0% found this document useful (0 votes)
4 views21 pages

General Data Protection Regulation

The General Data Protection Regulation (GDPR) is the EU's primary data protection law effective since May 25, 2018, aimed at giving individuals control over their personal data and ensuring transparent handling by organizations. It applies to both automated and certain manual processing of personal data related to EU residents, regardless of the organization's location. Key principles include lawful processing, data minimization, and individuals' rights to access, rectify, and erase their data.

Uploaded by

Anjali
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views21 pages

General Data Protection Regulation

The General Data Protection Regulation (GDPR) is the EU's primary data protection law effective since May 25, 2018, aimed at giving individuals control over their personal data and ensuring transparent handling by organizations. It applies to both automated and certain manual processing of personal data related to EU residents, regardless of the organization's location. Key principles include lawful processing, data minimization, and individuals' rights to access, rectify, and erase their data.

Uploaded by

Anjali
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

General Data Protection Regulation (GDPR) – Comprehensive Explanation Guide

Introduction
The General Data Protection Regulation (GDPR) is the European Union’s principal data
protection law. It came into effect on 25 May 2018 and governs how organisations collect,
use, store, and protect personal data belonging to individuals within the European Union
(EU) and the European Economic Area (EEA).
It also applies to organisations outside the EU that offer goods or services to EU residents or
monitor their behaviour online.
Objectives
 To give individuals greater control over their personal information.
 To ensure organisations handle data transparently and securely.
 To harmonise data protection laws across EU member states.
Key Concepts

Term Meaning

Any information identifying a living individual (e.g., name, email, ID


Personal Data
number).

Processing Any action performed on data collection, storage, use, or deletion.

Data Controller The entity that decides how and why personal data is processed.

Data Processor The entity that processes data on behalf of a controller.

Data Subject The individual whose personal data is being processed.

Scope
GDPR applies to automated (digital) and certain manual processing of personal data related
to EU/EEA individuals.
It affects businesses, educational institutions, governments, and non-profits—regardless of
where they are located—if they handle EU data.

Article 1 – Subject-Matter and Objectives


This Regulation lays down rules relating to the protection of natural persons regarding the
processing of personal data and rules relating to the free movement of such data.
Explanation:
Article 1 sets the foundation of the GDPR. It defines its purpose:
1. To protect individuals’ fundamental rights and freedoms, especially their right to
privacy.
2. To ensure the free flow of personal data within the EU without restrictions between
member states.
Key Points
 GDPR protects people, not companies.
 The law balances privacy with the free movement of data to support commerce.

Article 2 – Material Scope


Applies to the processing of personal data wholly or partly by automated means and to
manual processing forming part of a filing system.
Explanation:
Article 2 explains where the Regulation applies.
It covers both automated processing (e.g., databases, apps) and manual records if
organised systematically (e.g., paper student files). Private or purely personal household
activities—like keeping personal contacts—are excluded.
Key Points
 Business, academic, and government data processing is covered.
 Family or personal activities are excluded.
 Manual files count only if structured for easy access.

Article 3 – Territorial Scope


Applies to controllers or processors in the EU, and also outside the EU if they process data of
EU residents for offering goods/services or monitoring behaviour.
Explanation:
Article 3 gives the GDPR extra-territorial reach.

Even a company outside Europe must comply if it collects or analyses data from EU
individuals—for example, an Indian university enrolling EU student online.
Key Points
 Location of the company doesn’t matter; location of the data subject does.
 Applies to both online and offline activities involving EU residents.

Article 4 – Definitions
Provides definitions for key terms such as personal data, processing, controller, processor,
consent, and profiling.
Explanation:
Article 4 clarifies terminology used throughout the Regulation.
Each term has a precise legal meaning. For instance, “consent” must be freely given,
specific, informed, and unambiguous.
Key Points
 Understanding definitions is essential for compliance.
 Terms like “personal data breach,” “supervisory authority,” and “profiling” have
specific interpretations under the law.

Article 5 – Principles Relating to Processing of Personal Data


Personal data must be processed lawfully, fairly, and transparently; collected for specific
purposes; limited to what is necessary; accurate; stored no longer than necessary; and
secured.
Explanation:
Article 5 lists the core data protection principles that every organisation must follow.

Principle Description

Lawfulness, Fairness & Data must be processed openly and with a valid legal
Transparency basis.

Purpose Limitation Use data only for the specific purpose collected.

