Laws · GDPR ·art-1-par-2 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.
How it connects
Cited by
- CJEU: Data retention obligations interfere with Article 7 CFR privacy rights
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020
- Guidelines 01/2022 on data subject rights - Right of access
- Statement 2/2025 on the implementation of the PNR Directive in light of CJEU Judgment C-817/19
- Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation
All 44
- EDPB- EDPS Joint Opinion 01/2025 on the Proposal for a Regulation on simplification measures for SMEs and SMCs, in particular the record-keeping obligation under Art. 30(5) GDPR
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- Opinion 2/2026 on the Proposal for a Directive amending Directives (EU) 2016/2341 and 2016/97 as regards the strengthening of the framework for occupational retirement provision
- Digital Rights Ireland Ltd v Minister for Communications
- EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- DSB (Austria) - 2026-0.016.479
- BGH: Preselected checkbox for web analytics cookies does not constitute valid consent
- DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health
- Guidelines 01/2023 on Article 37 Law Enforcement Directive
- EDPB-EDPS Joint Opinion 04/2022 on the Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse
- EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space
- EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)
- Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data
- Statement 05/2021 on the Data Governance Act in light of the legislative developments
- EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)
- Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679)
- X v Russmedia Digital SRL and Inform Media Press SRL
- Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- A v Patērētāju tiesību aizsardzības centrs
- European Commission v Republic of Poland
- Hauptpersonalrat der Lehrerinnen und Lehrer beim Hessischen Kultusministerium v Minister des Hessischen Kultusministeriums
- OT v Vyriausioji tarnybinės etikos komisija
- Ligue des droits humains ASBL v Conseil des ministres
- Mircom International Content Management & Consulting (M.I.C.M.) Limited v Telenet BVBA
- Facebook Ireland Ltd and Others v Gegevensbeschermingsautoriteit
- Tele2 Sverige AB v Post- och telestyrelsen and Secretary of State for the Home Department v Tom Watson and Others
- Tietosuojavaltuutettu v Satakunnan Markkinapörssi Oy and Satamedia Oy
- United Kingdom of Great Britain and Northern Ireland v European Parliament and Council of the European Union
- The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how
- Austrian DSB: Employee who shared customer's phone number acted as GDPR controller
- DSB: Retailer must grant full access and delete data after third-party fraud order
- DSB (Austria) - DSB-D124.5337
- KHO: Consent required for cookies and web requests; no CJEU referral needed
- VG Munich: university may be GDPR controller for professors' editorial work emails
- Persónuvernd (Iceland) - 2025010364
- LG Frankfurt am Main - 2-06 O 234/25
- Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to
- Icelandic DPA opens formal proceedings against Isavia over ANPR parking cameras at