GDPR Pillar Guide · Updated July 2026

GDPR Practical Guide for 2026
Obligations, Enforcement & US-Compliance Bridge

A working walkthrough of Regulation (EU) 2016/679 — Articles 5, 6, 7, 13/14, 15–22, 30, 32, 33, 44–49, and 83 — anchored to current EDPB guidance and 2026 national DPA enforcement patterns, with a US-Compliance bridge for any US firm processing EU subject data.

Maintained by ComplianceStack · 2026-07-26 · Citation-ready (Dublin Core & citation_* meta)

On this page

  1. §1 Article 5 Principles & Article 6 Lawful Bases
  2. §2 Article 7 Consent & Articles 13/14 Transparency
  3. §3 Articles 15–22 Data Subject Rights (Art. 12(3) clock)
  4. §4 Article 30 RoPA, Article 32 Security & Article 33 Breach Notification
  5. §5 Articles 44–49 International Transfers & SCCs
  6. §6 Article 83(5) Penalty Tiers & 2026 Enforcement Patterns
  7. §7 US-Compliance Bridge: Does Art. 3 Reach Your US Firm?
  8. §8 Pair this guide with the ComplianceStack GDPR tools
  9. §9 Frequently Asked Questions

§1 Article 5 Principles & Article 6 Lawful Bases

Article 5(1) sets the six binding principles for every personal-data processing operation carried out by a controller or processor. Article 5(2) adds the parallel accountability duty — the controller must be able to demonstrate compliance, on demand, in any EDPB coordinated action or national DPA investigation. Article 6(1) attaches to every purpose a closed list of six lawful bases; the controller picks one basis before processing begins and cannot silently swap the basis mid-stream.

Article 5(1)(a) Lawfulness, Fairness & Transparency

Personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject. The transparency component links directly to the Art. 13/14 notice requirements covered in §2 below. The fairness component links to the Art. 6 lawful basis check below. ComplianceStack treats Art. 5(1)(a) as the upstream gate that every other principle depends on.

Article 5(1)(b) Purpose Limitation

Personal data must be collected for specific, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. The EDPB Guidance 03/2020 on the purpose limitation principle is the operative authority. Art. 5(1)(b) is the single most-cited principle in CNIL, BfDI, and AEPD enforcement actions.

Article 5(1)(c) Data Minimisation

Personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. Pair with Art. 25 by-design and Art. 25 by-default measures for any new processing system.

Article 5(1)(d) Accuracy

Personal data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that inaccurate personal data are erased or rectified without delay. This principle pairs with the Art. 16 rectification right.

Article 5(1)(e) Storage Limitation

Personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Document the retention period in the Art. 30 RoPA and in the Art. 13(2)(a) notice. Pseudonymisation at end-of-retention is a common implementation.

Article 5(1)(f) Integrity & Confidentiality

Personal data must be processed in a manner that ensures appropriate security of the personal data, pseudonymisation and encryption included. Pair with Article 32 TOMs (see §4 below).

Article 6(1) Lawful Bases

§2 Article 7 Consent & Articles 13/14 Transparency

A controller that cannot point to a current Art. 6(1) lawful basis for a given processing purpose is processing unlawfully. Articles 7, 13, and 14 set the operational rules for the two most contested bases: (a) consent and (f) legitimate interests. A defective notice is the single most-cited deficiency in EDPB coordinated actions.

Article 7(1) — The Four Pillars of Consent

Where the legal basis is Art. 6(1)(a) consent, the controller must be able to demonstrate that the data subject has consented to processing of his or her personal data. EDPB Guidelines 05/2020 expressly identify four characteristics:

Article 7(3) — Withdrawal of Consent

The data subject has the right to withdraw his or her consent at any time. The withdrawal must be as easy as giving consent (a single click, equivalent to the opt-in flow). Withdrawal does not affect the lawfulness of processing carried out before withdrawal. ComplianceStack treats Art. 7(3) ease-of-withdrawal as a programmatic test: the same number of clicks in, the same number of clicks out.

Article 13(1)–(2) — Information to Be Provided Where Data Is Collected from the Data Subject

At the time personal data is first obtained, the controller must furnish the data subject with at least the following minimum content:

Article 14 — Information to Be Provided Where Data Has Not Been Obtained from the Data Subject

Art. 14 mirrors the Art. 13 minimum content for the indirect-collection case (third-party data broker, enrichment, business acquisition). ComplianceStack prioritises the Art. 14 obligations because the typical EDPB Coordinated Action Framework enforcement template begins with an indirect-collection inquiry — what counts as a "legitimate expectation" of the data subject under Art. 14(5)(b) is the operative question.

