Regulation (EU) 2016/679 (General Data Protection Regulation)
Below is what the official text of Regulation (EU) 2016/679 (General Data Protection Regulation) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit business established in EU or EEA: Applies, or may apply: conditions to check.
- A US business with users in EU or EEA: Applies, or may apply: conditions to check.
- A US business with no users in EU or EEA: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | Lays down rules on the protection of natural persons with regard to the processing of personal data and on the free movement of such data; binds controllers and processors.Official wordingThis Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data. | publications.europa.eu read 2026-10-06 |
| When it applies to a business | Applies to processing in the context of an establishment of a controller or processor in the Union, and to controllers/processors not established in the Union when offering goods or services to, or monitoring the behaviour of, data subjects in the Union. Conditions to check: The text says 'Union'; extension to the EEA is by the 'Text with EEA relevance' note, not read from an EEA decision. 'Establishment', 'offering' and 'monitoring' are not defined in Art. 3. Art. 2(2) exempts e.g. purely personal or household activity and some public-authority processing. No size or revenue threshold. Official wordingThis Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: (a) the offering of goods or services | publications.europa.eu read 2026-10-06 |
| In force from | 2018-05-25 Entered into force on the twentieth day after publication; applies from 25 May 2018 Official wordingIt shall apply from 25 May 2018. | publications.europa.eu read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Included in the paid checklist. See the checklist | — |
| Breach notification | Included in the paid checklist. See the checklist | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here