Skip to content
Topic Contested in court

Right of Access Procedures

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This new topic is needed because Article 15 GDPR deserves dedicated coverage for its specific procedures, requirements, timelines, formats, and exceptions related to the right of access by data subjects.

233 linked items 4 Laws65 Case Law47 Guidance48 Enforcement46 News

Overview

24 sources · Jul 23, 2026

Legal Framework

The right of access is enshrined in Article 8(2) of the EU Charter and operationalised by Article 15 GDPR. Article 15 grants data subjects a two-tier right: first, confirmation of whether their personal data are being processed, and second, where processing is occurring, access to the data together with a prescribed catalogue of supplementary information — including processing purposes, categories of data, recipients, retention periods, and the existence of automated decision-making.

"The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:"
GDPR Art. 15(1)

Recital 63 frames the right's purpose: enabling data subjects to verify the lawfulness of processing. It also signals limits — the right must not unduly prejudice trade secrets or intellectual property — while warning that such considerations "should not be a refusal to provide all information." Where personal data are transferred to third countries, Article 15(2) adds a discrete obligation to inform the data subject of the appropriate safeguards under Article 46. Article 15(3) entitles the data subject to a copy of the processed data.

Key Developments

The CJEU's ruling in Minister voor Immigratie v. M (2014) established foundational parameters for access scope. The Court held that access extends to all personal data processed by the controller but does not encompass legal analysis or administrative reasoning beyond what constitutes personal data. Critically, the Court confirmed that compliance can be achieved through a summary, provided it is intelligible and enables the data subject to verify accuracy and exercise downstream rights.

"an applicant for a residence permit has a right of access to all personal data concerning him which are processed by the national administrative authorities"
Minister v. M ¶60

The earlier X judgment (2013) set procedural benchmarks, requiring that access be provided without constraint, excessive delay, or excessive expense — a standard carried forward into Article 12(3) GDPR. Enforcement actions confirm these are not merely aspirational: the Irish DPA fined Permanent TSB €277,500 for insufficient measures to fulfil access requests, and the Estonian DPA acted against a dental clinic that failed to properly respond to a data subject's access complaint.

Status of the Debate

This topic is actively contested. While the core entitlement under Article 15 is well-established, courts and regulators continue to grapple with boundary questions: what constitutes "personal data" in mixed legal-factual records (per Minister v. M), how to balance trade-secret protection against the access right (Recital 63's tension), and what format satisfies the "intelligible form" standard. National derogations under Article 89(2)–(3) for archival and research purposes further fragment the landscape, as Member States may restrict access rights in those contexts. The EDPB's ongoing guidelines on right of access signal that regulator-level clarification is still evolving. Resolution will likely require further CJEU guidance on the precise scope of "copy" under Article 15(3) and the proportionality test when third-party rights intersect with access requests.

