Skip to content
Topic Contested in court

Controllers

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Entities that determine purposes and means of processing

2,713 linked items 83 Laws233 Case Law362 Guidance1924 Enforcement65 News

Overview

21 sources · Jul 15, 2026

Legal Framework

The concept of "controller" is defined in Article 4(7) GDPR as the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing personal data. This definition is deliberately broad, capturing any entity that exercises decision-making authority over why and how personal data are processed.

Article 24 GDPR places primary responsibility for compliance squarely on the controller—not the processor. The controller must implement appropriate technical and organisational measures to ensure and demonstrate that processing is carried out in accordance with the Regulation. This accountability obligation means the controller must adopt internal policies, impose contractual obligations on processors under Article 28, and maintain documentation sufficient to prove compliance. Article 24(3) further provides that adherence to approved codes of conduct under Article 40 or certification mechanisms under Article 42 serves as an element by which the controller can demonstrate compliance.

Article 29 GDPR reinforces the controller's authority: any person acting under the controller's authority with access to personal data may process those data only on the controller's instructions, unless required to do so by Union or Member State law. Article 26 GDPR expressly contemplates joint controllership—situations where multiple parties together determine purposes and means, as commonly arises in collaborative arrangements.

Key Developments

The CJEU's ruling in Fashion ID GmbH & Co. KG v. Verbraucherzentrale NRW eV clarified that a controller's transparency obligations extend only to the operations for which that controller actually determines the purposes and means. A party that plays a limited role in processing is not responsible for the entire processing operation but only for the segment it controls. This narrows the scope of accountability for embedded third-party tools and similar arrangements.

In Jehovah's Witnesses, the CJEU held that controllers cannot systematically refuse data subject access requests by invoking the privacy of third parties without examining the specific circumstances. Each request requires individualized assessment.

The Schrems II judgment underscored that controllers transferring data outside the EU must document their transfer impact assessments and suitable safeguards in their Article 30 records, reinforcing the documentation burden on controllers.

Enforcement actions illustrate the consequences of failing to meet controller obligations. The Spanish DPA fined a landlord €1,800 for deploying video surveillance in rental apartments without a sufficient legal basis. The Romanian DPA imposed a €20,000 fine on Tensa Art Design S.A. after the controller obstructed the investigation into its processing activities—demonstrating that failure to cooperate with supervisory authorities compounds liability.

Practical Guidance

  • Document your role determination: For each processing activity, record whether you act as controller, joint controller, or processor. The Fashion ID ruling confirms that accountability is proportionate to actual decision-making authority over purposes and means.

  • Establish internal accountability policies: Article 24(1)–(2) requires controllers to implement and be able to demonstrate compliance through documented policies, not ad hoc practices. Certification mechanisms and approved codes of conduct under Articles 42 and 40 can serve as evidence.

  • Bind processors contractually: Under Article 28, controllers must impose data protection terms on all processors. Liability for compliance failures extends to the controller if processor oversight is inadequate.

  • Restrict internal access on a need-to-know basis: Article 29 mandates that personnel acting under the controller's authority process data only on instructions. Implement access controls and documented authorization hierarchies.

