GDPRFree Resource

EU GDPR Scope, Roles, Rights, and Transfers

Start with one use of : confirm whether the GDPR applies, identify who decides its purposes and means, record the lawful basis, and then connect that activity to transparency, rights, security, risk, supplier, and transfer duties.

By Sorena AIUpdated 2026No signup required
Quick scan
GDPR
Processing inventory
Start from Article 30-style records: purposes, categories of data subjects and , recipients, retention periods, transfer destinations, and security measures. If an organisation has fewer than 250 staff, record whether Article 30(5)'s limited exception actually applies; it does not cover non-occasional processing, processing likely to create risk, or processing that includes Article 9 or Article 10 data.
Operational controls
For each processing activity, connect the lawful basis to privacy notices, consent or legitimate-interest evidence, rights intake, contracts, access controls, and triggers.
Regulator-ready evidence
Keep signed role decisions, Article 28 terms, DSAR logs, breach assessments, DPIAs, transfer assessments, SCC modules, and remediation records together.

Follow the recommended path below: scope one processing activity, assign its roles, choose and record the lawful basis, then connect notices, rights, Article 30 records, processors, security, , breach, retention, and transfer evidence.

Key dates
Art. 2-3
Scope
Art. 6
Lawful basis
72h
Breach notice
Art. 83
Fines
GDPR questions this hub helps resolve
Scope and roles
Check whether is processed in an activity covered by Article 2 and whether Article 3 connects it to the EU. Then name the , any joint controllers, processors, recipients, EU representative, and authority touchpoints for that activity, not for the organisation in the abstract.
Lawful basis and rights
Tie each purpose to an Article 6 lawful basis. If Article 9 special-category or Article 10 criminal-offence data is involved, document the additional condition or legal authority. Then align the notice, retention rule, and rights workflow with that decision.
Risk, incidents, and transfers
Decide whether a DPO must be designated, whether Article 35 requires a before processing, which Article 32 security measures fit the risk, how breaches will be escalated, and whether Chapter V permits each transfer outside the EEA.
Map processing
Name roles
Document evidence
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Feb 21, 2026
Updated
Jul 24, 2026

Regulation (EU) 2016/679 has applied since 25 May 2018 and is directly applicable EU law. EDPB and supervisory-authority guidance explains how regulators interpret and apply it rather than replacing the legal text. The GDPR also leaves room for Member State rules in areas such as children's consent, employment, public-sector processing, health, research, and penalties, so check the relevant national law and authority procedure before making a local decision.

GDPR Timeline

Key operating clocks for GDPR privacy programs

Track GDPR work that has legal or operational timing pressure: rights responses without undue delay and generally within one month under Article 12, with a possible two-month extension for complex or numerous requests; supervisory-authority breach notification without undue delay and, where feasible, within 72 hours under Article 33; DPIAs before high-risk processing; and event-driven transfer reassessments. If Article 36 prior consultation is required and the authority considers the intended processing would infringe the GDPR, it has up to eight weeks to give written advice, may extend by six weeks for complexity, and may suspend those periods while waiting for requested information. Consultation must happen before the processing starts.

Loading timeline...
Recommended reading path

Choose the next GDPR decision

New to the GDPR? Start with the processing activity, scope, roles, and lawful basis. If those decisions are already documented, jump to rights, accountability evidence, risk and incidents, transfers, deadlines, or a focused comparison.

1

Start here: scope, roles, and lawful basis

Decide whether the GDPR applies to a specific processing activity, who acts as controller or processor, which principles and lawful basis govern it, and which additional conditions need investigation.

2

Transparency, people's rights, and sensitive uses

Turn the processing decision into understandable notices and workable request handling, then apply the additional rules for children, sensitive data, profiling, and significant automated decisions.

3

Accountability, suppliers, and operating evidence

Build the records that connect GDPR conclusions to owners, systems, suppliers, retention controls, legitimate-interest assessments, and repeatable compliance work.

