Compare with different regulatory event:

Description

Adopted Regulation (EU) 2016/679 (GDPR) introducing data protection requirements

On 27 April 2016, the European Parliament and the Council adopted the General Data Protection Regulation (GDPR) which creates a comprehensive data protection regulation within the European Union. The GDPR introduces new obligations for organisations collecting, storing and processing data, as well as rights for data subjects. The GDPR provides six legal bases for the processing of personal data (user consent, contract, legal obligations, vital interests of the data subject, public interest and legitimate interest). It requires organisations collecting, storing and processing personal data to implement appropriate technical and organisational measures to protect the personal data of individuals against unlawful processing, loss, destruction or damage. Furthermore, organisations would be obliged to appoint a data protection officer to ensure that data controllers and processors comply with the requirements outlined in the regulation. Regarding data subject rights, chapter three of the GDPR outlines the rights, including among others the right to access to personal data, and rectification and erasure of personal data. Furthermore, the GDPR gives data subjects the right to access information about data processing, including the type of that that is processed and who has access to their data. Individuals also have the right to submit a complaint if they believe that their rights were violated. Regarding data breaches, the GDPR obliges organisations collecting, storing and processing data to notify the authorities in the case of data breaches within 72 hours after the incident and conduct an assessment of the data breach.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
supranational
Government Branch
legislature
Government Body
parliament

Complete timeline of this policy change

Hide details
2012-01-25
under deliberation

On 25 January 2012, the European Commission published its proposal for the General Data Protection …

2016-04-27
adopted

On 27 April 2016, the European Parliament and the Council adopted the General Data Protection Regu…

2018-05-25
in force

On 25 May 2018, the General Data Protection Regulation (GDPR) enters into force. The GDPR introduce…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data: identity: data collection
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: identity: storage (any form)
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: identity: data processing
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Recordkeeping requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
consumer data: location: data collection
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
consumer data: location: storage (any form)
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
consumer data: location: data processing
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Recordkeeping requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: genetic: data collection
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: genetic: storage (any form)
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: genetic: data processing
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Recordkeeping requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
TBR - Prohibition
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: health: data collection
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: health: storage (any form)
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: health: data processing
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Recordkeeping requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
TBR - Prohibition
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: biometric: data collection
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: biometric: storage (any form)
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: biometric: data processing
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
User right to withdraw consent
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Recordkeeping requirement
User right to information about third-parties, with which data has been shared
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
TBR - Prohibition
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: information pertaining to minors: data collection
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Customer age limit
User consent: Opt-in requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: information pertaining to minors: storage (any form)
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Customer age limit
User consent: Opt-in requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: information pertaining to minors: data processing
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Recordkeeping requirement
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
TBR - Prohibition
Complaint mechanism requirement
Local operations requirement
Customer age limit
User consent: Opt-in requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: ethnicity: data collection
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: ethnicity: storage (any form)
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: ethnicity: data processing
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Recordkeeping requirement
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
TBR - Prohibition
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: political orientation: data collection
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: political orientation: storage (any form)
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: political orientation: data processing
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Recordkeeping requirement
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
TBR - Prohibition
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: religious beliefs: data collection
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: religious beliefs: storage (any form)
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: religious beliefs: data processing
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Recordkeeping requirement
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Technical standard adherence
Regulator cooperation requirements
User right against automated decision making
TBR - Prohibition
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: sexual orientation: data collection
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: sexual orientation: storage (any form)
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Regulator cooperation requirements
User right against automated decision making
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: sexual orientation: data processing
Regulatory tool
User right to rectification of personal data
User consent: Other requirement
User right to deletion of personal data
User consent: Permit user opt-out
Preventive security requirement
User right to restriction of personal data processing
Responsive security requirement
Designation of responsible employee
Recordkeeping requirement
Purpose/processing limitation
Duty to appoint compliance officer
Private code of conduct requirement
User notification requirement
Regulator notification requirement
User consent: Opt-in requirement
Regulator cooperation requirements
User right against automated decision making
TBR - Prohibition
Complaint mechanism requirement
Local operations requirement
Sanctions
Restitution of damages
Suspension of business
Fine
Regulated subjects
1
personal data: information that is publicly available: data collection
Regulatory tool
User consent: Permit user opt-out
User right to restriction of personal data processing
Purpose/processing limitation
User notification requirement
User consent: Opt-in requirement
Complaint mechanism requirement
Sanctions
Regulated subjects
1
personal data: information that is publicly available: storage (any form)
Regulatory tool
User consent: Other requirement
User consent: Permit user opt-out
User right to restriction of personal data processing
Recordkeeping requirement
Purpose/processing limitation
User notification requirement
User consent: Opt-in requirement
Complaint mechanism requirement
Sanctions
Regulated subjects
1
personal data: information that is publicly available: data processing
Regulatory tool
User consent: Other requirement
User consent: Permit user opt-out
User right to restriction of personal data processing
Recordkeeping requirement
Purpose/processing limitation
User notification requirement
User consent: Opt-in requirement
Complaint mechanism requirement
Sanctions
Regulated subjects
1
personal data: financial or credit information: data collection
personal data: financial or credit information: storage (any form)
personal data: financial or credit information: data processing

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data: identity: data collection

personal data: identity: storage (any form)

personal data: identity: data processing

consumer data: location: data collection

consumer data: location: storage (any form)

consumer data: location: data processing

personal data: genetic: data collection

personal data: genetic: storage (any form)

personal data: genetic: data processing

personal data: health: data collection

personal data: health: storage (any form)

personal data: health: data processing

personal data: biometric: data collection

personal data: biometric: storage (any form)

personal data: biometric: data processing

personal data: information pertaining to minors: data collection

personal data: information pertaining to minors: storage (any form)

personal data: information pertaining to minors: data processing

personal data: ethnicity: data collection

personal data: ethnicity: storage (any form)

personal data: ethnicity: data processing

personal data: political orientation: data collection

personal data: political orientation: storage (any form)

personal data: political orientation: data processing

personal data: religious beliefs: data collection

personal data: religious beliefs: storage (any form)

personal data: religious beliefs: data processing

personal data: sexual orientation: data collection

personal data: sexual orientation: storage (any form)

personal data: sexual orientation: data processing

personal data: information that is publicly available: data collection

personal data: information that is publicly available: storage (any form)

personal data: information that is publicly available: data processing

personal data: financial or credit information: data collection

personal data: financial or credit information: storage (any form)

personal data: financial or credit information: data processing