Skip to content
Topic Contested in court

Representatives

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Representatives of controllers not established in the EU

199 linked items 13 Laws52 Case Law23 Guidance57 Enforcement27 News

Overview

24 sources · Jul 23, 2026

Legal Framework

The representative regime under the GDPR operates as a bridge between the Regulation's extraterritorial reach and its enforcement machinery. Article 3(2) extends the GDPR to controllers and processors not established in the Union when they offer goods or services to data subjects in the Union or monitor their behaviour there. Article 3(3) likewise applies the Regulation to controllers not established in the Union but in a place where Member State law applies by virtue of public international law. Article 27 GDPR (referenced in the enforcement guidance below) then requires such controllers and processors to designate a representative in the Union, unless an exemption applies.

The transparency obligations reinforce this mechanism. Article 13(1)(a) requires controllers collecting data directly from data subjects to provide:

"the identity and the contact details of the controller and, where applicable, of the controller's representative"
GDPR Art. 13(1)(a)

A parallel obligation exists in Article 14(1)(a) for data not obtained from the data subject. The representative thus functions both as an enforcement contact point for supervisory authorities and as a transparency anchor for data subjects.

Key Developments

The EDPB has confirmed the interplay between territorial scope and the representative requirement. In its Guidelines 9/2022 on personal data breach notification, the Board stated:

"Article 27 GDPR requires a controller (and a processor) to designate a representative in the EU where Article 3(2) GDPR applies."
EDPB Guidelines 9/2022 §72

This means a non-EU controller caught by Article 3(2) that experiences a breach remains bound by Articles 33 and 34 notification obligations — and the representative serves as the local interface for that compliance.

The CJEU in Fashion ID addressed the information duty in the context of joint controllers, holding:

"the controller or his representative must provide, as a minimum, the information referred to in that provision to the subject whose data are being collected"
Fashion ID ¶104

While Fashion ID concerned joint-controller liability under Article 26, the Court's confirmation that the information obligation attaches to "the controller or his representative" underscores that the representative's role is not merely formal — it is a channel through which statutory information duties are discharged.

Status of the Debate

The core obligation to designate a representative under Article 27 when Article 3(2) applies is settled in the guidance. What remains contested is the boundary of Article 3(2) itself — particularly the meaning of "offering goods or services" and "monitoring behaviour" — which determines whether the representative requirement is triggered at all. The EDPB's Guidelines 3/2018 provide the prevailing interpretive framework, but courts have not yet produced a definitive ruling on the precise thresholds for Article 3(2)(a) and (b) in novel factual settings. A CJEU reference on the scope of "offering goods or services" to data subjects in the Union would resolve the principal open question.

