
The General Data Protection Regulation: A Section-by-Section Deep Dive into Regulation (EU) 2016/679
This course walks through Regulation (EU) 2016/679 in document order, from its legal foundations and recitals to its operative rules, enforcement system, and closing provisions. Learners will be able to interpret the GDPR's scope, principles, rights, organisational duties, transfer mechanisms, supervisory procedures, remedies, penalties, and rules for specific processing contexts.
The first lecture plays free — no account needed.
What you'll learn
- Students will be able to identify the GDPR's issuing institutions, legal status, objectives, and overall structure.
- Students will be able to relate the Regulation to fundamental rights, technological change, and the internal market.
- Students will be able to distinguish the GDPR's protection objective from its parallel objective of preserving the free movement of personal data.
- Students will be able to summarise why the Union selected a regulation rather than relying on continued national implementation of a directive.
- Students will be able to distinguish identifiable, pseudonymised, and anonymous information using the recital framework.
- Students will be able to assess whether consent is specific, informed, freely given, and expressed through a clear affirmative act.
- Students will be able to compare consent, contract, legal obligation, vital interests, public tasks, and legitimate interests as legal bases.
- Students will be able to apply the stated factors for evaluating whether further processing is compatible with an original purpose.
- Students will be able to identify the heightened concerns and principal derogations associated with sensitive data.
- Students will be able to describe how transparency requirements change when information is directed to children.
Prerequisites
- GDPR objectives
- Material and territorial scope
- Fundamental-rights foundation
- Processing principles
- Legal bases
- Consent
Course Content
16 modules · 6h 32m total
Why the European Union Adopted the GDPR
Regulation (EU) 2016/679 is a directly applicable legislative act issued by the European Parliament and the Council, but its opening recitals reveal the problems it was designed to solve. This module situates the document within Union law while tracing its fundamental-rights, technological, enforcement, and internal-market foundations.
From Identifiability to Lawful Processing
Whether information is personal data often turns on identifiability, context, and the means reasonably likely to be used. The recitals then connect those threshold questions to consent, pseudonymisation, processing principles, lawful bases, and the compatibility of new purposes.
Sensitive Data, Transparency, and the Architecture of Individual Rights
The GDPR intensifies protection when processing exposes highly sensitive aspects of a person while also demanding information that ordinary people can actually use. Its recitals map the full sequence of individual rights, from access and correction to objection, portability, erasure, and protection against automated decisions.
Accountability in Practice: Risk, Security, Breaches, and Governance
Compliance is not merely a claim; the controller must select, implement, document, and be able to demonstrate appropriate measures. These recitals build the GDPR's risk-based governance model and follow it through security incidents, impact assessments, data protection officers, codes, and certification.
International Transfers Without Diluting Union Protection
Personal data may cross borders, but the protection attached to it must not disappear at the Union's edge. The transfer recitals set out a layered system of adequacy decisions, safeguards, corporate rules, derogations, and limits on unsupported foreign disclosure demands.
Independent Supervision and the One-Stop-Shop System
Cross-border enforcement requires authorities that are independent at home yet capable of reaching common outcomes across the Union. These recitals introduce supervisory competence, lead-authority coordination, mutual assistance, consistency procedures, and the European Data Protection Board.
Remedies, Sanctions, and Context-Specific Reconciliation
Rights need complaints, courts, compensation, and penalties to become effective, yet data protection must also coexist with expression, research, employment, archives, and other social institutions. These recitals show how enforcement and contextual derogations fit within one protective framework.
From the Recitals to the Operative Core
The final recitals settle institutional powers, transition, subsidiarity, and legislative relationships before the binding articles begin. Articles 1–4 then turn the Regulation's foundations into operative objectives, scope rules, exclusions, and an essential vocabulary.
The Operative Principles, Transparency Duties, and Right of Access
Articles 5–15 convert the recital framework into enforceable requirements governing lawful processing, consent, sensitive data, communications, and access. The result is a connected system in which controllers must justify processing and give individuals usable visibility into it.
Individual Control and the Controller's Organisational Duties
The GDPR gives individuals tools to correct, remove, contain, move, or contest data processing, then places corresponding organisational responsibilities on those deciding how processing occurs. This module links rights under Articles 16–23 with design, joint control, representation, and processor contracting under Articles 24–28.
