CHAPTER XIFINAL PROVISIONS

Article 99Entry into force and application

Official text

(1)This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.

(2)It shall apply from 25 May 2018.

Commentary

Article 99 is the final provision of the GDPR. It determines two distinct dates:

  1. the date on which the GDPR entered into force as an EU legislative act; and

  2. the later date from which its substantive provisions became applicable and enforceable.

Although Article 99 is short, the distinction between entry into force and application is legally important. The GDPR did not become fully applicable immediately after it entered into force. Instead, the EU legislature created a two-year transitional period to allow Member States, supervisory authorities, controllers, processors and other affected organisations to prepare for the new legal framework.

There is no recital specifically assigned to Article 99. The provision should therefore be understood in light of its wording, the general rules on EU legislation in Article 297 TFEU, and related transitional provisions, particularlyArticles 91, 92 and 94 GDPR andRecital 171.

1. Structure and purpose of Article 99

Article 99 contains two paragraphs, each performing a different function:

  • Article 99(1) determines when the GDPR entered into force.

  • Article 99(2) determines when the GDPR began to apply.

These dates must not be treated as interchangeable. Entry into force means that the GDPR became part of the EU legal order. Application means that its substantive rules became operational and generally enforceable against those subject to the Regulation.

The timeline can be summarised as follows:

  • 4 May 2016: GDPR published in the Official Journal of the European Union.

  • 24 May 2016: GDPR entered into force.

  • 25 May 2018: GDPR became applicable.

  • 25 May 2018: Directive 95/46/EC was repealed under Article 94(1).

The period between 24 May 2016 and 25 May 2018 was therefore a transitional or implementation period. It was not an optional extension after the GDPR had already become enforceable. During that period, the Regulation existed as EU law, but its general substantive obligations had not yet become applicable.


2. Article 99(1): Entry into force

Article 99(1) states that the GDPR entered into force on the twentieth day following its publication in the Official Journal of the European Union.

The GDPR was published in the Official Journal on 4 May 2016. Applying the twenty-day rule, it entered into force on24 May 2016.

This corresponds with the general rule in Article 297(1) TFEU, under which EU legislative acts enter into force on the date specified in them or, if no date is specified, on the twentieth day following publication.


3. 2.1 Meaning of “entry into force”

Entry into force means that the GDPR became a valid part of the EU legal framework. From 24 May 2016, the Regulation legally existed and could support preparatory, institutional and transitional action.

However, entry into force did not mean that every controller and processor was immediately required to comply with all operative GDPR duties. That result followed only from the application date specified in Article 99(2).

This distinction is common in legislation involving significant structural reform. A legislative act may enter into force first, while its obligations become applicable later. The intervening period permits the establishment of institutions, adoption of implementing arrangements, revision of national laws and preparation by regulated entities.

Illustration

A retailer processing customer data in June 2016 was not yet subject to the GDPR’s directly applicable operational framework merely because the Regulation had entered into force. Until 25 May 2018, the applicable data protection framework continued to include Directive 95/46/EC as implemented through national law. Nevertheless, the retailer had formal notice that its processing systems would need to comply with the GDPR by 25 May 2018.


4. 2.2 Why publication matters

Publication in the Official Journal gives authoritative public notice of EU legislation. It provides the official text from which the commencement period is calculated.

The publication requirement supports legal certainty. Individuals, organisations and Member States must be capable of determining:

  • the authentic legislative text;

  • the date of entry into force;

  • the date from which obligations apply;

  • the time available for preparation.

A preliminary political agreement, press release or adopted draft does not substitute for formal publication. Article 99 ties commencement to the official legislative process.


5. 2.3 Effect during the transitional period

Once the GDPR entered into force, the EU institutions and Member States had to respect the legislative transition it established. They could begin or complete measures needed for its application.

During the transition period, Member States could:

  • review laws implementing Directive 95/46/EC;

  • repeal or amend incompatible provisions;

  • adopt supplementary national rules where the GDPR permitted them;

  • prepare rules concerning employment, journalism, research and other opening clauses;

  • reorganise or strengthen supervisory authorities.

Supervisory authorities could similarly develop guidance, procedures and enforcement structures in anticipation of the application date.

The Commission could also exercise relevant preparatory powers where the GDPR permitted action after entry into force. For example, the delegation of power under Articles 12(8), 43(8) and 92 began from 24 May 2016.


6. Article 99(2): Application from 25 May 2018

Article 99(2) states that the GDPR applies from 25 May 2018. From that date, its substantive and procedural requirements became operational.

This means that from 25 May 2018, processing falling within the GDPR’s material and territorial scope had to comply with requirements including:

  • the principles in Article 5;

  • the legal bases in Article 6;

  • the conditions for consent in Article 7;

  • transparency obligations under Articles 12 to 14;

  • data subject rights under Articles 15 to 22;

  • controller accountability under Article 24;

  • processor requirements under Article 28;

  • security obligations under Article 32;

  • breach notification under Articles 33 and 34;

  • international transfer rules under Chapter V;

  • supervisory and enforcement mechanisms;

  • administrative fines under Article 83.

Illustration

An organisation operating a customer database created in 2012 could continue processing after 25 May 2018 only if that continuing processing complied with the GDPR. The age of the database did not remove it from the Regulation. The relevant question was whether the processing occurring on and after the application date met GDPR requirements.


7. 3.1 Purpose of the two-year transition

The GDPR introduced substantial changes to the previous framework. The transition period allowed affected organisations to identify and address compliance gaps before enforcement began.

