Skip to content
Topic Contested in court

Processing

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Any operation performed on personal data

3,539 linked items 88 Laws313 Case Law386 Guidance2549 Enforcement136 News

Overview

16 sources · Jul 15, 2026

Legal Framework

Article 4(2) GDPR defines processing as any operation or set of operations performed on personal data, whether or not by automated means. The definition is deliberately broad, encompassing collection, recording, storage, alteration, retrieval, disclosure, alignment, restriction, erasure, and destruction. Article 2(1) and (2) establishes the material scope: the Regulation applies to processing wholly or partly by automated means, and to non-automated processing of data forming part of a filing system. This expansive formulation ensures that virtually any interaction with personal data falls within the GDPR's reach.

Article 29 GDPR imposes a fundamental constraint on processing operations: processors and any person acting under the authority of the controller or processor may process personal data only on the controller's instructions, unless bound by Union or Member State law. This provision operationalizes the controller's responsibility for determining purposes and means, as defined in Article 4(7). Article 30 requires both controllers and processors to maintain records of processing activities, creating an auditable trail that supervisory authorities can inspect.

The rationale is structural: by defining processing broadly and anchoring accountability to the controller concept, the GDPR ensures that no data manipulation escapes regulatory oversight, regardless of the technical method employed.

Key Developments

In Schrems II (C-311/18), the Court of Justice confirmed that supervisory authorities bear responsibility for monitoring whether processing operations—including transfers to third countries—comply with EU rules, reinforcing that processing accountability cannot be displaced by adequacy decisions alone. The Court's reasoning in paragraphs 8 through 10 underscores that technological scale and globalization have intensified the need for processing oversight.

In Fashion ID (C-210/16), the Court established a critical limitation on information duties tied to processing: operators must provide information to data subjects only regarding the specific operations for which that operator actually determines purposes and means. This narrows the scope of Article 13 obligations for joint controllers and clarifies that processing accountability is operation-specific rather than blanket-based.

Enforcement confirms that deficient processing foundations attract significant penalties. The Norwegian DPA's €1.82 million fine against Elkjøp AS targeted insufficient legal basis for processing, while Romania's ANSPDCP fined Poșta Română €5,000 for inadequate technical safeguards during processing operations. These decisions signal that authorities examine both the legal basis and the technical conditions under which processing occurs.

