Skip to content
Topic Contested in court

Personal Data

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Information relating to identified or identifiable natural persons

3,741 linked items 201 Laws400 Case Law417 Guidance2256 Enforcement361 News

Overview

21 sources · Jul 15, 2026

Legal Framework

Personal data under the GDPR encompasses any information relating to an identified or identifiable natural person, as defined in Article 4(1). The Regulation's material scope, governed by Article 2, extends to the wholly or partly automated processing of such data, as well as non-automated processing within structured filing systems. Article 3 establishes territorial scope: the GDPR applies to controllers established in the Union processing data in the context of that establishment's activities, regardless of whether processing occurs within the EU. An "establishment" requires effective and actual activity through stable arrangements—even minimal activity suffices, including through a commercial agent collecting payments for an internet service. The Regulation also reaches non-EU controllers offering goods or services to, or monitoring, data subjects within the Union.

Article 6 provides the six lawful bases for processing, with consent under Article 6(1)(a) requiring that the data subject exercise genuine, free will—consent is invalid where the subject lacks a real choice or cannot refuse or withdraw without detriment (Recital 42). Separate consent must be obtainable for distinct processing operations. Article 10 imposes stricter conditions for data relating to criminal convictions, permitting processing only under official authority control or via Union/Member State law with appropriate safeguards. Articles 13 and 14 specify transparency obligations when collecting personal data, while Article 34 mandates notifying data subjects of breaches likely to result in high risk.

Key Developments

The CJEU's judgment in Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems (Schrems II) confirmed that national supervisory authorities bear independent responsibility for verifying whether transfers to third countries comply with GDPR requirements, even where an adequacy decision exists. The Court invalidated the Privacy Shield, emphasizing that protections must be assessed against the reality of third-country government surveillance practices.

In Google LLC v. CNIL, the CJEU addressed the territorial reach of de-referencing obligations, holding that while EU law does not currently require global de-referencing, it does not prohibit it either. National authorities retain competence to weigh privacy rights against freedom of information under national fundamental rights standards.

Enforcement actions confirm regulators' focus on security obligations. The Romanian DPA fined SSG SELECT SOLUTIONS €2,000 under Articles 29 and 32 for insufficient technical and organizational measures, and imposed a €5,000 fine on Poșta Română for comparable security deficiencies.

Practical Guidance

  • Verify establishment nexus carefully: Assess whether any EU-based activity—even through agents or subsidiaries—constitutes a stable arrangement triggering Article 3 territorial scope, particularly where advertising or payment collection occurs within the Union.

  • Audit consent mechanisms against the freedom requirement: Ensure consent is granular, separately obtainable for distinct purposes, and revocable without penalty, per Recital 42 and the doctrinal interpretation of Articles 3:33 and 3:35 of the Dutch Civil Code applied by analogy.

  • Apply Article 10 restrictions to criminal records data: Confirm that any processing of conviction data occurs exclusively under official authority control or pursuant to Member State law providing explicit safeguards; comprehensive conviction registers require official authority oversight.

  • Implement breach notification readiness: Establish protocols to assess whether a breach is likely to result in high risk to data subjects, triggering Article 34 notification obligations, and prepare communication templates in advance.