Operational Accountability: Records, Security, DPIAs, and DPOs
Articles 29–39 supply the operational machinery for controlled processing, auditability, secure systems, breach response, high-risk review, and independent compliance advice. The module follows a processing operation from authorised access through incident management and prior regulatory consultation.
Codes, Certification, and Structured Transfer Safeguards
The GDPR supplements direct regulatory duties with sector-specific codes and voluntary certification, but neither mechanism displaces legal responsibility. Articles 40–47 then show how approved instruments and binding corporate rules can also support lawful international transfers.
Transfer Exceptions and the Powers of Independent Authorities
When ordinary transfer mechanisms do not apply, Articles 48–50 impose narrow conditions rather than a general escape route. The text then turns to the authorities responsible for enforcing the entire framework, specifying their independence, competence, tasks, investigative tools, and corrective powers.
Cross-Border Enforcement and the Consistency Mechanism
A cross-border case may involve one lead authority, several concerned authorities, competing objections, joint investigations, and urgent threats to individual rights. Articles 60–67 establish the procedures that turn this complex network into coordinated decisions and, where necessary, binding Board resolution.
The European Data Protection Board, Remedies, Liability, and Fines
The GDPR's institutional apex is an independent Union body capable of issuing guidance, opinions, and binding dispute decisions. Articles 68–84 connect that governance structure to complaints, litigation, representation, compensation, joint liability, and two major tiers of administrative fines.
Special Processing Contexts and the GDPR's Final Legal Settlement
The closing chapters test how the general framework operates alongside expression, public access, employment, research, secrecy, and religious governance before settling delegated powers, repeal, review, and application. The binding clause and cited instruments then place the GDPR within the wider Union legal order, revealing how its rights, duties, institutions, and enforcement mechanisms form one directly applicable system.
Read the Textbook
Read every chapter for free, right here in your browser.
Why begin with recitals?
The full name of Regulation (EU) 2016/679 is Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). This module calls it the GDPR or the Regulation.
The material in this module is Recitals (1) to (25), introduced by "Whereas:". Recitals explain why the European Union adopted the GDPR: the rights at stake, the failures of the earlier legal framework, the growth of digital data flows, and the intended territorial reach. They are not the GDPR's operative Articles. Therefore, when a recital says natural persons should have control, this module keeps that language as should rather than converting it into a mandatory rule.
Study Flashcards
Key concepts from this course as flashcard pairs.
Why the European Union Adopted the GDPR
Recital (1): What is the starting proposition?
"The protection of natural persons in relation to the processing of personal data is a fundamental right."
Recital (4): Is data protection absolute?
No. It must be considered in relation to its function in society and balanced against other fundamental rights in accordance with proportionality.
Recital (7): What individual-centred objective is stated?
"Natural persons should have control of their own personal data." The recital uses should, not shall.
Recital (13): What is the internal-market rule?
Free movement of personal data within the Union must not be restricted or prohibited for reasons connected with protecting natural persons regarding processing.
Recital (15): What does technological neutrality mean here?
Protection should not depend on the techniques used; it addresses automated processing and qualifying manual filing-system processing.
Recital (18): What limits the household exemption?
The activity must be purely personal or household and thus have no connection to professional or commercial activity.
+2 more flashcards
From Identifiability to Lawful Processing
Identifiable natural person
Under Recital (26), assess all means reasonably likely to be used for direct or indirect identification, including singling out, costs, time, available technology, and technological developments.
Pseudonymisation
Pseudonymised data that can be attributed to a natural person through additional information should be considered information on an identifiable natural person.
Anonymous information
Information not relating to an identified or identifiable person, or anonymised so the data subject is not or no longer identifiable; Recital (26) says GDPR principles should not apply to it.
Consent
A clear affirmative act establishing a freely given, specific, informed and unambiguous indication of agreement. Silence, pre-ticked boxes, and inactivity should not constitute consent.
Freely given
Consent should not be regarded as freely given where the data subject lacks genuine or free choice or cannot refuse or withdraw without detriment.
Transparency
Information and communication should be easily accessible and easy to understand, using clear and plain language.
+3 more flashcards
Sensitive Data, Transparency, and the Architecture of Individual Rights
Special categories and photographs
Recital (51) says sensitive data merit specific protection. Photographs should not systematically be special-category data; they are biometric data only when processed through specific technical means allowing unique identification or authentication.
