TermsBox
PricingBlog
LoginGet Started
PricingBlogLogin
Get Started
  1. Home
  2. Blog
  3. UE 2016 679 Explained: The EU Regulation Behind the GDPR
Legal Compliance

UE 2016 679 Explained: The EU Regulation Behind the GDPR

Learn what UE 2016 679 means, how Regulation (EU) 2016/679 became the GDPR, who must comply, the rights it grants, and how to meet its requirements.

TermsBox Team|July 28, 202612 min read

If you have seen a privacy policy cite "UE 2016 679" or "Regulamento UE 2016/679" and wondered what it refers to, the answer is the General Data Protection Regulation (GDPR). UE 2016 679 is the official citation number of the EU's data protection law: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016. This guide explains where the number comes from, who must comply, what the regulation requires, and how to meet those requirements on your own website. It is educational content rather than legal advice, so consult a qualified attorney for guidance specific to your situation.

What Is UE 2016 679?

UE 2016 679 is Regulation (EU) 2016/679, better known as the General Data Protection Regulation (GDPR). It is the European Union law that governs how organizations collect, use, store, and share the personal data of people in the EU and the European Economic Area (EEA).

The regulation was adopted on 27 April 2016 and became fully applicable on 25 May 2018 after a two-year transition period. It replaced the older Data Protection Directive 95/46/EC, which dated back to 1995 and could not keep up with modern data processing.

Three facts make Regulation (EU) 2016/679 different from the directive it replaced:

  • It is a regulation, not a directive. It applies directly and identically in all 27 EU member states without needing national implementing laws.
  • It has extraterritorial reach. It applies to organizations anywhere in the world that target or monitor people in the EU.
  • It carries real penalties. Fines can reach 20 million EUR or 4% of global annual turnover under Article 83.

The full official text spans 99 articles and 173 recitals, organized into 11 chapters covering principles, rights, obligations, transfers, and enforcement.

Why the Regulation Is Called UE 2016 679

The name follows the EU's standard system for numbering legislation. Every EU legal act receives a citation composed of the type of act, the year of adoption, and a sequential number. For this law, the official English citation is "Regulation (EU) 2016/679."

The order of the elements changes with the language, which is why you see several variants of the same reference:

  • UE 2016 679 or Regolamento UE 2016/679: the Italian form. "UE" stands for Unione Europea.
  • 2016 679 UE: the same reference with the number placed first, common in Spanish and Portuguese citations such as "Reglamento (UE) 2016/679."
  • EU 2016/679 or Regulation (EU) 2016/679: the English form used in the official journal.
  • GDPR: the informal English acronym for General Data Protection Regulation. In Italian it is often called RGPD (Regolamento Generale sulla Protezione dei Dati).

All of these point to the same law. If a contract, privacy policy, or vendor questionnaire cites "2016 679 UE," it is asking about GDPR compliance, nothing more exotic. The English-language perspective on the same citation is covered in our EU Regulation 2016/679 guide.

Who Must Comply with UE 2016 679?

Article 3 defines the territorial scope, and it is broader than many business owners expect. The regulation applies in two situations.

Establishment in the EU (Article 3(1)). Any organization with an establishment in the EU must comply when processing personal data in the context of that establishment. This covers EU companies of every size, from multinationals to a freelance designer in Milan.

Targeting people in the EU (Article 3(2)). Organizations with no EU presence must still comply if they either:

  1. Offer goods or services to people in the EU, even for free. Signals include EU-currency pricing, EU shipping options, or localized language versions.
  2. Monitor the behavior of people in the EU. Analytics tools, advertising pixels, and tracking cookies on a website with EU visitors typically qualify.

A practical example: a US-based SaaS company with a pricing page in euros and Google Analytics running on its site falls under Regulation (EU) 2016/679 twice over, despite having no office in Europe.

Note that the regulation protects people located in the EU, not EU citizens abroad. It also applies regardless of whether payment happens. A free newsletter that collects email addresses from EU subscribers is in scope.

The Data Protection Principles of Regulation (EU) 2016/679

Article 5 sets out seven principles that govern every processing activity. Regulators cite these principles in most enforcement decisions, so they are worth knowing precisely:

  1. Lawfulness, fairness, and transparency: process data legally and tell people what you are doing.
  2. Purpose limitation: collect data for specified, explicit purposes and do not reuse it incompatibly.
  3. Data minimization: collect only what is adequate, relevant, and necessary.
  4. Accuracy: keep personal data accurate and up to date.
  5. Storage limitation: keep data no longer than needed for the stated purpose.
  6. Integrity and confidentiality: secure data against unauthorized access, loss, and damage.
  7. Accountability: be able to demonstrate compliance with all of the above (Article 5(2)).