  • Prepare individualized responses to data subject requests: Following Jehovah's Witnesses, controllers must assess each access request on its merits rather than applying blanket refusals based on third-party privacy concerns.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 83
art 29 Processing under the authority of the controller or processor GDPR Apr 2016 art 28 Processor GDPR Apr 2016 art 24 Responsibility of the controller GDPR Apr 2016 art 26 Joint controllers GDPR Apr 2016 art 79 Right to an effective judicial remedy against a controller or processor GDPR Apr 2016 rec 81 Recital 81 — processor guarantees and contract requirements GDPR Apr 2016 rec 95 Recital 95 — processor assistance with DPIA and prior consultation GDPR Apr 2016 rec 80 Recital 80 — non-EU controller processor representative requirement GDPR Apr 2016 rec 36 Recital 36 — main establishment of controller and processor GDPR Apr 2016 rec 29 Recital 29 — incentives for pseudonymisation within controller GDPR Apr 2016 rec 74 Recital 74 — controller responsibility liability and compliance measures GDPR Apr 2016 art 16 Right to rectification GDPR Apr 2016 art 19 Notification obligation regarding rectification or erasure of personal data or restriction of processing GDPR Apr 2016 art 44 General principle for transfers GDPR Apr 2016 art 48 Transfers or disclosures not authorised by Union law GDPR Apr 2016 art 31 Cooperation with the supervisory authority GDPR Apr 2016 rec 109 Recital 109 — standard data protection clauses contractual flexibility GDPR Apr 2016 rec 78 Recital 78 — data protection by design and default GDPR Apr 2016 rec 145 Recital 145 — jurisdiction choice for data subject proceedings GDPR Apr 2016 rec 114 Recital 114 — Data transfer safeguards absent adequacy decision GDPR Apr 2016 Show 63 more →
Case Law 233
¶3 Please choose Bulgarian (bg) Spanish (es) Czech (cs) Danish (da) German (de) Estonian (et) Greek (el) English (en) French (fr) Croatian (hr) Italian (… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶6 Article 2 of that directive provides: ‘For the purposes of this Directive: (a) “personal data” shall mean any information relating to an identified or… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶7 Article 7 of that directive states: ‘Member States shall provide that personal data may be processed only if: (a) the data subject has unambiguously g… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶8 Article 10 of Directive 95/46, headed ‘Information in cases of collection of data from the data subject’, provides: ‘Member States shall provide that … Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV 40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 492/23 Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) – Court of Justice of the European Union Dec 2025 460/20 Judgment of the Court (Grand Chamber) of 8 December 2022.#TU and RE v Google LLC.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Directive 95/46/EC – Article 12(b) – Point (a) of the first paragraph of Article 14 – Regulation (EU) 2016/679 – Article 17(3)(a) – Operator of an internet search engine – Research carried out on the basis of a person’s name – Displaying a l Court of Justice of the European Union Dec 2022 154/21 Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C Court of Justice of the European Union Jan 2023 667/21 Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal Court of Justice of the European Union Dec 2023 33/22 Judgment of the Court (Grand Chamber) of 16 January 2024.#Österreichische Datenschutzbehörde v WK.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Article 16 TFEU – Regulation (EU) 2016/679 – Article 2(2)(a) – Scope – Exclusions – Activities which fall outside the scope of Union law – Article 4(2) TEU – Activities concerning national security – Committee of inquir Court of Justice of the European Union Jan 2024 26/22 Judgment of the Court (First Chamber) of 7 December 2023.#UF and AB v Land Hessen.#Requests for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Principle of ‘lawfulness’ – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interests pursued by the controller or by Court of Justice of the European Union Dec 2023 CJEU HvJ EU 9 januari 2025, C‑394/23 (Mousse). CJEU Jan 2025 557/20 Judgment of the General Court (Eighth Chamber, Extended Composition) of 26 April 2023.#Single Resolution Board v European Data Protection Supervisor.#Protection of personal data – Procedure for granting compensation to shareholders and creditors following the resolution of a bank – Decision of the EDPS in which it found that the SRB failed to fulfil its obligations concerning the processing of personal data – Article 15(1)(d) of Regulation (EU) 2018/1725 – Concept of personal data – Article 3(1) General Court Apr 2023 340/21 VB v Natsionalna agentsia za prihodite CJEU Dec 2023 73/16 Judgment of the Court (Second Chamber) of 27 September 2017.#Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy.#Request for a preliminary ruling from the Najvyšší súd Slovenskej republiky.