Data Minimisation Collect only what is needed.

Accuracy Keep information correct and updated.

Storage Limitation Delete data when no longer necessary.

Integrity & Confidentiality Keep it secure against unauthorised access.

Accountability Organisations must be able to prove compliance.


Example:
If an educational institution collects a student’s data for admission, it can’t later use that data
for marketing without new consent.
Article 6 – Lawfulness of Processing
Processing is lawful only if one of the following applies: consent, contract, legal obligation,
vital interests, public task, or legitimate interests pursued by the controller.
Explanation:
Article 6 explains the legal bases under which data can be processed. An organisation must
always have at least one lawful reason.
The six lawful bases are:
1. Consent – freely given, specific, informed, and unambiguous permission.
2. Contract – processing necessary to perform a contract (e.g., employee payroll).
3. Legal Obligation – required by law (e.g., tax filings).
4. Vital Interests – to protect someone’s life.
5. Public Task – carried out in public interest or under official authority.
6. Legitimate Interests – the organisation’s genuine business reason, provided it doesn’t
override individual rights.
Example:
A university uses student contact details to send exam schedules (contract basis), but must
obtain consent before sending marketing emails.

Article 7 – Conditions for Consent


Consent must be freely given, specific, informed, and unambiguous. Controllers must prove
consent and make withdrawal as easy as giving it.
Explanation:
Article 7 defines the conditions for valid consent.
 It must not be forced or hidden in terms and conditions.
 Individuals must be told exactly what they are agreeing to.
 They should be able to withdraw consent at any time without penalty.
 The controller must record proof of consent.
Example:
If someone ticks a box agreeing to receive newsletters, that’s valid consent — but pre-ticked
boxes or silence do not count.
Article 8 – Conditions Applicable to Children’s Consent
When offering online services directly to children, consent is valid only if given or authorised
by a parent when the child is below 16 (member states may lower to 13).
Explanation:
Children deserve extra protection.
Controllers must make reasonable efforts to verify parental consent where applicable.
Privacy notices should be written in clear, simple language that children can understand.
Example:
An online learning platform collecting data from 14-year-olds must ensure a parent or
guardian gives permission.

Article 9 – Processing of Special Categories of Personal Data


Processing of sensitive data (racial origin, politics, religion, health, sexual orientation, etc.) is
prohibited unless specific conditions apply.
Explanation:
This article bans processing of “special category” data unless one of the exceptions applies,
such as:
 Explicit consent
 Employment and social protection law requirements
 Vital interests
 Legitimate activities of a non-profit body
 Data made public by the subject
 Medical, public health, or research reasons
Example:
A hospital can process patients’ medical records for treatment without separate consent under
the “healthcare” exception.

Article 10 – Processing of Personal Data Relating to Criminal Convictions and Offences


Data about criminal offences may be processed only under government control or where
authorised by law.
Explanation:
This limits who can handle criminal data usually law enforcement or entities specifically
permitted by national law. Private employers, for instance, may process criminal records only
when legally allowed (e.g., background checks for security roles).

Article 11 – Processing That Does Not Require Identification


If the purposes do not require identification, controllers need not maintain or collect
identifying data.
Explanation:
Organisations shouldn’t collect more information than necessary.
If a purpose can be achieved anonymously, there’s no need to gather or keep identity details.
Example:
A website collecting anonymous survey data on user satisfaction doesn’t need names or
emails.

Article 12 – Transparent Information, Communication and Modalities


Controllers must provide information in a concise, transparent, intelligible, and easily
accessible form, using clear language.
Explanation:
Article 12 requires privacy notices and communications to be understandable to everyone.
Legal jargon or buried information violates transparency. Responses to individual requests
must be provided within one month.

Article 13 – Information to Be Provided Where Personal Data Are Collected from the
Data Subject
When collecting data directly, controllers must tell individuals:
 Who they are,
 Purpose and legal basis,
 Recipients, retention, rights, and complaint options.
Explanation:
This is the privacy notice requirement. It ensures people know what’s happening with their
data at the time of [Link] providing this information makes processing unlawful.
Example:
An online form collecting names and emails must include a privacy statement explaining how
the data will be used.
Article 14 – Information to Be Provided Where Personal Data Have Not Been Obtained
from the Data Subject
If data are obtained indirectly, individuals must still be informed within a reasonable time
(max one month).
Explanation:
When data come from third parties (like marketing lists), the controller must inform
individuals about data origin, purpose, and rights. Exceptions exist where providing the
notice is impossible or would require disproportionate effort.