EU GDPR Checklist: scope, lawful basis, DSARs, DPIA, RoPA, transfers
This GDPR checklist helps review scope, lawful basis, notices, DSAR handling, DPIAs, RoPA, processor contracts, SCC transfers, breach notification, retention, security, and evidence.
Read guide
EU GDPR Compliance Checklist: scope, rights, DPIA, RoPA, transfers
Practical EU GDPR compliance guide for mapping scope, lawful basis, notices, data-subject rights, DPIAs, RoPA, processor terms, breaches, transfers, retention, security, and penalties.
Read guide
EU GDPR Record of Processing Activities Template: Article 30 RoPA Fields
Build a GDPR Article 30 record of processing activities with separate controller and processor fields for purposes, data categories, recipients, transfers, erasure time limits, and security measures.
Read guide
EU GDPR Article 30 RoPA Intake Workflow
This GDPR Article 30 RoPA intake workflow helps capture controller and processor fields, owners, transfers, retention, security measures, and evidence before a processing activity goes live.
Read guide
EU GDPR Processor Contracts and Vendor Management | Article 28 Evidence Guide
EU GDPR Article 28 guide for processor contracts, sub-processor controls, controller-processor role boundaries, vendor evidence, and SCC transfer clauses where applicable.
Read guide
EU GDPR Retention and Erasure Schedule
Build an EU GDPR retention and erasure schedule with purpose-based periods, expiry actions, Article 17 decisions, recipient notices, and deletion evidence.
Read guide
EU GDPR Lawful Basis and LIA Workflow for Article 6(1)(f)
Assess GDPR legitimate interests with a purpose, necessity, balancing, Article 21 objection, and evidence-record workflow based on Article 6(1)(f).
Read guide
EU GDPR LIA Template for Article 6(1)(f)
This EU GDPR legitimate interests assessment template helps document Article 6(1)(f) purpose, necessity, balancing, safeguards, objection rights, and evidence.
Read guide
4

Risk, security incidents, and enforcement

Screen high-risk processing before launch, preserve DPIA and prior-consultation evidence, operate the separate breach risk tests, and understand supervisory-authority and penalty exposure.

5

International transfers and operating clocks

Select and document the Chapter V route for each restricted transfer, assess SCC-based transfers in context, and separate legal deadlines from internal review cadences.

6

Compare regimes or answer a focused question

Use comparisons to identify parallel workstreams, not equivalence, and use the FAQ when you already know the GDPR question you need to resolve.

GDPR vs EU AI Act: privacy controls for AI systems
Map the GDPR work that remains necessary when an AI system processes personal data, including lawful basis, notices, DPIAs, Article 22, rights, security, records, and transfers.
Read guide
GDPR vs EU Data Act: personal data, connected products, and access rights
Compare GDPR privacy duties with EU Data Act rights and duties for connected-product data, third-party access, data holders, users, contracts, cloud switching, and enforcement.
Read guide
EU GDPR vs ePrivacy Directive: personal data, cookies, consent, and communications
Compare the EU GDPR and ePrivacy Directive for personal data processing, consent and lawful basis, cookies and terminal access, electronic communications, and parallel compliance.
Read guide
EU GDPR vs California CCPA: scope, rights, opt-outs, and evidence
Compare EU GDPR and California CCPA scope, roles, consumer rights, response times, sale and sharing opt-outs, risk assessments, contracts, transfers, and enforcement.
Read guide
EU GDPR vs Brazil LGPD: scope, legal bases, rights, incidents, and transfers
Compare EU GDPR and Brazil LGPD scope, actors, legal bases, rights timing, security incidents, international transfers, evidence, regulators, and penalties.
Read guide
EU GDPR vs UK GDPR: Scope, Rights, Transfers, and Evidence
Compare the EU GDPR and amended UK GDPR across scope, rights, automated decisions, accountability, breaches, regulators, and international transfers.
Read guide
EU GDPR FAQ: scope, lawful basis, rights, DPIA, breaches, transfers
Direct EU GDPR FAQ answers on scope, controller and processor roles, lawful basis, data subject rights, DPIAs, breach notification, international transfers, and Article 83 fine tiers.
Read guide
Next step

Turn GDPR scope decisions into owned privacy work

This GDPR hub is the shared entry point for processing inventory, role mapping, lawful-basis records, rights operations, triage, breach readiness, transfer governance, and accountability evidence.

What this unlocks
  • Start from one processing activity and record the purpose, data categories, data subjects, recipients, retention period, transfer destination, and security controls.
  • Use Research Copilot for cited questions about scope, and status, lawful basis, rights, triggers, breach notification, SCCs, adequacy, and Article 83 penalty exposure.
  • Use SSOT to keep RoPA records, Article 28 contracts, DSAR logs, breach assessments, DPIAs, transfer assessments, SCCs, and remediation evidence connected to owners and review dates.
  • Route unsupported national-law questions, authority-specific procedures, and case-specific transfer risks to counsel instead of treating this root artifact as a complete legal opinion.
EU GDPR compliance artifact preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.