General Data Protection Regulation (GDPR)
The EU regime for processing personal data: lawful basis, the data-protection principles, heightened conditions for health data as a special category, security of processing, breach notification, data-subject rights, and restrictions on transfers outside the EU.
Always verify against the current published text before relying on it for a submission or inspection.
Scope & applicability
Any processing of personal data by an organisation established in the EU, or targeting individuals in the EU. In regulated life sciences it reaches clinical-trial data, pharmacovigilance case records, and employee and healthcare-professional data — running alongside GxP obligations rather than instead of them, which is where the retention-versus-erasure tension arises.
Key requirements
- Article 5 — the processing principles, including purpose limitation, data minimisation and storage limitation
- Article 6 lawful basis and Article 9 conditions for processing health and other special-category data
- Article 32 — security of processing appropriate to risk, including pseudonymisation and encryption where appropriate
- Article 33 — notification of a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours
- Chapter V — transfers to third countries, and Article 89 safeguards and derogations for scientific research
Implementation tips
- Resolve the retention conflict as policy, not per request: GxP and clinical-trial law impose retention periods that a Article 17 erasure request cannot override, and the lawful basis and retention schedule should state that in advance
- Consent under GDPR and informed consent to participate in a trial are different instruments — conflating them is the most common design error in clinical data protection
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
Regulation (EU) 2016/679: frequently asked questions
Quick answers to common questions about Regulation (EU) 2016/679.
What is Regulation (EU) 2016/679?
Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR) — is a regulation issued by the European Commission — EudraLex (European Union). The EU regime for processing personal data: lawful basis, the data-protection principles, heightened conditions for health data as a special category, security of processing, breach notification, data-subject rights, and restrictions on transfers outside the EU.
Who does Regulation (EU) 2016/679 apply to?
Any processing of personal data by an organisation established in the EU, or targeting individuals in the EU. In regulated life sciences it reaches clinical-trial data, pharmacovigilance case records, and employee and healthcare-professional data — running alongside GxP obligations rather than instead of them, which is where the retention-versus-erasure tension arises.
What are the key requirements of Regulation (EU) 2016/679?
EC Regulation (EU) 2016/679 requires, among other things: Article 5 — the processing principles, including purpose limitation, data minimisation and storage limitation; Article 6 lawful basis and Article 9 conditions for processing health and other special-category data; Article 32 — security of processing appropriate to risk, including pseudonymisation and encryption where appropriate; Article 33 — notification of a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours.
When was Regulation (EU) 2016/679 last updated?
The current version of Regulation (EU) 2016/679 dates from May 2018.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.