Skip to content

Running commentary · living document · revised 7 July 2026

GDPR

Regulation (EU) 2016/679 on the protection of personal data. What it does, how the obligations fit together, and a commentary on each of the 99 articles, with the full text alongside. The article text here is the official English from EUR-Lex; the citations are held against the source, not against second-hand summaries.

TL;DR

The GDPR unifies the protection of personal data across the EU and reaches even businesses outside the Union that target people within it. It rests on the principles in Art. 5 (lawfulness, minimisation, accountability), the six legal bases in Art. 6, and the catalogue of data-subject rights, from access through erasure to objection. It imposes compliance that can be demonstrated: records of processing, security, breach notification within 72 hours, an impact assessment for risky processing, and, where relevant, a DPO. Transfers outside the EU only through the conditions of Chapter V. Supervision in the Czech Republic is carried out by the ÚOOÚ, and fines reach up to EUR 20 million or 4% of worldwide turnover. It applies from 25 May 2018.

The route to compliance

A nine-step compliance guide exists as a Czech-jurisdiction resource, written around the Czech adaptation Act No. 110/2019 Sb. It is only in Czech: the route to compliance (in Czech) walks from mapping the data through legal bases, the duty to inform and records to incidents and demonstrating compliance, in nine steps, with a template linked at each one.

What the Regulation is about

The GDPR is directly applicable across the Union and technology-neutral. It does not say what software you may run; it says on what conditions you may process data about people, and it wants you to be able to demonstrate compliance at any time (the accountability principle). The approach is risk-based: the more sensitive and extensive the processing, the more obligations accrue, from records through the impact assessment to prior consultation with the supervisory authority. The Czech Republic accompanied the Regulation with Act No. 110/2019 Sb., which designated the ÚOOÚ, lowered the age of a child's consent to 15 years, and used the opening clauses.

The mechanics of the obligations rest on a pair of roles. The controller determines the purposes and means and bears the main responsibility; the processor works for it under a contract pursuant to Art. 28. Around that the obligation chain of Chapter IV is layered: data protection by design and by default, records of activities, security, notifying a breach to the authority within 72 hours and, where the risk is high, to the people affected too, the impact assessment (DPIA), and a DPO wherever Art. 37 requires one.

Data subject the person the data is about
the controller informs (Art. 13 and 14) the data subject exercises rights (Art. 15 to 22)
Controller determines the purposes and means
contract and instructions (Art. 28) processes only for the controller
Processor acts on the controller's instructions
breach notified within 72 hours (Art. 33)
Supervisory authority in the Czech Republic, the ÚOOÚ
A complaint under Art. 77 goes from the data subject straight to the supervisory authority; compensation under Art. 82 goes to a court.

The second half of the Regulation is about enforcement. The data subject has the catalogue of rights in Chapter III and three ways to press them: a free complaint to the ÚOOÚ, an action against the controller, and a claim for compensation for material and non-material damage under Art. 82. Cross-border cases are run by the lead supervisory authority under the one-stop-shop, and disputes between authorities are decided bindingly by the European Data Protection Board.

For this site the GDPR is interesting as a template too. The AI Act follows it with a similar regulatory logic. It shares extraterritoriality, protection by design and impact assessment (the parallel between the DPIA and the FRIA), and the logic of Art. 22 on automated decision-making has its counterpart in the right to an explanation under Art. 86 of the AI Act. The two regulations layer: an AI system that processes personal data satisfies both. The comparison runs on the AI Act card (in Czech).

Key parameters

27 April 2016

Adoption of the Regulation; it entered into force on the twentieth day after publication in the Official Journal.

25 May 2018

Application (Art. 99). From this date the GDPR applies directly and, at EU level, replaced Directive 95/46/EC. The Czech Act No. 101/2000 Sb. was not repealed until Act No. 110/2019 Sb., with effect from 24 April 2019.

24 April 2019

The Czech adaptation Act No. 110/2019 Sb., on personal data processing, takes effect. It designates the ÚOOÚ as the supervisory authority, lowers the age of a child's consent to 15 years, and implements the opening clauses.

fines

Two tiers under Art. 83: up to EUR 10 million or 2% of worldwide turnover, and up to EUR 20 million or 4% (the principles, the legal bases, the rights of data subjects, transfers). The higher of the two figures always applies.

