Explore Cenitia’s compliance workflow and availability.Cenitia compliance workflow

How it works →
Cenitia
How it worksServicesLibraryGlossaryRegulationsToolsAbout
Reserve your spot
How it worksServicesLibraryGlossaryRegulationsToolsAbout
← Regulations

EU Regulation · GDPR

General Data Protection Regulation

Regulation (EU) 2016/679

The General Data Protection Regulation governs how the personal data of people in the EU is processed. It is relevant to any connected product that collects personal data, and shapes obligations such as data minimisation, security of processing and breach notification.

What it covers

Any product that processes the personal data of people in the EU — names, emails, identifiers, biometrics or location.

How it applies to your product

Most connected hardware ends up in scope because it collects personal data — a user account, a device identifier, location or biometrics. The practical duties are data minimisation, security of processing, and breach notification, and they sit alongside the product’s CE-marking file rather than inside it. The CRA and GDPR increasingly overlap on the security of connected devices.

Authoritative source

Always confirm against the primary text on EUR-Lex — the official EU legal database.

Read Regulation (EU) 2016/679 on EUR-Lex ↗

Check your product

Free tools

  • EU Directive Selector →
Cenitia

The EU compliance engine for hardware manufacturers. Cited drafts, electronic signing, regulation watching — all in one place.

A product of Inovasense s.r.o., Bratislava, Slovakia · Data hosted in Stockholm, EU

Site

  • How it works
  • Expert services & pricing
  • Library
  • Glossary
  • Regulations
  • By product type
  • Tools
  • About

Legal

  • Imprint
  • Privacy
  • Terms

© 2026 Inovasense s.r.o. · cenitia.com

Operated in Slovakia · Evidence, expert review and clear service scope