EU GDPR Scope, Roles, Rights, and Transfers
Start with one use of : confirm whether the GDPR applies, identify who decides its purposes and means, record the lawful basis, and then connect that activity to transparency, rights, security, risk, supplier, and transfer duties.
Follow the recommended path below: scope one processing activity, assign its roles, choose and record the lawful basis, then connect notices, rights, Article 30 records, processors, security, , breach, retention, and transfer evidence.
Regulation (EU) 2016/679 has applied since 25 May 2018 and is directly applicable EU law. EDPB and supervisory-authority guidance explains how regulators interpret and apply it rather than replacing the legal text. The GDPR also leaves room for Member State rules in areas such as children's consent, employment, public-sector processing, health, research, and penalties, so check the relevant national law and authority procedure before making a local decision.
Key operating clocks for GDPR privacy programs
Track GDPR work that has legal or operational timing pressure: rights responses without undue delay and generally within one month under Article 12, with a possible two-month extension for complex or numerous requests; supervisory-authority breach notification without undue delay and, where feasible, within 72 hours under Article 33; DPIAs before high-risk processing; and event-driven transfer reassessments. If Article 36 prior consultation is required and the authority considers the intended processing would infringe the GDPR, it has up to eight weeks to give written advice, may extend by six weeks for complexity, and may suspend those periods while waiting for requested information. Consultation must happen before the processing starts.
Choose the next GDPR decision
New to the GDPR? Start with the processing activity, scope, roles, and lawful basis. If those decisions are already documented, jump to rights, accountability evidence, risk and incidents, transfers, deadlines, or a focused comparison.
Start here: scope, roles, and lawful basis
Decide whether the GDPR applies to a specific processing activity, who acts as controller or processor, which principles and lawful basis govern it, and which additional conditions need investigation.
Transparency, people's rights, and sensitive uses
Turn the processing decision into understandable notices and workable request handling, then apply the additional rules for children, sensitive data, profiling, and significant automated decisions.
Accountability, suppliers, and operating evidence
Build the records that connect GDPR conclusions to owners, systems, suppliers, retention controls, legitimate-interest assessments, and repeatable compliance work.
Risk, security incidents, and enforcement
Screen high-risk processing before launch, preserve DPIA and prior-consultation evidence, operate the separate breach risk tests, and understand supervisory-authority and penalty exposure.
International transfers and operating clocks
Select and document the Chapter V route for each restricted transfer, assess SCC-based transfers in context, and separate legal deadlines from internal review cadences.
Compare regimes or answer a focused question
Use comparisons to identify parallel workstreams, not equivalence, and use the FAQ when you already know the GDPR question you need to resolve.
Turn GDPR scope decisions into owned privacy work
This GDPR hub is the shared entry point for processing inventory, role mapping, lawful-basis records, rights operations, triage, breach readiness, transfer governance, and accountability evidence.
- Start from one processing activity and record the purpose, data categories, data subjects, recipients, retention period, transfer destination, and security controls.
- Use Research Copilot for cited questions about scope, and status, lawful basis, rights, triggers, breach notification, SCCs, adequacy, and Article 83 penalty exposure.
- Use SSOT to keep RoPA records, Article 28 contracts, DSAR logs, breach assessments, DPIAs, transfer assessments, SCCs, and remediation evidence connected to owners and review dates.
- Route unsupported national-law questions, authority-specific procedures, and case-specific transfer risks to counsel instead of treating this root artifact as a complete legal opinion.