Case law in a nutshell

The decisions that the practice of the GDPR actually stands on, one sentence each. The links lead to the primary sources; the selection also draws on the overviews at the gdpr.cz portal, and the annotations are my own. For Articles 4, 6, 7, 15, 22, 26, 32, 45, 57 and 82 the same decisions are worked directly into the commentary.

  • C-582/14 Breyer (2016): a dynamic IP address is personal data where the controller has a legal means to re-identify the person.
  • C-673/17 Planet49 (2019): a pre-ticked box is not consent; for cookies an active expression of will is required.
  • C-40/17 Fashion ID (2019): a website with an embedded social-network button is a joint controller for the collection and transmission of visitors' data.
  • C-311/18 Schrems II (2020): the Privacy Shield is struck down; standard contractual clauses require an assessment and, where needed, additional safeguards.
  • C-252/21 Meta Platforms (2023): compliance with the GDPR may also be assessed by a competition authority, and personalised advertising without a proper legal basis does not stand.
  • C-300/21 and C-340/21 (2023): compensation takes more than the infringement alone, yet there is no threshold of seriousness, and the fear of misuse of data after a leak can be enough.
  • C-579/21 Pankki S (2023): the right of access also covers information on when and why the data was accessed.
  • C-446/21 Schrems v. Meta and C-621/22 KNLTB (2024): advertising data is subject to minimisation, with no unlimited time or scope, and a legitimate interest can be a purely commercial one.
  • C-394/23 Mousse (ECLI:EU:C:2025:2, 9 January 2025): the title "Mr" or "Ms" is not necessary for selling a ticket; minimisation applies even to small form fields.
  • C-416/23 (ECLI:EU:C:2025:3, 9 January 2025): an authority may not shelve complaints because of their number; only manifestly unfounded or excessive ones may be refused.
  • C-203/22 (ECLI:EU:C:2025:117, 27 February 2025): in automated decision-making a meaningful explanation of the procedure used is owed, and trade secrets are not an absolute bar.
  • T-354/22 Bindl (ECLI:EU:T:2025:4, 8 January 2025): the General Court ordered the Commission to pay EUR 400 in non-material damage for the unlawful transfer of an IP address to the United States (Regulation 2018/1725, the GDPR's counterpart for the EU institutions).
  • T-553/23 Latombe (ECLI:EU:T:2025:831, 3 September 2025): the EU–US Data Privacy Framework held before the General Court and the action was dismissed (an appeal has been brought against the judgment).
  • C-413/23 P EDPS v. SRB (ECLI:EU:C:2025:645, 4 September 2025): whether pseudonymised data is personal data is assessed relatively, by the means available to the particular actor. On appeal the Court of Justice set aside the General Court's judgment and referred the case back, holding that for the controller's duty to inform, identifiability is assessed from the controller's standpoint at the moment of collection (Regulation 2018/1725, the GDPR's counterpart for the EU institutions).
  • C-97/23 P WhatsApp (ECLI:EU:C:2026:81, 10 February 2026): a binding decision of the European Data Protection Board can be challenged directly before the EU courts (the Court of Justice dealt with admissibility; the General Court will decide the merits).
  • Monitoring at work: the Strasbourg line of Bărbulescu v. Romania (2017) and López Ribalda v. Spain (2019), plus Czech practice (NS 21 Cdo 1771/2011, NSS 10 As 245/2016): a proportionality test and prior notice to employees.

Document templates

The Regulation comes with paperwork. A set of templates written from scratch against the text of the Regulation covers the controller's basic documentation (clause, records, policy, processor contract, balancing test), consents, the DPO, personal data breaches, handling requests and letters to data subjects. They are a Czech-jurisdiction resource, in Czech: all 35 templates → (in Czech)

Article-by-article commentary

All 99 articles by chapter, each with a short commentary. Open an article and inside there is the full text as well. The commentary deepens as it goes.

Chapter I · Art. 1–4

General provisions

The purpose, which processing the Regulation covers, how far it reaches, and the glossary of terms.