Practical Guidance

  • Map every processing operation against Article 4(2)'s enumerated activities—collection, storage, alteration, disclosure, erasure—and confirm each has a valid legal basis under Article 6 before operations begin.
  • Ensure Article 29 compliance by contractually binding all subprocessors and internal personnel to process data solely on documented controller instructions, with no independent purpose determination permitted.
  • Maintain Article 30 records that identify each processing operation, its purpose, legal basis, data categories, recipients, retention periods, and technical safeguards—these records are the primary instrument authorities use to assess compliance.
  • Apply the Fashion ID principle when multiple parties are involved: delineate precisely which processing operations each party controls, and limit transparency obligations to those specific operations rather than assuming joint responsibility for the entire processing chain.
  • Before any international transfer as part of processing operations, conduct a transfer impact assessment consistent with Schrems II requirements, evaluating whether the third country's surveillance framework undermines the adequacy of protection for the processing at issue.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 88
art 5 Principles relating to processing of personal data GDPR Apr 2016 art 10 Processing of personal data relating to criminal convictions and offences GDPR Apr 2016 art 30 Records of processing activities GDPR Apr 2016 rec 82 Recital 82 — records of processing activities GDPR Apr 2016 rec 50 Recital 50 — compatible further processing of personal data GDPR Apr 2016 art 59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox AI Act Jun 2024 rec 162 Recital 162 — statistical processing of personal data GDPR Apr 2016 rec 23 Recital 23 — extraterritorial scope non EU controllers GDPR Apr 2016 rec 80 Recital 80 — non-EU controller processor representative requirement GDPR Apr 2016 rec 74 Recital 74 — controller responsibility liability and compliance measures GDPR Apr 2016 rec 36 Recital 36 — main establishment of controller and processor GDPR Apr 2016 rec 19 Recital 19 — criminal law data processing exclusion GDPR Apr 2016 rec 47 Recital 47 — legitimate interests as processing legal basis GDPR Apr 2016 rec 49 Recital 49 — network and information security processing GDPR Apr 2016 rec 10 Recital 10 — personal data protection safeguarding AI Act Jun 2024 rec 14 Recital 14 — Union data protection and privacy law NIS2 Dec 2022 rec 121 Recital 121 — lawful personal data processing for cybersecurity NIS2 Dec 2022 rec 72 Recital 72 — profiling subject to regulation rules GDPR Apr 2016 rec 39 Recital 39 — lawful fair transparent personal data processing GDPR Apr 2016 rec 89 Recital 89 — abolition of general notification obligation GDPR Apr 2016 Show 68 more →
Case Law 313
¶3 Please choose Bulgarian (bg) Spanish (es) Czech (cs) Danish (da) German (de) Estonian (et) Greek (el) English (en) French (fr) Croatian (hr) Italian (… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶6 Article 2 of that directive provides: ‘For the purposes of this Directive: (a) “personal data” shall mean any information relating to an identified or… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶4 Recital 10 of Directive 95/46 states: ‘Whereas the object of the national laws on the processing of personal data is to protect fundamental rights and… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶5 Article 1 of Directive 95/46 provides: ‘1. In accordance with this Directive, Member States shall protect the fundamental rights and freedoms of natur… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV 40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 793/19 Judgment of the Court (Grand Chamber) of 20 September 2022.#Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH.#Requests for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Directive 2002/58/EC – Article 15(1) – Court of Justice of the European Union Oct 2022 582/14 Patrick Breyer v Bundesrepublik Deutschland CJEU Oct 2016 34/21 Judgment of the Court (First Chamber) of 30 March 2023.#Hauptpersonalrat der Lehrerinnen und Lehrer beim Hessischen Kultusministerium v Minister des Hessischen Kultusministeriums.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing of data in the employment context – Regional school system – Teaching by videoconference due to the COVID-19 pandemic – Court of Justice of the European Union Mar 2023 492/23 Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) – Court of Justice of the European Union Dec 2025 460/20 Judgment of the Court (Grand Chamber) of 8 December 2022.#TU and RE v Google LLC.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Directive 95/46/EC – Article 12(b) – Point (a) of the first paragraph of Article 14 – Regulation (EU) 2016/679 – Article 17(3)(a) – Operator of an internet search engine – Research carried out on the basis of a person’s name – Displaying a l Court of Justice of the European Union Dec 2022 154/21 Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C Court of Justice of the European Union Jan 2023 746/18 Judgment of the Court (Grand Chamber) of 2 March 2021.#Criminal proceedings against H. K.#Request for a preliminary ruling from the Riigikohus.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Directive 2002/58/EC – Providers of electronic communications services – Confidentiality of the communications – Limitations – Article 15(1) – Articles 7, 8 and 11 and Article 52(1) of the Charter of Fundamental Rights of the European Union – Legisl Court of Justice of the European Union Mar 2021 245/19 Judgment of the Court (Grand Chamber) of 6 October 2020.#État luxembourgeois v B and Others.#Requests for a preliminary ruling from the Cour administrative (Luxembourg).#References for a preliminary ruling – Directive 2011/16/EU – Administrative cooperation in the field of taxation – Articles 1 and 5 – Decision ordering that information be provided to the competent authority of a Member State, acting in response to a request for exchange of information from the competent authority of another Mem Court of Justice of the European Union Oct 2020 667/21 Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal Court of Justice of the European Union Dec 2023 140/20 Judgment of the Court (Grand Chamber) of 5 April 2022.