Article 15 – Right of Access by the Data Subject


Individuals have the right to obtain confirmation whether their data are being processed and
access to that data.
Explanation:
This gives individuals the right to know and see the personal data an organisation holds
about them.
Controllers must provide a copy of the data and explain how it’s being used.
Requests must be free of charge (except in rare cases of excessive requests).
Example:
An employee can request a copy of all HR records held about them, and the employer must
respond within one month.
Article 16 – Right to Rectification
Individuals have the right to have inaccurate personal data corrected and incomplete data
completed without undue delay.
Explanation:
If a person finds errors in the information an organisation holds, they can demand correction.
The organisation must act promptly and notify any third parties with whom the data were
shared.
Example:
A student notices their wrong date of birth in school records; the school must correct it
quickly.

Article 17 – Right to Erasure (“Right to be Forgotten”)


Individuals may request deletion of their personal data when it’s no longer needed, consent is
withdrawn, or processing is unlawful.
Explanation:
Article 17 lets people ask for their data to be erased. Controllers must comply unless retention
is required by law, public interest, or legal claims.
Example:
A user deletes their online account and asks the company to remove all related data—this
must be honoured unless legal obligations require retention.

Article 18 – Right to Restriction of Processing


Individuals may restrict processing if they contest accuracy, object to processing, or require
data for legal claims.
Explanation:
When restricted, the organisation can store data but not use it further except with consent or
for legal reasons.
Example:
An employee disputes an evaluation record; HR must freeze use of that data until the dispute
is resolved.

Article 19 – Notification Obligation Regarding Rectification or Erasure or Restriction


Controllers must inform recipients of any rectification, erasure, or restriction of personal data
unless impossible or disproportionate.
Explanation:
If data were shared with third parties, they too must be informed of corrections or deletions.
Transparency ensures consistency across systems.

Article 20 – Right to Data Portability


Individuals can receive their personal data in a structured, commonly used, machine-readable
format and transmit it to another controller.
Explanation:
This right enhances personal control and competition. It applies only to data processed by
automated means and based on consent or contract.
Example:
A customer can request their banking transaction history to move to another bank.
Article 21 – Right to Object
Individuals can object at any time to processing based on legitimate interests or public tasks,
and to direct marketing.
Explanation:
Upon objection, processing must stop unless compelling legitimate grounds override the
individual’s interests. For direct marketing, the objection is absolute.
Example:
A person opts out of promotional emails; the company must stop sending them.

Article 22 – Automated Individual Decision-Making, Including Profiling


Individuals have the right not to be subject to decisions based solely on automated processing
that significantly affect them.
Explanation:
This protects against harmful outcomes from AI or algorithms without human involvement
(e.g., automated job rejection). Exceptions exist if necessary for a contract or authorised by
law, with safeguards.

Article 23 – Restrictions
Member States may restrict certain rights and obligations for national security, defence, or
public interest purposes.
Explanation:
Governments can limit GDPR rights through laws when necessary for safety or justice but
must respect fundamental rights and proportionality.

Article 24 – Responsibility of the Controller


Controllers must implement appropriate technical and organisational measures to ensure and
demonstrate compliance.
Explanation:
Accountability is central. Controllers must not only follow GDPR but prove it through
documentation, policies, and regular review.
Example:
Maintaining a data protection policy and audit trail to show compliance.