Art. 1 Subject-matter and objectives

A twofold purpose: the protection of natural persons when personal data is processed, and the free movement of data within the Union. Both sides of the coin are used in interpretation; protection is not an end in itself and must not become a barrier to the internal market.

Art. 2 Material scope

It covers wholly or partly automated processing and the manual processing of data held in a filing system. Outside its scope are purely personal or household activity, activity outside the scope of Union law, and the criminal-law field (covered by Directive (EU) 2016/680, in the Czech Republic Title III of Act No. 110/2019 Sb.).

Art. 3 Territorial scope

Territorial scope. Besides establishment in the EU, it also reaches controllers in third countries who offer goods or services to people in the EU or monitor their behaviour. The extraterritorial template later taken over by the AI Act in Art. 2.

Art. 4 Definitions

A glossary of 26 definitions. Personal data is drawn broadly (identifiability, even indirect, is enough), and processing is practically any operation on data. The key split is between the controller (who determines the purposes and means) and the processor (who processes for the controller); the whole Regulation's allocation of duties hangs on it. A dynamic IP address is personal data where the controller has a legal means to re-identify the person (C-582/14 Breyer), and whether pseudonymised data is personal data is judged relatively, by the means available to the particular actor (C-413/23 P EDPS v. SRB).

Chapter II · Art. 5–11

Principles

The most-cited part of the Regulation. The principles of processing, the legal bases, and the special regimes for sensitive data.

Art. 5 Principles relating to processing of personal data

Seven principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and over them all accountability, the duty not only to comply but to be able to demonstrate it. A breach of the principles sits in the top fine tier of Art. 83(5).

Art. 6 Lawfulness of processing

Six legal bases: consent, contract, legal obligation, vital interests, public interest and legitimate interests. Legitimate interests requires a balancing test against the rights of the data subject. Paragraph 4 deals with the compatibility of a new purpose with the original one. The first question in any analysis of processing is which basis it rests on. A legitimate interest can be a purely commercial one (C-621/22 KNLTB), yet Meta's personalised advertising could not rest on it, and a breach of the Regulation may also be assessed by a competition authority (C-252/21 Meta Platforms).

Art. 7 Conditions for consent

Consent must be demonstrable, clearly separated from other matters, and as easy to withdraw as it was to give. Paragraph 4 targets coerced consent: performance of a contract must not be conditional on consent that the performance does not need. A pre-ticked box is not consent (C-673/17 Planet49).

Art. 8 Conditions applicable to child's consent in relation to information society services

A child's consent for information-society services. The default threshold is 16 years, and States may lower it to 13. The Czech Republic lowered it to 15 years (§ 7 of Act No. 110/2019 Sb.).

Art. 9 Processing of special categories of personal data

Special categories (health, biometrics for identification, beliefs, orientation and others) may in principle not be processed unless one of ten exceptions applies, among them explicit consent, employment and social law, vital interests, health care or public health.

Art. 10 Processing of personal data relating to criminal convictions and offences

Data on convictions and criminal offences may be processed only by a public authority, or by anyone else only on the basis of a law providing appropriate safeguards.

Art. 11 Processing which does not require identification

A controller need not acquire additional identifying data just to comply with the Regulation. If it cannot identify the data subject, the rights under Art. 15 to 20 do not apply, unless the data subject supplies the identification themselves.

Chapter III · Art. 12–23

Rights of the data subject

The catalogue of rights that requests, complaints and disputes rest on.

Art. 12 Transparent information, communication and modalities for the exercise of the rights of the data subject

The modalities for exercising rights. Communication is to be concise, intelligible and free of charge; the reply comes without undue delay and within one month at the latest, extendable by two months for complex requests. Manifestly unfounded or excessive requests may be refused or charged for, and the burden of proof is on the controller.

Art. 13 Information to be provided where personal data are collected from the data subject

The information to be provided where data is obtained directly from the data subject: the identity of the controller, the purposes and legal bases, the recipients, the storage period, the rights, and any automated decision-making. The basis of every privacy notice.

