EU Data Protection Law and the General Data Protection Regulation (GDPR)

A complete guide to the GDPR and Europe’s data protection framework, prepared by Prof. de la Torre (Santa Clara Law), covering key principles, rights, lawful bases, scope, and compliance obligations, with links to additional resources for further guidance.

EU Data Protection Law and the General Data Protection Regulation (GDPR)
ChatGPT generated from - Portrait of Dardanelles, Washinton D.C., between 1938 and 1948

Data Protection Law - A Distinct European Tradition

The General Data Protection Regulation (GDPR) is often described as Europe's privacy law. However, its text does not even mention the word "privacy." Why?

The GDPR is a data protection law, and data protection is a legal concept that is related to—but different from—the right to privacy.

Unlike many jurisdictions that primarily regulate informational privacy, the European approach places individuals at the center of technological development by regulating the processing of personal data, whether such data is private or not. This framework emphasizes accountability, transparency, lawful processing, and individual rights as essential safeguards in an increasingly digital society.


Privacy and data protection are not the same thing

Privacy protects individuals against unjustified intrusions into their private lives.

Traditionally, privacy law asks questions such as: Was information about someone's private life improperly disclosed? Was someone subjected to unwanted surveillance? Was there an unreasonable intrusion into personal autonomy?

Data protection law asks a different set of questions. Rather than focusing only on secrecy or confidentiality, it regulates how personal data may be collected, used, stored, shared, and deleted using computerized databased (or files that can easily be computerized), regardless of whether the information is private, public, confidential, or already widely available.

For example, a person's name, business email address, or publicly available social media profile may not be private information, yet they are still personal data subject to data protection law. The key question is not whether information is secret, but whether it relates to an identifiable individual and how organizations process it. 

Why Europe created data protection law

Modern data protection law emerged in Europe during the 1970s as governments began to recognize that computers fundamentally changed the risks associated with personal information.

In the wake of this technical development, european lawmakers concluded that privacy law was not enough to address the challenges posed by automated data processing, which made it possible to collect, combine, analyze, and retain vast amounts of information about individuals. Early data protection laws therefore sought to regulate the use of computers themselves by establishing rules governing how organizations process personal data and by granting enforceable rights to individuals. The first laws appeared in Germany and Sweden, followed by legislation across Europe and, in 1981, the Council of Europe's Convention 108—the first binding international treaty dedicated to data protection. See: Convention 108 Explained: The International Treaty That Shaped Modern Data Protection

As data protection law evolved, several European countries elevated it from ordinary legislation to constitutional status. Portugal's Constitution of 1976 is generally regarded as the first European constitution to recognize a right to data protection. Spain followed in 1978, and its Constitutional Court subsequently clarified that the right to data protection is separate and independent from the constitutional right to privacy. See: Constitutional Data Protection Law


Data Protection Law: A distinct legal right that originated in Europe in the 1970s as the “protection of individuals in the context of automated data processing.” It regulates how personal data is processed whether or not the information is private. In the EU, data protection and privacy are separate fundamental rights. Data protection laws now exist in many countries worldwide. The United States does not recognize an equivalent, as a distinct legal right separate from privacy.

One of the most significant milestone came with the adoption of the Charter of Fundamental Rights of the European Union (See: What is the Charter of Fundamental Rights?). The Charter recognizes:

  • Article 7: the right to respect for private and family life; and
  • Article 8: the separate fundamental right to the protection of personal data.

In sum, while privacy and data protection complement one another, they protect different interests and impose different legal obligations. 

What is the GDPR?

The General Data Protection Regulation (GDPR) is the principal legislative instrument through which the European Union implements and gives practical effect in the private sector to the constitutional right recognized in Article 8 of the Charter.

The Regulation establishes common rules governing the processing of personal data, creates enforceable rights for individuals, imposes accountability obligations on organizations, and empowers independent supervisory authorities to oversee compliance. It also builds upon decades of earlier European legislation and case law, including the 1995 Data Protection Directive and the jurisprudence of the Court of Justice of the European Union. 

To understand how the GDPR works, however, it is essential to first become familiar with the legal concepts on which it is built. Many of the provisions rely on specialized terminology and principles that form the foundation of European data protection law. Below I introduce these core concepts and provide links to more detailed articles exploring each in depth.

