EU · 2016/679 · source-led dossier

European Union
GDPR

Regulation (EU) 2016/679

What this record can establish

  • The regulation's published architecture for principles, lawful bases, rights, accountability, transfers and supervision.
  • That the regulation has applied since 25 May 2018.

What it cannot establish

  • That enforcement and guidance are uniform across every Member State and sector.
  • That detail is inherently better or worse than a more concise legislative model.

Instrument and status timeline

Publication, operation and evidence are different moments.

17-factor research index

Questions defined. Evidence stays qualitative.

Every factor remains inspectable without implying that evidence across frameworks is numerically equivalent.

01

Readable rules

How the legal architecture can be found, understood and translated into a research plan.

Moderate

The official text provides a detailed architecture; issue-specific national law and guidance may still matter.

  1. clarity
    Accessibility and drafting clarity

    How much interpretation is needed before a team can identify the rule that governs its activity?

    Open framework evidence record
    Current dossier record
    The official text provides a detailed architecture; issue-specific national law and guidance may still matter.
    Seek
    Controlling text, amendment history, commencement records and an issue-specific reading path.
    Avoid
    Shorter text is not automatically clearer, safer or cheaper to implement.
    No jurisdiction value
  2. scope
    Scope and extra-territorial reach

    Which entities, people, data and overseas activities fall inside the framework?

    Open framework evidence record
    Current dossier record
    The official text provides a detailed architecture; issue-specific national law and guidance may still matter.
    Seek
    Definitions, territorial provisions, exclusions, coverage thresholds and relevant official guidance.
    Avoid
    A national market presence does not by itself prove that a specific activity is covered.
    No jurisdiction value
  3. grounds
    Permitted grounds and processing architecture

    Which processing grounds exist, and how does an organisation document the one it relies on?

    Open framework evidence record
    Current dossier record
    The official text provides a detailed architecture; issue-specific national law and guidance may still matter.
    Seek
    Operative ground or exception, purpose record, applicable conditions and supporting documentation.
    Avoid
    Matching labels across laws do not make processing grounds interchangeable.
    No jurisdiction value
  4. notice
    Notice and consent usability

    What must a person be told, when, and in what form before data is used?

    Open framework evidence record
    Current dossier record
    The official text provides a detailed architecture; issue-specific national law and guidance may still matter.
    Seek
    Operative notice duties, delivery context, language or accessibility rules and tested user comprehension.
    Avoid
    Publishing a notice does not prove that people saw or understood it.
    No jurisdiction value
02

Individual agency

What people can understand, choose, contest and ask organisations to do.

Moderate

Articles 12–22 set out an extensive rights framework, but practical access and outcomes require jurisdiction-specific evidence.

  1. withdrawal
    Withdrawal and preference control

    Can a person reverse a choice through a practical, understandable route?

    Open framework evidence record
    Current dossier record
    Articles 12–22 set out an extensive rights framework, but practical access and outcomes require jurisdiction-specific evidence.
    Seek
    Operative withdrawal rule, interface steps, downstream propagation and documented exceptions.
    Avoid
    A stated right to withdraw does not prove that the practical route is equivalent to giving consent.
    No jurisdiction value
  2. rights
    Individual rights and grievance pathways

    Which rights exist, and what must happen before a person can obtain a remedy?

    Open framework evidence record
    Current dossier record
    Articles 12–22 set out an extensive rights framework, but practical access and outcomes require jurisdiction-specific evidence.
    Seek
    Operative right, identity and timing rules, refusal grounds, escalation path and outcome evidence.
    Avoid
    A longer catalogue of rights does not by itself show that remedies are more accessible.
    No jurisdiction value
  3. children
    Children and guardian treatment

    How does the framework recognise age, guardianship and risks to younger people?

    Open framework evidence record
    Current dossier record
    Articles 12–22 set out an extensive rights framework, but practical access and outcomes require jurisdiction-specific evidence.
    Seek
    Age definition, guardian mechanism, applicable safeguards, exceptions and child-facing design evidence.
    Avoid
    A single age threshold does not capture the whole child-safety or guardian model.
    No jurisdiction value
  4. automated
    Automated decision and algorithmic accountability

    What transparency or recourse applies when automated processing affects a person?

    Open framework evidence record
    Current dossier record
    Articles 12–22 set out an extensive rights framework, but practical access and outcomes require jurisdiction-specific evidence.
    Seek
    Scope of covered decisions, explanation or notice duties, contest route and evidence of human review.
    Avoid
    Generic transparency language does not establish a right against every automated outcome.
    No jurisdiction value
03

Organisational architecture

How duties, safeguards, risk processes and transfer mechanisms are organised.

Moderate

Controller, processor, security, impact-assessment and transfer duties are explicit; burden cannot be inferred from text alone.

  1. processor
    Processor and accountability architecture

    Who remains accountable when processing is delegated or shared?

    Open framework evidence record
    Current dossier record
    Controller, processor, security, impact-assessment and transfer duties are explicit; burden cannot be inferred from text alone.
    Seek
    Role definitions, contracts, instruction boundaries, onward delegation and responsibility for failures.
    Avoid
    Vendor terminology in one framework cannot be copied directly into another role system.
    No jurisdiction value
  2. security
    Security and breach response

    Which safeguards and breach steps are specified, and when are they triggered?