Art. 14 Information to be provided where personal data have not been obtained from the data subject

The same for data obtained elsewhere, with the source and the categories of data added, within one month or at the first contact. Exceptions apply, among others, for disproportionate effort in archiving and research.

Art. 15 Right of access by the data subject

The right of access: confirmation that processing is taking place, information about it, and a copy of the data being processed. The copy must not adversely affect the rights of others. In practice the most frequently exercised right and the gateway to disputes. The data subject has the right to know when and why their data was accessed (C-579/21 Pankki S), and in automated decision-making to receive a meaningful explanation of the procedure used, with trade secrets not being an absolute bar (C-203/22).

Art. 16 Right to rectification

The right to rectification of inaccurate data and completion of incomplete data.

Art. 17 Right to erasure (‘right to be forgotten’)

The right to erasure where the purpose has fallen away, consent has been withdrawn, an objection has succeeded, or the processing was unlawful. Exceptions for freedom of expression, legal obligations, public health, archiving, and the establishment, exercise or defence of legal claims. For data that has been made public, a duty to inform other controllers is added.

Art. 18 Right to restriction of processing

The right to restriction of processing as a temporary handbrake while accuracy is contested, an objection is pending, or in place of erasure.

Art. 19 Notification obligation regarding rectification or erasure of personal data or restriction of processing

The controller notifies rectifications, erasures and restrictions to every recipient to whom it disclosed the data.

Art. 20 Right to data portability

Portability: the data provided by the data subject in a machine-readable format, and where feasible transmitted directly to another controller. Only for processing based on consent or contract and carried out by automated means.

Art. 21 Right to object

An objection to processing based on legitimate or public interest: the controller must demonstrate compelling legitimate grounds, otherwise it must stop. Against direct marketing the objection is absolute; after it the processing must cease.

Art. 22 Automated individual decision-making, including profiling

The right not to be subject to a decision based solely on automated processing with legal or similarly significant effects, subject to exceptions (contract, legal basis, explicit consent) and safeguards including human intervention. According to the CJEU judgment in C-634/21 SCHUFA (7 December 2023), an automated credit-scoring assessment is already such a decision where a third party draws on it decisively for its own decision. The forerunner of Art. 86 of the AI Act, which addresses the same situation from the procedural side.

Art. 23 Restrictions

Member States and the Union may restrict the rights by law for listed interests (security, criminal proceedings, the administration of justice and others), only to the extent necessary.

Chapter IV · Art. 24–43

Controller and processor

The core of the obligations for businesses. Accountability, processor contracts, records, security, incidents, the DPIA and the DPO.

Art. 24 Responsibility of the controller

The responsibility of the controller: to put in place appropriate technical and organisational measures according to the nature and risks of the processing, and to be able to demonstrate them. The risk-based approach that then returns in Art. 25, 32 and 35.

Art. 25 Data protection by design and by default

Data protection by design and by default. Data protection is built into the design of systems, and the default settings process only the necessary minimum. The sister principle to the design requirements in the AI Act.

Art. 26 Joint controllers

Joint controllers allocate their duties by an arrangement and make the essence of it available to data subjects. The data subject may exercise their rights against any of them, and the arrangement does not bind anyone externally. A website operator who embeds a social-network button that collects visitors' data is also a joint controller (C-40/17 Fashion ID).

Art. 27 Representatives of controllers or processors not established in the Union

Controllers and processors outside the EU that the Regulation reaches through Art. 3 designate a representative in the Union in writing.

Art. 28 Processor

A processor acts only under a contract with the mandatory content of paragraph 3: the controller's instructions, confidentiality, security, the conditions for engaging sub-processors, cooperation, erasure or return at the end, and audit rights. The most frequently reviewed contract type in the whole Regulation.

Art. 29 Processing under the authority of the controller or processor

Anyone with access to the data processes it only on the controller's instructions.

Art. 30 Records of processing activities

Records of processing activities for both controllers and processors. The exemption for organisations under 250 employees is full of holes (it does not apply to non-occasional processing, to risk, or to special categories), so in practice almost everyone keeps records.

Art. 31 Cooperation with the supervisory authority

Mandatory cooperation with the supervisory authority on request.