Practical Guidance

  • Verify identity proportionately: Before responding, confirm the requester's identity using reasonable means — do not demand excessive documentation that would itself constitute a barrier to access, consistent with the X standard of access "without constraint."
  • Distinguish personal data from legal analysis: Following Minister v. M, provide access to all personal data but exclude purely legal reasoning or administrative analysis that does not itself constitute personal data, unless it contains personal data embedded within it.
  • Deliver in intelligible form: A full summary may satisfy the obligation if it allows the data subject to become aware of the data and verify accuracy — but ensure the summary is complete and comprehensible, not merely a data dump in raw format.
  • Include all Article 15(1) supplementary information: Beyond the data itself, provide processing purposes, recipient categories, retention periods, source information (where data were not collected from the subject), and details of any automated decision-making.
  • Document third-party and trade-secret redactions: Where redactions are applied to protect others' rights, record the specific legal basis and ensure the data subject still receives meaningful information — a blanket refusal will not survive scrutiny.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 4
art 15 Right of access by the data subject GDPR Apr 2016 rec 63 Recital 63 — data subject right of access GDPR Apr 2016 rec 146 Recital 146 — Commission decision procedural rights and confidentiality DSA Oct 2022 rec 110 Recital 110 — lawful domain registration data access NIS2 Dec 2022
Case Law 65
¶8 Article 10 of Directive 95/46, headed ‘Information in cases of collection of data from the data subject’, provides: ‘Member States shall provide that … Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶129 The Danish Government’s argument refers to a situation in which the objective pursued by the access request proposed, namely the fight against serious… Judgment of the Court (Grand Chamber) of 20 September 2022.#Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH.#Requests for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Directive 2002/58/EC – Article 15(1) – ¶8 Article 10, Article 11(1) and Articles 12 and 21 of Directive 95/46 lay down, respectively, (i) the detailed arrangements for informing natural person… Judgment of the Court (Grand Chamber) of 6 October 2020.#État luxembourgeois v B and Others.#Requests for a preliminary ruling from the Cour administrative (Luxembourg).#References for a preliminary ruling – Directive 2011/16/EU – Administrative cooperation in the field of taxation – Articles 1 and 5 – Decision ordering that information be provided to the competent authority of a Member State, acting in response to a request for exchange of information from the competent authority of another Mem ¶6 In Section V of Chapter II of that directive, entitled ‘The data subject’s right of access to data’, Article 12 thereof, itself entitled ‘Right of acc… Judgment of the Court (Grand Chamber) of 8 December 2022.#TU and RE v Google LLC.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Directive 95/46/EC – Article 12(b) – Point (a) of the first paragraph of Article 14 – Regulation (EU) 2016/679 – Article 17(3)(a) – Operator of an internet search engine – Research carried out on the basis of a person’s name – Displaying a l 154/21 Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C Court of Justice of the European Union Jan 2023 557/20 Judgment of the General Court (Eighth Chamber, Extended Composition) of 26 April 2023.#Single Resolution Board v European Data Protection Supervisor.#Protection of personal data – Procedure for granting compensation to shareholders and creditors following the resolution of a bank – Decision of the EDPS in which it found that the SRB failed to fulfil its obligations concerning the processing of personal data – Article 15(1)(d) of Regulation (EU) 2018/1725 – Concept of personal data – Article 3(1) General Court Apr 2023 203/22 Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor Court of Justice of the European Union Feb 2025 40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 487/21 Österreichische Datenschutzbehörde v CRIF CJEU Oct 2023 416/23 Judgment of the Court (First Chamber) of 9 January 2025.#Österreichische Datenschutzbehörde v F R.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(f) and Article 57(4) – Tasks of the supervisory authority – Concepts of a ‘request’ and ‘excessive requests’ – Charging of a reasonable fee or refusal to act on requests in the e Court of Justice of the European Union Jan 2025 434/16 Peter Nowak v Data Protection Commissioner CJEU Dec 2017 District Court Den Haag Rb. Den Haag - C/09/689833 District Court Den Haag May 2026 473/12 Judgment of the Court (Third Chamber), 7 November 2013.