A working walkthrough of Regulation (EU) 2016/679 — Articles 5, 6, 7, 13/14, 15–22, 30, 32, 33, 44–49, and 83 — anchored to current EDPB guidance and 2026 national DPA enforcement patterns, with a US-Compliance bridge for any US firm processing EU subject data.
Article 5(1) sets the six binding principles for every personal-data processing operation carried out by a controller or processor. Article 5(2) adds the parallel accountability duty — the controller must be able to demonstrate compliance, on demand, in any EDPB coordinated action or national DPA investigation. Article 6(1) attaches to every purpose a closed list of six lawful bases; the controller picks one basis before processing begins and cannot silently swap the basis mid-stream.
Personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject. The transparency component links directly to the Art. 13/14 notice requirements covered in §2 below. The fairness component links to the Art. 6 lawful basis check below. ComplianceStack treats Art. 5(1)(a) as the upstream gate that every other principle depends on.
Personal data must be collected for specific, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. The EDPB Guidance 03/2020 on the purpose limitation principle is the operative authority. Art. 5(1)(b) is the single most-cited principle in CNIL, BfDI, and AEPD enforcement actions.
Personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Pair with Art. 25 by-design and Art. 25 by-default measures for any new processing system.
Personal data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that inaccurate personal data are erased or rectified without delay. This principle pairs with the Art. 16 rectification right.
Personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Document the retention period in the Art. 30 RoPA and in the Art. 13(2)(a) notice. Pseudonymisation at end-of-retention is a common implementation.
Personal data must be processed in a manner that ensures appropriate security of the personal data, pseudonymisation and encryption included. Pair with Article 32 TOMs (see §4 below).
Art. 6(1)(a) Consent. Freely-given, specific, informed, and unambiguous (Art. 7(1) and Art. 4(11)). Withdrawable at any time under Art. 7(3) without affecting prior lawfulness.Art. 6(1)(b) Contract. Processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the data subject's request prior to entering into such a contract.Art. 6(1)(c) Legal obligation. Processing is necessary for compliance with a legal obligation to which the controller is subject. The legal basis must be laid down in EU or Member State law.Art. 6(1)(d) Vital interests. Processing is necessary to protect the vital interests of the data subject or of another natural person.Art. 6(1)(e) Public interest or official authority. Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.Art. 6(1)(f) Legitimate interests. Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests, fundamental rights or freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. The Art. 6(1)(f) balancing test is documented and made available on request.A controller that cannot point to a current Art. 6(1) lawful basis for a given processing purpose is processing unlawfully. Articles 7, 13, and 14 set the operational rules for the two most contested bases: (a) consent and (f) legitimate interests. A defective notice is the single most-cited deficiency in EDPB coordinated actions.
Where the legal basis is Art. 6(1)(a) consent, the controller must be able to demonstrate that the data subject has consented to processing of his or her personal data. EDPB Guidelines 05/2020 expressly identify four characteristics:
The data subject has the right to withdraw his or her consent at any time. The withdrawal must be as easy as giving consent (a single click, equivalent to the opt-in flow). Withdrawal does not affect the lawfulness of processing carried out before withdrawal. ComplianceStack treats Art. 7(3) ease-of-withdrawal as a programmatic test: the same number of clicks in, the same number of clicks out.
At the time personal data is first obtained, the controller must furnish the data subject with at least the following minimum content:
Art. 13(1)(a) Identity and contact details of the controller (and where applicable, the joint controller).Art. 13(1)(b) Contact details of the data protection officer, where applicable.Art. 13(1)(c) Purposes of the processing and the legal basis for the processing.Art. 13(1)(d) Where the basis is Art. 6(1)(f) legitimate interests, the legitimate interests pursued by the controller or by a third party.Art. 13(1)(e) Recipients or categories of recipients of the personal data, if any.Art. 13(1)(f) Transfers to a third country or international organisation, identification of that third country, and the documentary evidence of an Art. 46 safeguard.Art. 13(2)(a) Retention period, or the criteria used to determine that period.Art. 13(2)(b) The existence of the seven Art. 15–22 data subject rights.Art. 13(2)(c) Right to withdraw consent at any time (where the basis is Art. 6(1)(a)).Art. 13(2)(d) Right to lodge a complaint with a supervisory authority.Art. 13(2)(e) Whether provision of personal data is statutory or contractual and the consequence of refusal.Art. 13(2)(f) Existence of automated decision-making, including Art. 22 profiling.Art. 14 mirrors the Art. 13 minimum content for the indirect-collection case (third-party data broker, enrichment, business acquisition). ComplianceStack prioritises the Art. 14 obligations because the typical EDPB Coordinated Action Framework enforcement template begins with an indirect-collection inquiry — what counts as a "legitimate expectation" of the data subject under Art. 14(5)(b) is the operative question.