Article 25 – Data Protection by Design and by Default


Controllers must integrate data protection into processing activities and systems from the start
and ensure only necessary data are processed by default.
Explanation:
Privacy should be built into every system (“privacy by design”) and settings should default to
the most privacy-friendly option (“privacy by default”).
Example:
A new mobile app limits data collection to what’s essential unless the user opts in for more
features.
Article 26 – Joint Controllers
When two or more organisations jointly determine how and why personal data are processed,
they become joint controllers.
They must transparently define their respective roles and responsibilities, especially
regarding how data subjects can exercise their rights.
A clear internal arrangement or contract should state who handles responses and
communications.
Example:
A university and an online testing company jointly collect student data; both are responsible
for ensuring GDPR compliance.
Article 27 – Representatives of Controllers or Processors Not Established in the Union
Non-EU companies subject to GDPR (because they process EU residents’ data) must appoint
a representative in the EU.
This representative acts as a contact point for data subjects and supervisory authorities.
Certain small or occasional processors may be exempt.
Article 28 – Processor
Controllers must use only processors who give sufficient guarantees to meet GDPR
requirements.
A data-processing agreement (DPA) is mandatory, describing subject-matter, duration,
purpose, type of data, and security measures.
Processors may act only on documented instructions from the controller.
Example: A payroll vendor processes employee data under a written DPA defining
confidentiality and deletion obligations.
Article 29 – Processing Under the Authority of the Controller or Processor
Employees or contractors who handle personal data must follow only the controller’s or
processor’s instructions.
They are prohibited from using data for personal purposes.
Article 30 – Records of Processing Activities
Both controllers and processors must maintain written (including electronic) records of
processing activities—listing purposes, categories of data, recipients, transfers, retention
periods, and security measures.
This record proves accountability and should be available to regulators on request.
Article 31 – Co-operation with the Supervisory Authority
Controllers and processors must co-operate with the supervisory authority (such as the ICO in
the UK or CNIL in France) when requested, by providing information or access needed for
investigations.
Article 32 – Security of Processing
Organisations must implement appropriate technical and organisational security measures
such as encryption, pseudonymisation, access controls, and regular testing.
Security measures should match the risk level—higher risk data (health, finance) needs
stronger protection.
Example:
Encrypting stored data and limiting access only to authorised staff.
Article 33 – Notification of a Personal Data Breach to the Supervisory Authority
When a personal-data breach occurs, the controller must notify the supervisory authority
within 72 hours of becoming aware, unless the breach is unlikely to risk individuals’ rights.
Notifications must describe the nature of the breach, affected data categories, consequences,
and remedial actions.
Processors must inform controllers without delay after discovering a breach.
Example:
If a laptop containing unencrypted student data is stolen, the organisation must report it
within 72 hours and document mitigation steps.

Article 34 – Communication of a Personal Data Breach to the Data Subject


When a breach is likely to result in high risk to individuals’ rights and freedoms, the
organisation must also inform the affected people without undue delay.
The communication should describe the nature of the breach, potential consequences, and
what measures are being taken to mitigate it.
If the data was encrypted or anonymised, notification to individuals may not be necessary.
Example:
If hackers steal users’ plain-text passwords, those users must be notified immediately.

Article 35 – Data Protection Impact Assessment (DPIA)


Controllers must perform a Data Protection Impact Assessment before undertaking
processing that could pose high risks to individuals such as large-scale profiling, biometric
data use, or monitoring public areas.
The DPIA identifies risks and sets mitigation measures. Supervisory authorities can issue lists
of operations requiring DPIAs.
Example:
A new facial-recognition system at an airport must undergo a DPIA before launch.

Article 36 – Prior Consultation


If a DPIA reveals high risk that cannot be mitigated, the controller must consult the
supervisory authority before starting the processing. The authority may give advice or
restrictions to ensure adequate protection.

Article 37 – Designation of the Data Protection Officer (DPO)


Certain organisations must appoint a Data Protection Officer, particularly when:
 Processing is by a public authority,
 Large-scale monitoring of individuals occurs, or
 Large-scale processing of special-category data takes place.
The DPO advises on compliance, monitors practices, and acts as a contact for authorities and
individuals.

Article 38 – Position of the Data Protection Officer


The DPO must operate independently and without conflict of interest.
They report directly to top management, must be provided adequate resources, and cannot be
dismissed for performing their duties.
Article 39 – Tasks of the Data Protection Officer
The DPO’s responsibilities include:
 Informing and advising the organisation on GDPR obligations.
 Monitoring compliance and internal audits.
 Providing advice on DPIAs.
 Co-operating with supervisory authorities.
 Acting as a contact point for individuals.

Article 40 – Codes of Conduct


Industry bodies may develop Codes of Conduct to help interpret GDPR for specific sectors
(education, healthcare, finance, etc.).
These codes require approval by the supervisory authority and may include monitoring
mechanisms.
Adhering to an approved code can demonstrate compliance.

Article 41 – Monitoring of Approved Codes of Conduct


Independent bodies accredited by supervisory authorities will monitor adherence to these
codes.
They ensure ongoing compliance and handle complaints from individuals or members.

Article 42 – Certification
GDPR encourages data protection certification mechanisms (seals, marks) to demonstrate
compliance.
Certification is voluntary but provides assurance to customers and partners that data
protection standards are met.
Example:
An ISO-like privacy certification showing that an organisation meets GDPR standards.