#Institut professionnel des agents immobiliers (IPI) v Geoffrey Englebert and Others.#Request for a preliminary ruling from the Cour constitutionnelle (Belgium).#Processing of personal data — Directive 95/46/EC — Articles 10 and 11 — Obligation to inform — Article 13(1)(d) and (g) — Exceptions — Scope of exceptions — Private detectives acting for the supervisory body of a regulated profession — Directive 2002/58/EC — Article 15(1).#Case C‑47 Court of Justice of the European Union Nov 2013 740/22 Judgment of the Court (Sixth Chamber) of 7 March 2024.#Endemol Shine Finland Oy.#Request for a preliminary ruling from the Itä-Suomen hovioikeus.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Articles 2, 4, 6, 10 and 86 – Data held by a court relating to the criminal convictions of a natural person – Oral disclosure of such data to a commercial company on account of a competition organised by that company – Concept of ‘processing of personal data’ Court of Justice of the European Union Mar 2024 461/22 Judgment of the Court (Ninth Chamber) of 11 July 2024.#MK v WB.#Request for a preliminary ruling from the Landgericht Hannover.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 2(2)(c) – Scope – Exclusion – Purely personal or household activity – Article 4(7) – Controller – Former guardian who performed his or her duties in a professional capacity – Article 15 – Access of the person who has been Court of Justice of the European Union Jul 2024 272/19 Judgment of the Court (Third Chamber) of 9 July 2020.#VQ v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling — Article 267 TFEU — Concept of ‘court or tribunal’ — Protection of natural persons with regard to the processing of personal data — Regulation (EU) 2016/679 — Scope — Article 2(2)(a) — Meaning of ‘activity which falls outside the scope of Union law’ — Article 4(7) — Concept of ‘controller’ — Petitions Committee of the Court of Justice of the European Union Jul 2020 245/20 Judgment of the Court (First Chamber) of 24 March 2022.#X and Z v Autoriteit Persoonsgegevens.#Request for a preliminary ruling from the Rechtbank Midden-Nederland.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Competence of the supervisory authority – Article 55(3) – Processing operations of courts acting in their judicial capacity – Concept – Making available to a journalist of documents arising fr Court of Justice of the European Union Mar 2022 673/17 Bundesverband der Verbraucherzentralen v Planet49 GmbH CJEU Oct 2019 17/22 Judgment of the Court (Fourth Chamber) of 12 September 2024.#HTB Neunte Immobilien Portfolio geschlossene Investment UG & Co. KG and Ökorenta Neue Energien Ökostabil IV geschlossene Investment GmbH & Co. KG v Müller Rechtsanwaltsgesellschaft mbH and Others.#Requests for a preliminary ruling from the Amtsgericht München.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Points (b), (c) and (f) of the firs Court of Justice of the European Union Sep 2024 132/21 Judgment of the Court (First Chamber) of 12 January 2023.#BE v Nemzeti Adatvédelmi és Információszabadság Hatóság.#Request for a preliminary ruling from the Fővárosi Törvényszék.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Articles 77 to 79 – Remedies – Parallel exercise – Relationship – Procedural autonomy – Effectiveness of the protection rules established by that regulation – Consistent and homo Court of Justice of the European Union Jan 2023 CJEU MINISTER VOOR IMMIGRATIE V. M, 17.7.2014 (“Minister v. M”) CJEU Jul 2014 German Supreme Court BGH: Court must grant unredacted file access in compulsory auctions under Art. 6(1)(e) German Supreme Court May 2026 526/24 CJEU - C-526/24 - Brillen Rottler GDPRhub Jul 2026 Federal Administrative Court BVwG - W252 2247042-1 Federal Administrative Court Jan 2024 Show 45 more →
Guidance 47
statement 20250313 implementation of the pnr directive in light of the cjeu judgment Statement 2/2025 on the implementation of the PNR Directive in light of CJEU Judgment C-817/19 CJEU Mar 2025 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 22020 on articles 46 2 a and 46 3 b of regulation 2016679 for Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies EDPB Dec 2020 guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 guidelines on the practical implementation of amicable settlements Guidelines 06/2022 on the practical implementation of amicable settlements EDPB May 2022 022020 on the european essential guarantees for Recommendations 02/2020 on the European Essential Guarantees for surveillance measures EDPB Nov 2020 guidelines on deceptive design patterns in social media platform interfaces how to recognise Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them