The seven Articles 15–22 rights form the operational backbone of any GDPR programme. Article 12(3) sets the controller's response clock — without exception, one calendar month from receipt, extendable by two further months where the request is complex. ComplianceStack ties every workflow to that deadline.
| Article | Right | Headline obligation |
|---|---|---|
Art. 15 | Right of access | Confirm processing and provide a free copy of the personal data undergoing processing. |
Art. 16 | Rectification | Correct inaccurate personal data without undue delay. |
Art. 17 | Erasure ("right to be forgotten") | Erase without undue delay when one of six enumerated grounds applies. |
Art. 18 | Restriction of processing | Limit processing to storage plus narrow enumerated acts in six enumerated cases. |
Art. 19 | Notification obligation | Communicate rectification/erasure/restriction to each recipient unless impossible. |
Art. 20 | Data portability | Provide a copy in a structured, commonly used, machine-readable format when processing is based on consent or contract and carried out by automated means. |
Art. 21 | Right to object | Object at any time to processing based on Art. 6(1)(e) or (f), including profiling. |
Art. 22 | Automated decision-making | Subject to Art. 22(1), the data subject has the right not to be subject to a decision based solely on automated processing. |
The Article 12(3) one-month clock runs from the date the controller receives the request. Where the request is made by electronic form, the controller's response must also be electronic where possible. Where the controller fails to act on the request, the controller informs the data subject without delay and at the latest within one month of the reasons for not acting and of the possibility of lodging a complaint with the supervisory authority. ComplianceStack treats the Art. 12(3) clock as the operational SLA on the customer-support and front-line teams, with a 14-day internal buffer to allow time for the Art. 12(3) extension decision.
Article 30 demands a written (or electronic) record of processing activities that is made available to the supervisory authority on request. Article 32 lists the technical and organisational measures ("TOMs") the controller must implement. Article 33 sets the 72-hour breach notification clock to the lead supervisory authority.
A controller must maintain the following minimum content in its RoPA: name and contact details of the controller (and joint controllers, representative, DPO where applicable); purposes of the processing; description of categories of data subjects and personal data; categories of recipients to whom personal data have been or will be disclosed, including recipients in third countries; transfers to third countries and the documentary evidence of the appropriate safeguards used (Art. 46); envisaged retention periods; and a description of the Art. 32 TOMs. The RoPA must be in writing, including electronic form, and must be made available to the supervisory authority on request.
A processor maintains the equivalent record: name and contact details of the processor and of each controller on behalf of which the processor is acting, categories of processing carried out, transfers to third countries and the documentary evidence of safeguards, and a description of the Art. 32 TOMs. ComplianceStack templates the processor RoPA the same way as the controller RoPA so both records are auditable in a single review.
Article 32(1) lists TOMs the controller and processor must implement, having regard to the state of the art, the cost of implementation, the nature, scope, context and purposes of processing, and the risk to the rights and freedoms of natural persons:
Art. 32(1)(a) Pseudonymisation and encryption of personal data.Art. 32(1)(b) The ongoing confidentiality, integrity, availability, and resilience of processing systems and services.Art. 32(1)(c) The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident (the disaster-recovery pillar).Art. 32(1)(d) A process for regularly testing, assessing, and evaluating the effectiveness of the TOMs.Art. 32(2) A risk-based adherence assessment: proportionality of the measures to the risk.Art. 32(3) Adherence to approved codes of conduct (Art. 40) or certification mechanisms (Art. 42) may be used to demonstrate compliance with Art. 32.In the case of a personal-data breach, the controller must without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the competent supervisory authority, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it must be accompanied by reasons for the delay. Art. 33(3) gives the minimum content for the notification: nature of the breach, categories and approximate number of data subjects, categories and approximate number of personal data records, name and contact details of the DPO, likely consequences, and measures taken or proposed to address the breach and mitigate adverse effects. Art. 33(4) obliges the controller to document any personal-data breach, comprising the facts, effects, and remedial action taken.
