GDPR
General Data Protection Regulation (Regulation (EU) 2016/679)
- Jurisdiction
- European Union · EU
- In force since
- 25 May 2018
- Primary source
- Official text
Who it applies to
Any organisation processing personal data of people in the EU, regardless of where it is established.
Documents it requires
- Privacy policy
- Cookie policy and consent banner
- Data processing agreement (DPA)
Rights it grants
- Access a copy of their data
- Correct inaccurate data
- Have their data deleted
- Receive their data in a portable format
- Object to certain processing
- Restrict processing
- Withdraw consent at any time
- Ask for human review of an automated decision
Cookies and consent
Nothing non-essential may load before the visitor agrees. Analytics and marketing scripts must be blocked until then — a banner that only informs is not enough.
Key provisions
- Art. 6 — Lawful bases for processing
- Art. 13 — Information to provide when collecting data
- Art. 15–22 — Data subject rights
- Art. 28 — Processor contracts (DPA)
- Art. 44–49 — International transfers
What we are watching in Unión Europea
These are the changes our update engine tracks for this market. When one takes effect, the documents it affects are regenerated and republished — you do not have to notice it yourself.
- EU AI Act — modelos de propósito general (GPAI)2 August 2025
Obligaciones para proveedores de modelos de IA de propósito general: documentación técnica y resúmenes de datos de entrenamiento.
- EU Data Act12 September 2025
Nuevas reglas de acceso y portabilidad de datos generados por productos y servicios conectados.
- EU AI Act — obligaciones de transparencia (art. 50)from 2 August 2026
Aplican las obligaciones de transparencia del Reglamento de IA: avisar de que se interactúa con IA y etiquetar el contenido generado. El Omnibus digital (adoptado en junio de 2026) mantiene esta fecha.
- EU AI Act — fin de la gracia para el marcado de contenido (Omnibus digital)from 2 December 2026
Termina el periodo de gracia del Omnibus digital: los sistemas de IA generativa ya comercializados antes del 2 de agosto de 2026 deben incorporar el marcado legible por máquina del contenido generado (art. 50.2).
- EU AI Act — sistemas de alto riesgo (Anexo III)from 2 December 2027
Aplican las obligaciones para sistemas de alto riesgo independientes del Anexo III, aplazadas del 2 de agosto de 2026 al 2 de diciembre de 2027 por el Omnibus digital; los sistemas embebidos en productos regulados (Anexo I) pasan al 2 de agosto de 2028.
- EU AI Act — sistemas de alto riesgo embebidos (Anexo I)from 2 August 2028
Aplican las obligaciones para sistemas de IA de alto riesgo embebidos en productos regulados (Anexo I), aplazadas al 2 de agosto de 2028 por el Omnibus digital.
See what your site is actually missing
Paste your URL. We fetch the live page, detect the trackers, payments and AI calls that really ship to visitors, and tell you which documents and consent you need. No signup.
No signup · result in seconds
GDPR for your kind of product
- GDPR for a SaaS
- GDPR for a marketplace
- GDPR for an online store
- GDPR for a mobile app
- GDPR for an AI chatbot
- GDPR for an AI image generator
- GDPR for an AI writing tool
- GDPR for a fintech app
- GDPR for a health app
- GDPR for an education platform
- GDPR for a community platform
- GDPR for a newsletter
- GDPR for a booking site
- GDPR for a portfolio site
This page is an engineering summary of publicly available regulatory requirements, generated from LexVibe's framework registry — not legal advice. Every framework links to its official text so you can check it yourself. For decisions about your own compliance posture, consult the primary sources and a lawyer qualified in the relevant jurisdiction.