Article 43 – Certification Bodies


Certification bodies responsible for granting seals or marks must be accredited by supervisory
authorities.
They evaluate organisations objectively and revoke certification if non-compliance occurs.
Article 44 – General Principle for Transfers
Personal data can be transferred outside the EU/EEA only if the same level of protection
guaranteed by the GDPR is maintained.
This ensures that individuals’ data remains protected even when handled abroad.
Transfers must comply with the conditions set out in Articles 45–49.
Example:
An EU-based university sharing student data with an Indian partner must ensure adequate
safeguards are in place.

Article 45 – Transfers on the Basis of an Adequacy Decision


The European Commission can decide that a non-EU country provides an adequate level of
protection.
Transfers to those countries are allowed without further authorisation.
Examples of such jurisdictions include Japan, the UK, and Switzerland (as of current
adequacy decisions).

Article 46 – Transfers Subject to Appropriate Safeguards


When there’s no adequacy decision, transfers may still occur if the controller or processor
provides appropriate safeguards, such as:
 Standard Contractual Clauses (SCCs),
 Binding Corporate Rules (BCRs),
 Approved Codes of Conduct or Certifications,
 Legally binding agreements between public authorities.
These safeguards ensure enforceable rights and effective legal remedies for individuals.

Article 47 – Binding Corporate Rules (BCRs)


BCRs are internal company policies that allow multinational groups to transfer personal data
within their entities across borders while ensuring GDPR compliance.

They must be approved by supervisory authorities and legally binding on all members of the
group.
Example:
A multinational education group with campuses in Europe and Asia uses BCRs to transfer
staff and student data lawfully.

Article 48 – Transfers or Disclosures Not Authorised by Union Law


Requests for data from foreign governments or courts are only valid if based on
international agreements (e.g., mutual legal assistance treaties). Organisations must not
disclose data to third-country authorities unless legally permitted by the EU or member state
law.

Article 49 – Derogations for Specific Situations


In the absence of adequacy or safeguards, transfers are still allowed in limited cases, such as:
 Explicit consent from the individual,
 Contract performance,
 Important reasons of public interest,
 Legal claims,
 Protection of vital interests, or
 Transfers from public registers.
These are exceptions, not the rule, and should be used sparingly.

Article 50 – International Co-operation for the Protection of Personal Data


The EU and its supervisory authorities must co-operate with foreign regulators to ensure
effective enforcement of privacy rights globally.
This includes sharing information, supporting investigations, and promoting consistent global
standards
Article 51 – Supervisory Authority
Each EU Member State must establish at least one independent public authority to monitor
GDPR application — known as the Supervisory Authority (SA).
They ensure compliance, handle complaints, and enforce [Link]: the ICO (UK),
CNIL (France), BfDI (Germany).

Article 52 – Independence
Supervisory Authorities act with full independence, free from political or external influence.
Their members must be impartial and cannot be dismissed arbitrarily.

Article 53 – General Conditions for the Members of the Supervisory Authority


Members are appointed through transparent procedures, must have suitable qualifications,
and serve fixed terms. They must maintain secrecy regarding confidential information.

Article 54 – Rules on the Establishment of the Supervisory Authority


Each country defines the legal framework for its SA, covering structure, funding, and staff.
However, independence and adequate resources are mandatory requirements.

Article 55 – Competence
Supervisory Authorities handle cases in their own country. If processing is cross-border, the
lead authority (where the main establishment is located) takes the lead in coordination with
others.

Article 56 – Competence of the Lead Supervisory Authority


The lead authority oversees cross-border processing and acts as the main point of contact
for controllers or processors operating in multiple countries.

Article 57 – Tasks
Authorities’ main duties include:
 Monitoring and enforcing GDPR.
 Promoting awareness of data protection rights.
 Handling complaints.
 Conducting investigations and audits.
 Advising governments on legislative matters.

Article 58 – Powers
Supervisory Authorities can:
 Order controllers to comply with GDPR.
 Impose administrative fines.
 Conduct investigations, audits, and data access requests.
 Approve codes of conduct and certification bodies.

Article 59 – Activity Reports


Each authority must publish annual activity reports summarising investigations, penalties,
and progress.

Article 60 – Co-operation Between the Lead Supervisory Authority and Other


Authorities
Supervisory authorities must co-operate on cross-border cases to ensure consistent
enforcement.
They exchange relevant information and seek consensus on decisions.