No compelled identification
Where processed data do not permit identification, the controller should not be obliged to acquire additional information solely to identify the person for GDPR compliance. It should not refuse additional information supplied to support rights.
Transparency
Information should be concise, easily accessible, easy to understand, and use clear and plain language; visualisation may be appropriate. Child-directed information should be understandable to a child.
Request response
Recital (59) says the controller should respond without undue delay and at the latest within one month, and give reasons when it does not intend to comply.
Access
Access enables a person to know about collected data and verify lawfulness. It includes, in particular, purposes, possible retention period, recipients, automatic-processing logic, and certain profiling consequences.
Erasure and restriction
Erasure may apply in Recital (65)'s listed circumstances but has listed lawful-retention limits. Restriction may involve making data unavailable or technically preventing further processing and change.
+2 more flashcards
Accountability in Practice: Risk, Security, Breaches, and Governance
Accountability in Recital (74)
The controller should implement appropriate and effective measures and be able to demonstrate compliance, considering nature, scope, context, purposes, and risk.
Objective risk evaluation
Recital (76): assess whether processing involves a risk or a high risk by reference to its nature, scope, context, and purposes.
Data protection by design and by default
Recital (78): the controller should adopt internal policies and implement measures meeting these principles; examples include minimisation and pseudonymisation as soon as possible.
DPIA
Recital (84): for processing likely to result in high risk, the controller should carry out a DPIA evaluating the origin, nature, particularity, and severity of risk.
Large-scale public monitoring
Recital (91): a DPIA is equally required for monitoring publicly accessible areas on a large scale, especially with optic-electronic devices.
Breach notification
Recital (85): notify without undue delay and, where feasible, no later than 72 hours after awareness, unless the breach is unlikely to result in a risk.
+3 more flashcards
International Transfers Without Diluting Union Protection
Transfer baseline
Recital (101): "the level of protection of natural persons ensured in the Union by this Regulation should not be undermined", including in cases of onward transfers.
Adequacy decision
Recital (103): the Commission may decide that a third country, territory, specified sector, or international organisation offers an adequate level of protection. Transfers may then take place without further authorisation.
Essential equivalence
Recital (104): "The third country should offer guarantees ensuring an adequate level of protection essentially equivalent to that ensured within the Union".
Appropriate safeguards
Recital (108): in the absence of adequacy, the controller or processor should take measures to compensate through appropriate safeguards for the data subject.
Binding corporate rules
Recital (110): approved rules usable by a group for transfers to organisations within the same group, provided they contain essential principles and enforceable rights.
Residual compelling legitimate interests
Recital (113): a possible route for not repetitive transfers concerning only a limited number of data subjects, and only in residual cases where no other transfer ground applies.
+2 more flashcards
Independent Supervision and the One-Stop-Shop System
Complete independence
Recital (117) treats supervisory authorities empowered to perform tasks and exercise powers with complete independence as essential to protecting natural persons.
Supervisory authority concerned
Under Recital (124), an authority may be concerned because an establishment is on its territory, residents there are substantially affected, or a complaint was lodged with it.
Lead authority
For the Recital (124) cross-border conditions, the authority for the main establishment or single establishment should act as lead authority.
One-stop-shop local case
Recital (127) allows a non-lead authority to handle a case confined to one Member State and its data subjects, after informing the lead authority without delay.
Mutual-assistance non-response
If no response is received within one month of receipt of the request, Recital (133) says the requesting authority may adopt a provisional measure.
Urgent provisional-measure limit
Recital (137): a specified period of validity which should not exceed three months.
+1 more flashcards
Remedies, Sanctions, and Context-Specific Reconciliation
Complaint right in Recital (141)
Every data subject should have the right to lodge a complaint with a single supervisory authority, particularly in the Member State of habitual residence.
Representative body conditions
It is not-for-profit, constituted under Member State law, has public-interest statutory objectives, and is active in personal-data protection.
Board annulment timing
A concerned supervisory authority has two months from notification. A directly and individually concerned controller, processor, or complainant has two months from publication on the Board website.
Compensation standard
Data subjects should receive full and effective compensation for the damage they have suffered.