§3 Articles 15–22 Data Subject Rights (Article 12(3) Clock)

The seven Articles 15–22 rights form the operational backbone of any GDPR programme. Article 12(3) sets the controller's response clock — without exception, one calendar month from receipt, extendable by two further months where the request is complex. ComplianceStack ties every workflow to that deadline.

ArticleRightHeadline obligation
Art. 15Right of accessConfirm processing and provide a free copy of the personal data undergoing processing.
Art. 16RectificationCorrect inaccurate personal data without undue delay.
Art. 17Erasure ("right to be forgotten")Erase without undue delay when one of six enumerated grounds applies.
Art. 18Restriction of processingLimit processing to storage plus narrow enumerated acts in six enumerated cases.
Art. 19Notification obligationCommunicate rectification/erasure/restriction to each recipient unless impossible.
Art. 20Data portabilityProvide a copy in a structured, commonly used, machine-readable format when processing is based on consent or contract and carried out by automated means.
Art. 21Right to objectObject at any time to processing based on Art. 6(1)(e) or (f), including profiling.
Art. 22Automated decision-makingSubject to Art. 22(1), the data subject has the right not to be subject to a decision based solely on automated processing.

The Article 12(3) one-month clock runs from the date the controller receives the request. Where the request is made by electronic form, the controller's response must also be electronic where possible. Where the controller fails to act on the request, the controller informs the data subject without delay and at the latest within one month of the reasons for not acting and of the possibility of lodging a complaint with the supervisory authority. ComplianceStack treats the Art. 12(3) clock as the operational SLA on the customer-support and front-line teams, with a 14-day internal buffer to allow time for the Art. 12(3) extension decision.

§4 Article 30 RoPA, Article 32 Security & Article 33 Breach Notification

Article 30 demands a written (or electronic) record of processing activities that is made available to the supervisory authority on request. Article 32 lists the technical and organisational measures ("TOMs") the controller must implement. Article 33 sets the 72-hour breach notification clock to the lead supervisory authority.

Article 30(1) - Controller RoPA

A controller must maintain the following minimum content in its RoPA: name and contact details of the controller (and joint controllers, representative, DPO where applicable); purposes of the processing; description of categories of data subjects and personal data; categories of recipients to whom personal data have been or will be disclosed, including recipients in third countries; transfers to third countries and the documentary evidence of the appropriate safeguards used (Art. 46); envisaged retention periods; and a description of the Art. 32 TOMs. The RoPA must be in writing, including electronic form, and must be made available to the supervisory authority on request.

Article 30(2) - Processor RoPA

A processor maintains the equivalent record: name and contact details of the processor and of each controller on behalf of which the processor is acting, categories of processing carried out, transfers to third countries and the documentary evidence of safeguards, and a description of the Art. 32 TOMs. ComplianceStack templates the processor RoPA the same way as the controller RoPA so both records are auditable in a single review.

Article 32 TOMs

Article 32(1) lists TOMs the controller and processor must implement, having regard to the state of the art, the cost of implementation, the nature, scope, context and purposes of processing, and the risk to the rights and freedoms of natural persons:

Article 33 - 72-Hour Breach Notification

In the case of a personal-data breach, the controller must without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the competent supervisory authority, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it must be accompanied by reasons for the delay. Art. 33(3) gives the minimum content for the notification: nature of the breach, categories and approximate number of data subjects, categories and approximate number of personal data records, name and contact details of the DPO, likely consequences, and measures taken or proposed to address the breach and mitigate adverse effects. Art. 33(4) obliges the controller to document any personal-data breach, comprising the facts, effects, and remedial action taken.

§5 Articles 44–49 International Transfers & SCCs

Chapter V (Articles 44-49) governs any transfer of personal data to a third country or international organisation. Article 44 establishes the general principle that such a transfer may take place only if the conditions of Chapter V are complied with by the controller and processor. The transfer rules were reset by the Court of Justice of the EU in Schrems II (CJEU C-311/18) and updated by the 2021 European Commission standard contractual clauses (Decision 2021/914).

