REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

of 27 April 2016

on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)

(Text with EEA relevance)

THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

Whereas:

  1. The protection of natural persons in relation to the processing of personal data is a fundamental right.
  2. The principles of, and rules on the protection of natural persons with regard to the processing of their personal data should respect their fundamental rights and freedoms.
  3. Directive 95/46/EC of the European Parliament and of the Council (2) .
  4. The processing of personal data should be designed to serve mankind.

HAVE ADOPTED THIS REGULATION:

(1) OJ C 229, 31.7.2012, p. 90 .

(2) Directive 95/46/EC of the European Parliament ( OJ L 281, 23.11.1995, p. 31 ).

CHAPTER I

General provisions

Article 1

Subject-matter and objectives

  1. This Regulation lays down rules relating to the protection of natural persons.
  2. This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.

Article 2

Material scope

  1. This Regulation applies to the processing of personal data.
  2. This Regulation does not apply to the processing of personal data:
    1. in the course of an activity which falls outside the scope of Union law;
    2. by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU ;

Article 4

Definitions

For the purposes of this Regulation:

  1. personal data means any information relating to an identified or identifiable natural person ( data subject ); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  2. processing means any operation or set of operations which is performed on personal data or on sets of personal data , whether or not by automated means.

CHAPTER II

Rights of the data subject

Section 1

Transparency and modalities

Article 12

Transparent information, communication and modalities for the exercise of the rights of the data subject

  1. The controller shall take appropriate measures to provide any information referred to in Articles 13 and 14 .
  2. The controller shall facilitate the exercise of data subject rights under Articles 2 to 4 .

Section 2

Information and access to personal data

Article 13

Information to be provided where personal data are collected from the data subject

  1. Where personal data relating to a data subject are collected from the data subject , the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information:
    1. the identity and the contact details of the controller and, where applicable, of the controller's representative;
  2. In addition to the information referred to in paragraph 1, the controller shall, at the time when personal data are obtained, provide the data subject with the following further information necessary to ensure fair and transparent processing :
    1. the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period;
    2. the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concerning the data subject or to object to processing as well as the right to data portability;

Article 14

Information to be provided where personal data have not been obtained from the data subject

  1. Where personal data have not been obtained from the data subject , the controller shall provide the data.
  2. In addition to the information referred to in paragraph 1, the controller shall provide the data.

Final

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 27 April 2016 .

For the European Parliament

The President

M. SCHULZ

For the Council

The President

J.A. HENNIS-PLASSCHAERT