  • Article 29 WP: The Article 29 Working Party (WP29) was the EU’s independent advisory body that helped interpret and promote consistent application of European data protection law before being replaced by the EDPB under the GDPR in 2018. See: What Was the Article 29 Working Party?
  • Controller: Controllers are individuals or entities that, alone or in jointly with others, determine the purposes and the means of the processing of personal data.. For more see: What is a controller?
  • Co-Controller: Two or more natural or legal persons, public authorities, agencies, or other bodies that jointly determine the purposes and means of the processing of personal data. For more see: What are ‘joint controllers’ (a.k.a. ‘co-controllers’)?
  • Data Subject: The individual to whom the personal data relates. For more see: What is a data subject?
  • Personal Data: Any information relating to an identified or identifiable natural person (‘data subject’) NOTE: In the US we ofter refer to Personal Information (or PI) instead. For more see: What is ‘personal data’ under EU data protection law?
  • Processor: A processor is an individual or entity that process personal data on behalf of the controller. For more see: What is a processor?
  • Special Category of Data: Special category data is a category of sensitive personal data that receives enhanced protection under Article 9 of the GDPR because its misuse could pose significant risks to an individual's fundamental rights and freedoms.For more see: What is "Special Categories of Data" under the GDPR?

Who and What Does the GDPR Regulate?

Not every activity involving personal data is governed by the GDPR. There are two threshold questions to consider: First, does the processing fall within the GDPR's material scope? In other words, is the activity one that the Regulation actually governs? Second, does it fall within the GDPR's territorial scope?That is, does the Regulation apply to the organizations or processing activities involved? Only if the answer to both questions is yes do the substantive rules of the GDPR apply. 

The material scope of the GDPR is defined primarily by Article 2. As a general rule, the Regulation applies to the automated processing of personal data and to manual processing where the personal data forms part of, or is intended to form part of, a structured filing system. Certain activities—such as purely personal or household activities, some law enforcement activities, and certain national security functions—fall outside the GDPR's scope. 

The territorial scope of the GDPR is governed by Article 3. The Regulation applies not only to organizations established in the European Union (i.e. organizations that have an "establishment" in the European Union), but also, in many circumstances, to organizations outside the EU (because it offers goods or services to individuals located in the Union, or because it monitors their behavior while they are in the Union.) As a result, the GDPR has an extraterritorial reach that extends well beyond Europe's borders. 

The Principles of the GDPR

Once an organization determines that the GDPR applies, it must ensure that every processing activity complies with the data protection principles set out in Article 5. Although referred to as "principles," these are not merely aspirational guidelines or broad interpretive concepts as the term is often understood in U.S. law. Rather, they are binding legal obligations that controllers and processors must comply with. Failure to do so may result in significant administrative fines, regulatory enforcement, and civil liability..

The GDPR establishes seven core principleslawfulness, fairness and transparencypurpose limitationdata minimizationaccuracystorage limitationintegrity and confidentiality (security); and accountability.

For more see: What does “lawfulness, fairness and transparency” mean under the GDPR?; What does "Purpose Limitation" mean under the GDPR?; What is "Data Minimization" under the GDPR?; What is "Accuracy" under the GDPR?; What is "Storage Limitation" under the GDPR?; What is "Integrity and Confidentiality" under the GDPR?; and What is "Accountability" under the GDPR?

Rather than imposing isolated obligations, these principles provide the framework for interpreting and applying the GDPR's more detailed requirements. Organizations are expected not only to comply with them but also to be able to demonstrate that compliance.

Valid Purposes for Processing under the GDPR

Once a Controller determines that the GDPR applies and that a particular processing activity is lawful, it must identify a valid lawful basis under Article 6 before processing any personal data.

Unlike many legal systems, the GDPR does not presume that processing is permitted unless prohibited. Instead, processing is generally prohibited unless it falls within one of the lawful bases expressly recognized by the Regulation. If no lawful basis applies, the processing is unlawful and violates the principle of lawfulness, fairness, and transparency. 

The GDPR establishes six lawful bases for processing: consent; performance of a contract; compliance with a legal obligation; protection of vital interests; performance of a task carried out in the public interest or in the exercise of official authority; and legitimate interests. No lawful basis is inherently superior to another. The appropriate basis depends on the specific purpose of the processing, the relationship between the controller and the individual, and whether the processing is necessary to achieve the stated purpose.

For more see: What is "Consent" under the GDPR?What is "Contractual Necessity" under the GDPR?What is "Legal Obligation" under the GDPR?What is "Vital Interest" under the GDPR?What is "Public Task" under the GDPR?What are "Legitimate Interests" under the GDPR?

Processing special categories of personal data (sometimes referred to as "sensitive personal data") is subject to an additional layer of protection. Identifying a lawful basis under Article 6 is necessary but not sufficient. Controllers must also identify one of the limited exceptions set out in Article 9 of the GDPR that permits the processing of special categories of data, such as explicit consent, employment and social protection obligations, vital interests, substantial public interest, healthcare, scientific or historical research, or other specified circumstances. Unless both Article 6 and Article 9 are satisfied, the processing of special category data is prohibited under the GDPR.

See- Special Category of Data: Special category data is a category of sensitive personal data that receives enhanced protection under Article 9 of the GDPR because its misuse could pose significant risks to an individual's fundamental rights and freedoms.For more see: What is "Special Categories of Data" under the GDPR?