Practical Guidance

  • Determine establishment status first. Assess whether your organisation has an "establishment" in the Union under Article 3(1). If not, evaluate whether Article 3(2)(a) or (b) applies — only then does the Article 27 representative obligation arise.
  • Designate a representative in every relevant Member State. Article 27 requires designation in a Member State where the data subjects are located, unless processing is occasional, non-likely-to-result-in-risk, and not involving special-category data.
  • Include representative contact details in all privacy notices. Both Article 13(1)(a) and Article 14(1)(a) require disclosure of the representative's contact details where applicable — omitting this is a standalone transparency violation.
  • Ensure the representative can act as a breach-notification contact. Per the EDPB's Guidelines 9/2022 §72, non-EU controllers subject to Article 3(2) must comply with Articles 33 and 34; the representative should be positioned to facilitate timely notification to the competent supervisory authority.
  • Document the Article 3(2) analysis. Maintain a written territorial-scope assessment demonstrating why the representative is or is not required, so that the decision can be defended if challenged by a supervisory authority.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 13
rec 116 Recital 116 — non-EU digital service provider EU representative NIS2 Dec 2022 rec 82 Recital 82 — EU authorised representative for third-country providers AI Act Jun 2024 rec 44 Recital 44 — third country intermediary EU legal representative DSA Oct 2022 rec 80 Recital 80 — non-EU controller processor representative requirement GDPR Apr 2016 rec 131 Recital 131 — European Board for Digital Services establishment DSA Oct 2022 rec 42 Recital 42 — single electronic point of contact DSA Oct 2022 rec 118 Recital 118 — complaints to digital services coordinator DSA Oct 2022 rec 123 Recital 123 — supervision by member state of establishment DSA Oct 2022 rec 150 Recital 150 — Commission general regulation evaluation DSA Oct 2022 rec 149 Recital 149 — service recipients right to mandate representatives DSA Oct 2022 rec 25 Recital 25 — public international law applicable controllers GDPR Apr 2016 rec 133 Recital 133 — temporary suspensions and prohibitions as enforcement NIS2 Dec 2022 rec 67 Recital 67 — high-quality data governance for AI AI Act Jun 2024
Case Law 52
¶8 Article 10 of Directive 95/46, headed ‘Information in cases of collection of data from the data subject’, provides: ‘Member States shall provide that … Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV ¶17 Article 13 of the GDPR, entitled ‘Information to be provided where personal data are collected from the data subject’, provides, in paragraph 1(a) the… Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) – ¶18 Article 14 of that regulation, entitled ‘Information to be provided where personal data have not been obtained from the data subject’, provides in par… Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) – ¶49 According to settled case-law, the use of the expression ‘any information’ in the definition of the concept of ‘personal data’ in Article 4(1) of the … Judgment of the Court (Grand Chamber) of 2 December 2025.#X v Russmedia Digital SRL and Inform Media Press SRL.#Request for a preliminary ruling from the Curtea de Apel Cluj.#Reference for a preliminary ruling – Protection of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Responsibility of the operator of an online marketplace for the publication of personal data contained in advertisements placed on its online marketplace by user advertisers – Article 5(2) – 40/17 Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV CJEU Jul 2019 582/14 Patrick Breyer v Bundesrepublik Deutschland CJEU Oct 2016 65/23 Judgment of the Court (Eighth Chamber) of 19 December 2024.#MK v K GmbH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6 Court of Justice of the European Union Dec 2024 638/23 Judgment of the Court (Eighth Chamber) of 27 February 2025.#Amt der Tiroler Landesregierung v Datenschutzbehörde.#Request for a preliminary ruling from the Verwaltungsgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 4(7) – Concept of ‘controller’ – Direct designation of the controller by national law – Auxiliary administrative entity in the service of a regional government – Lack of Court of Justice of the European Union Feb 2025 473/12 Judgment of the Court (Third Chamber), 7 November 2013.#Institut professionnel des agents immobiliers (IPI) v Geoffrey Englebert and Others.#Request for a preliminary ruling from the Cour constitutionnelle (Belgium).