#Reference for a preliminary ruling — Charter of Fundamental Rights of the European Union — Articles 7, 8 and 47 — Directive 95/46/EC — Articles 1, 7 and 13 — Processing of personal data — Article 4(3) TEU — Drawing up of a list of personal data — Subject matter — Ta Court of Justice of the European Union Sep 2017 210/16 Unabhängiges Landeszentrum für Datenschutz v Wirtschaftsakademie Schleswig-Holstein CJEU Jun 2018 413/23 Judgment of the Court (First Chamber) of 4 September 2025.#European Data Protection Supervisor v Single Resolution Board.#Appeal – Protection of natural persons with regard to the processing of personal data – Procedure for granting compensation to shareholders and creditors of a banking institution following the resolution of that institution – Decision of the European Data Protection Supervisor finding that the Single Resolution Board failed to fulfil its obligations relating to the processing Court of Justice of the European Union Sep 2025 203/22 Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor Court of Justice of the European Union Feb 2025 293/12 Digital Rights Ireland Ltd v Minister for Communications CJEU Apr 2014 37/20 Judgment of the Court (Grand Chamber) of 22 November 2022.#WM and Sovim SA v Luxembourg Business Registers.#Requests for a preliminary ruling from the Tribunal d'arrondissement de Luxembourg.#Reference for a preliminary ruling – Prevention of the use of the financial system for the purposes of money laundering or terrorist financing – Directive (EU) 2018/843 amending Directive (EU) 2015/849 – Amendment to Article 30(5), first subparagraph, point (c), of Directive 2015/849 – Access for any member Court of Justice of the European Union Nov 2022 507/23 Judgment of the Court (Eighth Chamber) of 4 October 2024.#A v Patērētāju tiesību aizsardzības centrs.#Request for a preliminary ruling from the Augstākā tiesa (Senāts).#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 82(1) – Right to compensation and liability – Unlawful processing of data – Infringement of the right to protection of personal data – Concept of ‘damage’ – Compensation for non-material damage in the form of apologies – Whether Court of Justice of the European Union Oct 2024 621/22 Judgment of the Court (Ninth Chamber) of 4 October 2024.#Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens.#Request for a preliminary ruling from the Rechtbank Amsterdam.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Lawfulness of processing – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interest Court of Justice of the European Union Oct 2024 638/23 Judgment of the Court (Eighth Chamber) of 27 February 2025.#Amt der Tiroler Landesregierung v Datenschutzbehörde.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Direct designation of the controller by national law – Auxiliary administrative entity in the service of a regional government – Lack of Court of Justice of the European Union Feb 2025 446/21 Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos Court of Justice of the European Union Oct 2024 Show 213 more →
Guidance 362
guidelines 022024 on article 48 gdpr Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 guidelines for identifying a controller or processors lead supervisory authority Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority EDPB Apr 2023 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines 202402 article48 v2 Guidelines 02/2024 on Article 48 GDPR EDPB Jun 2025 052021 on the interplay between the application of article 3 and the Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR EDPB Feb 2023 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on the application of article 60 gdpr Guidelines 02/2022 on the application of Article 60 GDPR EDPB Mar 2022 guidelines on the territorial scope of the gdpr Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) EDPB Nov 2019 for identifying a controller or processors lead supervisory Guidelines for identifying a controller or processor's lead supervisory authority, WP244 rev.01 EDPB May 2018 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 182021 on the draft standard contractual clauses Opinion 18/2021 on the draft Standard Contractual Clauses submitted by the LT SA (Article 28(8) GDPR) EDPB May 2021 172020 on the draft standard contractual clauses Opinion 17/2020 on the draft Standard Contractual Clauses submitted by the SI SA (Article 28(8) GDPR) EDPB May 2020 142019 on the draft standard contractual clauses Opinion 14/2019 on the draft Standard Contractual Clauses submitted by the DK SA (Article 28(8) GDPR) EDPB Jul 2019 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 van de tekst in de afbeeldingen in de bijlage Translations proofread by EDPB Members. This language version has not yet been proofread. EDPB Nov 2025 edps joint opinion 12021 on standard contractual clauses between EDPB-EDPS Joint Opinion 1/2021 on standard contractual clauses between controllers and processors EDPB Jan 2021 Show 342 more →
Enforcement 1924