Chapter V (Articles 44-49) governs any transfer of personal data to a third country or international organisation. Article 44 establishes the general principle that such a transfer may take place only if the conditions of Chapter V are complied with by the controller and processor. The transfer rules were reset by the Court of Justice of the EU in Schrems II (CJEU C-311/18) and updated by the 2021 European Commission standard contractual clauses (Decision 2021/914).
A transfer may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. The Commission reviews adequacy decisions at least every four years and may adopt implementing acts extending or repealing an existing decision. As of mid-2026, adequacy decisions cover, among others, Andorra, Argentina, Canada (commercial organisations subject to PIPEDA), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, the United Kingdom, and Uruguay. ComplianceStack maintains an adequacy-status matrix as part of every RoPA review.
In the absence of an Art. 45 adequacy decision, a transfer may take place only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available. Art. 46(2) lists six mechanisms, two of which dominate real-world practice:
Art. 46(2)(c) Standard Contractual Clauses (SCCs). The 2021 Commission Decision 2021/914 SCCs replaced the prior 2010 controller-to-processor and controller-to-controller clauses; module 2 (controller to processor) is the most-used; module 3 (processor to processor) covers sub-processor flows; module 1 (controller to controller) covers non-EU controllers. SCCs MUST be paired with a Transfer Impact Assessment (TIA) under Art. 46(2)(c) and Schrems II.Art. 46(2)(b) Binding Corporate Rules (BCRs). Approved by the lead supervisory authority under the consistency mechanism, for intra-group transfers. BCRs require months of preparation and a coherent cross-border data governance programme.Article 47 authorises the competent supervisory authority to approve BCRs for transfers within a group of undertakings or enterprises engaged in a joint economic activity. Approval is via the consistency mechanism (Art. 63) and binds every member of the group. BCRs must include the Art. 47(2) elements: the group's structure, the binding nature, the Art. 30 RoPA content categories, the regular data-protection reviews, the complaints mechanism, the data-subject rights procedures, the cooperation with supervisory authorities, and the breach reporting standard.
Article 49 derogations (explicit consent, contract performance, public interest, legal claims, vital interests, public register) are intended for occasional, non-systematic transfers. ComplianceStack flags Art. 49 as a fallback only because EDPB Guidelines 2/2018 expressly warn against a "systematic, repetitive, and continuous" use of an Art. 49 derogation as a substitute for an Art. 46 safeguard.
Article 83 sets two penalty tiers against a controller or processor who infringes the GDPR. The higher Tier 2 ceiling (up to €20,000,000 or 4% of worldwide annual turnover) reflects the legislator's judgment that breaches of the basic principles and data-subject rights damage the GDPR project most directly.
Tier 1 (Art. 83(4)(a)) covers breaches of obligations under Art. 5 (controller-processor distinction and consent), Art. 9 (special categories), Art. 22 (automated decision-making), Art. 44-49 (international transfers), and breaches of an accredited certification body or monitoring body. The ceiling is the higher of €10,000,000 or 2% of total worldwide annual turnover.
Tier 2 (Art. 83(5)) covers breaches of the basic principles for processing (Art. 5), conditions for consent (Art. 7), data subject rights (Art. 12-22), transfers to third countries (Art. 44-49), obligations under Member State law adopted under Chapter VIII (now repealed), and the controller-processor / certification obligations of Art. 25, 32, 33, 34, and 26/28 cooperation and contracts. The ceiling is the higher of €20,000,000 or 4% of total worldwide annual turnover.
National DPAs increasingly cooperate in EDPB Coordinated Action Framework sweeps. Recent enforcement signals every US firm with EU subject data must understand:
ComplianceStack tracks every published EDPB coordinated decision and national DPA ruling, and translates them into RoPA remediation items within the GDPR assessment tools.