Art. 32 Security of processing

Security appropriate to the risk, with pseudonymisation and encryption expressly named, the ability to ensure confidentiality, integrity, availability and resilience, recovery after an incident, and regular testing of the effectiveness of the measures. A successful hacker attack does not in itself mean the measures were inappropriate; appropriateness is judged against the risk (C-340/21).

Art. 33 Notification of a personal data breach to the supervisory authority

A personal data breach is notified to the supervisory authority without undue delay, where feasible within 72 hours, unless the risk to people's rights is unlikely. A processor notifies the controller without undue delay. Internal records of all breaches are mandatory in every case, including those not notified.

Art. 34 Communication of a personal data breach to the data subject

Where the risk to people is high, the breach is communicated to them too, in clear terms and with recommendations. Exceptions apply where there was effective protection (encryption), where subsequent measures were taken, or where it would take disproportionate effort (then a public communication).

Art. 35 Data protection impact assessment

A data protection impact assessment (DPIA) before processing that is likely to be high-risk, typically a systematic and extensive evaluation of people including profiling, large-scale processing of special categories, or systematic monitoring of public areas. The ÚOOÚ maintains a list of operations that always require a DPIA. The methodological forerunner of the FRIA in Art. 27 of the AI Act.

Art. 36 Prior consultation

Where a DPIA shows a high residual risk that the controller cannot mitigate, it goes to the supervisory authority for prior consultation before processing.

Art. 37 Designation of the data protection officer

A data protection officer is mandatory for public authorities, for large-scale regular and systematic monitoring, and for large-scale processing of special categories. There may be one for a group, and the DPO may be internal or external.

Art. 38 Position of the data protection officer

The position of the DPO: involvement in all data protection matters, resources, independence (no instructions on how to perform the role, no dismissal for performing it) and direct access to top management.

Art. 39 Tasks of the data protection officer

The tasks of the DPO: to inform and advise, monitor compliance, advise on the DPIA, and act as the contact point for the authority and for data subjects.

Art. 40 Codes of conduct

Associations may draw up codes of conduct that specify the Regulation for their sector, approved by the supervisory authority.

Art. 41 Monitoring of approved codes of conduct

Compliance with a code may be monitored by an accredited body, without prejudice to the powers of the supervisory authority.

Art. 42 Certification

Voluntary certifications, seals and marks as evidence of compliance, valid for at most three years; certification does not reduce liability.

Art. 43 Certification bodies

Certification bodies are accredited by the supervisory authority or the national accreditation body.

Chapter V · Art. 44–50

Transfers to third countries

The chain of conditions for every transfer of personal data outside the EU and the EEA.

Art. 44 General principle for transfers

The general principle: a transfer outside the EU only where the conditions of Chapter V are met, including for onward transfers. The level of protection must not be undermined by the transfer.

Art. 45 Transfers on the basis of an adequacy decision

A transfer on the basis of a Commission adequacy decision, in which case no specific authorisation is needed. For the United States the current decision is the one for the EU–US Data Privacy Framework. History shows that such decisions fall at the Court of Justice (C-311/18 Schrems II), while the current framework has so far held before the General Court (T-553/23 Latombe).

Art. 46 Transfers subject to appropriate safeguards

Without an adequacy decision, appropriate safeguards step in, most often the Commission's standard contractual clauses, and further binding corporate rules, approved codes or certifications.

Art. 47 Binding corporate rules

Binding corporate rules (BCR) for transfers within a group, with their required content and approval by the supervisory authority through the consistency mechanism.

Art. 48 Transfers or disclosures not authorised by Union law

A judgment or decision of a third-country authority does not by itself justify a transfer; it is recognised only on the basis of an international agreement. A safeguard against foreign orders being enforced directly against European data.

Art. 49 Derogations for specific situations

Derogations for specific situations: explicit consent after being warned of the risks, necessity for a contract, legal claims, vital interests and others. They are read narrowly, as a last resort, not a routine channel.

Art. 50 International cooperation for the protection of personal data

International cooperation between the Commission, the supervisory authorities and third countries.

