# GDPR Summary, The Key Articles on One Page

> The GDPR on one page: its eleven chapters and their most important articles, each summarised in a single sentence.

- Source: https://www.sidd.swiss/en/insights/gdpr-summary/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Dr. Dominic Staiger
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

The EU General Data Protection Regulation (GDPR, EU 2016/679) contains 99 articles and 173 recitals, organised into eleven chapters. For practical compliance work it is enough to know the most important 30 articles, they cover about 95% of daily compliance work. This page gives you a one-page overview: each of the eleven chapters with its key articles in one sentence each.

What you will take away:

- the eleven GDPR chapters and their function;
- the key articles per chapter as a TL;DR;
- links to SIDD deep-dive articles where you need more detail;
- the parallel application of DSG and GDPR in Switzerland.

This summary is intended as a reference, not as a replacement for reading the Regulation itself (eur-lex.europa.eu) or for case-specific advice. It will, however, help you cite the right article quickly in negotiations, audits and discussions.

## Chapter I (Art. 1–4), General provisions

**Art. 1, Subject matter and objectives:** protection of natural persons in the processing of their data and free movement of data in the EU.

**Art. 2, Material scope:** applies to wholly or partly automated processing and to non-automated processing forming part of a filing system. Exceptions: purely personal/household activities, law enforcement (separate Directive 2016/680).

**Art. 3, Territorial scope:** establishment principle and market location principle. Providers outside the EU are also caught if they offer goods/services to EU persons or monitor their behaviour, see our deep-dive [Article 27 GDPR](https://www.sidd.swiss/einblicke/artikel-27-dsgvo) on the EU representative.

**Art. 4, Definitions:** 26 legal definitions, including «personal data», «processing», «controller», «processor», «recipient», «third party», «consent», «personal data breach», «profiling», «pseudonymisation», «main establishment».

## Chapters II–III (Art. 5–23), Principles and data subject rights

**Art. 5, Principles:** lawfulness, fairness, transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability.

**Art. 6, Lawfulness of processing:** the six legal bases (consent, contract, legal obligation, vital interests, public interest, legitimate interest).

**Art. 7, Conditions for consent:** demonstrable, freely given, informed, unambiguous, withdrawable at any time.

**Art. 8, Child consent:** minimum age 16, Member States may lower to 13 (DE: 16, AT: 14, FR: 15).

**Art. 9, Special categories:** prohibition with ten exceptions (including explicit consent, employment law obligation, vital interests, healthcare).

**Art. 10, Criminal data:** only by or under the supervision of public authorities.

**Art. 12, Modalities of information:** intelligible, transparent, easily accessible, in plain language.

**Art. 13–14, Information duty** at direct and indirect collection respectively.

**Art. 15, Right of access:** right to confirmation, copy and detailed information; one month deadline (extendable to three).

**Art. 16, Rectification; Art. 17, Erasure («right to be forgotten»); Art. 18, Restriction; Art. 20, Data portability; Art. 21, Objection; Art. 22, Automated individual decisions incl. profiling.**

## Chapter IV (Art. 24–43), Controller and processor

**Art. 24, Responsibility of the controller:** appropriate TOMs for compliance and demonstration.

**Art. 25, Data Protection by Design / by Default:** data protection from the conception phase and in the default settings.

**Art. 26, Joint controllers:** transparent agreement on roles.

**Art. 27, EU representative:** duty for controllers/processors not established in the EU, see [our EU representative service](https://www.sidd.swiss/en/services/eu-representative).

**Art. 28, Processor:** mandatory DPA components (10 items in paragraph 3).

**Art. 30, Records of processing activities:** controller and processor, exemption under (5) for SMEs <250 employees without high risk.

**Art. 32, Security of processing:** appropriate TOMs, pseudonymisation/encryption, resilience, restorability, regular review.

**Art. 33, Notification of breaches to the supervisory authority:** 72 hours from becoming aware.

**Art. 34, Communication to the data subject:** for high risk, without undue delay.

**Art. 35, Data Protection Impact Assessment (DPIA):** for high risk, with consultation of the supervisory authority under Art. 36 if not sufficiently mitigated.

**Art. 37–39, DPO:** mandatory for public authorities, core activity with extensive regular monitoring or extensive processing of special categories; position, tasks.

