Regulation (EU) 2016/679 (General Data Protection Regulation)
- Document
- 27 April 2016
- Event
- 25 May 2018
- Retrieved
- 16 September 2026
The workload
A controller or processor handling an EU or UK resident's personal data has to establish a lawful basis for each processing activity before doing it, not just publish a privacy notice afterward. Verified: the regulation's own text, adopted 27 April 2016 and applicable from 25 May 2018, requires under Article 6 that processing be lawful only if and to the extent that at least one of six conditions applies — consent, contract necessity, legal obligation, vital interests, public task, or a legitimate interest weighed against the person's rights. Articles 12 and 13 add a second task: telling the person, in plain language at the time data is collected, who the controller is, why the data is processed, and how long it will be kept. Nothing in that text is conditional on the size of the business doing the processing.
What the documents show
Verified: Article 30(5) sets GDPR's one explicit size-based exception — a derogation from keeping a written record of processing activities for an enterprise or an organisation employing fewer than 250 persons, unless its processing is high-risk, non-occasional, or touches special-category data, in which case even a small organisation must keep the record. Verified: the European Commission's own GDPR timeline page, retrieved 16 September 2026, states that in May 2025 it adopted a Single Market Simplification proposal to extend that derogation to organisations under 750 employees — but this is a proposal the Commission has put forward, not an amendment the regulation's own text yet contains, so the enacted threshold remains 250 employees as of this writing.
The operating cost
The regulation charges no registration fee; its cost shows up in enforcement. Verified: Article 83 lets a supervisory authority fine a controller up to €20,000,000 or, for an undertaking, up to 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher, for infringements of the basic processing principles in Articles 5, 6, 7 and 9, with a lower €10,000,000-or-2%-of-turnover ceiling for other obligations such as recordkeeping and security measures.
The stop condition
The regulation names scope conditions rather than a size floor: its obligations apply for as long as personal data of an EU or UK resident is being processed, and do not lapse below any revenue or headcount figure, apart from the narrow Article 30(5) recordkeeping derogation described above.
- Has a specific Article 6 lawful basis been identified and documented for each category of personal data processed, rather than assumed?
- Does the Article 13 notice given at collection state a retention period and recipient categories, not only that data is collected?
- If relying on the Article 30(5) recordkeeping derogation, does any processing activity involve special-category data or non-occasional risk that removes it?
GDPR's size-based leniency is one narrow derogation inside one article, not a general small-business exemption from the regulation.
Sources & reading trail
States Article 6 lawful-basis conditions, Article 12/13 notice duties, the Article 30(5) 250-employee recordkeeping derogation, and the Article 83 fine ceilings.
Source published: 27 April 2016 · Retrieved: 16 September 2026
Confirms the adoption, entry-into-force and applicability dates, and states the Commission's May 2025 proposal to extend the recordkeeping derogation to under-750-employee organisations.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.