GDPR Recitals
All 173 recitals of Regulation (EU) 2016/679. Recitals explain the reasoning behind each article and are the main interpretive aid for the GDPR. Click any recital to open its full text.
- Rec. 1Data Protection as a Fundamental Right
- Rec. 2Respect of the Fundamental Rights and Freedoms
- Rec. 3Directive 95/46/EC Harmonisation
- Rec. 4Data Protection in Balance with Other Fundamental Rights
- Rec. 5Cooperation Between Member States to Exchange Personal Data
- Rec. 6Ensuring a High Level of Data Protection Despite the Increased Exchange of Data
- Rec. 7The Framework is Based on Control and Certainty
- Rec. 8Adoption into National Law
- Rec. 9Different Standards of Protection by the Directive 95/46/EC
- Rec. 10Harmonised Level of Data Protection Despite National Scope
- Rec. 11Harmonisation of the Powers and Sanctions
- Rec. 12Authorization of the European Parliament and the Council
- Rec. 13Taking Account of Micro, Small and Medium-Sized Enterprises
- Rec. 14Not Applicable to Legal Persons
- Rec. 15Technology Neutrality
- Rec. 16Not Applicable to Activities Regarding National and Common Security
- Rec. 17Adaptation of Regulation (EC) No 45/2001
- Rec. 18Not Applicable to Personal or Household Activities
- Rec. 19Not Applicable to Criminal Prosecution
- Rec. 20Respecting the Independence of the Judiciary
- Rec. 21Liability Rules of Intermediary Service Providers Shall Remain Unaffected
- Rec. 22Processing by an Establishment
- Rec. 23Applicable to Controllers/Processors Not Established in the Union if Data Subjects Within the Union are Targeted
- Rec. 24Applicable to Controllers/Processors Not Established in the Union if Data Subjects Within the Union are Profiled
- Rec. 25Applicable to Controllers Due to International Law
- Rec. 26Not Applicable to Anonymous Data
- Rec. 27Not Applicable to Data of Deceased Persons
- Rec. 28Introduction of Pseudonymisation
- Rec. 29Pseudonymisation at the Same Controller
- Rec. 30Online Identifiers for Profiling and Identification
- Rec. 31Not Applicable to Public Authorities in Connection with Their Official Tasks
- Rec. 32Conditions for Consent
- Rec. 33Consent to Certain Areas of Scientific Research
- Rec. 34Genetic Data
- Rec. 35Health Data
- Rec. 36Determination of the Main Establishment
- Rec. 37Group of undertakings
- Rec. 38Special Protection of Children's Personal Data
- Rec. 39Principles of Data Processing
- Rec. 40Lawfulness of Data Processing
- Rec. 41Legal Basis or Legislative Measures
- Rec. 42Burden of Proof and Requirements for Consent
- Rec. 43Freely Given Consent
- Rec. 44Performance of a Contract
- Rec. 45Fulfillment of Legal Obligations
- Rec. 46Vital Interests of the Data Subject
- Rec. 47Overriding Legitimate Interest
- Rec. 48Overriding Legitimate Interest Within Group of Undertakings
- Rec. 49Network and Information Security as Overriding Legitimate Interest
- Rec. 50Further Processing of Personal Data
- Rec. 51Protecting Sensitive Personal Data
- Rec. 52Exceptions to the Prohibition on Processing Special Categories of Personal Data
- Rec. 53Processing of Sensitive Data in Health and Social Sector
- Rec. 54Processing of Sensitive Data in Public Health Sector
- Rec. 55Public Interest in Processing by Official Authorities for Objectives of Recognized Religious Communities
- Rec. 56Processing Personal Data on People's Political Opinions by Parties
- Rec. 57Additional Data for Identification Purposes
- Rec. 58The Principle of Transparency
- Rec. 59Procedures for the Exercise of the Rights of the Data Subjects
- Rec. 60Information Obligation
- Rec. 61Time of Information
- Rec. 62Exceptions to the Obligation to Provide Information
- Rec. 63Right of Access
- Rec. 64Identity Verification
- Rec. 65Right of Rectification and Erasure
- Rec. 66Right to be Forgotten
- Rec. 67Restriction of Processing
- Rec. 68Right of Data Portability
- Rec. 69Right to Object
- Rec. 70Right to Object to Direct Marketing
- Rec. 71Profiling
- Rec. 72Guidance of the European Data Protection Board Regarding Profiling
- Rec. 73Restrictions of Rights and Principles
- Rec. 74Responsibility and Liability of the Controller
- Rec. 75Risks to the Rights and Freedoms of Natural Persons
- Rec. 76Risk Assessment
- Rec. 77Risk Assessment Guidelines
- Rec. 78Appropriate Technical and Organisational Measures
- Rec. 79Allocation of the Responsibilities
- Rec. 80Designation of a Representative
- Rec. 81The Use of Processors
- Rec. 82Record of Processing Activities
- Rec. 83Security of Processing
- Rec. 84Risk Evaluation and Impact Assessment
- Rec. 85Notification Obligation of Breaches to the Supervisory Authority
- Rec. 86Notification of Data Subjects in Case of Data Breaches
- Rec. 87Promptness of Reporting / Notification
- Rec. 88Format and Procedures of the Notification