Chapter VI · Art. 51–59

Independent supervisory authorities

The standing and powers of the supervisory authorities. In the Czech Republic the supervisory authority is the ÚOOÚ.

Art. 51 Supervisory authority

Each State sets up an independent supervisory authority. In the Czech Republic this is the Úřad pro ochranu osobních údajů (Office for Personal Data Protection, ÚOOÚ) under Act No. 110/2019 Sb.

Art. 52 Independence

Complete independence: no external instructions, its own budget and staff.

Art. 53 General conditions for the members of the supervisory authority

The authority's members are appointed transparently, with qualifications required and safeguards against dismissal on grounds other than those set by law.

Art. 54 Rules on the establishment of the supervisory authority

The establishment, term of office and duty of confidentiality are governed by the law of the Member State.

Art. 55 Competence

The authority's competence is on the territory of its own State, with an exception for processing by courts acting in their judicial capacity.

Art. 56 Competence of the lead supervisory authority

The lead supervisory authority, determined by the controller's main establishment, handles cross-border cases (the one-stop-shop). One point of contact for data subjects, one main counterpart for cross-border controllers.

Art. 57 Tasks

A catalogue of tasks: to monitor and enforce, raise awareness, handle complaints, cooperate, keep the DPIA lists and more. Handling complaints is free of charge. A high number of complaints does not relieve the authority of its duty to deal with them; only manifestly unfounded or excessive requests may be refused or charged for (C-416/23).

Art. 58 Powers

Powers that are investigative (information, audits, access to premises), corrective (warnings, reprimands, orders, limitation up to a ban on processing, ordering erasure, and fines) and authorising or advisory. A ban on processing can hurt more than a fine.

Art. 59 Activity reports

Annual activity reports.

Chapter VII · Art. 60–76

Cooperation and consistency

The machinery for cross-border cases: the lead authority, the consistency mechanism and the European Data Protection Board.

Art. 60 Cooperation between the lead supervisory authority and the other supervisory authorities concerned

The mechanics of cooperation between the lead authority and the authorities concerned: draft decisions, relevant and reasoned objections, and referral to the Board where there is disagreement.

Art. 61 Mutual assistance

Mutual assistance between authorities: information and permitted inquiries, with one month to reply.

Art. 62 Joint operations of supervisory authorities

Joint operations and joint investigations by authorities of several States.

Art. 63 Consistency mechanism

The consistency mechanism: the framework for the consistent application of the Regulation across the Union through the Board.

Art. 64 Opinion of the Board

Board opinions on draft measures by authorities that have Union-wide reach (DPIA lists, clauses, BCR and others).

Art. 65 Dispute resolution by the Board

Binding dispute resolution by the Board, among other things where there are relevant objections to a lead authority's draft decision. The final word in cross-border cases.

Art. 66 Urgency procedure

The urgency procedure: an authority's provisional measures with immediate effect on its own territory, and a rapid opinion from the Board.

Art. 67 Exchange of information

Electronic exchange of information between the authorities and the Board.

Art. 68 European Data Protection Board

The European Data Protection Board (EDPB), a body of the Union made up of the heads of the national authorities and the European Data Protection Supervisor.

Art. 69 Independence

The independence of the Board.

Art. 70 Tasks of the Board

The tasks of the Board: consistent application, guidelines and recommendations (in practice a key source of interpretation), opinions and binding decisions.

Art. 71 Reports

The Board's annual reports.

Art. 72 Procedure

The Board decides by simple majority, and its rules of procedure by a two-thirds majority.

Art. 73 Chair

Election of the Chair of the Board and the deputy chairs.

Art. 74 Tasks of the Chair

The tasks of the Chair: convening, organising, and the time limits in dispute resolution.

Art. 75 Secretariat

The Board's secretariat is provided by the European Data Protection Supervisor under the direction of the Chair of the Board.

Art. 76 Confidentiality

The confidentiality of the Board's discussions where the Board so decides.

Chapter VIII · Art. 77–84

Remedies, liability and penalties

The complaint, the court actions, compensation and the famous fine ceilings.

Art. 77 Right to lodge a complaint with a supervisory authority

The right to lodge a complaint with a supervisory authority, in particular in the place of residence, place of work or place of the infringement. The free and most common entry point into enforcement.

