The law governs collection, processing, use and security by individuals, legal entities and organisations without legal personality.
Grounds and consent: Articles 5 to 8 require a statutory ground or consent. Article 8 specifies the information that must precede consent, requires written paper or electronic evidence, permits withdrawal and rejects silence as consent.
Sensitive data: Articles 9 and 10 impose heightened limits on sensitive, genetic and biometric data.
Transfers and deletion: Article 14 generally requires law, treaty or consent for transfers abroad. Article 15 prescribes deletion grounds.
Rights and processors: Articles 16, 18 and 19 cover access, copies, correction, deletion, withdrawal, complaints, controller records and written processor terms.
Security, incidents and assessments: Articles 20 to 23 require a security programme, immediate harmful-incident notices, incident records and assessments for automated decisions affecting rights or regular sensitive-data processing. Article 22(6) requires annual incident records to be sent to the National Human Rights Commission each January.
Articles 8-10 - consent and protected data.
Articles 14-20 - transfers, deletion, rights, processors and security.
Articles 21-24 - notices, incidents, assessments and supervision.