Alternative to a fine
For a minor infringement, or where a likely fine is a disproportionate burden to a natural person, a reprimand may be issued instead of a fine.
Fine effectiveness formula
The fines imposed should be effective, proportionate and dissuasive.
+4 more flashcards
From the Recitals to the Operative Core
Personal data
Any information relating to an identified or identifiable natural person, called the data subject.
Processing
Any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means.
Controller
The person, authority, agency, or other body that alone or jointly with others determines the purposes and means of processing.
Processor
The person, authority, agency, or other body that processes personal data on behalf of the controller.
Pseudonymisation
Processing so data cannot be attributed to a specific data subject without additional information, provided that information is kept separately and protected by technical and organisational measures.
Cross-border processing
Either processing in the context of establishments in more than one Member State, or single-establishment processing that substantially affects or is likely substantially to affect data subjects in more than one Member State.
The Operative Principles, Transparency Duties, and Right of Access
Article 5(2): What is accountability?
The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 ('accountability').
Article 6(1): What is the lawfulness threshold?
Processing shall be lawful only if and to the extent that at least one of the following applies.
Article 7(3): What is the withdrawal usability rule?
It shall be as easy to withdraw as to give consent.
Article 8(1): What is the default child-consent age for direct information society services?
The processing of the personal data of a child shall be lawful where the child is at least 16 years old. A Member State lower age may not be below 13.
Article 12(3): What is the normal request deadline?
Without undue delay and in any event within one month of receipt of the request.
Article 14(3)(a): What is the general indirect-collection deadline?
Within a reasonable period after obtaining the personal data, but at the latest within one month.
+1 more flashcards
Individual Control and the Controller's Organisational Duties
Article 16: What can the data subject obtain?
Without undue delay, **the rectification of inaccurate personal data concerning him or her.** Incomplete data may also be completed, including by a supplementary statement, taking account of processing purposes.
Article 17: When does the controller's erasure duty arise?
Where one Article 17(1) ground applies: no longer necessary, qualifying consent withdrawal, qualifying objection, unlawful processing, legal obligation, or specified Article 8(1) collection.
Article 18: Does restriction mean no processing whatsoever?
No. Storage is excepted. Other processing is limited to consent, legal claims, protection of another person's rights, or important Union or Member State public interest.
Article 20: What two conditions are required for portability?
Processing must be based on the specified consent or contract grounds, and it must be carried out by automated means. The data also concern the person and were provided by that person.
Article 21: What follows from an objection to direct marketing?
**Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.**
Article 22: Name the minimum safeguards in contract and explicit-consent cases.
At least human intervention by the controller, an opportunity to express a point of view, and an opportunity to contest the decision.
+2 more flashcards
Operational Accountability: Records, Security, DPIAs, and DPOs
Article 29 instruction rule
A processor and a person acting under controller or processor authority with access to personal data **"shall not process those data except on instructions from the controller"**, unless Union or Member State law requires it.
Article 30 controller record
Each controller and, where applicable, its representative **"shall maintain a record of processing activities under its responsibility."**
Article 30 small-organisation condition
The limitation concerns **"an enterprise or an organisation employing fewer than 250 persons"**, but does not apply where listed risk, non-occasional-processing, or sensitive/criminal-data conditions are present.
Article 32 security standard
Controllers and processors shall implement **"appropriate technical and organisational measures to ensure a level of security appropriate to the risk."**
Article 33 deadline
A controller notifies the authority **"without undue delay and, where feasible, not later than 72 hours after having become aware of it"**, unless the breach is unlikely to result in a risk.
Article 34 individual communication trigger
Where a breach is likely to result in high risk, **"the controller shall communicate the personal data breach to the data subject without undue delay."**
+3 more flashcards
Codes, Certification, and Structured Transfer Safeguards
Article 40(1): What is the stated purpose of codes?
They are "codes of conduct intended to contribute to the proper application of this Regulation".
Article 40(4): What must a code contain?
Mechanisms enabling the Article 41(1) body to carry out the mandatory monitoring of compliance.
Article 42(3): Is certification compulsory?
No. "The certification shall be voluntary and available via a process that is transparent."
How long can Article 42 certification last?
A maximum period of three years, renewable under the same conditions if requirements continue to be met.
How long can Article 43 accreditation last?