- Rec. 89Elimination of the General Reporting Requirement
- Rec. 90Data Protection Impact Assessement
- Rec. 91Necessity of a Data Protection Impact Assessment
- Rec. 92Broader Data Protection Impact Assessment
- Rec. 93Data Protection Impact Assessment at Authorities
- Rec. 94Consultation of the Supervisory Authority
- Rec. 95Support by the Processor
- Rec. 96Consultation of the Supervisory Authority in the Course of a Legislative Process
- Rec. 97Data Protection Officer
- Rec. 98Preparation of Codes of Conduct by Organisations and Associations
- Rec. 99Consultation of Stakeholders and Data Subjects in the Development of Codes of Conduct
- Rec. 100Certification
- Rec. 101General Principles for International Data Transfers
- Rec. 102International Agreements for an Appropriate Level of Data Protection
- Rec. 103Appropriate Level of Data Protection Based on an Adequacy Decision
- Rec. 104Criteria for an Adequacy Decision
- Rec. 105Consideration of International Agreements for an Adequacy Decision
- Rec. 106Monitoring and Periodic Review of the Level of Data Protection
- Rec. 107Amendment, Revocation and Suspension of Adequacy Decisions
- Rec. 108Appropriate Safeguards
- Rec. 109Standard Data Protection Clauses
- Rec. 110Binding Corporate Rules
- Rec. 111Exceptions for Certain Cases of International Transfers
- Rec. 112Data Transfers due to Important Reasons of Public Interest
- Rec. 113Transfers Qualified as Not Repetitive and that Only Concern a Limited Number of Data Subjects
- Rec. 114Safeguarding of Enforceability of Rights and Obligations in the Absence of an Adequacy Decision
- Rec. 115Rules in Third Countries Contrary to the Regulation
- Rec. 116Cooperation Among Supervisory Authorities
- Rec. 117Establishment of Supervisory Authorities
- Rec. 118Monitoring of the Supervisory Authorities
- Rec. 119Organisation of Several Supervisory Authorities of a Member State
- Rec. 120Features of Supervisory Authorities
- Rec. 121Independence of the Supervisory Authorities
- Rec. 122Responsibility of the Supervisory Authorities
- Rec. 123Cooperation of the Supervisory Authorities with Each Other and with the Commission
- Rec. 124Lead Authority Regarding Processing in Several Member States
- Rec. 125Competences of the Lead Authority
- Rec. 126Joint Decisions
- Rec. 127Information of the Supervisory Authority Regarding Local Processing
- Rec. 128Responsibility Regarding Processing in the Public Interest
- Rec. 129Tasks and Powers of the Supervisory Authorities
- Rec. 130Consideration of the Authority with which the Complaint has been Lodged
- Rec. 131Attempt of an Amicable Settlement
- Rec. 132Awareness-Raising Activities and Specific Measures
- Rec. 133Mutual Assistance and Provisional Measures
- Rec. 134Participation in Joint Operations
- Rec. 135Consistency Mechanism
- Rec. 136Binding Decisions and Opinions of the Board
- Rec. 137Provisional Measures
- Rec. 138Urgency Procedure
- Rec. 139European Data Protection Board
- Rec. 140Secretariat and Staff of the Board
- Rec. 141Right to Lodge a Complaint
- Rec. 142The Right of Data Subjects to Mandate a Not-For-Profit Body, Organisation or Association
- Rec. 143Judicial Remedies
- Rec. 144Related Proceedings
- Rec. 145Choice of Venue
- Rec. 146Indemnity
- Rec. 147Jurisdiction
- Rec. 148Penalties
- Rec. 149Penalties for Infringements of National Rules
- Rec. 150Administrative Fines
- Rec. 151Administrative Fines in Denmark and Estonia
- Rec. 152Power of Sanction of the Member States
- Rec. 153Processing of Personal Data Solely for Journalistic Purposes or for the Purposes of Academic, Artistic or Literary Expression
- Rec. 154Principle of Public Access to Official Documents
- Rec. 155Processing in the Employment Context
- Rec. 156Processing for Archiving, Scientific or Historical Research or Statistical Purposes
- Rec. 157Information from Registries and Scientific Research
- Rec. 158Processing for Archiving Purposes
- Rec. 159Processing for Scientific Research Purposes
- Rec. 160Processing for Historical Research Purposes
- Rec. 161Consenting to the Participation in Clinical Trials
- Rec. 162Processing for Statistical Purposes
- Rec. 163Production of European and National Statistics
- Rec. 164Professional or Other Equivalent Secrecy Obligations
- Rec. 165No Prejudice of the Status of Churches and Religious Associations
- Rec. 166Delegated Acts of the Commission
- Rec. 167Implementing Powers of the Commission
- Rec. 168Implementing Acts on Standard Contractual Clauses
- Rec. 169Immediately Applicable Implementing Acts
- Rec. 170Principle of Subsidiarity and Principle of Proportionality
- Rec. 171Repeal of Directive 95/46/EC and Transitional Provisions
- Rec. 172Consultation of the European Data Protection Supervisor
- Rec. 173Relationship to Directive 2002/58/EC