{
  "code": "GDPR",
  "name": "EU General Data Protection Regulation (GDPR)",
  "version": "2018",
  "issuing_body": "European Parliament and Council",
  "description": "Regulation on the protection of natural persons with regard to the processing of personal data",
  "regions": ["eu"],
  "industries": ["all"],
  "effective_date": "2018-05-25",
  "is_global": false,
  "requirements": [
    {
      "reference_code": "Art.5",
      "title": "Principles relating to processing of personal data",
      "requirement_type": "mandatory",
      "category": "Data Processing Principles",
      "children": [
        { "reference_code": "Art.5.1.a", "title": "Lawfulness, fairness and transparency", "description": "Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject.", "requirement_type": "mandatory" },
        { "reference_code": "Art.5.1.b", "title": "Purpose limitation", "description": "Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in incompatible manner.", "requirement_type": "mandatory" },
        { "reference_code": "Art.5.1.c", "title": "Data minimisation", "description": "Personal data shall be adequate, relevant and limited to what is necessary.", "requirement_type": "mandatory" },
        { "reference_code": "Art.5.1.d", "title": "Accuracy", "description": "Personal data shall be accurate and, where necessary, kept up to date.", "requirement_type": "mandatory" },
        { "reference_code": "Art.5.1.e", "title": "Storage limitation", "description": "Personal data shall be kept in a form which permits identification of data subjects for no longer than necessary.", "requirement_type": "mandatory" },
        { "reference_code": "Art.5.1.f", "title": "Integrity and confidentiality", "description": "Personal data shall be processed in a manner that ensures appropriate security.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "Art.6",
      "title": "Lawfulness of processing",
      "requirement_type": "mandatory",
      "category": "Legal Basis",
      "children": [
        { "reference_code": "Art.6.1", "title": "Legal basis for processing", "description": "Processing shall be lawful only if and to the extent one of the listed conditions applies.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "Art.13",
      "title": "Information to be provided where personal data are collected from the data subject",
      "requirement_type": "mandatory",
      "category": "Data Subject Rights",
      "description": "Where personal data relating to a data subject are collected from the data subject, the controller shall provide information at the time of collection."
    },
    {
      "reference_code": "Art.17",
      "title": "Right to erasure ('right to be forgotten')",
      "requirement_type": "mandatory",
      "category": "Data Subject Rights",
      "description": "The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay."
    },
    {
      "reference_code": "Art.25",
      "title": "Data protection by design and by default",
      "requirement_type": "mandatory",
      "category": "Technical Measures",
      "description": "The controller shall implement appropriate technical and organisational measures for ensuring that, by default, only personal data which are necessary for each specific purpose are processed."
    },
    {
      "reference_code": "Art.28",
      "title": "Processor",
      "requirement_type": "mandatory",
      "category": "Vendor Management",
      "description": "Where processing is to be carried out on behalf of a controller, the controller shall only use processors providing sufficient guarantees.",
      "children": [
        { "reference_code": "Art.28.3", "title": "Data Processing Agreement", "description": "Processing by a processor shall be governed by a contract or other legal act.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "Art.32",
      "title": "Security of processing",
      "requirement_type": "mandatory",
      "category": "Technical Measures",
      "description": "Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.",
      "children": [
        { "reference_code": "Art.32.1.a", "title": "Pseudonymisation and encryption", "description": "Implement pseudonymisation and encryption of personal data.", "requirement_type": "mandatory" },
        { "reference_code": "Art.32.1.b", "title": "Ongoing confidentiality, integrity, availability", "description": "Ensure ongoing confidentiality, integrity, availability and resilience of processing systems.", "requirement_type": "mandatory" },
        { "reference_code": "Art.32.1.c", "title": "Restoration of availability", "description": "Restore the availability and access to personal data in a timely manner in the event of a physical or technical incident.", "requirement_type": "mandatory" },
        { "reference_code": "Art.32.1.d", "title": "Testing effectiveness", "description": "A process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "Art.33",
      "title": "Notification of a personal data breach to the supervisory authority",
      "requirement_type": "mandatory",
      "category": "Incident Response",
      "description": "In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours notify the supervisory authority."
    },
    {
      "reference_code": "Art.35",
      "title": "Data protection impact assessment",
      "requirement_type": "mandatory",
      "category": "Risk Assessment",
      "description": "Where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall carry out an assessment of the impact."
    },
    {
      "reference_code": "Art.37",
      "title": "Designation of the data protection officer",
      "requirement_type": "recommended",
      "category": "Governance",
      "description": "The controller and the processor shall designate a data protection officer in specific cases."
    },
    {
      "reference_code": "Art.44",
      "title": "General principle for transfers",
      "requirement_type": "mandatory",
      "category": "Cross-border Transfers",
      "description": "Any transfer of personal data to a third country shall take place only if the conditions laid down in the GDPR are complied with."
    }
  ]
}