  • Monitor emerging regulatory guidance on AI: The Dutch DPA's July 2026 guidance on generative AI under the GDPR signals increased scrutiny of how AI systems process personal data—assess training data and output generation against Article 6 lawful bases and Article 13 transparency requirements.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 201
art 5 Principles relating to processing of personal data GDPR Apr 2016 art 10 Processing of personal data relating to criminal convictions and offences GDPR Apr 2016 art 9 Processing of special categories of personal data GDPR Apr 2016 art 15 Right of access by the data subject GDPR Apr 2016 art 12 Transparent information, communication and modalities for the exercise of the rights of the data subject GDPR Apr 2016 art 13 Information to be provided where personal data are collected from the data subject GDPR Apr 2016 art 14 Information to be provided where personal data have not been obtained from the data subject GDPR Apr 2016 art 19 Notification obligation regarding rectification or erasure of personal data or restriction of processing GDPR Apr 2016 art 34 Communication of a personal data breach to the data subject GDPR Apr 2016 art 33 Notification of a personal data breach to the supervisory authority GDPR Apr 2016 art 50 International cooperation for the protection of personal data GDPR Apr 2016 rec 142 Recital 142 — nonprofit body data subject representation GDPR Apr 2016 rec 68 Recital 68 — data subject data portability right GDPR Apr 2016 rec 65 Recital 65 — data subject rectification and erasure rights GDPR Apr 2016 rec 61 Recital 61 — timing of data subject information provision GDPR Apr 2016 rec 51 Recital 51 — special categories of personal data protection GDPR Apr 2016 rec 50 Recital 50 — compatible further processing of personal data GDPR Apr 2016 rec 159 Recital 159 — scientific research personal data processing GDPR Apr 2016 rec 162 Recital 162 — statistical processing of personal data GDPR Apr 2016 rec 10 Recital 10 — personal data protection safeguarding AI Act Jun 2024 Show 181 more →
Case Law 400
¶2 Please choose Bulgarian (bg) Spanish (es) Czech (cs) Danish (da) German (de) Estonian (et) Greek (el) English (en) French (fr) Croatian (hr) Italian (… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶3 Please choose Bulgarian (bg) Spanish (es) Czech (cs) Danish (da) German (de) Estonian (et) Greek (el) English (en) French (fr) Croatian (hr) Italian (… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶6 Article 2 of that directive provides: ‘For the purposes of this Directive: (a) “personal data” shall mean any information relating to an identified or… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶24 Paragraph 15(1) of the TMG provides: ‘A service provider may collect and use the personal data of a user only to the extent necessary in order to faci… Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV 40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 793/19 Judgment of the Court (Grand Chamber) of 20 September 2022.#Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH.#Requests for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Directive 2002/58/EC – Article 15(1) – Court of Justice of the European Union Oct 2022 582/14 Patrick Breyer v Bundesrepublik Deutschland CJEU Oct 2016 34/21 Judgment of the Court (First Chamber) of 30 March 2023.#Hauptpersonalrat der Lehrerinnen und Lehrer beim Hessischen Kultusministerium v Minister des Hessischen Kultusministeriums.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing of data in the employment context – Regional school system – Teaching by videoconference due to the COVID-19 pandemic – Court of Justice of the European Union Mar 2023 492/23 Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) – Court of Justice of the European Union Dec 2025 245/19 Judgment of the Court (Grand Chamber) of 6 October 2020.#État luxembourgeois v B and Others.#Requests for a preliminary ruling from the Cour administrative (Luxembourg).#References for a preliminary ruling – Directive 2011/16/EU – Administrative cooperation in the field of taxation – Articles 1 and 5 – Decision ordering that information be provided to the competent authority of a Member State, acting in response to a request for exchange of information from the competent authority of another Mem Court of Justice of the European Union Oct 2020 460/20 Judgment of the Court (Grand Chamber) of 8 December 2022.#TU and RE v Google LLC.