    Open framework evidence record
    Current dossier record
    Controller, processor, security, impact-assessment and transfer duties are explicit; burden cannot be inferred from text alone.
    Seek
    Operative safeguard standard, trigger tests, notification recipients, timing and incident records.
    Avoid
    A detailed checklist does not prove effective security or consistent breach response.
    No jurisdiction value
  3. risk
    Data protection impact and risk duties

    When must an organisation investigate and document risk before processing?

    Open framework evidence record
    Current dossier record
    Controller, processor, security, impact-assessment and transfer duties are explicit; burden cannot be inferred from text alone.
    Seek
    Trigger criteria, required assessment content, reviewer or consultation route and retained decision record.
    Avoid
    Using an impact-assessment template does not prove that the relevant risks were identified.
    No jurisdiction value
  4. transfer
    Cross-border transfer model

    Which transfer routes exist, and what continuing safeguards travel with the data?

    Open framework evidence record
    Current dossier record
    Controller, processor, security, impact-assessment and transfer duties are explicit; burden cannot be inferred from text alone.
    Seek
    Destination, transfer route, restrictions, contract or assessment record and onward-transfer controls.
    Avoid
    A permitted destination does not remove continuing security or accountability duties.
    No jurisdiction value
  5. burden
    MSME implementation burden

    Which obligations create fixed costs, and what tailoring exists for smaller organisations?

    Open framework evidence record
    Current dossier record
    Controller, processor, security, impact-assessment and transfer duties are explicit; burden cannot be inferred from text alone.
    Seek
    Role-specific task inventory, exemptions or tailoring, recurring workload and organisation-level cost evidence.
    Avoid
    Concise legislation does not prove low implementation cost for a smaller organisation.
    No jurisdiction value
  6. interop
    Interoperability and ecosystem potential

    Could teams implement the rule through portable patterns without weakening legal context?

    Open framework evidence record
    Current dossier record
    Controller, processor, security, impact-assessment and transfer duties are explicit; burden cannot be inferred from text alone.
    Seek
    Compatible definitions, documented interfaces, governance ownership and tests across real operating contexts.
    Avoid
    Technical reuse does not make the underlying legal requirements equivalent.
    No jurisdiction value
04

Institutions and remedy

How rules are supervised, enforced, explained and tested through practice.

Moderate

The regulation defines independent supervisory authorities and cooperation, while implementation can vary by context.

  1. regulator
    Regulator design and procedural digitisation

    How can people and organisations reach the institution, and what can it do?

    Open framework evidence record
    Current dossier record
    The regulation defines independent supervisory authorities and cooperation, while implementation can vary by context.
    Seek
    Operative mandate, procedure, access route, published powers and evidence of actual use.
    Avoid
    A digital portal or broad statutory power does not prove timely or accessible resolution.
    No jurisdiction value
  2. penalties
    Penalty design

    How are sanctions linked to conduct, context and due process?

    Open framework evidence record
    Current dossier record
    The regulation defines independent supervisory authorities and cooperation, while implementation can vary by context.
    Seek
    Operative penalty provisions, decision factors, appeal route and dated enforcement records.
    Avoid
    A higher maximum penalty does not automatically mean stronger protection or enforcement.
    No jurisdiction value
  3. maturity
    Enforcement maturity and published guidance

    What has the framework's operation, guidance and enforcement record actually demonstrated?

    Open framework evidence record
    Current dossier record
    The regulation defines independent supervisory authorities and cooperation, while implementation can vary by context.
    Seek
    Dated guidance, decisions, enforcement records, appeal outcomes and evidence about access in practice.
    Avoid
    Age or publication volume alone is not a measure of institutional quality.
    No jurisdiction value
Q

TAKE TO COUNSEL / TEAMS

Operational questions, not prescriptions

Start the next conversation here.

  1. 01

    Which Member State laws and regulator guidance modify the issue under review?

  2. 02

    Which controller, processor or joint-controller role applies to each processing activity?

  3. 03

    What evidence demonstrates that a right or remedy is accessible in the relevant jurisdiction?

Official source rail

Open the record behind the summary.

Article revision record

What changed on this page.

This register begins with the private-preview editorial rebuild. It records material content, method, interface and trust-policy changes without inventing a history that predates the available repository evidence.

ROUTE/frameworks/gdpr
ENTRIES01
Inspect the full revision register
Legal or editorial substance changedAdded the same pair-aware 17-factor evidence path used by the other framework dossiers.
Why this changed
Symmetrical comparison requires the selected research question, evidence target and inference warning on both sides of the pair.
Claim impact
The dossier exposes the official EU record without converting reader attention into a GDPR or DPDP score.
Review state
Human legal or editorial review still required
Change ID
DOSSIER-GDPR-20260826-01
Source impactEU-01 · EUR-Lex / Official Journal of the European Union

Source record

Source record

Authority
Pinpoint
Legal status
Checked
Basis

Official guidance can explain a rule, but it does not replace the controlling legal text.