NAIH (Hungary) NAIH fines online store HUF 10M for missing and inadequate privacy notice NAIH (Hungary) Apr 2026 NAIH (Hungary) NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations NAIH (Hungary) May 2026 Garante per la protezione dei dati personali (Italy) Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts Garante per la protezione dei dati personali (Italy) Jul 2026 NAIH (Hungary) NAIH fines online store HUF 2M for unclear and incomplete privacy notice NAIH (Hungary) Jul 2026 CNIL (France) CNIL fines energy supplier for mishandling data subject access and objection requests CNIL (France) Jul 2026 AKI (Estonia) AKI (Estonia) - No. 2.1-1/24/397-890-38 AKI (Estonia) Apr 2026 IP (Slovenia) Slovenian DPA fines controller €1,282 for missing Art. 28(3) processor contract IP (Slovenia) Aug 2026 Tietosuojavaltuutetun toimisto (Finland) Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 Tietosuojavaltuutetun toimisto (Finland) Jul 2026 AEPD (Spain) AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage AEPD (Spain) Jul 2026 IMY (Sweden) IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border IMY (Sweden) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA finds GDPR applies to US-based Character.AI service Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful Garante per la protezione dei dati personali (Italy) May 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: OPI of Pisa must remove residential addresses from public register Garante per la protezione dei dati personali (Italy) Jul 2026 AEPD (Spain) AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator AEPD (Spain) Jul 2026 UODO (Poland) UODO (Poland) - DKN.5131.5.2025 UODO (Poland) May 2026 VDAI (Lithuania) VDAI (Lithuania) - 3R-1143 VDAI (Lithuania) Jun 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: Employer's recording of locker opening and destruction of contents Garante per la protezione dei dati personali (Italy) Jun 2026 UODO (Poland) UODO (Poland) - DKN.5131.27.2023 UODO (Poland) May 2026 Show 1904 more →
News 65
GDPRhub ICO (UK) - ACRO Criminal Records Office GDPRhub Aug 2026 GDPRhub Datatilsynet (Norway) - 23/00435-62 GDPRhub Aug 2026 GDPRhub ANSPDCP (Romania) - ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL GDPRhub Aug 2026 GDPRhub DSB (Austria) - DSB-D124.1749 GDPRhub Aug 2026 GDPRhub GDPRhub style guide GDPRhub Aug 2026 GDPRhub Rb. Rotterdam - ROT 25/8349, 25/8350, 25/6295, 25/6296 and 25/6297 GDPRhub Aug 2026 GDPRhub UODO (Poland) - DKE.561.1.2026 GDPRhub Aug 2026 GDPRhub DSB (Austria) - DSB-D550.1284 GDPRhub Aug 2026 GDPRhub ANSPDCP (Romania) - AMATO BESTSELLER S.R.L. GDPRhub Aug 2026 GDPRhub Garante per la protezione dei dati personali (Italy) - 10273026 GDPRhub Aug 2026 GDPRhub DPC (Ireland) - IN-19-9-4 GDPRhub Aug 2026 European Data Protection Board The Italian Supervisory Authority fined a company 120 000 EUR for tracking five employees who drove company cars European Data Protection Board Jun 2026 GDPRhub CNIL (France) - SAN-2025-014 GDPRhub Jan 2026 European Data Protection Board EDPB identifies challenges hindering the full implementation of the right to erasure European Data Protection Board Feb 2026 GDPRhub Article 40 of the GDPR (General Data Protection Regulation). GDPRhub Jan 2026 GDPRhub SO Warszawa - C 310/23 GDPRhub Jan 2026 GDPRhub VDAI (Litouwen) - Besluit nr. 3R-1700. GDPRhub Jan 2026 NL GDPRhub Article 40 of the GDPR (General Data Protection Regulation). GDPRhub Jan 2026 GDPRhub VDAI (Lithuania) - Decision No. 3R-1700. GDPRhub Jan 2026 GDPRhub SO Warszawa - Case C 310/23 GDPRhub Jan 2026 Show 45 more →
Literature 44
SSRN Electronic Journal Data Controller, Processor or a Joint Controller: Towards Reaching GDPR Compliance in the Data and Technology Driven World SSRN Electronic Journal Jan 2020 Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza Dec 2023 Computer law & security review If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Computer law & security review Jan 2026 Journal Scientific and Applied Research HOW GDPR TREATS AUTOMATED DECISION-MAKING Journal Scientific and Applied Research Nov 2025 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 Awang Long Law Review PROTECTION OF DATA SUBJECT RIGHTS IN THE TRANSFER OF PERSONAL DATA BETWEEN DATA CONTROLLERS IN INDONESIA: A COMPARATIVE ANALYSIS OF THE PDP LAW AND THE EU GDPR Awang Long Law Review Jan 2026 Unio - EU Law Journal Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU Unio - EU Law Journal Jun 2025 Journal of Data Protection Privacy GDPR Glasnost: Spain’s AEPD raises the transparency bar and sanctions two banks Journal of Data Protection Privacy Dec 2021 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 Bankarstvo GDPR: A new challenge for personal data protection Bankarstvo Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Luxembourg: Reshaping the National Context to Adjust to the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Poland: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Journal of Risk Regulation The Court of Justice on the Excessiveness of Access Requests under the GDPR European Journal of Risk Regulation Jul 2026 European Data Protection Law Review Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit? European Data Protection Law Review Jan 2022 European Data Protection Law Review GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Ireland: A Brief Overview of the Implementation of the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR European Data Protection Law Review Jan 2017 Show 24 more →
Tools 2
ICO ICO documentation templates (records of processing, Article 30) ICO Jul 2026 European Commission Standard Contractual Clauses (SCCs) for international transfers European Commission Jul 2026