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Directive 95/46/EC – Article 12(b) – Point (a) of the first paragraph of Article 14 – Regulation (EU) 2016/679 – Article 17(3)(a) – Operator of an internet search engine – Research carried out on the basis of a person’s name – Displaying a l Court of Justice of the European Union Dec 2022 154/21 Judgment of the Court (First Chamber) of 12 January 2023.#RW v Österreichische Post AG.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 15(1)(c) – Data subject’s right of access to his or her data – Information about the recipients or categories of recipient to whom the personal data have been or will be disclosed – Restrictions.#C Court of Justice of the European Union Jan 2023 746/18 Judgment of the Court (Grand Chamber) of 2 March 2021.#Criminal proceedings against H. K.#Request for a preliminary ruling from the Riigikohus.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Directive 2002/58/EC – Providers of electronic communications services – Confidentiality of the communications – Limitations – Article 15(1) – Articles 7, 8 and 11 and Article 52(1) of the Charter of Fundamental Rights of the European Union – Legisl Court of Justice of the European Union Mar 2021 667/21 Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal Court of Justice of the European Union Dec 2023 140/20 Judgment of the Court (Grand Chamber) of 5 April 2022.#G.D. v The Commissioner of the Garda Síochána and Others.#Request for a preliminary ruling from the Supreme Court.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of the communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Access to data – Subsequent court supervision – Directive 2002/58 Court of Justice of the European Union Apr 2022 33/22 Judgment of the Court (Grand Chamber) of 16 January 2024.#Österreichische Datenschutzbehörde v WK.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Article 16 TFEU – Regulation (EU) 2016/679 – Article 2(2)(a) – Scope – Exclusions – Activities which fall outside the scope of Union law – Article 4(2) TEU – Activities concerning national security – Committee of inquir Court of Justice of the European Union Jan 2024 65/23 Judgment of the Court (Eighth Chamber) of 19 December 2024.#MK v K GmbH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6 Court of Justice of the European Union Dec 2024 26/22 Judgment of the Court (First Chamber) of 7 December 2023.#UF and AB v Land Hessen.#Requests for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Principle of ‘lawfulness’ – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interests pursued by the controller or by Court of Justice of the European Union Dec 2023 204/21 Judgment of the Court (Grand Chamber) of 5 June 2023.#European Commission v Republic of Poland.#Failure of a Member State to fulfil obligations – Second subparagraph of Article 19(1) TEU – Article 47 of the Charter of Fundamental Rights of the European Union ‐ Rule of law – Effective legal protection in the fields covered by EU law – Independence of judges – Article 267 TFEU – Possibility of making a reference to the Court for a preliminary ruling – Primacy of EU law – Jurisdiction in relation t Court of Justice of the European Union Jun 2023 CJEU HvJ EU 9 januari 2025, C‑394/23 (Mousse). CJEU Jan 2025 557/20 Judgment of the General Court (Eighth Chamber, Extended Composition) of 26 April 2023.#Single Resolution Board v European Data Protection Supervisor.#Protection of personal data – Procedure for granting compensation to shareholders and creditors following the resolution of a bank – Decision of the EDPS in which it found that the SRB failed to fulfil its obligations concerning the processing of personal data – Article 15(1)(d) of Regulation (EU) 2018/1725 – Concept of personal data – Article 3(1) General Court Apr 2023 340/21 VB v Natsionalna agentsia za prihodite CJEU Dec 2023 CJEU JH v Policejní prezidium CJEU Nov 2025 73/16 Judgment of the Court (Second Chamber) of 27 September 2017.#Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy.#Request for a preliminary ruling from the Najvyšší súd Slovenskej republiky.#Reference for a preliminary ruling — Charter of Fundamental Rights of the European Union — Articles 7, 8 and 47 — Directive 95/46/EC — Articles 1, 7 and 13 — Processing of personal data — Article 4(3) TEU — Drawing up of a list of personal data — Subject matter — Ta Court of Justice of the European Union Sep 2017 Show 380 more →
Guidance 417