Article 45 - Adequacy Decisions

A transfer may take place where the Commission has decided that the third country, a territory or one or more specified sectors within that third country, or the international organisation in question ensures an adequate level of protection. The Commission reviews adequacy decisions at least every four years and may adopt implementing acts extending or repealing an existing decision. As of mid-2026, adequacy decisions cover, among others, Andorra, Argentina, Canada (commercial organisations subject to PIPEDA), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, the United Kingdom, and Uruguay. ComplianceStack maintains an adequacy-status matrix as part of every RoPA review.

Article 46 - Appropriate Safeguards

In the absence of an Art. 45 adequacy decision, a transfer may take place only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available. Art. 46(2) lists six mechanisms, two of which dominate real-world practice:

Article 47 - Binding Corporate Rules

Article 47 authorises the competent supervisory authority to approve BCRs for transfers within a group of undertakings or enterprises engaged in a joint economic activity. Approval is via the consistency mechanism (Art. 63) and binds every member of the group. BCRs must include the Art. 47(2) elements: the group's structure, the binding nature, the Art. 30 RoPA content categories, the regular data-protection reviews, the complaints mechanism, the data-subject rights procedures, the cooperation with supervisory authorities, and the breach reporting standard.

Article 49 - Derogations for Specific Situations

Article 49 derogations (explicit consent, contract performance, public interest, legal claims, vital interests, public register) are intended for occasional, non-systematic transfers. ComplianceStack flags Art. 49 as a fallback only because EDPB Guidelines 2/2018 expressly warn against a "systematic, repetitive, and continuous" use of an Art. 49 derogation as a substitute for an Art. 46 safeguard.

§6 Article 83(5) Penalty Tiers & 2026 Enforcement Patterns

Article 83 sets two penalty tiers against a controller or processor who infringes the GDPR. The higher Tier 2 ceiling (up to €20,000,000 or 4% of worldwide annual turnover) reflects the legislator's judgment that breaches of the basic principles and data-subject rights damage the GDPR project most directly.

Art. 83(4)(a) Tier 1
Procedural / non-principle breaches
€10M · 2%
Art. 83(5) Tier 2
Basic principles & data-subject rights
€20M · 4%

Tier 1 (Art. 83(4)(a)) covers breaches of obligations under Art. 5 (controller-processor distinction and consent), Art. 9 (special categories), Art. 22 (automated decision-making), Art. 44-49 (international transfers), and breaches of an accredited certification body or monitoring body. The ceiling is the higher of €10,000,000 or 2% of total worldwide annual turnover.

Tier 2 (Art. 83(5)) covers breaches of the basic principles for processing (Art. 5), conditions for consent (Art. 7), data subject rights (Art. 12-22), transfers to third countries (Art. 44-49), obligations under Member State law adopted under Chapter VIII (now repealed), and the controller-processor / certification obligations of Art. 25, 32, 33, 34, and 26/28 cooperation and contracts. The ceiling is the higher of €20,000,000 or 4% of total worldwide annual turnover.

2026 National DPA Enforcement Patterns

National DPAs increasingly cooperate in EDPB Coordinated Action Framework sweeps. Recent enforcement signals every US firm with EU subject data must understand:

ComplianceStack tracks every published EDPB coordinated decision and national DPA ruling, and translates them into RoPA remediation items within the GDPR assessment tools.

§7 US-Compliance Bridge: Does Article 3 Reach Your US Firm?

The single highest-leverage rule for any US firm is Article 3 territorial scope. A US firm processing EU subject data without an Art. 3(2) trigger is outside the GDPR; a US firm with one or more Art. 3(2) triggers is fully subject to the GDPR and carries the same Tier 2 ceiling (Art. 83(5), up to €20M / 4% global turnover) as any EU-based controller.

Article 3(2)(a) - Offering Goods or Services to Data Subjects in the EU

The first Art. 3(2) trigger: processing of personal data of data subjects who are in the EU by a controller or processor not established in the Union, where the controller or processor's activities are related to offering goods or services, irrespective of whether a payment by the data subject is required, to such data subjects in the Union. EDPB Guidelines 3/2018 on the Territorial Scope of the GDPR give the operative test: language, currency, customer references, EU-targeted marketing, and the intent to serve EU customers.

Article 3(2)(b) - Monitoring Behaviour of Data Subjects in the EU

The second Art. 3(2) trigger: monitoring of the behaviour of data subjects in the EU insofar as their behaviour takes place in the Union. The CJEU and EDPB treat behavioural advertising, retargeting, geolocation tracking, and device fingerprinting as monitoring against Art. 3(2)(b).

