Regulatory primer

GDPR

Regulation (EU) 2016/679 — General Data Protection Regulation · European Union · In force since 25 May 2018

The GDPR is the EU's foundational data-protection regulation: lawful-basis requirements for processing personal data, data-subject rights, breach notification, cross-border-transfer rules, and explicit obligations on solely-automated decisioning. It's been in force since May 2018 with enforcement maturing each year.

Updated 15 May 2026·Reading time ~ 7 min·Regulator-first explainer

What it is

GDPR replaced Directive 95/46/EC and brought a horizontal, directly-applicable regulation across the EU. The shift from directive to regulation eliminated the divergence between member-state national laws (though each member state still has a supplementary law — UK GDPR diverged post-Brexit; Germany's BDSG layers on top; France's Loi Informatique et Libertés overlays).

Enforcement is decentralised: each member state has a Data Protection Authority (DPA) with investigative + corrective powers, supervised at EU level by the European Data Protection Board (EDPB) for consistency. For cross-border processing, a 'lead supervisory authority' coordinates with concerned authorities under Art. 60 (the one-stop-shop mechanism).

Penalties: up to €20M or 4% of global annual turnover for the most serious infringements (Art. 5 principles, lawful basis, data-subject rights, cross-border transfers). Up to €10M or 2% for other infringements (controller / processor obligations, certification, monitoring).

Who's in scope

  • Controllers + processors established in the EU, regardless of where the processing happens.
  • Controllers + processors outside the EU, when processing personal data of data subjects in the EU AND the processing relates to (a) offering goods/services to them, or (b) monitoring their behaviour in the EU.
  • EU institutions are subject to a parallel regulation (Reg. 2018/1725) — same principles, separate text.
  • Does NOT apply to personal / household activity, law-enforcement processing under the Law Enforcement Directive (2016/680), or activities outside Union law.

Key obligations

Art. 5 — principles relating to processing

Six principles: lawfulness, fairness, transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity + confidentiality. Plus accountability (Art. 5(2)): the controller must demonstrate compliance.

Art. 6 — lawful basis for processing

Six legal bases: consent, contract, legal obligation, vital interests, public interest, legitimate interests. Each processing activity needs an identified basis. Special-category data (Art. 9) requires an Art. 9(2) exception in addition.

Art. 12-22 — data subject rights

Right to information (Art. 13/14), access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), object (Art. 21), and not to be subject to solely-automated decisions (Art. 22).

Art. 22 — automated decisions

Data subject has right not to be subject to solely-automated decisions producing legal effects or similarly significant effects. Exceptions require explicit consent, contractual necessity, or member-state law — plus safeguards including meaningful human intervention. Schufa CJEU C-634/21 (2023) confirmed scoring-style processing is within scope when downstream actors draw strongly on it.

Art. 25 — data protection by design + default

Controllers must implement appropriate technical + organisational measures at the time of determining means of processing AND at the time of processing itself. By default, only personal data necessary for each specific purpose are processed.

Art. 28 — processor obligations

When a controller engages a processor, the relationship is governed by a contract (DPA). The DPA must specify: subject-matter, duration, nature + purpose, type of personal data, categories of data subjects, controller + processor obligations.

Applies to: Controllers + processors

Art. 30 — records of processing

Controllers + processors must maintain a record of processing activities under their responsibility (ROPA). Required content specified per Art. 30(1) for controllers, Art. 30(2) for processors. Small-organisation exemption (<250 employees) is narrow + qualified.

Art. 32 — security of processing

Appropriate technical + organisational measures: pseudonymisation + encryption, ongoing confidentiality + integrity + availability + resilience, ability to restore, regular testing.

Art. 33-34 — breach notification

Personal data breach → notify DPA without undue delay, where feasible within 72h (Art. 33). High-risk breach → also notify affected data subjects without undue delay (Art. 34).

Art. 35 — DPIA (Data Protection Impact Assessment)

Required when processing is likely to result in high risk — including systematic + extensive evaluation of personal aspects based on automated processing (including profiling) that produces legal effects.

Timeline + applicability

  • 25 May 2018GDPR became applicable across the EU (entered into force 24 May 2016 with a 2-year transition).
  • 7 Dec 2023CJEU C-634/21 (Schufa) — automated scoring with strong downstream reliance is itself within Art. 22 scope.
  • OngoingEDPB guidelines + DPA enforcement actions continue to clarify operational details, especially for AI + automated decision-making contexts.