statement 20250313 implementation of the pnr directive in light of the cjeu judgment Statement 2/2025 on the implementation of the PNR Directive in light of CJEU Judgment C-817/19 CJEU Mar 2025 032020 on the processing of data concerning health for the purpose Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak EDPB Apr 2020 22019 on the processing of personal data under article 61b gdpr in Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects EDPB Oct 2019 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 22020 on articles 46 2 a and 46 3 b of regulation 2016679 for Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies EDPB Dec 2020 guidelines on the criteria of the right to be forgotten in the search engines cases under th Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1) EDPB Jul 2020 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 29 working party guidelines on transparency under regulation 2016679 Article 29 Working Party - Guidelines on transparency under Regulation 2016/679 EDPB Apr 2018 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on the interplay of the second payment services directive and the gdpr Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR EDPB Dec 2020 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 012020 on processing personal data in the context of connected Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Mar 2021 guidelines on processing of personal data through video devices Guidelines 3/2019 on processing of personal data through video devices EDPB Jan 2020 42018 on the accreditation of certification bodies under article 43 Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679) EDPB Dec 2018 on the right to data portability under regulation 2016679 wp242 Guidelines on the right to data portability under Regulation 2016/679, WP242 rev.01 EDPB May 2018 022021 on the legal basis for the storage of credit card Recommendations 02/2021 on the legal basis for the storage of credit card data for the sole purpose of facilitating further online transactions EDPB May 2021 on processing of personal data through blockchain technologies Guidelines on processing of personal data through blockchain technologies EDPB Jul 2026 Show 397 more →
Enforcement 2256
NAIH (Hungary) NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations NAIH (Hungary) May 2026 NAIH (Hungary) NAIH fines online store HUF 10M for missing and inadequate privacy notice NAIH (Hungary) Apr 2026 NAIH (Hungary) NAIH fines online store HUF 2M for unclear and incomplete privacy notice NAIH (Hungary) Jul 2026 CNIL (France) CNIL fines energy supplier for mishandling data subject access and objection requests CNIL (France) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: Justice Ministry unlawful disclosure of employee health data in service order Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: OPI of Pisa must remove residential addresses from public register Garante per la protezione dei dati personali (Italy) Jul 2026 IMY (Sweden) IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border IMY (Sweden) Jul 2026 HDPA (Greece) HDPA (Greece) 33/2020 — Employee's access and erasure claims against the American College HDPA (Greece) Jul 2026 Tietosuojavaltuutetun toimisto (Finland) Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 Tietosuojavaltuutetun toimisto (Finland) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: Enna Health Authority violated GDPR by publishing judicial data Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: Employer's recording of locker opening and destruction of contents Garante per la protezione dei dati personali (Italy) Jun 2026 AEPD (Spain) AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator AEPD (Spain) Jul 2026 HDPA (Greece) HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens HDPA (Greece) May 2026 AEPD (Spain) AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage AEPD (Spain) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray Garante per la protezione dei dati personali (Italy) May 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful Garante per la protezione dei dati personali (Italy) May 2026 APDCAT (Catalonia) APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender APDCAT (Catalonia) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: Vasto municipality breached transparency duties over traffic cameras Garante per la protezione dei dati personali (Italy) Jun 2026 Show 2236 more →
News 361
