This document outlines the key aspects of the General Data Protection Regulation (GDPR), including processing principles such as privacy by design and data minimization. It discusses structuring data through anonymization and pseudonymization as well as profiling. Cross-border data transfers must follow models like EC model clauses or Binding Corporate Rules. The roles of controllers and processors are defined along with their responsibilities regarding records, breaches, and agreements. Data subjects' rights include access, rectification, objection and erasure. Enforcement is through national authorities and the European Data Protection Board, with fines of up to 20 million euros or 4% of annual global turnover for violations.