#G.D. v The Commissioner of the Garda Síochána and Others.#Request for a preliminary ruling from the Supreme Court.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of the communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Access to data – Subsequent court supervision – Directive 2002/58 Court of Justice of the European Union Apr 2022 33/22 Judgment of the Court (Grand Chamber) of 16 January 2024.#Österreichische Datenschutzbehörde v WK.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Article 16 TFEU – Regulation (EU) 2016/679 – Article 2(2)(a) – Scope – Exclusions – Activities which fall outside the scope of Union law – Article 4(2) TEU – Activities concerning national security – Committee of inquir Court of Justice of the European Union Jan 2024 65/23 Judgment of the Court (Eighth Chamber) of 19 December 2024.#MK v K GmbH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6 Court of Justice of the European Union Dec 2024 26/22 Judgment of the Court (First Chamber) of 7 December 2023.#UF and AB v Land Hessen.#Requests for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Principle of ‘lawfulness’ – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interests pursued by the controller or by Court of Justice of the European Union Dec 2023 CJEU HvJ EU 9 januari 2025, C‑394/23 (Mousse). CJEU Jan 2025 340/21 VB v Natsionalna agentsia za prihodite CJEU Dec 2023 73/16 Judgment of the Court (Second Chamber) of 27 September 2017.#Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy.#Request for a preliminary ruling from the Najvyšší súd Slovenskej republiky.#Reference for a preliminary ruling — Charter of Fundamental Rights of the European Union — Articles 7, 8 and 47 — Directive 95/46/EC — Articles 1, 7 and 13 — Processing of personal data — Article 4(3) TEU — Drawing up of a list of personal data — Subject matter — Ta Court of Justice of the European Union Sep 2017 203/22 Judgment of the Court (First Chamber) of 27 February 2025.#CK v Magistrat der Stadt Wien.#Request for a preliminary ruling from the Verwaltungsgericht Wien.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 15(1)(h) – Automated decision-making, including profiling – Scoring – Assessment of the creditworthiness of a natural person – Access to meaningful information about the logic involved in profiling – Verification of the accuracy of the infor Court of Justice of the European Union Feb 2025 597/19 Judgment of the Court (Fifth Chamber) of 17 June 2021.#Mircom International Content Management & Consulting (M.I.C.M.) Limited v Telenet BVBA.#Request for a preliminary ruling from the Ondernemingsrechtbank Antwerpen.#Reference for a preliminary ruling – Intellectual property – Copyright and related rights – Directive 2001/29/EC – Article 3(1) and (2) – Concept of ‘making available to the public’ – Downloading of a file containing a protected work via a peer-to-peer network and the simultaneous Court of Justice of the European Union Jun 2021 621/22 Judgment of the Court (Ninth Chamber) of 4 October 2024.#Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens.#Request for a preliminary ruling from the Rechtbank Amsterdam.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Lawfulness of processing – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interest Court of Justice of the European Union Oct 2024 Show 293 more →
Guidance 386
statement 20250313 implementation of the pnr directive in light of the cjeu judgment Statement 2/2025 on the implementation of the PNR Directive in light of CJEU Judgment C-817/19 CJEU Mar 2025 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines on the territorial scope of the gdpr Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) EDPB Nov 2019 guidelines on the application of article 60 gdpr Guidelines 02/2022 on the application of Article 60 GDPR EDPB Mar 2022 22019 on the processing of personal data under article 61b gdpr in Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects EDPB Oct 2019 29 working party guidelines on transparency under regulation 2016679 Article 29 Working Party - Guidelines on transparency under Regulation 2016/679 EDPB Apr 2018 guidelines for identifying a controller or processors lead supervisory authority Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority EDPB Apr 2023 22020 on articles 46 2 a and 46 3 b of regulation 2016679 for Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies EDPB Dec 2020 42018 on the accreditation of certification bodies under article 43 Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679) EDPB Dec 2018 012019 on the draft list of the european data protection Recommendation 01/2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 39.4 of Regulation (EU) 2018/1725) EDPB Jul 2019 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 guidelines on the interplay of the second payment services directive and the gdpr Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR EDPB Dec 2020 guidelines on the criteria of the right to be forgotten in the search engines cases under th Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) EDPB Jul 2020 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 032020 on the processing of data concerning health for the purpose Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak EDPB Apr 2020 guidelines on processing of personal data through video devices Guidelines 3/2019 on processing of personal data through video devices EDPB Jan 2020 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 Show 366 more →
Enforcement 2549