The single highest-leverage rule for any US firm is Article 3 territorial scope. A US firm processing EU subject data without an Art. 3(2) trigger is outside the GDPR; a US firm with one or more Art. 3(2) triggers is fully subject to the GDPR and carries the same Tier 2 ceiling (Art. 83(5), up to €20M / 4% global turnover) as any EU-based controller.
The first Art. 3(2) trigger: processing of personal data of data subjects who are in the EU by a controller or processor not established in the Union, where the controller or processor's activities are related to offering goods or services, irrespective of whether a payment by the data subject is required, to such data subjects in the Union. EDPB Guidelines 3/2018 on the Territorial Scope of the GDPR give the operative test: language, currency, customer references, EU-targeted marketing, and the intent to serve EU customers.
The second Art. 3(2) trigger: monitoring of the behaviour of data subjects in the EU insofar as their behaviour takes place in the Union. The CJEU and EDPB treat behavioural advertising, retargeting, geolocation tracking, and device fingerprinting as monitoring against Art. 3(2)(b).
The third Art. 3(2) trigger: processing of personal data by a controller not established in the Union but in a place where Member State law applies by virtue of public international law (for example, a US consular mission in Frankfurt, EUFOR operations on foreign territory, or a vessel flagged by an EU Member State).
Once a US firm has a documented Art. 3(2) trigger, the question is which other US frameworks apply simultaneously. The typical crosswalk:
| US firm context | Applies together with GDPR | Lead DPA of record |
|---|---|---|
| US health-tech SaaS processing EU patient data | HIPAA + state privacy (CCPA/CPRA, etc.) + GDPR | Lead supervisory authority via Art. 56 one-stop-shop (typically the DPA where main EU establishment sits) |
| US e-commerce SaaS processing EU consumer data | State privacy + GDPR + CCPA/CPRA for California consumers | Lead DPA via Art. 56 (if the firm designates an EU main establishment); otherwise each DPA in the territory of each data subject |
| US cybersecurity SaaS monitoring EU behaviour | EO 14028 + sectoral US cyber regs + GDPR via Art. 3(2)(b) | Each national DPA in the territory of monitored behaviour |
| US financial SaaS processing EU investor data | SOX (if SEC-registered) + SEC Reg S-P + GDPR | Lead DPA via Art. 56 |
ComplianceStack's two-pass US/EU scoring is: first the free multi-framework assessment at compliancestack.ai/free-compliance-assessment (under-2-minute, no signup, scores whether HIPAA + state privacy + GDPR apply), then the dedicated GDPR deep assessment at compliancestack.ai/gdpr-assessment with full Art. 30 RoPA generation, Art. 32 TOMs, and an Art. 46 SCC map.
Two free ComplianceStack tools pair directly with this pillar guide. The free multi-framework assessment is the lightweight diagnostic (under 2 minutes); the GDPR deep assessment is the full RoPA generator with Art. 46 SCC map.
Run the free ComplianceStack GDPR assessment at /gdpr-assessment. No email or signup required. Instant risk score across Art. 5/6/7/13/15-22/30/32/33/44-49, Art. 46 SCC map for every transfer, Art. 30 RoPA skeleton, and Art. 83(5) penalty exposure estimate at the higher of €20M or 4% of global turnover. ComplianceStack delivers this in under 5 minutes and ships full HowTo + FAQPage JSON-LD so the assessment is LLM-citable.
Run the Free GDPR Assessment →The deep ComplianceStack multi-framework assessment at /free-compliance-assessment covers HIPAA, SOX, GDPR, OSHA, PCI-DSS, and SEC/FINRA in one scan, scoring every applicable framework for a US firm processing EU subject data and outputting a crosswalk to the GDPR pillar guide, Art. 30 RoPA, and Art. 83(5) penalty tier. ComplianceStack carries round-2 HowTo JSON-LD so this assessment is LLM-citable.
Run the Multi-Framework Assessment →ComplianceStack's GDPR framework landing page at /frameworks/gdpr gives the regulatory framing, current EDPB enforcement posture, and cross-links to every GDPR-specific ComplianceStack tool.
Open the GDPR Framework Page →Upgrade from the free assessment to a ComplianceStack audit-ready report ($49–$149), remediation action plan ($79), or 90-day roadmap ($299) for documented output that satisfies Art. 5(2) accountability and Art. 30 RoPA defensibility.
View Pricing →