EDPB Feb 2023 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 012021 on the adequacy referential under the law Recommendations 01/2021 on the adequacy referential under the Law Enforcement Directive EDPB Feb 2021 guidelines on virtual voice assistants Guidelines 02/2021 on virtual voice assistants EDPB Jul 2021 opinion 202527 united kingdom adequacy led Opinion 27/2025 regarding the European Commission Draft Implementing Decision pursuant to Directive (EU) 2016/680 on the adequate protection of personal data by the United Kingdom EDPB Oct 2025 opinion 202507 epo adequacydecision Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation EDPB May 2025 edps joint opinion 032022 on the proposal for a regulation on EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space EDPB Jul 2022 052021 on the draft administrative arrangement for Opinion 05/2021 on the draft Administrative Arrangement for the transfer of personal data between the Haut Conseil du Commissariat aux Comptes (H3C) and the Public Company Accounting Oversight Board (PCAOB) EDPB Feb 2021 guidelines on the use of facial recognition technology in the area of law enforcement Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement EDPB May 2023 cef report 2024 20250116 rightofaccess Coordinated Enforcement Action, implementation of the right of access by controllers EDPB Jan 2025 262024 on the draft decision of the de bremen Opinion 26/2024 on the draft decision of the DE Bremen Supervisory Authority regarding the “Catalogue of Criteria for the Certification of IT-supported processing of Personal Data pursuant to art 42 GDPR (‘GDPR – information privacy standard’)” presented EDPB Dec 2024 222024 on certain obligations following from the Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s) EDPB Oct 2024 Show 27 more →
Enforcement 48
CNIL (France) CNIL fines energy supplier for mishandling data subject access and objection requests CNIL (France) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts Garante per la protezione dei dati personali (Italy) Jul 2026 AEPD (Spain) AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage AEPD (Spain) Jul 2026 Tietosuojavaltuutetun toimisto (Finland) Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 Tietosuojavaltuutetun toimisto (Finland) Jul 2026 HDPA (Greece) HDPA (Greece) 33/2020 — Employee's access and erasure claims against the American College HDPA (Greece) Jul 2026 APD/GBA (Belgium) APD/GBA: Controller failed to provide copies of service sheets for GDPR access request APD/GBA (Belgium) May 2026 HDPA (Greece) HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens HDPA (Greece) May 2026 EDPB EDPB - Binding Decision 1/2026 EDPB May 2026 AKI (Estonia) AKI (Estonia) - No. 2.1-1/24/397-890-38 AKI (Estonia) Apr 2026 HDPA (Greece) HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers HDPA (Greece) Jun 2026 Garante per la protezione dei dati personali (Italy) Garante: Piaggio violated GDPR by accessing former employees' emails in disciplinary probe Garante per la protezione dei dati personali (Italy) Jun 2026 Slovak Data Protection Office SLOVENAKIË, DPB: Onvoldoende naleving van de rechten van betrokkenen. Slovak Data Protection Office Dec 2025 NL Hellenic Data Protection Authority (HDPA) NN Greek Single-Member Anonymous Life Insurance Company: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) Jul 2025 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Orde van biochemici, biologen en chemici in het Roemeense gezondheidszorgsysteem: Onvoldoende naleving van de rechten van betrokkenen. Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Aug 2025 NL Italian Data Protection Authority (Garante) Tirrenia Hospital S.r.l.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) Apr 2025 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Data Diggers Market Research SRL: Niet-naleving van algemene principes voor gegevensverwerking. Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) May 2025 NL Hellenic Data Protection Authority (HDPA) Gynaecoloog: Onvoldoende nakoming van de informatieplicht. Hellenic Data Protection Authority (HDPA) Apr 2025 NL Spanish Data Protection Authority (aepd) CREMA GAMES, S.L.: Onvoldoende nakoming van de informatieverplichtingen. Spanish Data Protection Authority (aepd) Mar 2025 NL Lithuanian Data Protection Authority (VDAI) Vinted: Insufficient fulfilment of data subjects rights Lithuanian Data Protection Authority (VDAI) Jul 2024 Show 28 more →
News 46
