EdLaw int/eu/gdpr/README.md

language: en · status: in-force · last checked: 2026-09-04

General Data Protection Regulation (Regulation (EU) 2016/679)

The EU's data protection regulation, applicable since 25 May 2018 (Article 99 of the consolidated text). It applies to controllers/processors established in the EU and, extraterritorially, to those offering goods or services to (or monitoring) data subjects in the EU (Article 3). Enforced by national supervisory authorities, coordinated by the European Data Protection Board (EDPB).

This folder reproduces the EdTech-critical articles verbatim; the UK GDPR sibling carries the fuller retained-and-amended UK text. The two instruments share ancestry but have diverged materially since the UK's amendments:

Topic EU GDPR (this folder) UK GDPR
Child's consent age (ISS) 16 by default; Member States may lower to not below 13 (Art. 8) Fixed at 13 (Art. 8)
Automated decision-making Art. 22 in force Art. 22 repealed; regime is Arts. 22A–22D (DATA-SUBJECT-RIGHTS.md)
Fine ceilings EUR 10m/2% and EUR 20m/4% (Art. 83) £8.7m/2% and £17.5m/4% (ENFORCEMENT.md)
International transfers Arts. 44–49, adequacy decisions by the Commission (INTERNATIONAL-TRANSFERS.md) Restructured as Arts. 44A–49A, transfers approved by Secretary of State regulations (INTERNATIONAL-TRANSFERS.md)
Regulator National supervisory authorities + EDPB The Information Commissioner

Applicability to EdTech

Relevant wherever an EdTech service is offered to schools or users in the EU: the higher default consent age for children, the still-in-force Article 22 automated-decision regime, and the EU transfer rules (including the EU–UK relationship, which rests on an EU adequacy decision for the UK) all surface in EU customer RFIs.

Contents

Document Covers
PRINCIPLES.md Art. 5 — processing principles
LAWFUL-BASES.md Arts. 6, 7, 9 — lawfulness, consent, special categories
CHILDREN.md Art. 8 — child's consent (16 default / 13 floor)
AUTOMATED-DECISIONS.md Art. 22 — automated individual decision-making
CONTROLLER-PROCESSOR.md Art. 28 — processor contracts
SECURITY-AND-BREACH.md Arts. 32–34 — security, breach notification
INTERNATIONAL-TRANSFERS.md Arts. 44–46, 49 — transfers
ENFORCEMENT.md Art. 83 — administrative fines

Scope note: remaining articles (data subject rights 12–21, DPIA 35–36, and others) can be added with the same tooling when needed.

Sources

Meta

Built and re-verified mechanically — see tools/eur-lex: build_eu_gdpr.py extracts from the Cellar API copy of the consolidated text; build_eu_gdpr.py verify confirms every source paragraph appears verbatim. Do not hand-edit article text. Note the consolidated CELEX id is pinned in the script — if the EU amends the GDPR, a new consolidated version id must be adopted deliberately.