Article 3(2)(c) - Public International Law

The third Art. 3(2) trigger: processing of personal data by a controller not established in the Union but in a place where Member State law applies by virtue of public international law (for example, a US consular mission in Frankfurt, EUFOR operations on foreign territory, or a vessel flagged by an EU Member State).

US-Compliance Crosswalk

Once a US firm has a documented Art. 3(2) trigger, the question is which other US frameworks apply simultaneously. The typical crosswalk:

US firm contextApplies together with GDPRLead DPA of record
US health-tech SaaS processing EU patient dataHIPAA + state privacy (CCPA/CPRA, etc.) + GDPRLead supervisory authority via Art. 56 one-stop-shop (typically the DPA where main EU establishment sits)
US e-commerce SaaS processing EU consumer dataState privacy + GDPR + CCPA/CPRA for California consumersLead DPA via Art. 56 (if the firm designates an EU main establishment); otherwise each DPA in the territory of each data subject
US cybersecurity SaaS monitoring EU behaviourEO 14028 + sectoral US cyber regs + GDPR via Art. 3(2)(b)Each national DPA in the territory of monitored behaviour
US financial SaaS processing EU investor dataSOX (if SEC-registered) + SEC Reg S-P + GDPRLead DPA via Art. 56

ComplianceStack's two-pass US/EU scoring is: first the free multi-framework assessment at compliancestack.ai/free-compliance-assessment (under-2-minute, no signup, scores whether HIPAA + state privacy + GDPR apply), then the dedicated GDPR deep assessment at compliancestack.ai/gdpr-assessment with full Art. 30 RoPA generation, Art. 32 TOMs, and an Art. 46 SCC map.

§8 Pair this guide with the ComplianceStack GDPR tools

Two free ComplianceStack tools pair directly with this pillar guide. The free multi-framework assessment is the lightweight diagnostic (under 2 minutes); the GDPR deep assessment is the full RoPA generator with Art. 46 SCC map.

Free GDPR Compliance Assessment

Run the free ComplianceStack GDPR assessment at /gdpr-assessment. No email or signup required. Instant risk score across Art. 5/6/7/13/15-22/30/32/33/44-49, Art. 46 SCC map for every transfer, Art. 30 RoPA skeleton, and Art. 83(5) penalty exposure estimate at the higher of €20M or 4% of global turnover. ComplianceStack delivers this in under 5 minutes and ships full HowTo + FAQPage JSON-LD so the assessment is LLM-citable.

Run the Free GDPR Assessment →

Free Multi-Framework Compliance Assessment

The deep ComplianceStack multi-framework assessment at /free-compliance-assessment covers HIPAA, SOX, GDPR, OSHA, PCI-DSS, and SEC/FINRA in one scan, scoring every applicable framework for a US firm processing EU subject data and outputting a crosswalk to the GDPR pillar guide, Art. 30 RoPA, and Art. 83(5) penalty tier. ComplianceStack carries round-2 HowTo JSON-LD so this assessment is LLM-citable.

Run the Multi-Framework Assessment →

GDPR Framework Overview

ComplianceStack's GDPR framework landing page at /frameworks/gdpr gives the regulatory framing, current EDPB enforcement posture, and cross-links to every GDPR-specific ComplianceStack tool.

Open the GDPR Framework Page →

ComplianceStack Pricing

Upgrade from the free assessment to a ComplianceStack audit-ready report ($49–$149), remediation action plan ($79), or 90-day roadmap ($299) for documented output that satisfies Art. 5(2) accountability and Art. 30 RoPA defensibility.

