General Data Protection Regulation (GDPR)

Data protection glossary · 1 minute read

The General Data Protection Regulation is the European regulation that governs the processing of personal data uniformly throughout the EU.

Application and significance

It has applied directly in all Member States since May 2018 and forms the basis for almost all of a company's data protection obligations, from information obligations and data subject rights to breach notification duties.

The GDPR is Regulation (EU) 2016/679. It comprises 99 articles and 173 recitals that assist with its interpretation.

Scope

The GDPR applies to processing in the context of the activities of an establishment in the EU, regardless of where the processing takes place. It covers providers without an establishment in the EU if they offer goods or services to people in the EU or monitor their behaviour (market location principle).

Numerous opening clauses allow supplementary national rules, in Germany above all in the BDSG.

Art. 2 GDPR
Material scope.
Art. 3 GDPR
Territorial scope, including the market location principle.
Art. 5 GDPR
Principles relating to the processing of personal data.
Art. 99 GDPR
Entry into force and application from 25 May 2018.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.