The accountability principle is the one that catches organizations off guard. It is not enough to comply; you must be able to prove it through documentation such as records of processing activities (Article 30), consent logs, and data protection impact assessments (Article 35).

Legal Bases for Processing Under Article 6

Every use of personal data needs one of the six legal bases listed in Article 6(1). Choosing and documenting the correct basis is the foundation of compliance:

  • Consent (Article 6(1)(a)): a freely given, specific, informed, and unambiguous indication of agreement. Pre-ticked boxes do not count.
  • Contract (Article 6(1)(b)): processing needed to perform a contract with the person, such as shipping an order.
  • Legal obligation (Article 6(1)(c)): processing required by law, such as retaining invoices for tax purposes.
  • Vital interests (Article 6(1)(d)): protecting someone's life, relevant mostly in emergencies.
  • Public task (Article 6(1)(e)): official functions of public authorities.
  • Legitimate interests (Article 6(1)(f)): your business interests, balanced against the person's rights through a documented assessment.

Special categories of data, such as health information, religious beliefs, or biometric data, receive extra protection under Article 9 and generally require explicit consent or another narrow exception. Our guide to special category data covers those rules in detail.

The Rights UE 2016 679 Grants to Individuals

Chapter 3 (Articles 12 to 22) gives data subjects eight enforceable rights. Your privacy policy must explain these rights, and your business must be able to honor them, generally within one month of a request (Article 12(3)):

  • Right to be informed (Articles 13 and 14): people must receive clear information about your processing, usually via a privacy policy.
  • Right of access (Article 15): people can request a copy of their data, commonly called a subject access request.
  • Right to rectification (Article 16): correction of inaccurate data.
  • Right to erasure (Article 17): deletion of data in defined circumstances, often called the right to be forgotten.
  • Right to restriction of processing (Article 18): pausing processing during disputes.
  • Right to data portability (Article 20): receiving data in a machine-readable format.
  • Right to object (Article 21): stopping processing based on legitimate interests or direct marketing.
  • Rights around automated decision-making (Article 22): protection against purely automated decisions with legal or similarly significant effects.

For most small businesses, the operational work is straightforward: publish a compliant privacy policy, set up a contact channel for requests, and document how you respond. A privacy policy generator can produce the required disclosures, including the full list of data subject rights, in minutes.

Key Obligations for Businesses and Websites

Beyond principles and rights, Regulation (EU) 2016/679 imposes concrete operational duties. The most relevant ones for a typical website or online business are:

Privacy notices (Articles 13 and 14). You must inform people, at the time of collection, of your identity, purposes, legal bases, recipients, retention periods, and their rights. This is the legal core of every privacy policy.

Records of processing activities (Article 30). Organizations must document what data they process, why, and with whom they share it. The exemption for companies under 250 employees is narrow and rarely applies in practice, because it excludes any non-occasional processing.

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app. Create yours in minutes with TermsBox.

Generate Now

Data breach notification (Articles 33 and 34). You must notify your supervisory authority within 72 hours of becoming aware of a breach that risks people's rights, and notify affected individuals when the risk is high.

Data protection officer (Article 37). A DPO is mandatory for public authorities and for organizations whose core activities involve large-scale monitoring or large-scale processing of special category data.

Processor contracts (Article 28). Every vendor that processes personal data on your behalf, from your email provider to your analytics tool, needs a data processing agreement with the clauses Article 28(3) prescribes.

Cookies and consent. Non-essential cookies require prior opt-in consent under Article 5(3) of the ePrivacy Directive, read together with the GDPR's consent standard in Articles 4(11) and 7. A compliant cookie policy and consent banner cover this requirement. Platforms like TermsBox combine a scanner that detects the cookies and trackers actually running on your site with a consent banner and generated policies, which keeps the documentation aligned with reality.

Penalties and Enforcement Under Article 83

Article 83 creates two tiers of administrative fines, applied by national supervisory authorities such as the Garante (Italy), CNIL (France), the DPC (Ireland), and the ICO (UK, under the UK GDPR):

Tier Maximum Fine Example Violations
Lower tier (Article 83(4)) 10 million EUR or 2% of global annual turnover Missing processor contracts, failure to notify breaches, no records of processing
Upper tier (Article 83(5)) 20 million EUR or 4% of global annual turnover No legal basis, violating data subject rights, unlawful international transfers

In both tiers, the higher of the two amounts applies. Enforcement is no longer theoretical. Meta received a 1.2 billion EUR fine from the Irish DPC in 2023 over data transfers, Amazon was fined 746 million EUR by Luxembourg's authority, and the Italian Garante has fined telecom operators tens of millions of euros over unlawful marketing.

Small businesses are not exempt. Authorities regularly issue five-figure and six-figure fines for missing privacy policies, unlawful cookies, and ignored access requests. Beyond fines, Article 82 gives individuals the right to sue for compensation, and Article 58 lets authorities order processing bans, which can hurt more than any fine.

