lexiara

sec_3_4__para__2

The Regulation impacts most on operators whose core business is data processing and/or dealing with sensitive data. It also impacts on those that regularly and systematically monitor individuals on a large scale. These operators will most probably have to appoint a data protection officer, conduct a data protection impact assessment and notify data breaches if there is a risk to the rights and freedoms of individuals. By contrast, operators, in particular SMEs, which do not engage in high risk processing as their core activity will normally not be subject to these specific obligations of the Regulation.

· All articles ·

Source: EUR-Lex (Cellar) · retrieved 2026-09-07 · Text as adopted (Official Journal); later amendments are not incorporated in this text.