Controllers must identify and document the applicable lawful basis before processing begins and inform individuals of that basis through the required transparency notices. There is no standard form, however details sufficient to show that controllers properly considered which lawful basis applies to each processing purpose and justifications for the decision must be recorded. Failure to properly document the lawful basis is a breach of the principle of accountability.

Data Subject Rights

The GDPR does more than regulate how controllers and processors process personal data—it also grants individuals a comprehensive set of data subject rights designed to ensure they retain meaningful control over their personal information.

The GDPR establishes eight data subject rights. Together, they promote transparency, accountability, and individual control throughout the data processing lifecycle.

  • The Right to Be Informed: The right to be informed gives individuals the right to receive clear, transparent, and easily accessible information about how their personal data is collected and processed. This right reflects the GDPR's transparency principle and is primarily implemented through privacy notices. Controllers must explain, among other things, the purposes of the processing, the lawful basis relied upon, recipients of the data, applicable retention periods, and the rights available to data subjects. See also: What is the "Right to Be Informed" Under the GDPR?
  • The Right of Access: The right of access enables individuals to confirm whether a controller is processing their personal data and, where that is the case, to obtain a copy of the data together with information about the processing. This includes the purposes of the processing, categories of personal data, recipients, retention periods, transfers to third countries, the source of the data where applicable, and the existence of automated decision-making or profiling. See also: What is the "Right of Access" under the GDPR?
  • The Right to Rectification: The right to rectification allows individuals to require controllers to correct inaccurate personal data without undue delay. Where personal data is incomplete, individuals may also request that it be completed through the addition of supplementary information where appropriate. See also: What is the "Right to Rectification" under the GDPR?
  • The Right to Erasure: The right to erasure, commonly known as the right to be forgotten, permits individuals to request deletion of their personal data in specific circumstances, including where the data is no longer necessary, consent has been withdrawn, processing is unlawful, or the controller no longer has a valid lawful basis. The right is subject to several important exceptions, including where processing remains necessary to comply with legal obligations, perform tasks in the public interest, or establish, exercise, or defend legal claims. See also: What is the "Right to Erasure" (aka Right to be Forgotten) under the GDPR?
  • The Right to Restrict Processing: The right to restrict processing allows individuals to require controllers to temporarily suspend certain processing activities while retaining the personal data. Restriction is available in limited situations, including where the accuracy of the data is contested, the lawfulness of the processing is challenged, an objection is pending, or the data is required for legal claims. See also: What is the "Right to Restrict Processing" under the GDPR?
  • The Right to Data Portability: The right to data portability allows individuals to obtain personal data they have provided to a controller in a structured, commonly used, and machine-readable format and, where technically feasible, to transmit that data to another controller. This right applies only where processing is carried out by automated means and is based on consent or contractual necessity. See also: What is the "Right to Data Portability" under the GDPR?
  • The Right to Object: The right to object enables individuals to object to processing carried out on the basis of legitimate interests or public task. Upon receiving an objection, controllers must cease processing unless they can demonstrate compelling legitimate grounds that override the individual's rights and freedoms or establish that the processing is necessary for legal claims. Individuals also have an absolute right to object to processing for direct marketing purposes. See also: What is the "Right to Object" under the GDPR?
  • Rights Relating to Automated Decision-Making and Profiling: Article 22 grants individuals important safeguards against decisions based solely on automated processing, including profiling, where those decisions produce legal effects or similarly significant consequences. Subject to limited exceptions, individuals have the right not to be subject to such decisions and may request human intervention, express their views, and challenge the outcome. See also: What is the "Right to an Explanation" under the GDPR?

Lawful basis and data protection rights: The availability of certain data protection rights depends on the lawful basis relied upon for the processing.

Time Limits, Extensions, and Fees: The GDPR requires controllers to facilitate the exercise of data subject rights without undue delay and, in any event, within one month of receiving a valid request. The one-month period begins on the date the request is received and is calculated using calendar months. Where the corresponding date does not exist in the following month, the deadline falls on the last day of that month. If the deadline falls on a weekend or public holiday, controllers may respond on the next working day.

  • Extensions: Article 12(3) permits controllers to extend the response period by up to two additional months where a request is particularly complex or where an individual has submitted multiple requests. Controllers relying on an extension must notify the data subject within the initial one-month period, explain the reasons for the delay, and inform the individual of the revised response deadline.
  • Refusing to Act: Controllers may refuse to act on a request where it is manifestly unfounded or excessive, or where another limitation or exemption under the GDPR applies. When refusing to act, controllers must inform the individual without undue delay, explain the reasons for the refusal, advise the individual of the right to lodge a complaint with a supervisory authority, and inform them of their right to seek a judicial remedy.
  • Charging a Fee: As a general rule, controllers may not charge a fee for responding to a request to exercise data subject rights. An exception applies where a request is manifestly unfounded or excessive, in which case the controller may charge a reasonable fee reflecting the administrative costs of complying with the request. Alternatively, the controller may refuse to act on the request. Where a fee is charged, controllers are not required to process the request until the fee has been paid, and they must promptly inform the data subject of the reasons for the fee together with their rights to complain to a supervisory authority and seek judicial review.