#Processing of personal data — Directive 95/46/EC — Articles 10 and 11 — Obligation to inform — Article 13(1)(d) and (g) — Exceptions — Scope of exceptions — Private detectives acting for the supervisory body of a regulated profession — Directive 2002/58/EC — Article 15(1).#Case C‑47 Court of Justice of the European Union Nov 2013 319/20 Judgment of the Court (Third Chamber) of 28 April 2022.#Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband eV.#Request for a preliminary ruling from the Bundesgerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 80 – Representation of the data subjects by a not-for-profit association – Representative action Court of Justice of the European Union Apr 2022 621/22 Judgment of the Court (Ninth Chamber) of 4 October 2024.#Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens.#Request for a preliminary ruling from the Rechtbank Amsterdam.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 5(1)(a) – Lawfulness of processing – Point (f) of the first subparagraph of Article 6(1) – Necessity of processing for the purposes of the legitimate interest Court of Justice of the European Union Oct 2024 293/12 Digital Rights Ireland Ltd v Minister for Communications CJEU Apr 2014 673/17 Bundesverband der Verbraucherzentralen v Planet49 GmbH CJEU Oct 2019 446/21 Judgment of the Court (Fourth Chamber) of 4 October 2024.#Maximilian Schrems v Meta Platforms Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Online social networks – General terms of use relating to contracts concluded between a digital platform and a user – Personalised advertising – Article 5(1)(b) – Principle of purpos Court of Justice of the European Union Oct 2024 17/22 Judgment of the Court (Fourth Chamber) of 12 September 2024.#HTB Neunte Immobilien Portfolio geschlossene Investment UG & Co. KG and Ökorenta Neue Energien Ökostabil IV geschlossene Investment GmbH & Co. KG v Müller Rechtsanwaltsgesellschaft mbH and Others.#Requests for a preliminary ruling from the Amtsgericht München.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Points (b), (c) and (f) of the firs Court of Justice of the European Union Sep 2024 178/22 Judgment of the Court (Grand Chamber) of 30 April 2024.#Criminal proceedings against Unknown individuals.#Request for a preliminary ruling from the Giudice delle indagini preliminari presso il Tribunale di Bolzano.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – Directive 2002/58/EC – Article 15(1) – Articles 7, 8, 11 and Article 52(1) of the Charter of Court of Justice of the European Union Apr 2024 362/14 Maximillian Schrems v Data Protection Commissioner CJEU Oct 2015 CJEU VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”) CJEU Nov 2010 Supreme Administrative Court CE - 451423 Supreme Administrative Court Jun 2022 461/22 Judgment of the Court (Ninth Chamber) of 11 July 2024.#MK v WB.#Request for a preliminary ruling from the Landgericht Hannover.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 2(2)(c) – Scope – Exclusion – Purely personal or household activity – Article 4(7) – Controller – Former guardian who performed his or her duties in a professional capacity – Article 15 – Access of the person who has been Court of Justice of the European Union Jul 2024 434/16 Peter Nowak v Data Protection Commissioner CJEU Dec 2017 191/15 Judgment of the Court (Third Chamber) of 28 July 2016.#Verein für Konsumenteninformation v Amazon EU Sàrl.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling — Judicial cooperation in civil matters — Regulations (EC) No 864/2007 and (EC) No 593/2008 — Consumer protection — Directive 93/13/EEC — Data protection — Directive 95/46/EC — Online sales contracts concluded with consumers resident in other Member States — Unfair terms — General terms and co Court of Justice of the European Union Jul 2016 Federal Court of Justice BGH awards non-material GDPR damages for erroneous disclosure of applicant salary data Federal Court of Justice Jun 2026 768/21 Judgment of the Court (First Chamber) of 26 September 2024.#TR v Land Hessen.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 57(1)(a) and (f) – Tasks of the supervisory authority – Article 58(2) – Corrective powers – Administrative fine – Discretion of the supervisory authority – Limits.#Case C-768/21. Court of Justice of the European Union Sep 2024 Show 32 more →
Guidance 23
