General Data Protection Regulation (Regulation (EU) 2016/679)
The EU's data protection regulation, applicable since 25 May 2018 (Article 99 of the consolidated text). It applies to controllers/processors established in the EU and, extraterritorially, to those offering goods or services to (or monitoring) data subjects in the EU (Article 3). Enforced by national supervisory authorities, coordinated by the European Data Protection Board (EDPB).
This folder reproduces the EdTech-critical articles verbatim; the UK GDPR sibling carries the fuller retained-and-amended UK text. The two instruments share ancestry but have diverged materially since the UK's amendments:
| Topic | EU GDPR (this folder) | UK GDPR |
|---|---|---|
| Child's consent age (ISS) | 16 by default; Member States may lower to not below 13 (Art. 8) | Fixed at 13 (Art. 8) |
| Automated decision-making | Art. 22 in force | Art. 22 repealed; regime is Arts. 22A–22D (DATA-SUBJECT-RIGHTS.md) |
| Fine ceilings | EUR 10m/2% and EUR 20m/4% (Art. 83) | £8.7m/2% and £17.5m/4% (ENFORCEMENT.md) |
| International transfers | Arts. 44–49, adequacy decisions by the Commission (INTERNATIONAL-TRANSFERS.md) | Restructured as Arts. 44A–49A, transfers approved by Secretary of State regulations (INTERNATIONAL-TRANSFERS.md) |
| Regulator | National supervisory authorities + EDPB | The Information Commissioner |
Applicability to EdTech
Relevant wherever an EdTech service is offered to schools or users in the EU: the higher default consent age for children, the still-in-force Article 22 automated-decision regime, and the EU transfer rules (including the EU–UK relationship, which rests on an EU adequacy decision for the UK) all surface in EU customer RFIs.
Contents
| Document | Covers |
|---|---|
| PRINCIPLES.md | Art. 5 — processing principles |
| LAWFUL-BASES.md | Arts. 6, 7, 9 — lawfulness, consent, special categories |
| CHILDREN.md | Art. 8 — child's consent (16 default / 13 floor) |
| AUTOMATED-DECISIONS.md | Art. 22 — automated individual decision-making |
| CONTROLLER-PROCESSOR.md | Art. 28 — processor contracts |
| SECURITY-AND-BREACH.md | Arts. 32–34 — security, breach notification |
| INTERNATIONAL-TRANSFERS.md | Arts. 44–46, 49 — transfers |
| ENFORCEMENT.md | Art. 83 — administrative fines |
Scope note: remaining articles (data subject rights 12–21, DPIA 35–36, and others) can be added with the same tooling when needed.
Related
- UK GDPR — the UK's retained and amended descendant of this Regulation
- DPA 2018 — the UK companion statute
- EU AI Act — applies without prejudice to this Regulation (AI Act Art. 2(7)); AI systems processing personal data engage both
Sources
- EUR-Lex — Regulation (EU) 2016/679, consolidated text 02016R0679-20160504
- European Data Protection Board
Meta
Built and re-verified mechanically — see tools/eur-lex: build_eu_gdpr.py extracts from the Cellar API copy of the consolidated text; build_eu_gdpr.py verify confirms every source paragraph appears verbatim. Do not hand-edit article text. Note the consolidated CELEX id is pinned in the script — if the EU amends the GDPR, a new consolidated version id must be adopted deliberately.