Although the GDPR grants individuals extensive rights over their personal data, those rights are not absolute. Article 23 permits the European Union and Member States to restrict certain rights and controller obligations through legislative measures where doing so is necessary, proportionate, and respects the essence of the fundamental rights and freedoms.

Restrictions may be adopted only to safeguard important public interests, including national security, defense, public security, the prevention and prosecution of criminal offenses, judicial independence, public health, taxation, regulatory and supervisory functions, the rights and freedoms of others, and the enforcement of civil claims.

Legislative measures imposing restrictions must also include appropriate safeguards. Among other things, they should specify the purposes of the processing, the categories of personal data affected, the scope of the restriction, applicable security measures, retention periods, safeguards against misuse, and, where appropriate, the circumstances under which data subjects may be informed of the restriction.

Because Article 23 authorizes Member State-specific legislation, the scope of these restrictions may vary across the European Union. Controllers should therefore consider both the GDPR and any applicable national implementing laws when determining whether a particular data subject right may be limited in a given context.

For more information see:

Controller and processor obligations under the GDPR

The GDPR's compliance framework covers a broad range of organizational responsibilities:

Industry bodies may develop Codes of Conduct that provide practical guidance on applying the GDPR within a particular sector. Approved codes can help organizations demonstrate compliance. See: GDPR Codes of Conduct: What They Are And Why They Matter.

Organizations may obtain GDPR certifications to demonstrate that their products, services, or processing activities comply with recognized data protection standards. See: GDPR Certifications: Demonstrating Data Protection Compliance.


The GDPR not only grants individuals a wide range of privacy rights, but also imposes significant obligations on organizations that process personal data.

These responsibilities vary depending on whether the organization acts as a controller (the entity that determines why and how personal data is processed) or a processor (the entity that processes personal data on behalf of a controller).

Controllers bear primary responsibility for complying with the GDPR and must be able to demonstrate that compliance. Failure to do so may result in regulatory enforcement, administrative fines, corrective measures, or liability for damages.

Processors are also subject to a number of direct obligations under the GDPR, in addition to the contractual obligations they owe to controllers. A processor that fails to comply with the GDPR—or that processes personal data beyond or contrary to the controller's instructions—may itself be held liable and, in some cases, treated as a controller for the relevant processing activities.

Enforcement

Enforcement under the GDPR is designed to ensure that violations of data protection law result in consequences that are effective, proportionate, and dissuasive. Under Article 83, national supervisory authorities have the power to impose administrative fines either alongside or instead of other corrective measures available under Article 58, such as warnings, reprimands, orders to bring processing into compliance, or restrictions on processing. The GDPR does not provide for an automatic fine whenever an infringement occurs. Instead, supervisory authorities must assess the circumstances of each individual case, including the nature, gravity, and duration of the infringement, whether the conduct was intentional or negligent, the number of individuals affected, the harm suffered, and the controller's or processor's efforts to mitigate that harm.

The severity of enforcement also depends on the organisation's conduct and level of responsibility. Supervisory authorities may consider whether appropriate technical and organisational safeguards were in place, whether the organisation has committed previous infringements, how well it cooperated with the authority, and whether it promptly reported the infringement. Aggravating or mitigating circumstances, including financial benefits obtained from the violation, may also influence the amount of a fine. This approach gives supervisory authorities flexibility to distinguish between relatively minor compliance failures and serious or systematic violations while ensuring that penalties remain proportionate to the particular circumstances.

Article 83 establishes two principal tiers of maximum administrative fines. Certain infringements involving obligations imposed on controllers and processors may result in fines of up to €10 million or 2% of the undertaking's total worldwide annual turnover from the preceding financial year, whichever is higher. More serious infringements—including violations of the basic principles of processing, data subjects' rights, international data-transfer requirements, and failures to comply with supervisory-authority orders—may attract fines of up to €20 million or 4% of total worldwide annual turnover, whichever is higher.


The substantial potential penalties demonstrate that GDPR enforcement is intended not merely to punish past violations but also to encourage organizations to establish robust data-protection practices and deter future non-compliance.

Relevant Case Law

Case C-207/16 Ministerio Fiscal : This CJEU judgment in Case C-207/16 Ministerio Fiscal is part of the jurisprudence on the ePrivacy Directive, specifically Article 15 which broadly allows Member States to permit intrusions into the confidentiality of communications for certain specified reasons.