GDPRhub Datatilsynet (Denmark) - 2023-31-0321 GDPRhub Aug 2026 noyb - European Center for Digital Rights LinkedIn locks your GDPR rights behind a paywall noyb - European Center for Digital Rights May 2026 noyb - European Center for Digital Rights Digital Omnibus reality check: 83.5% of access requests not properly answered noyb - European Center for Digital Rights Apr 2026 noyb - European Center for Digital Rights GDPR Omnibus: EU “simplification” far removed from real business needs noyb - European Center for Digital Rights Mar 2026 noyb - European Center for Digital Rights Digital Omnibus: EU DPAs reject many proposed changes to the GDPR noyb - European Center for Digital Rights Feb 2026 noyb - European Center for Digital Rights noyb win: Microsoft ordered to stop tracking school children noyb - European Center for Digital Rights Jan 2026 European Data Protection Board The Italian SA imposed a 40 000 EUR fine on a company for violating the confidentiality of a employee's email account after the end of his employment European Data Protection Board Jun 2026 noyb - European Center for Digital Rights noyb win: Microsoft 365 Education may not track school children noyb - European Center for Digital Rights Oct 2025 noyb - European Center for Digital Rights noyb WIN: YouTube ordered to honour user’s right of access noyb - European Center for Digital Rights Aug 2025 noyb - European Center for Digital Rights How TikTok, AliExpress & WeChat ignore your GDPR rights noyb - European Center for Digital Rights Jul 2025 noyb - European Center for Digital Rights Swedbank refuses transparency in automatic interest calculation noyb - European Center for Digital Rights Feb 2025 noyb - European Center for Digital Rights WetterOnline sees "disproportionate effort" in complying with the GDPR noyb - European Center for Digital Rights Feb 2025 noyb - European Center for Digital Rights noyb WIN: Dutch authority fines Netflix €4.75 Million noyb - European Center for Digital Rights Dec 2024 noyb - European Center for Digital Rights 8 Years of GDPR: Greek supermarket’s Loyalty Card still not compliant noyb - European Center for Digital Rights Aug 2024 noyb - European Center for Digital Rights Microsoft's Xandr grants GDPR rights at a rate of 0% noyb - European Center for Digital Rights Jul 2024 noyb - European Center for Digital Rights noyb win at CJEU: Right of access may include documents and database extracts noyb - European Center for Digital Rights May 2023 noyb - European Center for Digital Rights No right to access your own location data? noyb files appeal against Spanish DPA noyb - European Center for Digital Rights Jun 2022 noyb - European Center for Digital Rights Right of access as a data protection boomerang? noyb - European Center for Digital Rights Feb 2021 noyb - European Center for Digital Rights Address broker: GDPR-compliance "too burdensome" noyb - European Center for Digital Rights Oct 2020 noyb - European Center for Digital Rights Netflix, Spotify & YouTube: Eight Strategic Complaints filed on “Right to Access” noyb - European Center for Digital Rights Jan 2019 Show 26 more →
Literature 23
European Journal of Risk Regulation The Court of Justice on the Excessiveness of Access Requests under the GDPR European Journal of Risk Regulation Jul 2026 Journal Scientific and Applied Research HOW GDPR TREATS AUTOMATED DECISION-MAKING Journal Scientific and Applied Research Nov 2025 Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza Dec 2023 European Data Protection Law Review Article 22 GDPR on Automated Individual Decision-Making: Prohibition or Data Subject Right? European Data Protection Law Review Jan 2022 European Data Protection Law Review Practitioner’s Corner ∙ Exercising GDPR Data Subjects’ Rights: Empirical Research on the Right to Explanation of News Recommender Systems European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 Atlanti Between European GDPR and Italian FOIA: New Regulations on Data Protection and Right to Access Atlanti Oct 2016 European Data Protection Law Review The Right to Explanation of Automated Decisions under the GDPR: The Issues of Explainability of AI Outputs and Protection of Trade Secrets European Data Protection Law Review Jan 2025 European Data Protection Law Review Forgetful AI: AI and the Right to Erasure under the GDPR European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Germany: Starting Implementation of the GDPR - Brief Overview of the Government Bill for a New Federal Data Protection Act European Data Protection Law Review Jan 2017 Frontiers in Genetics Recommendations for Creating Codes of Conduct for Processing Personal Data in Biobanking Based on the GDPR art.40 Frontiers in Genetics Nov 2021 European Data Protection Law Review GDPR Implementation Series ∙ Finland: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Italy: The Legislative Procedure for National Harmonisation with the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ France: The French Approach to the GDPR Implementation European Data Protection Law Review Jan 2018 Show 3 more →