A maximum period of five years, renewable on the same conditions if Article 43 requirements are met.
Article 45: How often must adequacy review occur?
The implementing act must provide for a periodic review at least every four years.
+2 more flashcards
Transfer Exceptions and the Powers of Independent Authorities
Article 48 foreign order rule
A foreign judgment or administrative decision "may only be recognised or enforceable in any manner if based on an international agreement" in force between the requesting third country and the Union or a Member State.
Article 49 explicit-consent condition
The data subject has explicitly consented to the proposed transfer, after having been informed of the possible risks arising from the absence of adequacy and appropriate safeguards.
Residual Article 49 transfer
It is available only after Articles 45 and 46 and the listed Article 49 derogations cannot support the transfer; it must be non-repetitive, concern limited data subjects, and satisfy the other cumulative conditions.
Independence rule
Each supervisory authority shall act with complete independence. Its members shall neither seek nor take instructions from anybody.
Court boundary
Supervisory authorities shall not be competent to supervise processing operations of courts acting in their judicial capacity.
Two Article 58 corrective powers
An authority may impose a temporary or definitive limitation including a ban on processing, and may order suspension of data flows to a recipient in a third country or international organisation.
Cross-Border Enforcement and the Consistency Mechanism
Article 60 consensus duty
The lead supervisory authority shall cooperate with the other supervisory authorities concerned in accordance with this Article in an endeavour to reach consensus.
Article 60 objection deadline
A concerned authority may express a relevant and reasoned objection within a period of four weeks after having been consulted.
Revised Article 60 draft
Where the lead authority intends to follow an objection, the revised draft is subject to the Article 60(4) procedure within a period of two weeks.
Union-wide compliance
The controller or processor shall take necessary measures to ensure compliance across processing activities in the context of all its establishments in the Union.
Mutual-assistance deadline
A requested authority shall take all appropriate measures to reply without undue delay and no later than one month after receiving the request.
Article 62 participation right
Where the stated multi-establishment or substantial multi-state-impact conditions apply, a supervisory authority of each relevant Member State shall have the right to participate in joint operations.
+3 more flashcards
The European Data Protection Board, Remedies, Liability, and Fines
What is the Board's core Article 70 task?
The Board shall ensure the consistent application of this Regulation.
How does the Board ordinarily take decisions?
The Board shall take decisions by a simple majority of its members, unless otherwise provided for in the GDPR.
What majority is required for the Board's rules of procedure?
A two-thirds majority of its members.
What is the Article 78 information-inaction trigger?
The competent supervisory authority does not handle a complaint or does not inform the data subject within three months on the progress or outcome of the complaint.
What two kinds of damage can Article 82 compensate?
Material and non-material damage, where suffered as a result of an infringement of the GDPR.
What are Article 83's two undertaking turnover percentages?
Up to 2% for the Article 83(4) tier and up to 4% for the Article 83(5) and 83(6) tiers, in each case with the stated EUR maximum and whichever-is-higher rule.
Special Processing Contexts and the GDPR's Final Legal Settlement
Article 85(1): What must Member States do?
They shall by law reconcile personal-data protection under the GDPR with freedom of expression and information, including journalism and academic, artistic, or literary expression.
Article 88(2): What must employment rules include?
Suitable and specific measures to safeguard the data subject's human dignity, legitimate interests and fundamental rights.
Article 89(1): What is the safeguard baseline?
Processing shall be subject to appropriate safeguards for rights and freedoms, including technical and organisational measures for data minimisation.
Article 91(1): When may comprehensive church rules continue?
They may continue to apply provided that they are brought into line with the GDPR.
Article 92: What is the objection period?
Three months from notification of the delegated act, extendable by three months at Parliament's or the Council's initiative.
Article 94: What happened on 25 May 2018?
Directive 95/46/EC was repealed with effect from that date.
+2 more flashcards
More in Legal
See all →
Mastering the EU NIS2 Directive: From Legal Framework to Practical Compliance

Commission Implementing Regulation (EU) 2024/2690: Cybersecurity Measures and Significant-Incident Thresholds

EU:s AI-förordning artikel för artikel

Understanding the EU’s New Legislative Framework

Förstå EU:s allmänna produktsäkerhetsförordning (GPSR) i detalj
