Free Consultation
Home Regulations General Data Protection Regulation (2016/679)
Regulation

General Data Protection Regulation (2016/679)

European Union · EU / EEA · Law

This page is a plain-English summary written by us, not legal advice — the official text is linked above. Our catalogue was last reviewed 2026-08-15; that is a review of the whole catalogue, not an independent legal verification of this entry.

Authority
European Union
Jurisdiction
EU / EEA
Type
Law
Status
In force
Maximum penalty
Up to €20M or 4% of global annual turnover
Catalogue reviewed
2026-08-15
Official source checked
2026-08-24 — unchanged since our last read
Official text

Status

In force since 2018

Requirements (4)

Art. 22 mandatory

Automated individual decision-making

Individuals have the right not to be subject to solely-automated decisions with legal/significant effects; provide human review, the right to contest, and meaningful information about the logic.

When this failed: Solely-automated decision without safeguards
Art. 35 mandatory

Data Protection Impact Assessment

Carry out a DPIA where processing is likely to result in a high risk to individuals (typical for profiling/AI on personal data).

Art. 5 mandatory

Principles of processing

Lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and accountability.

When this failed: ChatGPT leaked other users’ data via a cache bug
Art. 13–15 mandatory

Transparency to data subjects

Inform individuals about the processing and, for automated decisions, the logic involved and expected consequences.

Dates that matter

Enforcement 2018-05-25 · in force

GDPR Art. 22 — safeguards for automated decisions

Solely-automated decisions with legal/significant effect require safeguards incl. human review.

Action: Provide a meaningful human-review and contest path; run a DPIA.

Get told when this changes

Our agents re-read the official source every few hours and republish this page when it moves. Leave an email and you will hear about it — only when something actually changed.

Double opt-in. One confirmation email, then nothing until this regulation moves. Unsubscribe in one click.

Compare it with another regulation

The same obligation themes side by side — what both demand, what only one does, and which deadline lands first.

Real incidents citing this regulation

Editorial cross-reference: these are the curated case studies whose prevention note names this regulation. It is not a finding of legal breach.

critical 2022

Clearview AI unlawful biometric scraping

Clearview AI

Unlawful processing

Prevention: Lawful basis + DPIA + biometric-use restrictions

major Art. 32 2023

Samsung engineers leaked code into ChatGPT

Samsung

Data leakage

Prevention: PII/secret redaction in the action path + acceptable-use policy

major Art. 5 · Art. 32 2023

ChatGPT leaked other users’ data via a cache bug

OpenAI

Data leakage

Prevention: Data isolation + DPIA + incident response

major Art. 22 2023

Solely-automated decision without safeguards

Various (GDPR fines)

Unlawful automated decision

Prevention: Art. 22 safeguards: meaningful human review + contest