Primary documents, operating bodies, key case law, named voices, reference resources for the GDPR cluster.
Primary text
- Regulation (EU) 2016/679 — General Data Protection Regulation. Published OJEU 4 May 2016. Applicable 25 May 2018. Free at eur-lex.europa.eu.
- Recitals — 173 recitals providing interpretive context.
- Articles — 99 articles.
- Directive 95/46/EC — predecessor directive (historical reference).
- Directive (EU) 2016/680 — Law Enforcement Directive. Companion to GDPR for criminal law processing.
Operating bodies
EDPB (European Data Protection Board)
- Established by GDPR (replacing Article 29 Working Party).
- Composed of heads of national DPAs + European Data Protection Supervisor.
- Functions: ensure consistent application, issue guidelines, resolve cross-border disputes via consistency mechanism.
- Publishes Guidelines, Recommendations, Opinions, Binding Decisions.
National Data Protection Authorities (DPAs)
Member State independent supervisory authorities. Examples (subject to change):
- Germany — federated structure. BfDI (Federal Commissioner) for federal-level and telecommunications. State-level DPAs for state-regulated areas (LfD).
- France — CNIL (Commission Nationale de l'Informatique et des Libertés).
- Ireland — DPC (Data Protection Commission). Lead DPA for many US tech companies headquartered in Ireland.
- Spain — AEPD (Agencia Española de Protección de Datos).
- Italy — Garante per la protezione dei dati personali.
- Netherlands — Autoriteit Persoonsgegevens.
- UK — ICO (Information Commissioner's Office). UK GDPR replaces EU GDPR post-Brexit; substantially similar.
European Data Protection Supervisor (EDPS)
- Independent EU body supervising EU institutions' processing.
- Distinct from national DPAs.
Key CJEU jurisprudence
Pre-GDPR foundational
- Lindqvist (C-101/01, 2003) — early scope rulings.
- Google Spain (C-131/12, 2014) — right to be forgotten foundational ruling.
- Schrems I (C-362/14, 2015) — invalidated Safe Harbor (US adequacy decision); national DPA powers.
GDPR-era foundational
- Schrems II (C-311/18, 2020) — invalidated Privacy Shield; SCCs valid but require supplementary measures assessment.
- Maximillian Schrems v Facebook various — multiple consumer-rights and enforcement decisions.
- Various Article 22 (automated decision-making) rulings clarifying scope.
- Various legitimate interests rulings clarifying balancing test.
- Bundeskartellamt v Meta Platforms (C-252/21, 2023) — competition authorities can consider GDPR.
- Various right to access / erasure / portability decisions.
Recent (2024-2026)
- Multiple decisions on processing of special category data, automated decision-making, cross-border transfers, scope of national supervisory authority powers.
Notable enforcement actions
Tier-2 (€20M / 4%) fines
- Meta — €1.2B (May 2023, Schrems II SCCs violation), various smaller previous fines totaling >€2B by 2024.
- Amazon — €746M (July 2021, Luxembourg DPA).
- TikTok / ByteDance — €345M (September 2023, children's data, Ireland DPC).
- Uber — €290M (August 2024, international transfers, Netherlands DPA).
- WhatsApp — €225M (September 2021, transparency, Ireland DPC).
- Instagram — €405M (September 2022, children's data, Ireland DPC).
- Google — multiple fines, €90M and €60M (December 2021, cookie consent, France CNIL).
Tier-1 (€10M / 2%) fines
Multiple smaller fines for records, processor, transparency obligations.
Adjacent EU legislation
- EU AI Act (Reg 2024/1689) — co-applies with GDPR.
- ePrivacy Directive (2002/58/EC) + ePrivacy Regulation (proposed, in trilogue) — electronic communications privacy; cookies; direct marketing.
- Digital Services Act (Reg 2022/2065) — platform regulation; some GDPR overlap.
- Digital Markets Act (Reg 2022/1925) — gatekeeper regulation.
- NIS2 Directive (Dir 2022/2555) — cybersecurity; GDPR breach overlap.
- Data Act (Reg 2023/2854) — data sharing; non-personal data primarily.
- Data Governance Act (Reg 2022/868) — data intermediation, altruism.
- EHDS (European Health Data Space, Reg 2024/2854) — health data sharing; GDPR overlap.
International adequacy decisions
EU Commission adequacy decisions (Art 45) covering specific third countries' privacy frameworks:
- Andorra, Argentina, Faroe Islands, Guernsey, Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, UK, Uruguay.
- United States — under EU-US Data Privacy Framework (July 2023) for certified organizations only.
- Other — Canada (commercial sector).
Adequacy decisions are subject to periodic review.
Codes of conduct and certifications
- Various sector codes of conduct approved by DPAs.
- EuroPriSe — European Privacy Seal.
- EU Cloud Code of Conduct — cloud services GDPR.
- CISPE Code of Conduct — cloud infrastructure.
- Various ISO standards (ISO 27701 PIMS) as supporting evidence.
Named voices
Regulators and judges
- Andrea Jelinek — first EDPB Chair.
- Anu Talus — current EDPB Chair (since 2024).
- Wojciech Wiewiórowski — EDPS.
- Various national DPA heads — Helen Dixon (Ireland, recently retired), Marie-Laure Denis (France/CNIL), Mar España Martí (Spain/AEPD), etc.
Academics and commentators
- Christopher Kuner — leading academic on EU data protection.
- Paul De Hert — academic, Brussels Privacy Hub.
- Lokke Moerel — academic and practitioner.
- Various Brussels-based privacy lawyers and researchers.
Activists and critics
- Max Schrems — driving force behind Schrems I and II rulings, founded noyb.eu activist organization.
- noyb (None Of Your Business) — Vienna-based NGO. Files numerous complaints; significant influence on enforcement landscape.
- EDRi (European Digital Rights) — civil society engagement.
Practitioners
- IAPP (International Association of Privacy Professionals) — global certification + community organization.
- Various consultancies, in-house DPOs, privacy lawyers worldwide.
Reference resources
- eur-lex.europa.eu — official text source.
- edpb.europa.eu — EDPB guidelines, recommendations, opinions, decisions.
- gdpr.eu — informational portal (not official).
- iapp.org — IAPP resources, training, certification.
- noyb.eu — Schrems' organization, enforcement actions.
- enforcementtracker.com — non-official tracker of GDPR fines.
Adjacent global privacy regulations (Brussels effect targets)
- California: CCPA (2018), CPRA (2020).
- Brazil: LGPD (Lei Geral de Proteção de Dados, 2020).
- China: PIPL (Personal Information Protection Law, 2021).
- India: DPDP Act (Digital Personal Data Protection Act, 2023).
- South Korea: PIPA (Personal Information Protection Act, 2011 + revisions).
- Japan: APPI (Act on Protection of Personal Information).
- Singapore: PDPA (Personal Data Protection Act, 2012 + revisions).
- Various US states: Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, others through 2024-2026.
- Canada: PIPEDA + provincial variations.
- UK: UK GDPR + Data Protection Act 2018 (post-Brexit).