NAIH (Hungary) NAIH fines online store HUF 2M for unclear and incomplete privacy notice NAIH (Hungary) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Garante per la protezione dei dati personali (Italy) Jul 2026 NAIH (Hungary) NAIH fines online store HUF 10M for missing and inadequate privacy notice NAIH (Hungary) Apr 2026 NAIH (Hungary) NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations NAIH (Hungary) May 2026 Dutch Supervisory Authority for Data Protection (AP) Ridetech International B.V.: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) Apr 2026 CNIL (France) CNIL fines energy supplier for mishandling data subject access and objection requests CNIL (France) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA finds GDPR applies to US-based Character.AI service Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful Garante per la protezione dei dati personali (Italy) May 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: OPI of Pisa must remove residential addresses from public register Garante per la protezione dei dati personali (Italy) Jul 2026 HDPA (Greece) HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens HDPA (Greece) May 2026 AKI (Estonia) AKI (Estonia) - No. 2.1-1/24/397-890-38 AKI (Estonia) Apr 2026 IMY (Sweden) IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border IMY (Sweden) Jul 2026 Tietosuojavaltuutetun toimisto (Finland) Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 Tietosuojavaltuutetun toimisto (Finland) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: Justice Ministry unlawful disclosure of employee health data in service order Garante per la protezione dei dati personali (Italy) Jul 2026 UODO (Poland) UODO (Poland) - DKN.5131.5.2025 UODO (Poland) May 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: Vasto municipality breached transparency duties over traffic cameras Garante per la protezione dei dati personali (Italy) Jun 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: Employer's recording of locker opening and destruction of contents Garante per la protezione dei dati personali (Italy) Jun 2026 IP (Slovenia) Slovenian DPA fines controller €1,282 for missing Art. 28(3) processor contract IP (Slovenia) Aug 2026 AEPD (Spain) AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator AEPD (Spain) Jul 2026 Show 2529 more →
News 136
GDPRhub UODO (Poland) - DKE.561.1.2026 GDPRhub Aug 2026 GDPRhub DPC (Ireland) - IN-19-9-4 GDPRhub Aug 2026 European Data Protection Board EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain European Data Protection Board Jul 2026 European Data Protection Board Coordinated Supervision Committee extends scope to include Eurodac European Data Protection Board Jun 2026 European Data Protection Board The Italian Supervisory Authority fined a company 120 000 EUR for tracking five employees who drove company cars European Data Protection Board Jun 2026 European Data Protection Board Italian SA fines a company for post-sick leave questionnaires European Data Protection Board Jun 2026 European Data Protection Board The Italian SA imposed a 40 000 EUR fine on a company for violating the confidentiality of a employee's email account after the end of his employment European Data Protection Board Jun 2026 European Data Protection Board The Italian SA fined Poste Vita for data breach European Data Protection Board Jun 2026 GDPRhub Article 40 of the GDPR (General Data Protection Regulation). GDPRhub Jan 2026 Autoriteit Persoonsgegevens Ten municipalities fined for illegal processing of information regarding Islamic persons Autoriteit Persoonsgegevens Feb 2026 GDPRhub VDAI (Litouwen) - Besluit nr. 3R-1700. GDPRhub Jan 2026 NL GDPRhub CNIL (France) - SAN-2025-014 GDPRhub Jan 2026 GDPRhub Article 40 of the GDPR (General Data Protection Regulation). GDPRhub Jan 2026 European Data Protection Board Stakeholder event on political advertising: express your interest European Data Protection Board Jan 2026 GDPRhub USR - Reference number I-755/2025-8 GDPRhub Jan 2026 GDPRhub KHO - KHO:2025:86 GDPRhub Jan 2026 European Data Protection Board Making GDPR compliance easier through new initiatives: a key focus of the EDPB work programme 2026-2027 European Data Protection Board Feb 2026 European Data Protection Board EDPB contributes to the LED evaluation and adopts recommendations on the application for Processor BCR European Data Protection Board Jan 2026 GDPRhub CE - 492830 GDPRhub Jan 2026 GDPRhub CNIL (France) - SAN-2025-015 GDPRhub Jan 2026 Show 116 more →
Literature 65
SSRN Electronic Journal Data Controller, Processor or a Joint Controller: Towards Reaching GDPR Compliance in the Data and Technology Driven World SSRN Electronic Journal Jan 2020 SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – V: Public Interests amp; Exercise of Official Authority. SSRN Electronic Journal Jan 2019 SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – VII: Employment Purposes SSRN Electronic Journal Jan 2019 SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – IV: Vital Interests. SSRN Electronic Journal Jan 2019 SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – III: Legal Obligation. SSRN Electronic Journal Jan 2019 European Data Protection Law Review Civil Liability for Processing of Personal Data in the GDPR European Data Protection Law Review Jan 2019 SSRN Electronic Journal Unprotected Processing by Default vs Data Protection by Design and by Default Under the GDPR for Schrems II and GDPR SSRN Electronic Journal Jan 2022 SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – VI: Legitimate Interests SSRN Electronic Journal Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 Journal Scientific and Applied Research HOW GDPR TREATS AUTOMATED DECISION-MAKING Journal Scientific and Applied Research Nov 2025 European Data Protection Law Review Council of Europe ∙ Convention 108+, the GDPR, and Data Processing in the National Security Domain European Data Protection Law Review Jan 2022 SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – I: Consent. SSRN Electronic Journal Jan 2019 Pravo ta nauki IMPACT OF GDPR ON UKRAINIAN PERSONAL DATA PROTECTION LEGISLATION Pravo ta nauki Dec 2018 European Data Protection Law Review GDPR Implementation Series ∙ Latvia: Draft Personal Data Processing Law European Data Protection Law Review Jan 2018 Computer law & security review If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Computer law & security review Jan 2026 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 SN Computer Science Automating the Design and Development of Usable, GDPR-Aware Web Forms SN Computer Science Jul 2026 Show 45 more →
Tools 2
CNIL CNIL record of processing activities template CNIL Jul 2026 ICO ICO documentation templates (records of processing, Article 30) ICO Jul 2026