**Art. 40–43, Codes of conduct and certifications.**

## Chapter V (Art. 44–50), Third-country transfers

**Art. 44, Principle:** transfers only permissible if protection is ensured.

**Art. 45, Adequacy decision:** list of states with adequate protection (including Switzerland, UK, Israel, Japan, South Korea, New Zealand, Argentina, Uruguay, Canada in part, Faroe Islands, Andorra, Guernsey, Isle of Man, Jersey, and the US for DPF-certified companies).

**Art. 46, Appropriate safeguards:** EU SCC, Binding Corporate Rules (BCR), approved codes of conduct, certifications.

**Art. 47, Binding Corporate Rules (BCR):** for intra-group transfers.

**Art. 49, Derogations for specific situations:** explicit consent, contract performance, important reasons of public interest, legal claims, vital interests, public register extracts. To be construed strictly.

Importantly post-Schrems II: SCC alone do not suffice for non-DPF US, a Transfer Impact Assessment (TIA) assessing foreign authority access and, where necessary, supplementary measures (encryption, pseudonymisation) is required. Deep-dive: [Schrems II for Swiss companies](https://www.sidd.swiss/einblicke/schrems-ii-schweiz).

## Chapters VI–VII (Art. 51–76), Supervisory authorities and cooperation

**Art. 51–54, Supervisory authorities:** each Member State sets up one or more independent supervisory authorities; independence, resources, staff regulated.

**Art. 55, Competence:** in principle for the Member State's territory.

**Art. 56, Lead supervisory authority (Lead SA):** for cross-border processing, the supervisory authority of the main establishment.

**Art. 57, Tasks:** supervision, advice, complaint handling, awareness, approving codes of conduct, accrediting certification bodies.

**Art. 58, Powers:** investigation (audit, ordering power, access to premises/data), corrective (warning, order, fine), authorisations and consultations.

**Art. 60–67, Cooperation and consistency (One-Stop-Shop):** cooperation between Lead SA and concerned supervisory authorities, dispute resolution by the EDPB.

**Art. 68–76, EDPB (European Data Protection Board):** replaces the Article 29 Working Party, issues guidelines, decides in the consistency mechanism, coordinates national authorities.

## Chapters VIII–XI (Art. 77–99), Remedies, sanctions, final

**Art. 77, Right to lodge a complaint with the supervisory authority:** every data subject may turn to the supervisory authority, usually that of their residence.

**Art. 78, Judicial remedy against the supervisory authority; Art. 79, Judicial remedy against controller/processor.**

**Art. 80, Representation by associations:** standing for associations (NOYB, consumer organisations).

**Art. 82, Liability and right to compensation:** material and non-material damage, joint and several between controller and processor.

**Art. 83, Administrative fines:** two tiers: up to EUR 10m or 2% of global annual turnover (e.g. Art. 8, 11, 25–39, 42, 43); up to EUR 20m or 4% (Art. 5, 6, 7, 9, 12–22, 44–49, 58(1) and (2), non-compliance with orders).

**Art. 84, Other penalties:** Member States lay down additional sanctions.

**Art. 85–91, Special situations:** journalism, employee data protection, archiving/research/statistics, churches.

**Art. 92–99, Final provisions:** delegated acts, implementing provisions, reports, entry into force (25 May 2018).

## How SIDD supports you

This page is a quick reference, the depth lies in the application. As the Institute for Data Protection and Information Security, SIDD specialises in the parallel application of GDPR and DSG. We take on the role of [GDPR DPO under Art. 37 GDPR](https://www.sidd.swiss/en/services/data-protection-officer-eu), of [Data Protection Advisor under Art. 10 DSG](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland) and of [EU representative under Art. 27 GDPR](https://www.sidd.swiss/en/services/eu-representative) or [UK representative](https://www.sidd.swiss/en/services/uk-representative).

Typical mandates: building a consolidated compliance programme; ROPA under Art. 30 GDPR / Art. 12 DSG; privacy notice under Art. 12–14 GDPR / Art. 19 DSG; DPA standardisation under Art. 28 GDPR / Art. 9 DSG; third-country strategy under Art. 44–49 GDPR / Art. 16–18 DSG including DPF, SCC, TIA; [data protection workshops](https://www.sidd.swiss/en/services/data-protection-workshop-sme) for employees and executive boards.

Would you like to know which GDPR articles are concretely relevant to your processing? Request a non-binding [quote](https://www.sidd.swiss/en/quote) or reach out via the [contact form](https://www.sidd.swiss/en/contact). In a 30-minute initial call we will clarify the need and the next step.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
