EuroComply
Zarejestruj się
Official source map

GDPR official sources

Primary GDPR sources for SMEs: official regulation text, European Commission SME guidance, EDPB guidance, key articles, and EuroComply checklists.

What official sources should SMEs cite for GDPR?

The primary GDPR source is Regulation (EU) 2016/679, supported by European Commission SME guidance and European Data Protection Board guidance. SMEs should cite GDPR articles for legal obligations and keep operational evidence for lawful basis, ROPA, processor contracts, data subject rights, breach notification and DPIAs.

  • Article 5: Principles
  • Article 6: Lawful basis
  • Article 30: ROPA
  • Article 33: Breach notification
  • Article 35: DPIA
Primary sourceRegulation (EU) 2016/679
EuroComply source page/sources/gdpr
Last reviewed2026-05-11
Source: Regulation (EU) 2016/679Reviewed:

Key references

ReferenceTopicWhy it matters
Article 5PrinciplesBasis for accountability evidence.
Article 6Lawful basisEvery processing purpose needs one.
Article 30ROPAProcessing record obligation and SME exemptions.
Article 33Breach notification72-hour authority notification rule.
Article 35DPIARequired for high-risk processing.

Use the source map with an action plan

Official sources answer what the law says. EuroComply guides turn those references into owners, deadlines, evidence and dashboard-ready actions.

EU AI Act official sourcesNIS2 official sourcesDORA official sourcesData Act official sourcesPay Transparency Directive official sources