These are the recitals to the GDPR (Regulation (EU) 2016/679).

Please note: Unlike the articles of the GDPR, the recitals have not been provided with official headings. The headings used on this page have been assigned by us ourselves, based on the respective content, to make the information easier to scan and to improve understanding.

Inhaltsverzeichnis

Rec. 1 Data protection as a fundamental right
Rec. 2 Goals of the GDPR
Rec. 3 Purpose of Directive 95/46/EC
Rec. 4 Relation to other fundamental rights
Rec. 5 Exchange of personal data in the European Union
Rec. 6 Influence of technology and globalisation
Rec. 7 Creation of legal framework to secure individual rights
Rec. 8 Incorporation of rules into national law
Rec. 9 Uneven protection under Directive 95/46/EC
Rec. 10 Need for harmonised protection despite national scope
Rec. 11 Harmonisation of enforcement powers and sanctions
Rec. 12 Legal basis: Union competence for data protection
Rec. 13 Consideration of micro, small and medium-sized enterprises
Rec. 14 Applicability to natural persons
Rec. 15 Technology neutrality
Rec. 16 National and common security exclusions
Rec. 17 Adaptation of Regulation (EC) No 45/2001
Rec. 18 Exclusion for personal or household activities
Rec. 19 Exclusion for criminal prosecution and public security
Rec. 20 Respect for judicial independence
Rec. 21 Relationship with Directive 2000/31/EC
Rec. 22 Processing by an establishment in the Union
Rec. 23 Extra-territorial application for targeting data subjects in the Union
Rec. 24 Extra-territorial application for profiling data subjects in the Union
Rec. 25 Application to all controllers where Member State law applies
Rec. 26 Application to all personally identifiable information
Rec. 27 Exclusion for data of deceased persons
Rec. 28 Pseudonymisation as a safeguard
Rec. 29 Pseudonymisation within the same controller
Rec. 30 Risks of online identifiers
Rec. 31 Public authorities acting in official capacity
Rec. 32 Conditions for consent
Rec. 33 Consent in research contexts
Rec. 34 Definition of genetic data
Rec. 35 Definition of health data
Rec. 36 Determination of main establishment
Rec. 37 Rules for groups of undertakings
Rec. 38 Special need for protection of children
Rec. 39 General principles of processing
Rec. 40 Conditions for lawful processing
Rec. 41 References to other legal basis
Rec. 42 Evidence for consent
Rec. 43 Freedom of consent
Rec. 44 Processing in the context of a contract
Rec. 45 Processing based on legal obligation
Rec. 46 Processing to protect vital interests
Rec. 47 Processing based on legitimate interest
Rec. 48 Legitimate interests of controllers part of a group of undertakings
Rec. 49 Legitimate interest to ensure network and information security
Rec. 50 Further processing for different purposes
Rec. 51 Prohibition of the processing of sensitive data in general
Rec. 52 Allowed processing of sensitive data
Rec. 53 Processing sensitive data for health care
Rec. 54 Processing for public health
Rec. 55 Processing for officially recognised religious associations
Rec. 56 Processing of political data by political parties during electoral activities
Rec. 57 Identification of a data subject with additional data
Rec. 58 Principle of transparency
Rec. 59 Procedures for exercise of data subject rights
Rec. 60 Information obligations of controllers
Rec. 61 Timing of information to data subjects
Rec. 62 Exceptions to information obligations
Rec. 63 Right of access by the data subject
Rec. 64 Identity verification before access
Rec. 65 Right to rectification and erasure
Rec. 66 Implications of the right to be forgotten
Rec. 67 Restriction of processing as a safeguard
Rec. 68 Right to data portability
Rec. 69 Right to object to processing
Rec. 70 Right to object to direct marketing
Rec. 71 Automated decision-making and profiling
Rec. 72 Profiling
Rec. 73 Permissible restrictions of rights for public interest
Rec. 74 Responsibility and liability of controllers
Rec. 75 Risks to rights and freedoms of natural persons
Rec. 76 Risk-based approach to data protection
Rec. 77 Guidance and standards for risk assessment
Rec. 78 Appropriate technical and organisational measures
Rec. 79 Allocation of responsibilities between actors
Rec. 80 Designation of a representative in Union
Rec. 81 Use and governance of processors
Rec. 82 Records of processing activities
Rec. 83 Security of processing obligations
Rec. 84 Data protection impact assessment (DPIA)
Rec. 85 Notification of personal data breaches to supervisory authority
Rec. 86 Notification of data breaches to data subjects
Rec. 87 Promptness of breach reporting
Rec. 88 Form and content of breach notifications
Rec. 89 Elimination of general reporting requirements where unnecessary
Rec. 90 Data protection impact assessment necessity