Article 61 – Mutual Assistance


Authorities assist each other by sharing information and supporting enforcement actions
across borders.

Article 62 – Joint Operations


Two or more authorities may carry out joint investigations where cross-border processing
occurs.

Article 63 – Consistency Mechanism


A consistency mechanism ensures uniform application of GDPR across the EU.
The European Data Protection Board (EDPB) co-ordinates decisions among member
states.

Article 64 – Opinion of the Board


The EDPB may issue opinions on matters like draft codes of conduct, certification criteria, or
binding corporate rules.

Article 65 – Dispute Resolution by the Board


If supervisory authorities disagree, the EDPB resolves the dispute through binding decisions.

Article 66 – Urgency Procedure


In urgent cases (serious and immediate risks), an authority may act independently to protect
individuals, but must inform the Board and Commission.

Article 67–70 – Exchange of Information and the EDPB’s Role


The EDPB comprises representatives from each national authority and the European Data
Protection Supervisor.
It ensures consistent interpretation, advises the Commission, and promotes public awareness.

Articles 71–76 – EDPB Operations


These provisions define how the EDPB functions, its chair, voting, meetings, and reporting
obligations.

Article 77 – Right to Lodge a Complaint


Individuals may file complaints with their local supervisory authority if they believe their
data has been misused.

Article 78 – Right to Judicial Remedy Against a Supervisory Authority


If an individual disagrees with a supervisory authority’s decision, they may challenge it in
court.

Article 79 – Right to Judicial Remedy Against Controllers or Processors


Individuals can sue organisations directly if GDPR rights are violated.

Article 80 – Representation of Data Subjects


Non-profit bodies may represent individuals in complaints and court actions on data
protection matters.

Article 81 – Suspension of Proceedings


If similar proceedings occur in multiple member states, courts can coordinate or suspend
cases to avoid conflicts.

Article 82 – Right to Compensation and Liability


Anyone who suffers material or non-material damage from a GDPR violation can claim
compensation.
Controllers and processors share liability unless they prove they weren’t responsible.

Article 83 – General Conditions for Imposing Administrative Fines


Supervisory authorities can impose significant fines based on severity, intent, duration, and
co-operation shown.
Maximum penalties:
 Up to €10 million or 2% of annual global turnover for lesser infringements.
 Up to €20 million or 4% for serious breaches (like consent or data rights violations).

Article 84 – Penalties
Member states can establish additional penalties (criminal or administrative) for GDPR
breaches, consistent with EU law.

Article 85 – Processing and Freedom of Expression and Information


Member states must balance data protection with freedom of expression and journalism.
Media organisations may receive certain exemptions.

Article 86 – Processing and Public Access to Official Documents


Public authorities may disclose personal data in official documents if it aligns with
transparency laws and public interest.

Article 87 – National Identification Numbers


Countries may determine specific conditions for using identification numbers (like national
ID or tax numbers).

Article 88 – Employment Context


Member states can set additional rules for employee data, including recruitment, monitoring,
and HR records.

Article 89 – Archiving, Research, and Statistics


Processing for scientific, historical, or statistical purposes is allowed with safeguards like
anonymisation and data minimisation.

Article 90 – Obligations of Secrecy


Professionals bound by confidentiality (lawyers, doctors, journalists) may have special
exemptions respecting their obligations.

Article 91 – Existing Data Protection Rules in Churches and Religious Associations


Religious organisations with established data protection frameworks can continue using them
if consistent with GDPR
Article 92–94 – Delegated and Implementing Acts
These articles describe how the European Commission can adopt delegated acts to update or
refine technical aspects of GDPR.

Article 95 – Relationship with the ePrivacy Directive


GDPR does not affect the application of the ePrivacy Directive, which covers electronic
communications (cookies, marketing, etc.).

Article 96 – Relationship with Previously Concluded Agreements


Existing international data agreements remain valid if consistent with GDPR principles.

Article 97 – Commission Reports


The Commission must regularly review GDPR implementation and propose amendments if
necessary.

Article 98 – Review of Other Union Legal Acts


EU laws involving data processing may be reviewed to ensure alignment with GDPR.

Article 99 – Entry into Force and Application


GDPR entered into force on 25 May 2018 across the European Union and European
Economic Area, replacing the 1995 Data Protection Directive.

You might also like