How to Comply with UE 2016 679 on Your Website

Full compliance is a program, not a checkbox, but a typical website can cover the highest-risk requirements with a focused effort:

  1. Map your data. List what personal data you collect (forms, accounts, orders, analytics), why, and where it goes. This becomes your Article 30 record.
  2. Assign a legal basis to each purpose and document the choice, including legitimate interest assessments where relevant.
  3. Publish a compliant privacy policy covering all Article 13 disclosures: identity, purposes, legal bases, recipients, retention, rights, and complaint routes.
  4. Fix your cookies. Scan your site, classify cookies, block non-essential ones until consent, and publish a cookie policy.
  5. Sign processor agreements with every vendor touching personal data, and check where they transfer data (Chapter 5 governs transfers outside the EU).
  6. Prepare for rights requests and breaches. Define who answers requests within the one-month deadline and who handles the 72-hour breach notification.
  7. Review annually. New tools, new vendors, and new features change your data flows; your documents must follow.

If you want a structured starting point, work through our GDPR compliance checklist, which turns these steps into an itemized audit you can complete section by section.

Frequently Asked Questions

What does UE 2016 679 stand for?

UE 2016 679 refers to Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR). "UE" is the abbreviation for the European Union in Romance languages such as Italian, French, and Spanish, 2016 is the year of adoption, and 679 is the sequential number assigned to the regulation.

Is UE 2016 679 the same as the GDPR?

Yes, UE 2016 679 and the GDPR are the same law. UE 2016 679 is the official citation number of the regulation, while GDPR (General Data Protection Regulation) is its common name. Both refer to the EU data protection law that has applied since 25 May 2018.

Who has to comply with Regulation (EU) 2016/679?

Under Article 3, the regulation applies to any organization established in the EU that processes personal data, and to organizations outside the EU that offer goods or services to people in the EU or monitor their behavior. Company size does not matter; a one-person website can fall within scope.

What are the penalties for violating UE 2016 679?

Article 83 sets two tiers of administrative fines. Serious violations, such as processing without a legal basis or ignoring data subject rights, can reach 20 million EUR or 4% of global annual turnover, whichever is higher. Lesser violations can reach 10 million EUR or 2% of global turnover.

Does UE 2016 679 apply to businesses outside Europe?

Yes. Article 3(2) extends the regulation to organizations with no EU presence if they offer goods or services to people in the EU or monitor their behavior, for example through analytics or advertising cookies. A US or Asian website serving EU visitors must comply.

Do I need consent for everything under Regulation (EU) 2016/679?

No. Consent is only one of six legal bases in Article 6(1). You can also process personal data to perform a contract, meet a legal obligation, protect vital interests, perform a public task, or pursue legitimate interests. Consent is required mainly for marketing and non-essential cookies.

Related Tools

Privacy Policy Generator

Create a comprehensive privacy policy for your website or app

Related Articles

Legal Compliance

Privacy Policy vs Terms of Service: What's the Difference?

Privacy policy vs terms of service: learn what each document does, which one the law requires, what to include, and whether you need both on your website.

July 28, 202613 min read
Legal Compliance

What Are the 8 Principles of the Data Protection Act?

Learn what are the 8 principles of the data protection act, what each one requires, and how they map to the UK GDPR and Data Protection Act 2018 today.

July 28, 202613 min read
Legal Compliance

What a Data Subject Is: GDPR Definition, Rights, and Examples

Learn what a data subject is under GDPR, who qualifies, the rights they hold, and what your business must do to handle data subject requests correctly.

July 27, 202614 min read

Ready to Create Your Legal Documents?

Generate professional privacy policies, terms of service, and more in minutes. Free to start, no credit card required.

View All Generators

On This Page

  • What Is UE 2016 679?
  • Why the Regulation Is Called UE 2016 679
  • Who Must Comply with UE 2016 679?
  • The Data Protection Principles of Regulation (EU) 2016/679
  • Legal Bases for Processing Under Article 6
  • The Rights UE 2016 679 Grants to Individuals
  • Key Obligations for Businesses and Websites
  • Penalties and Enforcement Under Article 83
  • How to Comply with UE 2016 679 on Your Website
  • Frequently Asked Questions
TermsBox

Scan your website, auto-generate legal documents, add a consent banner, and stay compliant. One platform for everything.

Product
  • Cookie Scanner
  • Consent Banner
  • Cookie Policy Generator
  • Pricing
Generators
  • Privacy Policy Generator
  • Terms and Conditions Generator
  • EULA Generator
  • Disclaimer Generator
  • Return and Refund Policy Generator
Company
  • About
  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
GDPR
ePrivacy
CCPA
LGPD
Google Consent Mode v2
IAB TCF 2.2
© 2026 TermsBox. All rights reserved.