Rec. 91 DPIA for high-risk processing
Rec. 92 Broader requirements for DPIAs in certain contexts
Rec. 93 DPIAs for public authorities and bodies
Rec. 94 Consultation of supervisory authority for high-risk processing
Rec. 95 Processor support in consultations and DPIAs
Rec. 96 Consultation of supervisory authority during legislative processes
Rec. 97 Appointment and role of the data protection officer (DPO)
Rec. 98 Development of codes of conduct by organisations
Rec. 99 Stakeholder consultation in code development
Rec. 100 Certification mechanisms and seals
Rec. 101 International transfer general principles
Rec. 102 International agreements ensuring adequate protection
Rec. 103 Adequacy decisions for third countries
Rec. 104 Criteria for adequacy decisions
Rec. 105 Consideration of international agreements in adequacy
Rec. 106 Monitoring and periodic review of adequacy decisions
Rec. 107 Amendment, revocation, suspension of adequacy decisions
Rec. 108 Appropriate safeguards for international transfers
Rec. 109 Use of standard contractual clauses
Rec. 110 Binding corporate rules for intra-group transfers
Rec. 111 Specific exceptions permitting certain transfers
Rec. 112 Transfers for important public interest reasons
Rec. 113 Non-repetitive, limited transfers as exceptions
Rec. 114 Ensuring enforceability of rights absent adequacy decision
Rec. 115 Rules in third countries contrary to the Regulation
Rec. 116 Cooperation with supervisory authorities in third countries
Rec. 117 Establishment and independence of supervisory authorities
Rec. 118 Monitoring of supervisory authorities' performance
Rec. 119 Participation in the consistency mechanism
Rec. 120 Financial and human resources of a supervisory authority
Rec. 121 Constitution of supervisory authorities in the member states
Rec. 122 Competency of supervisory authorities
Rec. 123 Cooperation between supervisory authorities in the European Union
Rec. 124 Lead supervisory authority
Rec. 125 Competency of the load supervisory authority
Rec. 126 Joint decisions by supervisory authorities for cross-border processing
Rec. 127 Competency to handle local cases
Rec. 128 Excemption for processing in the public interest
Rec. 129 Tasks and effective powers of supervisory authorities
Rec. 130 Cooperation between lead supervisory authority and the authority where a complaint is lodged
Rec. 131 Amicable settlement with the controller
Rec. 132 Awareness-raising activities by supervisory authorities
Rec. 133 Assistance between supervisory authorities
Rec. 134 Joint operations by supervisory authorities
Rec. 135 Consistent application of the GDPR through a consistency mechanism
Rec. 136 Opinions and legally binding decisions of the Board
Rec. 137 Provisional measures to fulfll urgent need to protect rights and freedoms of data subjects
Rec. 138 Application of cross-border cooperation for urgent needs
Rec. 139 Promotion of consistent application of this Regulation
Rec. 140 Secretariat of the Board
Rec. 141 Right to lodge a complaint and to an effective judicial remedy
Rec. 142 Right to mandate a not-for-profit organisation to lodge complaints
Rec. 143 Effective judicial remedy
Rec. 144 Multiple proceedings at different courts
Rec. 145 Choice of jurisdiction for proceedings against a controller or processor
Rec. 146 Liability and compensation principles
Rec. 147 Jurisdiction
Rec. 148 Penalties by the supervisory authorities
Rec. 149 Criminal penalties for infringements of this Regulation
Rec. 150 Administrative fines
Rec. 151 Admiministrative fines in Denmark and Estonia
Rec. 152 Review and report on application of the Regulation
Rec. 153 Processing for journalistic, academic and artistic purposes
Rec. 154 Public access to official documents
Rec. 155 Protection of personal data of employees
Rec. 156 Safeguards for processing in official archives and registries
Rec. 157 Coupling information from registries for scientific research
Rec. 158 Archiving in the public interest
Rec. 159 Definition of scientific research
Rec. 160 Processing for historical research
Rec. 161 Consent in clinical trials and health research
Rec. 162 Processing for statistical purposes
Rec. 163 Production of European and national statistics
Rec. 164 Professional or equivalent secrecy obligations
Rec. 165 No prejudice to status of churches and religious associations
Rec. 166 Delegated acts by the Commission
Rec. 167 Implementing powers of the Commission
Rec. 168 Use of examination procedure for implementing acts
Rec. 169 Immediate adoption of implementing acts where necessary
Rec. 170 Principles of subsidiarity and proportionality
Rec. 171 Repeal of Directive 95/46/EC and transitional provisions
Rec. 172 Consultation of the European Data Protection Supervisor
Rec. 173 Relationship to Directive 2002/58/EC (ePrivacy)