Skip to content
Legiscope
Menu
Data Privacy

GDPR Articles Index: Article-by-Article Guide

Complete index of GDPR articles with deep-dive guides on each. Organised by topic: principles, lawful basis, rights, controllers, transfers, supervision.

In one sentence. This index is a navigable map of the 99 articles of the General Data Protection Regulation (Regulation (EU) 2016/679), organised by topic, with links to dedicated practical guides on each major provision. Use it as the starting point when you need to understand a specific GDPR Article in operational terms — what it requires, how it’s enforced, and how to comply.

The GDPR has 99 articles across 11 chapters. Most compliance work touches the same 30-40 articles repeatedly. This index groups them by topic and links to the deep-dive guides we’ve published on each. New guides are added regularly.

The authoritative source for every provision below is the consolidated text of Regulation (EU) 2016/679 on EUR-Lex; where an article has been interpreted by regulators, the European Data Protection Board (EDPB) guidelines are the reference DPAs apply in practice. Read the article text first, then the EDPB guidance, then the operational guide — that sequence keeps you anchored to the law rather than to secondary commentary.

Chapter I — General Provisions (Articles 1-4)

Chapter II — Principles (Articles 5-11)

Chapter III — Rights of the Data Subject (Articles 12-23)

Chapter IV — Controller and Processor (Articles 24-43)

Chapter V — Transfers to Third Countries (Articles 44-50)

Chapter VI — Supervisory Authorities (Articles 51-59)

Chapter VII — Cooperation and Consistency (Articles 60-76)

Chapter VIII — Remedies, Liability, Penalties (Articles 77-84)

Chapter IX — Specific Situations (Articles 85-91)

Articles 85-91 cover specific contexts: freedom of expression and information, public access to documents, national identification numbers, employment context, archiving and research, secrecy obligations, churches and religious associations.

Chapter X-XI — Delegated Acts and Final Provisions (Articles 92-99)

Procedural — entry into force, repeal of Directive 95/46, transitional provisions.

Cross-cutting topics

Some compliance work spans multiple articles:

How to use this index

  • For compliance work: navigate to the article you’re handling, read the dedicated guide, apply the practical patterns.
  • For audit preparation: use the index to verify your processing maps to the right articles.
  • For training: each guide doubles as a self-paced training module on its article.
  • For DPO functions: bookmark and use as reference during day-to-day work.

Which articles carry the highest enforcement risk

Not all 99 articles are equally likely to appear in a sanction decision. Across published DPA cases, the recurring offenders are a short list: Article 6 (no valid lawful basis), Article 5(1)(e) (excessive retention), Articles 13-14 (deficient transparency notices), Article 32 (inadequate security behind a breach), and Article 15 (failure to answer access requests). If your compliance programme is complete on those five, you have addressed the statistical majority of enforcement exposure. Article 83(5) places the principles, lawful-basis and data-subject-rights articles in the top fining tier — up to €20M or 4% of global turnover — which is why they concentrate regulator attention.

FAQ

How many articles does the GDPR have?

The GDPR (Regulation (EU) 2016/679) contains 99 articles organised into 11 chapters, supplemented by 173 recitals that aid interpretation. In day-to-day compliance work, roughly 30-40 articles are used repeatedly; the rest are procedural or institutional.

What is the difference between GDPR articles and recitals?

Articles are the binding legal provisions. Recitals are the numbered explanatory statements in the preamble that clarify legislative intent — they are not directly enforceable but courts and the EDPB rely on them to interpret ambiguous articles. Recital 47, for example, is central to reading the legitimate-interest basis in Article 6(1)(f).

Which GDPR articles impose the highest fines?

Two tiers apply under Article 83. Violations of principles (Articles 5-9) and data subject rights (Articles 12-22) fall in the higher tier — up to €20M or 4% of global annual turnover. Violations of controller/processor obligations such as records (Article 30) or security (Article 32) fall in the lower tier — up to €10M or 2%.

Where can I read the official GDPR article text?

The consolidated, up-to-date text is published on EUR-Lex as Regulation (EU) 2016/679 in all EU languages. Always work from that source rather than third-party reproductions, which can lag behind corrigenda.

Coming next

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
02Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

GDPR Article 46 lists multiple safeguards for international data transfers. Three dominate practice: Binding Corporate Rules (BCRs), Standard Contractual Clauses (SCCs), and the EU-U.S. Data Privacy…

April 30, 2026
03Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — so the software a DPO uses is now itself an accountability signal.

July 7, 2026
04Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
05Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026
06Data Privacy

Cassie (Syrenis) Alternatives & Comparison 2026

For a regulated-industry DPO, that distinction is the whole decision. Consent is one lawful basis under Art. 6(1)(a) GDPR; a compliance program is everything around it.

July 9, 2026
07Data Privacy

Consent Management Platforms Compared (2026)

Choosing the right consent management platform is one of the most consequential technical decisions an organisation makes for privacy compliance. A poorly configured CMP exposes you to enforcement…

March 28, 2026
08Data Privacy

Cookie Audit: How to Map Your Website's Cookies

A cookie audit is the foundational step for any website's GDPR and ePrivacy compliance. Without a complete, documented inventory of every cookie and tracking technology deployed on your site, your…

March 28, 2026