What's still being worked out

Areas where the regulation's interpretation is genuinely unsettled. Vendor pages skip this; we don't. Your counsel is the right venue for definitive guidance on your deployment.

  • Whether and how Art. 22 applies to scoring + profiling that's input to human decisions (post-Schufa, more is in scope than was previously assumed, but the exact boundary is contested).
  • What 'meaningful human intervention' (Art. 22(3)) requires in practice — EDPB WP251 + Recital 71 give principles, but operational thresholds (override rate, review depth, decision-maker authority) are case-by-case.
  • Cross-border transfers post-Schrems II — Standard Contractual Clauses + Transfer Impact Assessments remain the workaround for transfers to third countries without adequacy decisions; the legal landscape continues to evolve.
  • AI-training data + Art. 6 lawful basis — whether legitimate interests (Art. 6(1)(f)) covers training on scraped public-internet personal data is being litigated + DPA-decided in multiple member states.
  • Cookies + ePrivacy interaction — Art. 6 GDPR vs Art. 5(3) ePrivacy on cookie consent has been clarified by EDPB but national enforcement varies.

Sectors most affected

Primary sources

Where Promethean fits

Promethean addresses GDPR Art. 22 + Art. 25 + Art. 30 + Art. 32 in the AI-decisioning slice specifically. The L12 chain provides per-decision evidence of reviewer verdicts (the empirical proxy for 'meaningful human intervention' post-Schufa). Hash-only input + output records satisfy Art. 5(1)(c) data minimisation by construction (raw PII never enters the chain). Per-entry Ed25519 attestation + chain integrity satisfy Art. 32 technical-measures obligations for the audit-trail subsystem.

What Promethean does NOT solve

  • Lawful-basis determination (Art. 6) — that's controller responsibility.
  • Data subject rights workflow (Art. 12-22) — that's the operator's customer-facing system.
  • Cross-border-transfer compliance (Art. 44-50) — that's procurement + legal.
  • DPIA (Art. 35) — Promethean's chain is one evidence input to your DPIA, not a replacement for it.
  • Breach-notification workflow (Art. 33-34) — operator's incident-response process.

FAQ

Does GDPR apply to AI training data?

Yes, when the training data contains personal data of EU data subjects. Each processing activity needs an Art. 6 lawful basis. Whether legitimate interests (Art. 6(1)(f)) covers scraped public-internet personal data is contested + being decided case by case (the Italian Garante's actions against OpenAI; Norwegian Datatilsynet on Meta; EDPB Opinion 28/2024 on AI models). Special-category data (Art. 9 — race, health, biometrics) needs an additional Art. 9(2) exception.

What is the Schufa ruling and why does it matter?

CJEU Case C-634/21 (December 2023). A credit-bureau scoring decision is itself an Art. 22 automated decision when downstream actors (banks, lenders) draw strongly on the score for their decision. Effect: scoring-style processing previously treated as merely preparatory is now within Art. 22 scope, requiring Art. 22(2) exceptions + Art. 22(3) safeguards including meaningful human intervention.

What's 'meaningful human intervention' under Art. 22(3)?

Not formally defined in the GDPR text. EDPB Guidelines WP251 rev.01 + Recital 71 are the operative source: human involvement must be more than 'a token gesture'; the reviewer must have authority + competence to override; review must engage with the substance, not just rubber-stamp. Operationally, a non-trivial override rate over time is the empirical evidence regulators look for.

Are AI decisions automatically prohibited under GDPR?

No. Art. 22(1) gives data subjects the right not to be subject to solely-automated decisions producing legal effects or similarly significant effects. Art. 22(2) provides three exceptions: explicit consent, contractual necessity, or member-state law authorising the processing. When an exception applies, Art. 22(3) requires safeguards including meaningful human intervention + right to express the data subject's point of view + right to contest.

How does GDPR interact with the EU AI Act?

Complementary, not duplicative. GDPR governs personal-data processing; AI Act governs AI-system risk regardless of personal data. An AI system can be high-risk under AI Act + engage GDPR Art. 22 simultaneously. Concurrent supervision is normal — DPAs continue to enforce GDPR; national AI competent authorities enforce AI Act. The EDPB + AI Office coordinate via formal mechanisms.