Lex Browse everything How it works For developers

Directive (EU) 2016/680

as it stood on 2016-05-04, permalink: /eu-eurlex/32016l0680/2016-05-04

2016-04-272016-05-04

2 versions · click any mark to read the law as it stood that day · the one you are reading

Point-in-time view as at 2016-05-04. This version has been superseded, it applied 2016-05-04 → open. Jump to the version in force today or see exactly what changed next.
Text included, per-article reading view. Deterministic extraction of the verbatim retrieved document; each article carries its own hash and anchor. © European Union, 1998-2026. Reuse permitted with attribution under Commission Decision 2011/833/EU. Consolidated texts have no legal effect; only acts published in the Official Journal are authentic.
Outline, 65 provisions

Article 1 Article 2 Article 3 Article 4 Article 5 Article 6 Article 7 Article 8 Article 9 Article 10 Article 11 Article 12 Article 13 Article 14 Article 15 Article 16 Article 17 Article 18 Article 19 Article 20 Article 21 Article 22 Article 23 Article 24 Article 25 Article 26 Article 27 Article 28 Article 29 Article 30 Article 31 Article 32 Article 33 Article 34 Article 35 Article 36 Article 37 Article 38 Article 39 Article 40 Article 41 Article 42 Article 43 Article 44 Article 45 Article 46 Article 47 Article 48 Article 49 Article 50 Article 51 Article 52 Article 53 Article 54 Article 55 Article 56 Article 57 Article 58 Article 59 Article 60 Article 61 Article 62 Article 63 Article 64 Article 65

CHAPTER I — General provisions

Article 1, Subject-matter and objectives #art_1
Article 2, Scope #art_2
Article 3, Definitions #art_3

CHAPTER II — Principles

Article 4, Principles relating to processing of personal data #art_4
Article 5, Time-limits for storage and review #art_5
Article 6, Distinction between different categories of data subject #art_6
Article 7, Distinction between personal data and verification of quality of personal data #art_7
Article 8, Lawfulness of processing #art_8
Article 9, Specific processing conditions #art_9
Article 10, Processing of special categories of personal data #art_10
Article 11, Automated individual decision-making #art_11

CHAPTER III — Rights of the data subject

Article 12, Communication and modalities for exercising the rights of the data subject #art_12
Article 13, Information to be made available or given to the data subject #art_13
Article 14, Right of access by the data subject #art_14
Article 15, Limitations to the right of access #art_15
Article 16, Right to rectification or erasure of personal data and restriction of processing #art_16
Article 17, Exercise of rights by the data subject and verification by the supervisory authority #art_17
Article 18, Rights of the data subject in criminal investigations and proceedings #art_18

CHAPTER IV — Controller and processor / Section 1 — General obligations

Article 19, Obligations of the controller #art_19
Article 20, Data protection by design and by default #art_20
Article 21, Joint controllers #art_21
Article 22, Processor #art_22
Article 23, Processing under the authority of the controller or processor #art_23
Article 24, Records of processing activities #art_24
Article 25, Logging #art_25
Article 26, Cooperation with the supervisory authority #art_26
Article 27, Data protection impact assessment #art_27
Article 28, Prior consultation of the supervisory authority #art_28

CHAPTER IV — Controller and processor / Section 2 — Security of personal data

Article 29, Security of processing #art_29
Article 30, Notification of a personal data breach to the supervisory authority #art_30
Article 31, Communication of a personal data breach to the data subject #art_31

CHAPTER IV — Controller and processor / Section 3 — Data protection officer

Article 32, Designation of the data protection officer #art_32
Article 33, Position of the data protection officer #art_33
Article 34, Tasks of the data protection officer #art_34

CHAPTER V — Transfers of personal data to third countries or international organisations

Article 35, General principles for transfers of personal data #art_35
Article 36, Transfers on the basis of an adequacy decision #art_36
Article 37, Transfers subject to appropriate safeguards #art_37
Article 38, Derogations for specific situations #art_38
Article 39, Transfers of personal data to recipients established in third countries #art_39
Article 40, International cooperation for the protection of personal data #art_40

CHAPTER VI — Independent supervisory authorities / Section 1 — Independent status

Article 41, Supervisory authority #art_41
Article 42, Independence #art_42
Article 43, General conditions for the members of the supervisory authority #art_43
Article 44, Rules on the establishment of the supervisory authority #art_44

CHAPTER VI — Independent supervisory authorities / Section 2 — Competence, tasks and powers

Article 45, Competence #art_45
Article 46, Tasks #art_46
Article 47, Powers #art_47
Article 48, Reporting of infringements #art_48
Article 49, Activity reports #art_49

CHAPTER VII — Cooperation

Article 50, Mutual assistance #art_50
Article 51, Tasks of the Board #art_51

CHAPTER VIII — Remedies, liability and penalties

Article 52, Right to lodge a complaint with a supervisory authority #art_52
Article 53, Right to an effective judicial remedy against a supervisory authority #art_53
Article 54, Right to an effective judicial remedy against a controller or processor #art_54
Article 55, Representation of data subjects #art_55
Article 56, Right to compensation #art_56
Article 57, Penalties #art_57

CHAPTER IX — Implementing acts

Article 58, Committee procedure #art_58

CHAPTER X — Final provisions

Article 59, Repeal of Framework Decision 2008/977/JHA #art_59
Article 60, Union legal acts already in force #art_60
Article 61, Relationship with previously concluded international agreements in the field of judicial cooperation in criminal matters and police cooperation #art_61
Article 62, Commission reports #art_62
Article 63, Transposition #art_63
Article 64, Entry into force #art_64
Article 65, Addressees #art_65
Provenance and validity dates, identifier, hash
as of2016-05-04 → this version applied
valid2016-05-04 → open publisher-asserted
typeDIR Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA
languageen
published2016-05-04
lex_ideu-eurlex:32016l0680:2016-05-04
record sha25651eb62c0cd37e41292599156e3d7426ea36cfbe207587771de0e478303130a64
New here? What am I looking at?

This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.

It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.

“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.

← previous version (2016-04-27)   what changed?   timeline   next version (2016-05-04) →

tierA, publisher-supplied validity dates
history beginspublisher
index built2026-08-07T19:46:23Z · corpus 8d5e859
stamp signaturevalid (ECDSA-P256)