EU regulation · directly applicable Regulations / GDPR

GDPR: General Data Protection Regulation

The reference framework for data protection in the EU since 2018 — with a record of processing activities, a 72-hour breach-notification duty, comprehensive data-subject rights, and fines of up to 4% of global annual turnover.

What is GDPR

The oldest, but still central, building block of EU compliance.

Regulation (EU) 2016/679 (the "GDPR") regulates the processing of personal data uniformly across the EU and applies directly in all member states — to practically any organisation that processes the personal data of people in the EU, regardless of where it is based.

Central building blocks include the record of processing activities (ROPA, Art. 30), a data-protection impact assessment (DPIA, Art. 35) where processing is likely to result in high risk, comprehensive data-subject rights (including access, erasure, and data portability), and technical and organisational measures (TOMs, Art. 32).

Compared with NIS2, DORA, and the AI Act, the GDPR has been fully applicable since 2018 and is primarily refined through guidelines from the European Data Protection Board (EDPB) and national supervisory authorities (in Austria: the Datenschutzbehörde, DSB).

Timeline

Key deadlines

24.05.2016In force

GDPR enters into force

Regulation (EU) 2016/679 is published in the Official Journal; a two-year transition period follows before full applicability.

25.05.2018Applicable

GDPR fully applicable

Art. 99(2): the regulation's EU-wide application date — still in force today, with no further transition periods.

within 72hNotification duty

Notification of personal-data breaches

Art. 33(1): notification to the supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware of it".

ongoingFine framework

Up to €20 million or 4% of global annual turnover

Art. 83(5) (more severe infringements, incl. core principles, data-subject rights, international transfers); Art. 83(4) sets a lower framework of up to €10 million / 2% for other infringements, including certain notification-duty failures.

Core obligations

What the GDPR actually requires.

Record of processing activities (ROPA, Art. 30)

Documentation of all personal-data processing activities — purposes, categories, recipients, retention periods, references to TOMs.

Data-protection impact assessment (DPIA, Art. 35)

Where processing is likely to result in high risk to data subjects: a structured assessment of risk, necessity, and proportionality before processing begins.

Personal-data breach notification

Notification to the supervisory authority within 72 hours (Art. 33); where high risk exists, also notification to affected individuals (Art. 34).

Data-subject rights (DSAR)

Access, rectification, erasure, restriction, data portability, and objection — generally to be answered within one month (Art. 12(3)).

How ReportAct solves it

ROPA, DPIA, and DSAR — seamlessly linked to ISO 27001.

The ReportAct GDPR Framework Pack maintains a record of processing activities per Art. 30, supports data-protection impact assessments per Art. 35 with AI-assisted drafting, and provides a public DSAR inbox for data-subject requests (/dsar/[slug]).

The TOM assessment per Art. 32 is directly linked to the ISO/IEC 27001 control catalogue — technical and organisational measures don't need to be documented twice.

In the event of a notifiable personal-data breach, the sealed evidence chain provides proof of which measure was in force when — relevant for the 72-hour deadline and the documentation duty under Art. 33(5).

Product/positioning statement, not legal advice.

Primary sources

Read the originals

Regulation (EU) 2016/679 (GDPR), EUR-Lex https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
European Data Protection Board (EDPB) — Guidelines https://www.edpb.europa.eu/
Datenschutzbehörde (DSB) — Austrian national supervisory authority https://www.dsb.gv.at/

ReportAct is not a consultancy. This page does not constitute legal advice. The fine framework under Art. 83 is two-tiered: Art. 83(4) (up to €10 million / 2%) and Art. 83(5) (up to €20 million / 4%) apply to different kinds of infringements — which framework applies in a given case depends on the specific infringement. Our Terms of Service apply.

Next step

ROPA, DPIA, DSAR — sealed, not just claimed.

Start right away with your record of processing activities — including DSAR inbox and TOM assessment.