Controllers and processors could use this period to:

  • map personal data processing activities;

  • identify controllers, joint controllers and processors;

  • review lawful bases;

  • update privacy notices;

  • validate existing consent;

  • revise processor agreements;

  • develop retention schedules;

  • introduce data subject request procedures;

  • review international transfer arrangements;

  • strengthen security controls;

  • establish breach-response procedures;

  • conduct data protection impact assessments;

  • appoint Data Protection Officers where required;

  • build evidence of compliance.

Illustration

A hospital operating under pre-GDPR national law could use the transition period to catalogue patient-data processing, identify Article 6 and Article 9 grounds, revise notices, restrict access to medical records, document retention periods, and implement procedures for access and rectification requests. The transition period was therefore intended for active preparation. It was not a period during which organisations could wait until the final day and then begin assessing compliance.


8. 3.2 Continuing processing begun before 25 May 2018

The application date did not distinguish between new processing and processing already underway. A processing activity that began before 25 May 2018 became subject to the GDPR if it continued after that date.

This principle is reflected in Recital 171, which states that processing already underway should be brought into conformity with the GDPR during the two-year period.

Illustration

A company began profiling customers for marketing in 2015. If profiling continued after 25 May 2018, the company had to ensure by that date that the activity complied with purpose limitation, lawfulness, transparency, profiling requirements, objection rights and accountability. It could not rely indefinitely on the fact that the system had been introduced under the former Directive. At the same time, the GDPR did not require every processing operation to be stopped and restarted. Compliance depended on whether the continuing operation satisfied the GDPR from the application date.


Recital 171 specifically addressed consent obtained under Directive 95/46/EC. Controllers were not automatically required to obtain fresh consent from every data subject merely because the GDPR became applicable.

Existing consent could continue to support processing where the manner in which it had been obtained already satisfied GDPR standards, including that it was:

  • freely given;

  • specific;

  • informed;

  • unambiguous;

  • expressed through a clear affirmative action;

  • capable of withdrawal.

Illustration

A newsletter subscriber had actively selected an unticked marketing box in 2016 after receiving clear information about the newsletter. If this mechanism met GDPR conditions and withdrawal remained easy, new consent was not necessarily required in 2018. By contrast, legacy consent based on silence, inactivity, pre-ticked boxes, hidden clauses or bundled terms would generally not meet the GDPR’s stronger requirements.

Illustration

A company treated every customer who failed to opt out of marketing in 2014 as having consented. That implied permission would not normally satisfy Articles 4(11), 6(1)(a) and 7. The controller would need another lawful basis or fresh valid consent before continuing the consent-based processing after 25 May 2018.


10. Relationship with Article 94

Article 99 should be read closely with Article 94, which repealed Directive 95/46/EC with effect from 25 May 2018.

The two provisions were coordinated to avoid a gap or an unnecessary overlap:

  • until 24 May 2018, the Directive-based framework continued to operate;

  • from 25 May 2018, the GDPR became applicable;

  • on the same date, Directive 95/46/EC was repealed.

This created a direct transition from the former Directive framework to the GDPR.

Article 94(2) also preserves interpretative continuity by providing that references to the repealed Directive are to be understood as references to the GDPR, and references to the Article 29 Working Party are to be construed as references to the EDPB.


11. Relationship with Article 91

Article 99 is also relevant to Article 91, which concerns churches and religious associations or communities.

Under Article 91, comprehensive data protection rules applied by churches or religious bodies on 24 May 2016 could continue, provided those rules were brought into line with the GDPR.

The date of 24 May 2016 is significant because it is the GDPR’s date of entry into force.

Illustration

A religious community with an existing internal data protection framework could not continue that framework unchanged merely because it predated the GDPR. Its rules had to be adapted to align with the Regulation, and independent supervision had to meet Article 91 requirements.


12. Enforcement and acts occurring across the application date

Where conduct spans the application date, it is important to distinguish between:

  • completed processing before 25 May 2018;

  • processing continuing after that date;

  • new processing beginning after that date.

The GDPR applies to processing taking place from 25 May 2018 onward. This may include continued storage, because storage is itself “processing” under Article 4(2).

Illustration

A controller unlawfully collected data in 2017 but kept using and storing it after 25 May 2018. The original collection occurred before the GDPR applied, but the continuing storage and use after the application date must be assessed under the GDPR. This does not mean the GDPR automatically applies retrospectively to every completed act before 25 May 2018. The distinction depends on whether the relevant processing was completed or remained ongoing after the application date.


13. Practical significance of Article 99 today

The transition period has ended, but Article 99 remains important for:

  • determining the temporal applicability of the GDPR;

  • analysing historical processing;

  • assessing legacy consent;

  • interpreting enforcement concerning conduct spanning May 2018;

  • understanding the relationship between the Directive and the GDPR;

  • distinguishing entry into force from application.

It also illustrates a broader legislative principle: major regulatory reforms may legally exist before their operative obligations become enforceable.


14. Key Takeaways

Article 99 establishes two different commencement dates:

  • The GDPR entered into force on 24 May 2016, twenty days after publication on 4 May 2016.

  • The GDPR became applicable on 25 May 2018.

The period between those dates gave Member States, supervisory authorities, controllers and processors two years to prepare. Processing already underway had to be brought into conformity by the application date. Legacy consent could continue only if it already met GDPR standards. On 25 May 2018, Directive 95/46/EC was repealed and the GDPR became the operative EU data protection framework.

Article 99 is therefore not merely a closing formality. It defines the GDPR’s temporal scope, structures the transition from the former Directive, and determines the date from which the Regulation’s substantive rights, duties and enforcement framework became legally applicable.