seals and marks, for the purpose of demonstrating compliance with this Regulation of processing operations by controllers and processors.

Sources

Last verified:

This page is for information only and is not legal advice. It reproduces the regulation's own wording; always confirm against the primary source linked above and consult qualified counsel for how it applies to your organisation.

Cite this page

Attributing this record helps other researchers verify it independently.

"GDPR." Certifidex, FutureTechnologies. Last verified 29 August 2026. https://certifidex.com/regulations/gdpr

All regulations →