AI Policy Wiki
Dashboard

General Data Protection Regulation (GDPR)

high confidence · updated 2026-08-02

EU's foundational data protection framework (Regulation 2016/679), effective May 2018. The primary law governing personal data processing in the EU/EEA and the benchmark for global privacy regulation.

The General Data Protection Regulation, Regulation (EU) 2016/679, is the European Union's framework for the protection of personal data. Adopted on 27 April 2016 and effective from 25 May 2018, it governs the processing of personal data of individuals in the EU and EEA and applies extraterritorially to processing of EU residents' data regardless of where the processor is located. Its full title is "Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data."

Scope and definitions

The regulation applies across the EU/EEA and reaches processors outside the bloc when they process the personal data of EU residents, giving it extraterritorial effect. It establishes a principles-based regime built on data minimization and purpose limitation, under which personal data must be adequate, relevant, and limited to what is necessary for the stated purpose.

A higher standard applies to special category data, which includes health, biometric, genetic, racial or ethnic, religious, political, and sexual-orientation data, addressed in Article 9.

Key provisions

Processing requires a lawful basis under Article 6, drawn from consent, contract, legal obligation, vital interests, public task, or legitimate interest. The regulation grants individuals rights of access, rectification, erasure (the "right to be forgotten"), data portability, objection, and restriction of processing, along with rights regarding automated decision-making under Article 22. Controllers must conduct Data Protection Impact Assessments (DPIAs) for high-risk processing, and Article 25 requires data protection by design and by default.

Obligations by actor

Controllers and processors are supervised by national data protection authorities (DPAs). For cross-border processing, a "one-stop shop" mechanism designates a lead supervisory authority. The DPAs most active in the AI context are the DPC (Ireland), the lead supervisor for most major US technology companies (Meta, Google, OpenAI, Apple, Microsoft) because their EU headquarters are located in Ireland; the CNIL (France), active in AI-specific guidance and enforcement; and the ICO (UK), which administers the UK GDPR post-Brexit, a regime that remains substantially equivalent.

Enforcement and penalties

For the most serious violations, penalties can reach €20M or 4% of global annual turnover, whichever is higher.

Application to AI

The GDPR's interaction with AI raises several recurring compliance questions. Personal data contained in training corpora requires a lawful basis, and reliance on the legitimate-interest and public-interest bases for this purpose is contested. Article 22, which creates rights against decisions based solely on automated processing that produce significant effects, has a contested application to large language models. In OQ v Land Hessen (SCHUFA Holding (Scoring), Case C-634/21, 2023), the Court of Justice held that a credit-scoring probability value used by a bank to inform a loan refusal is itself a decision based solely on automated processing, and set three cumulative conditions: a decision, based solely on automated processing including profiling, producing legal or similarly significant effects. Ana Beduschi applies those conditions across a six-level model of agentic autonomy and concludes that Article 22(1) is engaged at every level except full human control — including where an agent seeks human approval or consults a human before deciding — while arguing that the regulation's controller-processor allocation survives agentic deployment intact, since only natural or legal persons can be controllers (Data protection in the era of agentic artificial intelligence (Beduschi)). She notes that the Digital Omnibus proposed in November 2025 could expand the lawful grounds for automated decisions, particularly on contractual necessity, while leaving the definition of a decision "based solely on automated processing" to existing case law. The transparency requirements of Articles 13 and 14, together with DPIA obligations, drive demand for interpretable AI. On cross-border transfers, the Schrems II ruling (2020) invalidated the Privacy Shield framework, leaving Standard Contractual Clauses (SCCs) as the primary mechanism for EU-to-US transfers.

Relationships