EU General Data Protection Regulation (2016/679)
The EU's comprehensive data protection and privacy regulation. Establishes principles for lawful processing, data subject rights, controller and processor obligations, breach notification (72 hours), data protection by design and by default, and cross-border transfer safeguards. Applies to any organisation processing personal data of EU residents.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| Art.5(1)(a) | Lawfulness, fairness and transparency | |
| Art.5(1)(b) | Purpose limitation | |
| Art.5(1)(c) | Data minimisation | |
| Art.5(1)(d) | Accuracy | |
| Art.5(1)(e) | Storage limitation | |
| Art.5(1)(f) | Integrity and confidentiality | |
| Art.5(2) | Accountability | |
| Art.6(1) | Lawfulness of processing — general | |
| Art.6(1)(a) | Lawfulness — consent as legal basis | |
| Art.6(1)(b) | Lawfulness — contractual necessity | |
| Art.6(1)(c) | Lawfulness — legal obligation | |
| Art.6(1)(f) | Lawfulness — legitimate interests | |
| Art.6(4) | Lawfulness — compatibility of further processing | |
| Art.7(1) | Conditions for consent — demonstrability | |
| Art.7(2) | Conditions for consent — distinguishable request | |
| Art.7(3) | Conditions for consent — right to withdraw | |
| Art.8(1) | Child's consent in relation to information society services | |
| Art.9(1) | Processing of special categories of personal data — prohibition | |
| Art.9(2) | Processing of special categories — exceptions | |
| Art.12(1) | Transparent information, communication and modalities — transparency | |
| Art.12(2) | Transparent information — facilitating exercise of data subject rights | |
| Art.12(7) | Transparent information — standardised icons | |
| Art.13(1) | Information to be provided where data collected from data subject | |
| Art.13(2) | Information to be provided — additional information for fair processing | |
| Art.14(1) | Information where data not obtained from data subject | |
| Art.14(2) | Information where data not obtained — additional details | |
| Art.15(1) | Right of access by the data subject | |
| Art.15(3) | Right of access — copy of data | |
| Art.16 | Right to rectification | |
| Art.17(1) | Right to erasure ('right to be forgotten') | |
| Art.17(2) | Right to erasure — notification to recipients | |
| Art.18(1) | Right to restriction of processing | |
| Art.19 | Notification obligation regarding rectification or erasure or restriction | |
| Art.20(1) | Right to data portability | |
| Art.20(2) | Right to data portability — direct transmission | |
| Art.21(1) | Right to object | |
| Art.22(1) | Automated individual decision-making, including profiling | |
| Art.22(2) | Automated decision-making — exceptions allowing automated processing | |
| Art.22(3) | Automated decision-making — safeguards | |
| Art.22(4) | Automated decision-making — special categories | |
| Art.24(1) | Responsibility of the controller — appropriate measures | |
| Art.24(2) | Responsibility of the controller — data protection policies | |
| Art.25(1) | Data protection by design | |
| Art.25(2) | Data protection by default | |
| Art.28(1) | Processor obligations — sufficient guarantees | |
| Art.28(2) | Processor obligations — sub-processor authorisation | |
| Art.28(3) | Processor obligations — binding contract terms | |
| Art.28(3)(a) | Processor contract — processing on documented instructions | |
| Art.28(3)(b) | Processor contract — confidentiality obligations | |
| Art.28(3)(c) | Processor contract — security measures per Art. 32 | |
| Art.28(3)(f) | Processor contract — audit and inspection rights | |
| Art.28(3)(g) | Processor contract — data deletion/return after services end | |
| Art.28(3)(h) | Processor contract — compliance demonstration and audit cooperation | |
| Art.28(4) | Processor obligations — sub-processor contract obligations | |
| Art.29 | Processing under the authority of the controller or processor | |
| Art.30(1) | Records of processing activities — controller | |
| Art.30(1)(g) | Records of processing — security measures description | |
| Art.30(2) | Records of processing activities — processor | |
| Art.30(2)(d) | Records of processing — processor security measures description | |
| Art.32(1) | Security of processing — appropriate technical and organisational measures | |
| Art.32(1)(a) | Security measures — pseudonymisation and encryption | |
| Art.32(1)(b) | Security measures — confidentiality, integrity, availability, resilience | AC-01 AC-02 AC-03 AC-05 AC-06 AC-07 AC-10 AC-11 AC-12 AC-17 AC-18 AC-19 AC-20 AU-05 AU-09 CM-01 CM-02 CM-03 CM-05 CM-06 CM-07 CP-01 CP-02 CP-08 IA-01 IA-02 IA-03 IA-04 IA-05 IA-06 MA-01 MA-02 MA-03 MA-04 MP-02 PE-01 PE-02 PE-03 PE-04 PE-05 PE-06 PE-08 PE-16 PE-17 PS-04 PS-05 SC-01 SC-02 SC-03 SC-05 SC-06 SC-07 SC-10 SC-15 SC-18 SC-23 SC-24 SI-01 SI-02 SI-03 SI-04 SI-07 SI-08 SI-11 |
| Art.32(1)(c) | Security measures — restore availability and access after incident | |
| Art.32(1)(d) | Security measures — regular testing and evaluation | |
| Art.32(2) | Security measures — risk assessment for appropriate level | |
| Art.32(4) | Security measures — personnel authorisation and confidentiality | |
| Art.33(1) | Notification of breach to supervisory authority — 72 hours | |
| Art.33(2) | Notification of breach — processor to controller notification | |
| Art.33(3) | Notification of breach — content requirements | |
| Art.33(3)(a) | Breach notification content — nature of breach | |
| Art.33(3)(b) | Breach notification content — DPO contact details | |
| Art.33(3)(d) | Breach notification content — measures taken | |
| Art.33(4) | Breach notification — phased provision of information | |
| Art.33(5) | Breach notification — documentation requirement | |
| Art.34(1) | Communication of breach to data subject — high risk | |
| Art.34(2) | Breach communication to data subject — content | |
| Art.34(3) | Communication of breach to data subject — exceptions | |
| Art.35(1) | Data protection impact assessment — requirement | |
| Art.35(3) | DPIA — mandatory cases | |
| Art.35(7) | DPIA — minimum content | |
| Art.35(7)(a) | DPIA content — systematic description of processing | |
| Art.35(7)(c) | DPIA content — risk assessment to data subjects | |
| Art.35(11) | DPIA — review when processing changes | |
| Art.36(1) | Prior consultation with supervisory authority | |
| Art.37(1) | Designation of the data protection officer | |
| Art.38(3) | Position of the DPO — independence and non-dismissal | |
| Art.39(1) | Tasks of the DPO | |
| Art.39(1)(b) | DPO tasks — monitoring compliance including training | |
| Art.44 | General principle for transfers to third countries | |
| Art.46(1) | Transfers subject to appropriate safeguards | |
| Art.46(2) | Appropriate safeguards — specific instruments for transfers | |
| Art.47(2)(n) | Binding corporate rules — training content | |
| Art.49(1) | Derogations for specific situations | |
| Rec.78 | Recital 78 — appropriate technical and organisational measures | |
| Rec.83 | Recital 83 — security measures including encryption |