Source record · tier 1 standards and regulators
Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU)
- Publisher
- The National Archives (legislation.gov.uk)
- URL
- https://www.legislation.gov.uk/eur/2016/679/contents/adopted
- Published
- 2016-05-04
- Updated
- unknown
- Accessed
- 2026-10-01
- HTTP status
- 200
- License
- Open Government Licence v3.0 for the rendering; EU legislative text reusable under Commission Decision 2011/833/EU; short excerpts and locators only
Source notes citing this source
- GDPR Article 15 gives the data subject a right to confirmation of processing, access to their personal data and supplementary information, and a copy of the personal data undergoing processing. in context
- GDPR Article 15(4) provides that the right to obtain a copy must not adversely affect the rights and freedoms of others. in context
- A transfer to a third country covered by a Commission adequacy decision does not require any specific authorisation. in context
- Where personal data is not obtained from the data subject, GDPR Article 14(3)(a) requires notice within a reasonable period and at the latest within one month of obtaining it. in context
- Because consent is withdrawable at any time and must be demonstrable, while legitimate interests is subject to a right to object, a contact center choosing a lawful basis for call recording is choosing which caller opt-out mechanism it must operate, not whether one exists. inferred in context
- GDPR defines biometric data as personal data from specific technical processing of physical, physiological or behavioural characteristics that allow or confirm unique identification of a person. in context
- GDPR Article 9(1) prohibits processing biometric data for the purpose of uniquely identifying a natural person unless an Article 9(2) exception, such as explicit consent, applies. in context
- GDPR defines consent as a freely given, specific, informed and unambiguous indication of wishes given by a statement or clear affirmative action. in context
- Under GDPR Article 7(3) a data subject may withdraw consent at any time, and withdrawal does not make processing carried out before the withdrawal unlawful. in context
- Absent adequacy or appropriate safeguards, Article 49(1)(a) permits a transfer on the data subject's explicit consent after being told of the risks, but this derogation does not apply to public authorities exercising public powers. in context
- GDPR Article 35(1) requires a data protection impact assessment before processing likely to result in a high risk, and Article 35(4) requires supervisory authorities to publish lists of operations that need one. in context
- Responses to data subject requests are free of charge, but for manifestly unfounded or excessive requests, particularly repetitive ones, the controller may charge a reasonable fee or refuse to act. in context
- Where the controller has reasonable doubts about the requester's identity it may ask for additional information needed to confirm it. in context
- GDPR Article 12(3) requires the controller to act on a data subject request under Articles 15 to 22 without undue delay and in any event within one month of receipt. in context
- The one-month period may be extended by two further months where necessary, and the controller must tell the data subject of the extension and reasons within the first month. in context
- The erasure right does not apply to the extent processing is necessary to comply with a Union or Member State legal obligation or for the establishment, exercise or defence of legal claims. in context
- GDPR Article 17(1) gives the data subject a right to erasure without undue delay on listed grounds, including that the data is no longer necessary, consent is withdrawn, or an objection succeeds. in context
- Infringements of the basic principles, lawful-basis and consent rules, data subject rights in Articles 12 to 22 and transfer rules carry administrative fines of up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher. in context
- GDPR Article 6(1) permits processing of personal data only where at least one of six lawful bases applies: consent, contract, legal obligation, vital interests, public task, or legitimate interests. in context
- When personal data is collected from the data subject, as when a caller is recorded, GDPR Article 13(1) requires the controller to give the prescribed information at the time the data is obtained. in context
- The Article 13 notice must state the controller's identity and contact details, the purposes and legal basis of processing, and the legitimate interests pursued where Article 6(1)(f) is relied on. in context
- The Article 13 notice must name the recipients or categories of recipients and, where applicable, the intended transfer to a third country and the safeguards relied on. in context
- The Article 13 notice must state how long the data will be stored or, if that is not possible, the criteria used to determine that period. in context
- Where processing rests on legitimate interests or public task, GDPR Article 21(1) lets the data subject object, after which the controller must stop unless it shows compelling legitimate grounds or needs the data for legal claims. in context
- GDPR Article 28(3) requires a binding contract under which the processor acts only on documented instructions, binds staff to confidentiality, secures the data, assists with data subject requests, deletes or returns data at the end, and allows audits. in context
- GDPR Article 28(1) requires a controller to use only processors that provide sufficient guarantees of appropriate technical and organisational measures. in context
- Without an adequacy decision, GDPR Article 46(2)(c) allows transfers under standard data protection clauses adopted by the Commission, provided enforceable rights and effective remedies are available. in context
- GDPR Article 5(1)(e) requires personal data, including recordings, to be kept in identifiable form no longer than necessary for the purposes of processing. in context
- A processor such as a CCaaS provider may not engage a sub-processor without the controller's prior specific or general written authorisation. in context
- Under a general written authorisation the processor must inform the controller of intended additions or replacements of sub-processors, giving the controller the opportunity to object. in context
- A processor must impose the same data protection obligations on its sub-processors by contract and remains fully liable to the controller for a sub-processor's failure. in context
Cite this source record
APA
WarmTransfer. (2016, May 4). Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU). WarmTransfer. https://warmtransfer.net/knowledge/sources/tna-legislation-eu-gdpr-2016-679-adopted
BibTeX
@misc{warmtransfer-tna-legislation-eu-gdpr-2016-679-adopted,
title = {Regulation (EU) 2016/679 (General Data Protection Regulation) - Original (As adopted by EU)},
author = {{WarmTransfer}},
year = {2016},
url = {https://warmtransfer.net/knowledge/sources/tna-legislation-eu-gdpr-2016-679-adopted},
note = {The National Archives (legislation.gov.uk), accessed 2026-10-01}
}