guidelines on the territorial scope of the gdpr Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) EDPB Nov 2019 guidelines for identifying a controller or processors lead supervisory authority Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority EDPB Apr 2023 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on the application of article 651a gdpr Guidelines 03/2021 on the application of Article 65(1)(a) GDPR EDPB May 2023 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 172021 on the draft decision of the french Opinion 17/2021 on the draft decision of the French Supervisory Authority regarding the European code of conduct submitted by the Cloud Infrastructure Service Providers (CISPE) EDPB May 2021 162021 on the draft decision of the belgian Opinion 16/2021 on the draft decision of the Belgian Supervisory Authority regarding the “EU Data Protection Code of Conduct for Cloud Service Providers” submitted by Scope Europe EDPB May 2021 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 232021 on the draft decision of the competent Opinion 23/2021 on the draft decision of the competent supervisory authority of Czech Republic regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jul 2021 102020 on the draft decision of the competent Opinion 10/2020 on the draft decision of the competent supervisory authorities of Germany regarding the approval of the requirements for accreditation of a code of conduct monitoring body pursuant to article 41 GDPR EDPB May 2020 32020 on the france data protection supervisory Opinion 3/2020 on the France data protection supervisory authority draft accreditation requirements for a code of conduct monitoring body pursuant to article 41 GDPR EDPB Jan 2020 122024 on the draft decision of the french Opinion 12/2024 on the draft decision of the French Supervisory Authority regarding the “Code of Conduct for Service Providers in Clinical Research” submitted by EUCROF EDPB Jun 2024 262024 on the draft decision of the de bremen Opinion 26/2024 on the draft decision of the DE Bremen Supervisory Authority regarding the “Catalogue of Criteria for the Certification of IT-supported processing of Personal Data pursuant to art 42 GDPR (‘GDPR – information privacy standard’)” presented EDPB Dec 2024 172020 on the draft standard contractual clauses Opinion 17/2020 on the draft Standard Contractual Clauses submitted by the SI SA (Article 28(8) GDPR) EDPB May 2020 142026 on the europrivacy certification criteria Opinion 14/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal pursuant to Article 42.5 GDPR EDPB Apr 2026 252022 regarding the european privacy seal europrise Opinion 25/2022 regarding the European Privacy Seal (EuroPriSe ) certification criteria for the certification of processing operations by processors EDPB Sep 2022 32019 concerning the questions and answers on the interplay Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR) EDPB Jan 2019 report 20250313 support pool experts programme 2024 Report on the use of SPE external experts in 2024 EDPB Mar 2025 note on the data privacy framework redress mechanism for Information Note on the Data Privacy Framework redress mechanism for national security purposes EDPB Apr 2024 Show 3 more →
Enforcement 57
Garante per la protezione dei dati personali (Italy) Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA finds GDPR applies to US-based Character.AI service Garante per la protezione dei dati personali (Italy) Jul 2026 CNIL (France) CNIL fines energy supplier for mishandling data subject access and objection requests CNIL (France) Jul 2026 IP (Slovenia) Slovenian DPA fines controller €1,282 for missing Art. 28(3) processor contract IP (Slovenia) Aug 2026 AEPD (Spain) AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage AEPD (Spain) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante: OPI of Pisa must remove residential addresses from public register Garante per la protezione dei dati personali (Italy) Jul 2026 AKI (Estonia) AKI (Estonia) - No. 2.1-1/24/397-890-38 AKI (Estonia) Apr 2026 ICO (UK) ICO (UK) - KRA Consultancy Ltd ICO (UK) May 2026 APDCAT (Catalonia) APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender APDCAT (Catalonia) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: Enna Health Authority violated GDPR by publishing judicial data Garante per la protezione dei dati personali (Italy) Jul 2026 IP (Slovenia) Slovenian DPA fines controller €1,198 for Art. 32 GDPR breach via pirated software IP (Slovenia) Jul 2026 IP (Slovenia) Slovenian DPA fines processor €2,802 for failing to patch known vulnerability (Art. 32) IP (Slovenia) May 2026 AEPD (Spain) AEPD sanctions Tiger Media Inc. for installing advertising cookies without user consent AEPD (Spain) Nov 2025 Garante per la protezione dei dati personali (Italy) Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray Garante per la protezione dei dati personali (Italy) May 2026 DSB (Austria) Austrian DSB rules 360-degree feedback unlawful without specific works agreement DSB (Austria) Mar 2026 AEPD (Spain) AEPD sanctions 23andMe for security failures in credential-stuffing breach AEPD (Spain) Oct 2025 Spanish Data Protection Authority (aepd) CLUB BALONCESTO TELDE: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) Jul 2025 Spanish Data Protection Authority (aepd) CLUB BALONCESTO TELDE: Onvoldoende juridische basis voor de verwerking van gegevens. Spanish Data Protection Authority (aepd) Jul 2025 NL APD/GBA (Belgium) Belgian DPA finds cookie banner without reject-all button and unequal withdrawal violates APD/GBA (Belgium) Oct 2024 APD/GBA (Belgium) APD/GBA (Belgium) - 113/2024 APD/GBA (Belgium) Sep 2024 Show 37 more →
