GDPR anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Primary documents, operating bodies, key case law, named voices, reference resources for the GDPR cluster.

Primary text

  • Regulation (EU) 2016/679 — General Data Protection Regulation. Published OJEU 4 May 2016. Applicable 25 May 2018. Free at eur-lex.europa.eu.
  • Recitals — 173 recitals providing interpretive context.
  • Articles — 99 articles.
  • Directive 95/46/EC — predecessor directive (historical reference).
  • Directive (EU) 2016/680 — Law Enforcement Directive. Companion to GDPR for criminal law processing.

Operating bodies

EDPB (European Data Protection Board)

  • Established by GDPR (replacing Article 29 Working Party).
  • Composed of heads of national DPAs + European Data Protection Supervisor.
  • Functions: ensure consistent application, issue guidelines, resolve cross-border disputes via consistency mechanism.
  • Publishes Guidelines, Recommendations, Opinions, Binding Decisions.

National Data Protection Authorities (DPAs)

Member State independent supervisory authorities. Examples (subject to change):

  • Germany — federated structure. BfDI (Federal Commissioner) for federal-level and telecommunications. State-level DPAs for state-regulated areas (LfD).
  • France — CNIL (Commission Nationale de l'Informatique et des Libertés).
  • Ireland — DPC (Data Protection Commission). Lead DPA for many US tech companies headquartered in Ireland.
  • Spain — AEPD (Agencia Española de Protección de Datos).
  • Italy — Garante per la protezione dei dati personali.
  • Netherlands — Autoriteit Persoonsgegevens.
  • UK — ICO (Information Commissioner's Office). UK GDPR replaces EU GDPR post-Brexit; substantially similar.

European Data Protection Supervisor (EDPS)

  • Independent EU body supervising EU institutions' processing.
  • Distinct from national DPAs.

Key CJEU jurisprudence

Pre-GDPR foundational

  • Lindqvist (C-101/01, 2003) — early scope rulings.
  • Google Spain (C-131/12, 2014) — right to be forgotten foundational ruling.
  • Schrems I (C-362/14, 2015) — invalidated Safe Harbor (US adequacy decision); national DPA powers.

GDPR-era foundational

  • Schrems II (C-311/18, 2020) — invalidated Privacy Shield; SCCs valid but require supplementary measures assessment.
  • Maximillian Schrems v Facebook various — multiple consumer-rights and enforcement decisions.
  • Various Article 22 (automated decision-making) rulings clarifying scope.
  • Various legitimate interests rulings clarifying balancing test.
  • Bundeskartellamt v Meta Platforms (C-252/21, 2023) — competition authorities can consider GDPR.
  • Various right to access / erasure / portability decisions.

Recent (2024-2026)

  • Multiple decisions on processing of special category data, automated decision-making, cross-border transfers, scope of national supervisory authority powers.

Notable enforcement actions

Tier-2 (€20M / 4%) fines

  • Meta — €1.2B (May 2023, Schrems II SCCs violation), various smaller previous fines totaling >€2B by 2024.
  • Amazon — €746M (July 2021, Luxembourg DPA).
  • TikTok / ByteDance — €345M (September 2023, children's data, Ireland DPC).
  • Uber — €290M (August 2024, international transfers, Netherlands DPA).
  • WhatsApp — €225M (September 2021, transparency, Ireland DPC).
  • Instagram — €405M (September 2022, children's data, Ireland DPC).
  • Google — multiple fines, €90M and €60M (December 2021, cookie consent, France CNIL).

Tier-1 (€10M / 2%) fines

Multiple smaller fines for records, processor, transparency obligations.

Adjacent EU legislation

  • EU AI Act (Reg 2024/1689) — co-applies with GDPR.
  • ePrivacy Directive (2002/58/EC) + ePrivacy Regulation (proposed, in trilogue) — electronic communications privacy; cookies; direct marketing.
  • Digital Services Act (Reg 2022/2065) — platform regulation; some GDPR overlap.
  • Digital Markets Act (Reg 2022/1925) — gatekeeper regulation.
  • NIS2 Directive (Dir 2022/2555) — cybersecurity; GDPR breach overlap.
  • Data Act (Reg 2023/2854) — data sharing; non-personal data primarily.
  • Data Governance Act (Reg 2022/868) — data intermediation, altruism.
  • EHDS (European Health Data Space, Reg 2024/2854) — health data sharing; GDPR overlap.

International adequacy decisions

EU Commission adequacy decisions (Art 45) covering specific third countries' privacy frameworks:

  • Andorra, Argentina, Faroe Islands, Guernsey, Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, UK, Uruguay.
  • United States — under EU-US Data Privacy Framework (July 2023) for certified organizations only.
  • Other — Canada (commercial sector).

Adequacy decisions are subject to periodic review.

Codes of conduct and certifications

  • Various sector codes of conduct approved by DPAs.
  • EuroPriSe — European Privacy Seal.
  • EU Cloud Code of Conduct — cloud services GDPR.
  • CISPE Code of Conduct — cloud infrastructure.
  • Various ISO standards (ISO 27701 PIMS) as supporting evidence.

Named voices

Regulators and judges

  • Andrea Jelinek — first EDPB Chair.
  • Anu Talus — current EDPB Chair (since 2024).
  • Wojciech Wiewiórowski — EDPS.
  • Various national DPA heads — Helen Dixon (Ireland, recently retired), Marie-Laure Denis (France/CNIL), Mar España Martí (Spain/AEPD), etc.

Academics and commentators

  • Christopher Kuner — leading academic on EU data protection.
  • Paul De Hert — academic, Brussels Privacy Hub.
  • Lokke Moerel — academic and practitioner.
  • Various Brussels-based privacy lawyers and researchers.

Activists and critics

  • Max Schrems — driving force behind Schrems I and II rulings, founded noyb.eu activist organization.
  • noyb (None Of Your Business) — Vienna-based NGO. Files numerous complaints; significant influence on enforcement landscape.
  • EDRi (European Digital Rights) — civil society engagement.

Practitioners

  • IAPP (International Association of Privacy Professionals) — global certification + community organization.
  • Various consultancies, in-house DPOs, privacy lawyers worldwide.

Reference resources

  • eur-lex.europa.eu — official text source.
  • edpb.europa.eu — EDPB guidelines, recommendations, opinions, decisions.
  • gdpr.eu — informational portal (not official).
  • iapp.org — IAPP resources, training, certification.
  • noyb.eu — Schrems' organization, enforcement actions.
  • enforcementtracker.com — non-official tracker of GDPR fines.

Adjacent global privacy regulations (Brussels effect targets)

  • California: CCPA (2018), CPRA (2020).
  • Brazil: LGPD (Lei Geral de Proteção de Dados, 2020).
  • China: PIPL (Personal Information Protection Law, 2021).
  • India: DPDP Act (Digital Personal Data Protection Act, 2023).
  • South Korea: PIPA (Personal Information Protection Act, 2011 + revisions).
  • Japan: APPI (Act on Protection of Personal Information).
  • Singapore: PDPA (Personal Data Protection Act, 2012 + revisions).
  • Various US states: Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, others through 2024-2026.
  • Canada: PIPEDA + provincial variations.
  • UK: UK GDPR + Data Protection Act 2018 (post-Brexit).

See also