RegulationEuropean UnionGlobal

GDPR

European Parliament and Council of the EU · Version Regulation 2016/679 · Effective May 25, 2018

EU regulation governing personal data processing with global reach wherever EU residents' data is involved.

Overview

The General Data Protection Regulation, EU Regulation 2016/679, became enforceable on May 25, 2018. It applies to any organization that processes personal data of individuals located in the European Union, regardless of where the organization itself is established. The regulation introduces direct obligations for both data controllers, who determine the purposes and means of processing, and data processors, who process data on behalf of controllers. Personal data is broadly defined as any information relating to an identified or identifiable natural person.

Processing personal data requires one of six lawful bases: consent, contract performance, legal obligation, vital interests, public task, or legitimate interests. Consent must be freely given, specific, informed, and unambiguous. Legitimate interests requires a documented balancing test against the data subject's rights. The regulation grants eight rights to data subjects: the right to be informed, the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object, and rights related to automated decision-making. Organizations must respond to data subject requests within one calendar month. Penalties reach up to €20 million or 4% of global annual turnover for the preceding financial year, whichever is higher.

Who Needs This

Any organization outside the EU that processes data of EU residents in connection with offering goods or services

Organizations monitoring the behavior of EU residents

EU-established organizations processing any personal data as part of their activities

Processors and sub-processors handling EU personal data under contract with controllers

US companies with EU customers, EU employees, or EU website visitors whose data is tracked

Structure at a Glance

Data processing principles, lawful bases for processing, conditions for consent, and processing of special categories of data.

Transparency, right of access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making.

Data protection by design and default, records of processing, Data Protection Impact Assessments, Data Protection Officers, and security requirements.

Adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules, and derogations for specific situations.

Complaint rights, supervisory authority powers, and administrative penalties.

AI Prompt Recipes

Copy these prompts directly into Claude or any capable model. Replace the bracketed placeholders with your organization-specific details.

Data Protection Impact Assessment

Use this when a processing activity is likely to result in high risk to individuals.

You are a Data Protection Officer conducting a GDPR Article 35 Data Protection Impact Assessment. Processing activity: [DESCRIBE THE PROCESSING ACTIVITY]. Data categories involved: [LIST DATA TYPES]. Technology used: [DESCRIBE SYSTEMS AND VENDORS]. Number of data subjects: [ESTIMATE]. Provide: (1) a determination of whether a DPIA is mandatory for this activity and why, (2) a systematic description of the processing and its purposes, (3) an assessment of necessity and proportionality, (4) identification of risks to rights and freedoms of data subjects with likelihood and severity ratings, and (5) recommended measures to address each risk.

Lawful Basis Assessment

Use this to determine and document the correct lawful basis for a processing activity.

I need to determine the appropriate GDPR lawful basis for the following processing activity: [DESCRIBE PROCESSING ACTIVITY AND ITS PURPOSE]. The data being processed: [DESCRIBE DATA TYPES AND DATA SUBJECTS]. Analyze each of the six lawful bases — consent, contract, legal obligation, vital interests, public task, and legitimate interests — against this activity. For the basis you recommend: explain why it applies, what documentation is needed to rely on it, what obligations it triggers, and what alternatives we have if the primary basis is challenged. If legitimate interests applies, draft the legitimate interests assessment.

Data Subject Rights Response

Use this when responding to an access, erasure, or portability request.

I have received a GDPR data subject request from [DESCRIBE DATA SUBJECT AND THEIR RELATIONSHIP TO OUR ORGANIZATION]. The request type is: [ACCESS / ERASURE / PORTABILITY / RECTIFICATION / OBJECTION]. Date received: [DATE]. My organization's relevant processing activities: [DESCRIBE]. Draft: (1) an acknowledgment response to the data subject confirming receipt and timeline, (2) an internal checklist of all systems that must be queried to fulfill this request, (3) any lawful grounds for refusing or limiting the request if applicable, and (4) the final response to the data subject.

International Transfer Analysis

Use this when transferring personal data outside the EEA.

I need to assess a personal data transfer under GDPR Chapter V. Transfer details: data being transferred is [DESCRIBE DATA TYPES], sent from [EEA COUNTRY] to [DESTINATION COUNTRY / ORGANIZATION]. Purpose: [DESCRIBE]. Current transfer mechanism: [DESCRIBE OR STATE NONE]. Analyze: (1) whether an adequacy decision covers this transfer, (2) whether Standard Contractual Clauses are appropriate and which module applies, (3) the transfer impact assessment requirements based on the destination country's laws, and (4) supplementary technical measures that may be needed to ensure equivalent protection.

Common Pitfalls

These are the mistakes practitioners see repeatedly in real assessments and implementation projects.

1

Consent obtained through a pre-ticked box or bundled with terms of service. GDPR consent must be a clear affirmative action. Bundled consent is invalid. Each distinct processing purpose requires separate consent.

2

Breach notification timeline misunderstood. The 72-hour clock to notify the supervisory authority starts from when the controller becomes aware, not when the breach occurs. Controllers must notify even if they do not yet have complete information.

3

Data processor agreements that do not include all required Article 28 clauses. Regulators have issued fines specifically for incomplete processor agreements. The clauses are enumerated and non-negotiable.

4

Legitimate interests basis used without a documented balancing test. The legitimate interests basis requires a three-part assessment: the interest must be legitimate, processing must be necessary, and the interest must not be overridden by the data subject's rights. Skipping the documentation creates enforcement exposure.

5

Records of Processing Activities treated as a one-time exercise. Article 30 records must be kept up to date. Every new processing activity, new vendor, or changed retention period must be reflected in the RoPA.

Cross-Framework Mapping

DPDPA

India's DPDPA 2023 was influenced by GDPR. Both require consent for processing, establish data subject rights, and require breach notification. Key differences include DPDPA's approach to data localization and its narrower definition of personal data.

ISO 27001

ISO 27001 A.5.34 addresses privacy and protection of personal data. Certified organizations have a technical foundation but GDPR compliance requires additional legal and operational programs beyond information security.

SOC 2

The SOC 2 Privacy criterion covers similar ground to GDPR's data subject rights and data handling requirements. SOC 2 Privacy reports are accepted by some EU organizations as partial evidence of privacy controls.

All content sourced from official issuing body documentation.

Official source ↗

Regulation

GDPR