General Data Protection Regulation
EU law on personal data protection and privacy.
Sectors
Banking & FinanceHealthcare & PharmaIT & CybersecurityTechnologyTelecommunicationsEducationeGovernmentInsuranceMedia & EntertainmentProfessional ServicesRetail & Consumer
Articles (99)
Article 1 — Subject-matter and objectivesArticle 2 — Material scopeArticle 3 — Territorial scopeArticle 4 — DefinitionsArticle 5 — Principles relating to processing of personal dataArticle 6 — Lawfulness of processingArticle 7 — Conditions for consentArticle 8 — Conditions applicable to child's consent in relation to information society servicesArticle 9 — Processing of special categories of personal dataArticle 10 — Processing of personal data relating to criminal convictions and offencesArticle 11 — Processing which does not require identificationArticle 12 — Transparent information, communication and modalities for the exercise of the rights of the data subjectArticle 13 — Information to be provided where personal data are collected from the data subjectArticle 14 — Information to be provided where personal data have not been obtained from the data subjectArticle 15 — Right of access by the data subjectArticle 16 — Right to rectificationArticle 17 — Right to erasure ( right to be forgotten )Article 18 — Right to restriction of processingArticle 19 — Notification obligation regarding rectification or erasure of personal data or restriction of processingArticle 20 — Right to data portabilityArticle 21 — Right to objectArticle 22 — Automated individual decision-making, including profilingArticle 23 — RestrictionsArticle 24 — Responsibility of the controllerArticle 25 — Data protection by design and by defaultArticle 26 — Joint controllersArticle 27 — Representatives of controllers or processors not established in the UnionArticle 28 — ProcessorArticle 29 — Processing under the authority of the controller or processorArticle 30 — Records of processing activitiesArticle 31 — Cooperation with the supervisory authorityArticle 32 — Security of processingArticle 33 — Notification of a personal data breach to the supervisory authorityArticle 34 — Communication of a personal data breach to the data subjectArticle 35 — Data protection impact assessmentArticle 36 — Prior consultationArticle 37 — Designation of the data protection officerArticle 38 — Position of the data protection officerArticle 39 — Tasks of the data protection officerArticle 40 — Codes of conductArticle 41 — Monitoring of approved codes of conductArticle 42 — CertificationArticle 43 — Certification bodiesArticle 44 — General principle for transfersArticle 45 — Transfers on the basis of an adequacy decisionArticle 46 — Transfers subject to appropriate safeguardsArticle 47 — Binding corporate rulesArticle 48 — Transfers or disclosures not authorised by Union lawArticle 49 — Derogations for specific situationsArticle 50 — International cooperation for the protection of personal dataArticle 51 — Supervisory authorityArticle 52 — IndependenceArticle 53 — General conditions for the members of the supervisory authorityArticle 54 — Rules on the establishment of the supervisory authorityArticle 55 — CompetenceArticle 56 — Competence of the lead supervisory authorityArticle 57 — TasksArticle 58 — PowersArticle 59 — Activity reportsArticle 60 — Cooperation between the lead supervisory authority and the other supervisory authorities concernedArticle 61 — Mutual assistanceArticle 62 — Joint operations of supervisory authoritiesArticle 63 — Consistency mechanismArticle 64 — Opinion of the BoardArticle 65 — Dispute resolution by the BoardArticle 66 — Urgency procedureArticle 67 — Exchange of informationArticle 68 — European Data Protection BoardArticle 69 — IndependenceArticle 70 — Tasks of the BoardArticle 71 — ReportsArticle 72 — ProcedureArticle 73 — ChairArticle 74 — Tasks of the ChairArticle 75 — SecretariatArticle 76 — ConfidentialityArticle 77 — Right to lodge a complaint with a supervisory authorityArticle 78 — Right to an effective judicial remedy against a supervisory authorityArticle 79 — Right to an effective judicial remedy against a controller or processorArticle 80 — Representation of data subjectsArticle 81 — Suspension of proceedingsArticle 82 — Right to compensation and liabilityArticle 83 — General conditions for imposing administrative finesArticle 84 — PenaltiesArticle 85 — Processing and freedom of expression and informationArticle 86 — Processing and public access to official documentsArticle 87 — Processing of the national identification numberArticle 88 — Processing in the context of employmentArticle 89 — Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposesArticle 90 — Obligations of secrecyArticle 91 — Existing data protection rules of churches and religious associationsArticle 92 — Exercise of the delegationArticle 93 — Committee procedureArticle 94 — Repeal of Directive 95/46/ECArticle 95 — Relationship with Directive 2002/58/ECArticle 96 — Relationship with previously concluded AgreementsArticle 97 — Commission reportsArticle 98 — Review of other Union legal acts on data protectionArticle 99 — Entry into force and application
Controls that address this (22)
EU_GDPR-CTRL-001 - Daily safeguarding reconciliationoperational · critical priority · Daily reconciliation between safeguarded customer balances, core ledger balances and safeguarded bank accounts. Variances above EUR 100 mustEU_GDPR-CTRL-002 - Critical ICT incident reportingoperational · critical priority · All major ICT incidents impacting payment services, customer data or availability must be classified within 4 hours and reported under DORA EU_GDPR-CTRL-003 - GDPR breach notification workflowoperational · critical priority · Personal data breaches must be assessed within 12 hours and reported to the Belgian DPA within 72 hours where risk to data subjects exists.