News 27
Electronic Frontier Foundation Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched Across the Country Electronic Frontier Foundation Jul 2026 EDPB Stakeholder event on anonymisation and pseudonymisation: express your interest EDPB Nov 2025 European Data Protection Board Strengthening data protection worldwide: EDPB meets with the countries and organisation with an adequacy decision European Data Protection Board Dec 2025 EDPB Strengthening data protection globally: The European Data Protection Board (EDPB) meets with countries and organizations subject to an adequacy decision. EDPB Dec 2025 EDPB Strengthening data protection globally: The European Data Protection Board (EDPB) is meeting with countries and organizations that have an adequacy decision. EDPB Dec 2025 EDPB Stakeholder event on anonymisation and pseudonymisation: express your interest. EDPB Nov 2025 EDPB Event for stakeholders on anonymization and pseudonymization: Please indicate your interest. EDPB Nov 2025 Legislation approved Legislation Oct 2025 Legislation Additional information following the debate on the law introducing the Citizen Service Number (BSN) and the digital government infrastructure (DIGG). Legislation Jun 2025 Government Report from a written consultation regarding... Government Jun 2025 Government Initiative proposal by members Ceder and Six Dijkstra regarding children's rights online. Government Apr 2025 NL EU Court Expert EU-Hof: consumentenbeschermings-verenigingen mogen representatieve vorderingen instellen tegen inbreuken op de bescherming van persoonsgegevens NL EU Court Expert Apr 2022 noyb - European Center for Digital Rights noyb approved as a “qualified entity” to file class actions in courts in Belgium noyb - European Center for Digital Rights Oct 2020 IT en Recht Court of Audit points out obstacles in implementation of GDPR in Netherlands in letter to Chamber IT en Recht Apr 2023 EURactiv Het EU-VS privacyakkoord vereist een grondige en kritische beoordeling. EURactiv Oct 2022 NL IAPP De Griekse toezichthouder heeft Clearview AI een boete van 20 miljoen euro opgelegd. IAPP Oct 2022 NL IAPP Greek SA fines Clearview AI for EUR 20M IAPP Oct 2022 Kromann Reumert DeFine is a calculator for GDPR fines based on method of the EDPB Kromann Reumert Feb 2022 EURactiv EU-US Privacy Framework needs a long hard look EURactiv Oct 2022 eucrim Mensenrechtenorganisaties bekritiseren de geautomatiseerde gegevensuitwisseling voor de samenwerking tussen de politie (voorstel Prüm II). eucrim Oct 2022 NL Show 7 more →
Literature 27
European Data Protection Law Review Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit? European Data Protection Law Review Jan 2022 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Cyprus: A Look into the Law for the Effective Application of the GDPR European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Slovenia: Introduction to the Most Recent Public Draft of the GDPR Implementing Law European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Ireland: A Brief Overview of the Implementation of the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Poland: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Finland: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Italy: The Legislative Procedure for National Harmonisation with the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ France: The French Approach to the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Luxembourg: Reshaping the National Context to Adjust to the GDPR European Data Protection Law Review Jan 2017 Journal of Data Protection Privacy General Data Protection Regulation (GDPR) ambiguity, national diversity and data protection officer certification: Implementing Art. 39(1) GDPR in France, Italy, Luxembourg and Spain Journal of Data Protection Privacy Sep 2021 European Data Protection Law Review GDPR Implementation Series ∙ Latvia: The Implementation of the GDPR in a New Legislative Framework European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Germany: Starting Implementation of the GDPR - Brief Overview of the Government Bill for a New Federal Data Protection Act European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR European Data Protection Law Review Jan 2017 Show 7 more →