Art. 78 Right to an effective judicial remedy against a supervisory authority

A judicial remedy against a legally binding decision of an authority and against its failure to act on a complaint.

Art. 79 Right to an effective judicial remedy against a controller or processor

A judicial remedy directly against the controller or processor, independently of a complaint to an authority. Proceedings may be brought where the establishment is or where the data subject resides.

Art. 80 Representation of data subjects

Non-profit bodies may represent the data subject, and (where the State allows it) act even without a mandate. The collective dimension, which the Representative Actions Directive builds on, and to whose annex the AI Act added itself in Art. 110.

Art. 81 Suspension of proceedings

A stay of proceedings where parallel proceedings on the same processing are pending before courts of several States.

Art. 82 Right to compensation and liability

The right to compensation for material and non-material damage. The controller is liable for infringements of the Regulation, the processor only for its own specific duties or for going beyond the instructions, jointly and severally with a right of recourse. Exemption only on proof that it is in no way responsible for the damage. An infringement of the Regulation does not by itself found a claim, but the damage need not cross any threshold of seriousness (C-300/21), and the fear of misuse of data after a leak can itself be non-material damage (C-340/21).

Art. 83 General conditions for imposing administrative fines

Two fine tiers: up to EUR 10 million or 2% of turnover (among others the controller and processor duties in Art. 8, 11, 25 to 39, 42, 43) and up to EUR 20 million or 4% of turnover (the principles, the legal bases, the rights of data subjects, transfers). The criteria in paragraph 2 (nature, intent, mitigation, recidivism, cooperation) are the checklist for arguing about the amount.

Art. 84 Penalties

States lay down other penalties for infringements not covered by fines, penalties that are effective, proportionate and dissuasive.

Chapter IX · Art. 85–91

Specific processing situations

The intersections with other values: journalism, official documents, employment, research, churches.

Art. 85 Processing and freedom of expression and information

Reconciliation with the right to freedom of expression and information: States set exceptions for journalism and academic, artistic and literary expression. In the Czech Republic, § 17 et seq. of Act No. 110/2019 Sb.

Art. 86 Processing and public access to official documents

Personal data in official documents may be disclosed under the rules on access to information; reconciliation with freedom of access to information.

Art. 87 Processing of the national identification number

States may further regulate the processing of national identification numbers, in the Czech Republic birth numbers.

Art. 88 Processing in the context of employment

An opening clause for the employment context: States may lay down more specific rules for processing in employment relationships (recruitment, performance of the contract, management and termination, monitoring).

Art. 89 Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes

Safeguards for archiving in the public interest, scientific and historical research and statistics (minimisation, pseudonymisation) and possible derogations from the rights of data subjects.

Art. 90 Obligations of secrecy

States may regulate the authority's powers over persons bound by professional secrecy, in the Czech Republic relevant among others for advocates.

Art. 91 Existing data protection rules of churches and religious associations

Churches and religious associations with comprehensive rules already in place may continue to apply them, provided they bring them into line, under a specific supervision.

Chapter XI · Art. 94–99

Final provisions

The relationship to the earlier Directive, to ePrivacy, and the start of application.

Art. 94 Repeal of Directive 95/46/EC

Repeal of Directive 95/46/EC; references to it are read as references to the Regulation. Continuity of interpretation, the old case law remains usable where the text carried over.

Art. 95 Relationship with Directive 2002/58/EC

The relationship to the e-Privacy Directive (2002/58/EC): where ePrivacy imposes specific obligations (cookies, electronic marketing), the GDPR does not add a second round of the same duties.

Art. 96 Relationship with previously concluded Agreements

International agreements on transfers concluded before the Regulation remain in force until amended.

Art. 97 Commission reports

Periodic Commission reports on the evaluation and review of the Regulation.

Art. 98 Review of other Union legal acts on data protection

The Commission may propose amendments to other Union data protection acts for the sake of consistency.

Art. 99 Entry into force and application

Entry into force on the twentieth day after publication and application from 25 May 2018. The whole era of enforcement is counted from that date.

Sources