What this record can establish
- The regulation's published architecture for principles, lawful bases, rights, accountability, transfers and supervision.
- That the regulation has applied since 25 May 2018.
EU · 2016/679 · source-led dossier
Regulation (EU) 2016/679
What this record can establish
What it cannot establish
Instrument and status timeline
The official text was adopted and published in the Official Journal.
EU-01 · EUR-Lex / Official Journal of the European UnionArticle 99 specifies the date from which the regulation applies.
EU-01 · EUR-Lex / Official Journal of the European Union17-factor research index
Every factor remains inspectable without implying that evidence across frameworks is numerically equivalent.
How the legal architecture can be found, understood and translated into a research plan.
The official text provides a detailed architecture; issue-specific national law and guidance may still matter.
How much interpretation is needed before a team can identify the rule that governs its activity?
Which entities, people, data and overseas activities fall inside the framework?
Which processing grounds exist, and how does an organisation document the one it relies on?
What must a person be told, when, and in what form before data is used?
What people can understand, choose, contest and ask organisations to do.
Articles 12–22 set out an extensive rights framework, but practical access and outcomes require jurisdiction-specific evidence.
Can a person reverse a choice through a practical, understandable route?
Which rights exist, and what must happen before a person can obtain a remedy?
How does the framework recognise age, guardianship and risks to younger people?
What transparency or recourse applies when automated processing affects a person?
How duties, safeguards, risk processes and transfer mechanisms are organised.
Controller, processor, security, impact-assessment and transfer duties are explicit; burden cannot be inferred from text alone.
Who remains accountable when processing is delegated or shared?
Which safeguards and breach steps are specified, and when are they triggered?
When must an organisation investigate and document risk before processing?
Which transfer routes exist, and what continuing safeguards travel with the data?
Which obligations create fixed costs, and what tailoring exists for smaller organisations?
Could teams implement the rule through portable patterns without weakening legal context?
How rules are supervised, enforced, explained and tested through practice.
The regulation defines independent supervisory authorities and cooperation, while implementation can vary by context.
How can people and organisations reach the institution, and what can it do?
How are sanctions linked to conduct, context and due process?
What has the framework's operation, guidance and enforcement record actually demonstrated?
TAKE TO COUNSEL / TEAMS
Operational questions, not prescriptions
Which Member State laws and regulator guidance modify the issue under review?
Which controller, processor or joint-controller role applies to each processing activity?
What evidence demonstrates that a right or remedy is accessible in the relevant jurisdiction?
Official source rail
Article revision record
This register begins with the private-preview editorial rebuild. It records material content, method, interface and trust-policy changes without inventing a history that predates the available repository evidence.
DOSSIER-GDPR-20260826-01