Regulation (EU) 2016/679

General Data Protection Regulation

Regulation — European Union
Effective: May 25, 2018 100 platforms tracked 5976 provisions indexed Enforced by: European Data Protection Board (EDPB), National Data Protection Authorities (DPAs) Last reviewed May 9, 2026

Overview

The General Data Protection Regulation is the European Union's comprehensive data protection framework, replacing the 1995 Data Protection Directive. It establishes strict requirements for how organizations collect, process, store, and share personal data of individuals in the EU and EEA.

GDPR grants data subjects specific rights including the right to access, rectification, erasure ("right to be forgotten"), data portability, and the right to object to automated decision-making. Organizations must demonstrate a lawful basis for processing (consent, contractual necessity, legitimate interest, legal obligation, vital interest, or public task) and implement appropriate technical and organizational safeguards.

Enforcement is carried out by national Data Protection Authorities coordinated through the European Data Protection Board. Penalties can reach up to €20 million or 4% of global annual turnover, whichever is higher — making GDPR one of the most consequential regulatory frameworks for platform governance globally.

Penalties

Up to €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. Lower-tier violations (e.g. record-keeping failures): up to €10 million or 2% of turnover.

Key Articles & Sections

Platforms We Track Subject to GDPR

Recent Changes Related to GDPR

ConductAtlas maps governance language to potentially relevant regulatory frameworks. Regulatory applicability and enforceability may vary by jurisdiction, enforcement context, and individual circumstances. This page is informational and does not constitute legal advice. Methodology

Provisions Governed by GDPR (5976 across 100 platforms)

Telehealth Services and Separate Medical Record Privacy Notice 23andMe
Medium
Genetic Data Retention After Account Deletion 23andMe
Medium
Prohibition on Insurance Company and Employer Use 23andMe
Medium
Genetic Data Research Use 23andMe
Medium
Data Sharing with Third-Party Service Providers 23andMe
Medium
International Data Transfers 23andMe
Medium
Age Restriction and Minimum Age Requirement 23andMe
Medium
CCPA Rights for California Residents 23andMe
Medium
Telehealth and Medical Record Privacy Notice 23andMe
Medium
Account Deletion and Sample Discard 23andMe
Medium
Terms Modification with Continued Use as Acceptance 23andMe
Medium
Sample Storage Choice 23andMe
Medium
Separate Medical Record Privacy Notice for Telehealth 23andMe
Medium
Account Deletion Right 23andMe
Medium
California Consumer Privacy Rights 23andMe
Medium
Restriction on Insurance Companies and Employers 23andMe
Medium
Intellectual Property License 23andMe
Medium
Sharing Features Participation (DNA Relatives and Connections) 23andMe
Medium
DNA Relatives and Sharing Features Consent 23andMe
Medium
International Data Transfers Activision
Medium
Data Retention Activision
Medium
California Opt-Out Rights (CCPA/CPRA) Activision
Medium
GDPR Rights for EU and UK Users Activision
Medium
Cookie and Behavioral Tracking Activision
Medium
Age Requirement and Parental Consent for Minors Activision
Medium
Marketing and Advertising Use of Data Activision
Medium
Gameplay and Behavioral Data Collection Activision
Medium
Cross-Border Data Transfers Activision
Medium
Acceptance by Use Activision
Medium
Microsoft Affiliate Data Sharing Activision
Medium

Showing 30 of 5976 provisions. View all →

Related Regulations

Official Source

View official regulation text →

Get alerted when platforms change their policies — including GDPR-relevant provisions.

Subscribe to Monitor — $19/mo

Frequently Asked Questions

What does GDPR require?

Which platforms does GDPR apply to?

ConductAtlas tracks GDPR-relevant provisions across 100 platforms. Each platform's specific provisions are classified by severity and mapped to GDPR requirements.

How does ConductAtlas monitor GDPR compliance?

ConductAtlas captures policy documents daily, classifies provisions by regulatory framework, and flags changes that affect GDPR obligations. Every change is archived with cryptographic verification.