In brief In summary, data protection law in the EU is intended to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) imposes a large number of obligations on those ‘processing’ personal data, and on the controllers of such processing, when they are in the scope of the relevant regime. They also grant rights to those whose personal data is processed (the ‘data subjects’). ‘Processing’ includes doing almost anything with personal data, including storing, sharing, deleting or using it. It is virtually impossible to operate a business or other organisation without processing personal data. Among other things, the ‘controllers’ of personal data processing are required to provide certain information to data subjects, such as to ensure they know why their personal data is being collected, how it is being used, who it is being shared with, and their own key rights (that is called the ‘right to be informed’). That