We help you navigate the data landscape as it actually is — not as regulators imagined it would be.
The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content.
The GDPR is organised into 11 Chapters containing 99 Articles. This guide lists every Article in order, with a short statement of each Article's purpose. Use the Chapter headings to navigate to the relevant section of the Regulation.

Covering all areas of data protection law

Listed in full numerical order

Became applicable 25 May 2018
Establishes the GDPR's subject matter, scope, territorial reach, and key definitions. These four Articles form the constitutional foundation of the entire Regulation.
Click for a deep dive into each Article
General Provisions
Material & Territorial
Core GDPR terminology
Sets the foundational principles and lawful bases that govern personal data processing. Every processing activity must be grounded in these Articles.
Article 5 — the cornerstone principle underpinning all processing
Article 6 — consent, contract, legal obligation, vital interests, public task, legitimate interests
Article 9 — health, biometric, racial, religious and other sensitive data require explicit justification
Defines the rights individuals have over their personal data and how organisations must respond. Chapter III is divided into five Sections covering transparency, access, rectification, objection and restrictions.

Sets out organisational responsibilities, accountability measures, security duties, breach notification rules, DPIAs, DPOs and conduct mechanisms. This is the most operationally detailed Chapter of the GDPR.
The accountability cycle under Chapter IV requires organisations to embed privacy at the design stage, maintain comprehensive records, implement robust security, and report breaches promptly — forming a continuous compliance loop.
Regulates international transfers of personal data outside the EU/EEA or to international organisations. No transfer may take place unless one of the mechanisms in Articles 44–49 is satisfied. Overview including considerations given to data sovereignty and data architecture can be found here.

Establishes the independence, powers and responsibilities of national data protection authorities. Each Member State must have at least one supervisory authority acting with full independence.
Supervisory authorities may conduct audits, request information and access premises under Article 58.
Authorities may issue warnings, reprimands, bans on processing and administrative fines under Article 58.
Authorities may approve codes of conduct, certifications and binding corporate rules under Article 58.
Creates cooperation mechanisms between supervisory authorities and the European Data Protection Board. This Chapter ensures the GDPR is applied consistently across all Member States.
Sets rights to complain, seek judicial remedies, claim compensation, and governs administrative fines and penalties. This Chapter gives the GDPR its enforcement teeth.
Up to €10 million or 2% of global annual turnover (whichever is higher) for infringements of obligations such as processor requirements, records, security and breach notification.
Up to €20 million or 4% of global annual turnover (whichever is higher) for infringements of core principles, data subject rights, and international transfer rules.
The final three Chapters address Member State flexibility for specific processing contexts, Commission powers to adopt delegated or implementing acts, and the transitional and closing provisions of the Regulation.
Allows Member States to adopt or maintain specific rules for particular processing contexts.
Sets mechanisms for Commission powers to adopt delegated or implementing acts.
Covers repeal, transitional arrangements, review, and entry into force and application.
GDPR