GDPRhub ANSPDCP (Romania) - ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL GDPRhub Aug 2026 GDPRhub Datatilsynet (Norway) - 23/00435-62 GDPRhub Aug 2026 GDPRhub ICO (UK) - ACRO Criminal Records Office GDPRhub Aug 2026 Autoriteit Persoonsgegevens Uber krijgt boete van bijna 825 miljoen euro voor geautomatiseerd blokkeren van chauffeurs Autoriteit Persoonsgegevens Aug 2026 NL Autoriteit Persoonsgegevens AP adviseert Twitch-gebruikers: zet instellingen uit voor delen van data met Amazon AI Autoriteit Persoonsgegevens Aug 2026 NL GDPRhub DSB (Austria) - DSB-D124.1749 GDPRhub Aug 2026 GDPRhub Rb. Rotterdam - ROT 25/8349, 25/8350, 25/6295, 25/6296 and 25/6297 GDPRhub Aug 2026 GDPRhub VG Berlin - 42 K 51.25 GDPRhub Aug 2026 GDPRhub DSB (Austria) - DSB-D550.1284 GDPRhub Aug 2026 GDPRhub UODO (Poland) - DKE.561.1.2026 GDPRhub Aug 2026 GDPRhub GDPRhub style guide GDPRhub Aug 2026 GDPRhub ANSPDCP (Romania) - AMATO BESTSELLER S.R.L. GDPRhub Aug 2026 Autoriteit Persoonsgegevens Visit the AP: Rule of Law Tour on 12 September 2026 Autoriteit Persoonsgegevens Aug 2026 GDPRhub DPC (Ireland) - IN-19-9-4 GDPRhub Aug 2026 Autoriteit Persoonsgegevens DPD: privacy risks from the use of menstruation apps Autoriteit Persoonsgegevens Aug 2026 Autoriteit Persoonsgegevens Dutch DPA provides childcare providers with guidance on signs of abuse Autoriteit Persoonsgegevens Jul 2026 Autoriteit Persoonsgegevens Ransomware attacks: learn from the mistakes of others Autoriteit Persoonsgegevens Jul 2026 Autoriteit Persoonsgegevens Dutch DPA assists developers and organizations with new GDPR guidelines for generative AI Autoriteit Persoonsgegevens Jul 2026 European Data Protection Board EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain European Data Protection Board Jul 2026 European Data Protection Board EDPB and AMLA to develop Joint Guidelines on partnerships for information sharing European Data Protection Board Jul 2026 Show 341 more →
Literature 100
SN Computer Science Automating the Design and Development of Usable, GDPR-Aware Web Forms SN Computer Science Jul 2026 Journal Scientific and Applied Research HOW GDPR TREATS AUTOMATED DECISION-MAKING Journal Scientific and Applied Research Nov 2025 Unio - EU Law Journal Privacy vs. business convenience: the Mousse judgment and the future of data protection in the EU Unio - EU Law Journal Jun 2025 International Data Privacy Law Personal data protection enforcement under GDPR—the Slovak experience International Data Privacy Law Jun 2024 Computer Law Security Review Clarifying “personal data” and the role of anonymisation in data protection law: Including and excluding data from the scope of the GDPR (more clearly) through refining the concept of data protection Computer Law Security Review Apr 2024 Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza Dec 2023 European Data Protection Law Review Data Governance Act: On International Transfers of Non-Personal Data and GDPR Mimesis European Data Protection Law Review Jan 2023 European Data Protection Law Review Article 22 GDPR on Automated Individual Decision-Making: Prohibition or Data Subject Right? European Data Protection Law Review Jan 2022 European Data Protection Law Review GDPR Implementation Series ∙ Czech Republic: Personal Data Protection Law European Data Protection Law Review Jan 2020 SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – VI: Legitimate Interests SSRN Electronic Journal Jan 2019 SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – I: Consent. SSRN Electronic Journal Jan 2019 SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – III: Legal Obligation. SSRN Electronic Journal Jan 2019 SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – VII: Employment Purposes SSRN Electronic Journal Jan 2019 European Data Protection Law Review Civil Liability for Processing of Personal Data in the GDPR European Data Protection Law Review Jan 2019 SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – V: Public Interests amp; Exercise of Official Authority. SSRN Electronic Journal Jan 2019 SSRN Electronic Journal Grounds for Lawful Processing of Personal Data in GDPR and Personal Data Protection Bill 2018, India (PDPB): Section – IV: Vital Interests. SSRN Electronic Journal Jan 2019 Pravo ta nauki IMPACT OF GDPR ON UKRAINIAN PERSONAL DATA PROTECTION LEGISLATION Pravo ta nauki Dec 2018 International Data Privacy Law The transfer of personal data to third countries under the GDPR: when does a recipient country provide an adequate level of protection? International Data Privacy Law Jul 2018 European Data Protection Law Review GDPR Implementation Series ∙ Latvia: Draft Personal Data Processing Law European Data Protection Law Review Jan 2018 Bankarstvo GDPR: A new challenge for personal data protection Bankarstvo Jan 2017 Show 80 more →
Tools 6
Autoriteit Persoonsgegevens Meldloket datalekken Autoriteit Persoonsgegevens Autoriteit Persoonsgegevens Jul 2026 NL CNIL CNIL GDPR guide for developers CNIL Jul 2026 European Commission Standard Contractual Clauses (SCCs) for international transfers European Commission Jul 2026 GDPR.eu (Proton) GDPR.eu compliance checklist GDPR.eu (Proton) Jul 2026 RVO AVG-regelhulp voor bedrijven RVO Jul 2026 NL EDPS EDPS Website Evidence Collector EDPS Jul 2026