GDPR Article 21: Right to Object to Processing
GDPR Article 21 gives data subjects the absolute right to object to direct marketing and a qualified right to object to processing under legitimate interests or public task.
Page 7 of 12
GDPR Article 21 gives data subjects the absolute right to object to direct marketing and a qualified right to object to processing under legitimate interests or public task.
GDPR Article 22 prohibits decisions based solely on automated processing that produce legal or similarly significant effects, with three narrow exceptions.
GDPR Article 25 requires data protection by design and by default. Implementation patterns, EDPB guidelines, and architectural examples for SaaS.
GDPR Article 32 requires appropriate technical and organizational security measures: encryption, pseudonymization, integrity, availability, regular testing.
GDPR Article 34 requires communicating personal data breaches to affected data subjects when there's high risk. Threshold, content, exemptions, timing.
GDPR Article 6 sets out the six lawful bases for processing personal data: consent, contract, legal obligation, vital interests, public task, legitimate interests.
GDPR Article 7 sets out conditions for valid consent: demonstrability, intelligible request, easy withdrawal, and freely given. Practical implementation guide.
GDPR Article 9 prohibits processing of special category data (health, biometrics, religion, etc.) except under 10 specific conditions including explicit consent.
Complete index of GDPR articles with deep-dive guides on each. Organised by topic: principles, lawful basis, rights, controllers, transfers, supervision.
GDPR Article 16 gives data subjects the right to have inaccurate personal data corrected and incomplete data completed. Procedure, deadlines, and exceptions.
GDPR Article 24 imposes the accountability obligation on the controller. Risk-based approach, technical and organisational measures, documentation, demonstrability.
GDPR Article 27 requires non-EU controllers targeting EU data subjects to designate an EU representative. Obligations, exemptions, and how to comply in 2026.
GDPR Article 33: notify the supervisory authority within 72 hours of a personal data breach. Process, content, exemptions, and enforcement.
GDPR Article 36 requires prior consultation with the supervisory authority when a DPIA shows high residual risk. Process, timeline, content, and consequences.
GDPR Article 4 defines 26 key terms: personal data, processing, controller, processor, consent, pseudonymization, biometric, profiling. Reference glossary.
GDPR Article 44 sets the general principle for international data transfers: protection must not be undermined. Safeguards hierarchy, adequacy, derogations.
GDPR Article 83 governs administrative fines: two tiers (up to €10M/2% or €20M/4%), 11 calculation criteria, and the EDPB Guidelines 04/2022 methodology.
UK GDPR vs EU GDPR in 2026: Data (Use and Access) Act changes, adequacy status, ICO vs EDPB approach, and the key compliance divergences that matter.