← Frameworks / Privacy Regulation

EU General Data Protection Regulation (2016/679)

The EU's comprehensive data protection and privacy regulation. Establishes principles for lawful processing, data subject rights, controller and processor obligations, breach notification (72 hours), data protection by design and by default, and cross-border transfer safeguards. Applies to any organisation processing personal data of EU residents.

Clauses: 95
Avg Coverage: 36.7%
Publisher: European Union Version: 2016/679
Clause Title SP 800-53 Controls
Art.5(1)(a) Lawfulness, fairness and transparency
Art.5(1)(b) Purpose limitation
Art.5(1)(c) Data minimisation
Art.5(1)(d) Accuracy
Art.5(1)(e) Storage limitation
Art.5(1)(f) Integrity and confidentiality
Art.5(2) Accountability
Art.6(1) Lawfulness of processing — general
Art.6(1)(a) Lawfulness — consent as legal basis
Art.6(1)(b) Lawfulness — contractual necessity
Art.6(1)(c) Lawfulness — legal obligation
Art.6(1)(f) Lawfulness — legitimate interests
Art.6(4) Lawfulness — compatibility of further processing
Art.7(1) Conditions for consent — demonstrability
Art.7(2) Conditions for consent — distinguishable request
Art.7(3) Conditions for consent — right to withdraw
Art.8(1) Child's consent in relation to information society services
Art.9(1) Processing of special categories of personal data — prohibition
Art.9(2) Processing of special categories — exceptions
Art.12(1) Transparent information, communication and modalities — transparency
Art.12(2) Transparent information — facilitating exercise of data subject rights
Art.12(7) Transparent information — standardised icons
Art.13(1) Information to be provided where data collected from data subject
Art.13(2) Information to be provided — additional information for fair processing
Art.14(1) Information where data not obtained from data subject
Art.14(2) Information where data not obtained — additional details
Art.15(1) Right of access by the data subject
Art.15(3) Right of access — copy of data
Art.16 Right to rectification
Art.17(1) Right to erasure ('right to be forgotten')
Art.17(2) Right to erasure — notification to recipients
Art.18(1) Right to restriction of processing
Art.19 Notification obligation regarding rectification or erasure or restriction
Art.20(1) Right to data portability
Art.20(2) Right to data portability — direct transmission
Art.21(1) Right to object
Art.22(1) Automated individual decision-making, including profiling
Art.22(2) Automated decision-making — exceptions allowing automated processing
Art.22(3) Automated decision-making — safeguards
Art.22(4) Automated decision-making — special categories
Art.24(1) Responsibility of the controller — appropriate measures
Art.24(2) Responsibility of the controller — data protection policies
Art.25(1) Data protection by design
Art.25(2) Data protection by default
Art.28(1) Processor obligations — sufficient guarantees
Art.28(2) Processor obligations — sub-processor authorisation
Art.28(3) Processor obligations — binding contract terms
Art.28(3)(a) Processor contract — processing on documented instructions
Art.28(3)(b) Processor contract — confidentiality obligations
Art.28(3)(c) Processor contract — security measures per Art. 32
Art.28(3)(f) Processor contract — audit and inspection rights
Art.28(3)(g) Processor contract — data deletion/return after services end
Art.28(3)(h) Processor contract — compliance demonstration and audit cooperation
Art.28(4) Processor obligations — sub-processor contract obligations
Art.29 Processing under the authority of the controller or processor
Art.30(1) Records of processing activities — controller
Art.30(1)(g) Records of processing — security measures description
Art.30(2) Records of processing activities — processor
Art.30(2)(d) Records of processing — processor security measures description
Art.32(1) Security of processing — appropriate technical and organisational measures
Art.32(1)(a) Security measures — pseudonymisation and encryption
Art.32(1)(b) Security measures — confidentiality, integrity, availability, resilience
Art.32(1)(c) Security measures — restore availability and access after incident
Art.32(1)(d) Security measures — regular testing and evaluation
Art.32(2) Security measures — risk assessment for appropriate level
Art.32(4) Security measures — personnel authorisation and confidentiality
Art.33(1) Notification of breach to supervisory authority — 72 hours
Art.33(2) Notification of breach — processor to controller notification
Art.33(3) Notification of breach — content requirements
Art.33(3)(a) Breach notification content — nature of breach
Art.33(3)(b) Breach notification content — DPO contact details
Art.33(3)(d) Breach notification content — measures taken
Art.33(4) Breach notification — phased provision of information
Art.33(5) Breach notification — documentation requirement
Art.34(1) Communication of breach to data subject — high risk
Art.34(2) Breach communication to data subject — content
Art.34(3) Communication of breach to data subject — exceptions
Art.35(1) Data protection impact assessment — requirement
Art.35(3) DPIA — mandatory cases
Art.35(7) DPIA — minimum content
Art.35(7)(a) DPIA content — systematic description of processing
Art.35(7)(c) DPIA content — risk assessment to data subjects
Art.35(11) DPIA — review when processing changes
Art.36(1) Prior consultation with supervisory authority
Art.37(1) Designation of the data protection officer
Art.38(3) Position of the DPO — independence and non-dismissal
Art.39(1) Tasks of the DPO
Art.39(1)(b) DPO tasks — monitoring compliance including training
Art.44 General principle for transfers to third countries
Art.46(1) Transfers subject to appropriate safeguards
Art.46(2) Appropriate safeguards — specific instruments for transfers
Art.47(2)(n) Binding corporate rules — training content
Art.49(1) Derogations for specific situations
Rec.78 Recital 78 — appropriate technical and organisational measures
Rec.83 Recital 83 — security measures including encryption