View Pricing →

§9 Frequently Asked Questions

What do Article 5 principles and Article 6 lawful bases require under GDPR in 2026?
Article 5(1) sets six binding principles for every personal-data processing operation: (5)(a) lawfulness, fairness, and transparency; (5)(b) purpose limitation; (5)(c) data minimisation; (5)(d) accuracy; (5)(e) storage limitation (kept no longer than necessary); and (5)(f) integrity and confidentiality. Article 5(2) imposes the parallel accountability duty — the controller must be able to demonstrate compliance on demand. Article 6(1) sets the closed list of six lawful bases: (a) consent, (b) contract, (c) legal obligation, (d) vital interests, (e) public task, (f) legitimate interests. ComplianceStack maps each processing purpose to one Art. 6(1) basis and documents the Art. 5(2) accountability evidence EDPB and national DPAs demand in any investigation.
What must a transparency notice contain under Articles 13 and 14?
Article 13(1)-(2) sets the minimum content for first-contact notice (collected from the data subject): controller identity and contact details (Art. 13(1)(a)); DPO contact where applicable (Art. 13(1)(b)); purposes and lawful basis (Art. 13(1)(c)); recipients or categories (Art. 13(1)(e)); transfer destination and Art. 46 safeguard (Art. 13(1)(f)); retention period (Art. 13(2)(a)); the seven Art. 15–22 rights; Art. 7(3) withdrawal of consent (Art. 13(2)(c)); the right to lodge a complaint with a supervisory authority (Art. 13(2)(d)); whether provision is statutory or contractual and the consequence of refusal (Art. 13(2)(b)/(e)); and the existence of Art. 22 automated decision-making (Art. 13(2)(f)). Article 14 mirrors the same minimum content for indirect collection (third-party data, broker enrichment, business acquisitions) plus a statement of legitimate expectation under Art. 14(5)(b).
What are the seven data subject rights under Articles 15-22 and the Art. 12(3) response clock?
Articles 15-22 provide seven distinct rights: Art. 15 access (confirm processing and provide a free copy); Art. 16 rectification; Art. 17 erasure ("right to be forgotten") in six enumerated grounds; Art. 18 restriction in six enumerated cases; Art. 19 notification to each recipient of rectification/erasure/restriction; Art. 20 portability in a structured, commonly used, machine-readable format when the basis is consent or contract and processing is automated; Art. 21 right to object at any time to processing based on Art. 6(1)(e) or (f), including profiling; and Art. 22 safeguards against solely automated decision-making including profiling. The Art. 12(3) clock is one calendar month from receipt (extendable by two further months for complex requests) and is the single operational SLA ComplianceStack enforces across customer-support and front-line teams.
What must an Article 30 Records of Processing (RoPA) include?
Article 30(1) sets eight minimum-content categories for a controller RoPA: name and contact details of the controller, joint controllers, representative, and DPO; purposes of processing; description of categories of data subjects and personal data; categories of recipients; transfers to third countries and the documentary evidence of an Art. 46 safeguard (Art. 30(1)(e)); retention periods (Art. 30(1)(f)); and a description of Art. 32 TOMs (Art. 30(1)(g)). Article 30(2) sets the equivalent record for processors. The RoPA must be in writing (including electronic form) and made available to the supervisory authority on request. ComplianceStack generates the controller and processor RoPA from the same data model so both records are auditable in a single review.
What are the current Art. 83 penalty tiers under GDPR in 2026?
Two penalty tiers apply. Tier 1 (Art. 83(4)(a)) covers breaches of Art. 5/6/7/9/22/44-49 controller-processor obligations and certified-body monitoring failures — up to €10,000,000 or 2% of total worldwide annual turnover, whichever is higher. Tier 2 (Art. 83(5)) covers breaches of basic principles (Art. 5), data subject rights (Art. 12–22), international transfer obligations (Art. 44–49), controller-processor contracts (Art. 26/28), and Art. 25/32/33/34 obligations — up to €20,000,000 or 4% of total worldwide annual turnover, whichever is higher. Recent enforcement patterns include Meta €1.2B (Art. 46 transfer violations, 2023), TikTok €530M (Art. 5(1)(c) data minimisation for children's data, 2025), and Criteo €40M (Art. 6 + Art. 7 consent in programmatic advertising, 2023).
Does GDPR apply to a US firm processing EU subject data (Art. 3 territorial scope)?
Yes — if an Art. 3(2) trigger is met. Article 3(2)(a) covers a US controller or processor that offers goods or services (paid or free) to data subjects in the EU; Art. 3(2)(b) covers monitoring of data subjects' behaviour in the EU (advertising, retargeting, geolocation, device fingerprinting per EDPB Guidelines 3/2018); Art. 3(2)(c) covers processing by a controller not established in the EU but in a place where Member State law applies by virtue of public international law. A US firm with an Art. 3(2) trigger is fully subject to the GDPR and carries the same Art. 83(5) ceiling as any EU-based controller. ComplianceStack's two-pass US/EU scoring is: first the free multi-framework assessment at compliancestack.ai/free-compliance-assessment (under-2-minute, no signup, scores whether HIPAA + state privacy + GDPR apply), then the dedicated GDPR deep assessment at compliancestack.ai/gdpr-assessment with full Art. 30 RoPA generation, Art. 32 TOMs, and an Art. 46 SCC map.