Permanent Legal Reference Guides
📘 Regulatory Texts & GDPR Articles (22)
In-depth legal analyses of Regulation (EU) 2016/679 articles:
Article 4 GDPR: Key Legal Definitions
Fundamental legal definitions in Article 4 GDPR: concept of personal data (Art. 4.1), processing (Art. 4.2), data controller (Art. 4.7), and data processor (Art. 4.8).
Article 5 GDPR: Cardinal Processing Principles & Accountability
Legal analysis of the cardinal principles in Article 5 GDPR: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and accountability.
Article 6 GDPR: The Six Lawful Grounds for Lawful Processing
Legal analysis of Article 6 GDPR: the six alternative legal bases for lawfulness of processing, valid consent criteria, and the legitimate interest three-part test (CJEU KNLTB).
Prohibition Principle and Exceptions for Sensitive Data
Legal regime of Article 9 GDPR: general prohibition of processing sensitive data (health, biometric, political opinions) and the ten statutory exceptions for lawfulness.
Criminal Data, Statutory Safeguards and Legal Newsdesk Sweden Ruling
Regime of Article 10 GDPR applicable to criminal convictions, offences and security measures: legal basis, safeguards and scope of CJEU judgment C-199/24 Legal Newsdesk Sweden.
Transparency Principles and Information to Data Subjects
Transparency obligations under Articles 12, 13 and 14 GDPR: mandatory content of privacy notices, clear and intelligible formats, time limits and exceptions.
Modalities of the Right of Access and Delivery of Data Copy
Legal framework of Article 15 GDPR and EDPB Guidelines 01/2022: scope of access rights, free first copy of data, specific recipients identification (CJEU C-154/21), and statutory one-month timeframe.
Rectification of Inaccurate Data and Completion of Incomplete Data
Legal framework of Article 16 GDPR: rectification without undue delay of inaccurate personal data, completion of incomplete data via supplementary statements, and recipient notification under Article 19.
The Right to Erasure and Lawful Exceptions
Conditions for applying Article 17 GDPR: 6 legitimate grounds for erasure, 5 statutory exceptions (freedom of expression, legal compliance, health, litigation) and Case C-199/24 Legal Newsdesk Sweden.
Restricting Processing Pending Verification of Rights
The four statutory cases for restriction of processing under Article 18 GDPR, technical freezing of restricted data, lifting procedure with prior notice, and recipient notification (Art. 19).
Exercising the Right to Data Portability
Legal framework of Article 20 GDPR and WP242 guidelines: right to data portability, structured and machine-readable formats (JSON, CSV, XML), cumulative conditions and exceptions.
Right to Object and Statutory Marketing Safeguards
Legal regime of Article 21 GDPR: right to object on grounds relating to particular situation (Art. 6(1)(e)-(f)), compelling legitimate grounds test, and unconditional absolute right to object to direct marketing.
Regulation of Automated Decision-Making and Profiling
Protective legal framework of Article 22 GDPR: general prohibition of solely automated decisions producing legal effects, exceptions and statutory right to human intervention.
Data Protection by Design and by Default Principles
Practical implementation of Article 25 GDPR and EDPB Guidelines 4/2019: integrating data protection principles upstream and establishing the most protective default configuration.
Article 28 GDPR: Data Processing Agreement & Mandatory Clauses
Comprehensive guide to Article 28 GDPR: mandatory clauses of the Data Processing Agreement (DPA), controller and processor responsibilities, sub-processors, and audit checklist.
Maintaining Records of Processing Activities
Records of processing activities obligations under Article 30 GDPR: mandatory content for controllers and processors, limits of the 250-employee exemption, and operational accountability compliance.
Security of Processing Through Risk-Appropriate Measures
Article 32 GDPR: pseudonymisation and encryption, confidentiality, integrity, availability and resilience, prompt restoration of access, and regular testing assessed against the state of the art and risk.
Personal Data Breach Notification Procedure
Personal data breach notification obligations under Article 33 GDPR: notifying the supervisory authority without undue delay and within 72 hours where feasible, and communicating high-risk breaches to data subjects (Art. 34).
Criteria and Methodology of the DPIA
Legal framework of the Data Protection Impact Assessment (Art. 35 GDPR): mandatory cases, WP248 high-risk criteria, assessment methodology, and prior consultation (Art. 36).
Status, Designation and Tasks of the DPO
Designation, position and tasks of the Data Protection Officer (DPO) under Articles 37-39 GDPR and WP243 guidelines: mandatory designation criteria, independence guarantees, and operational missions.
Appropriate Safeguards for International Transfers
Comprehensive guide to Article 46 GDPR: SCCs, BCRs, codes of conduct, certification mechanisms, binding commitments, TIA and supplementary measures for non-EEA transfers.
Criteria and Statutory Ceilings for Administrative Fines
Statutory ceilings and calculation criteria for administrative fines under Article 83 GDPR: Tier 1 (up to €10M / 2% turnover), Tier 2 (up to €20M / 4% turnover), proportionality and EDPB Guidelines 04/2022.
⚖️ Court of Justice Case Law (7)
Landmark judgments interpreting GDPR provisions:
CJEU C-131/12 Google Spain: Recognition of the Right to Dereferencing
Landmark CJEU judgment of 13 May 2014 (ECLI:EU:C:2014:317): recognition of the right to dereferencing against search engines and qualification as data controller.
CJEU C-311/18 Schrems II: Regime of International Data Transfers Outside the EU
CJEU judgment of 16 July 2020 (Schrems II): invalidation of Privacy Shield, conditional validity of SCCs and mandatory Transfer Impact Assessments (TIA).
CJEU C-252/21 Meta Platforms: Legal Bases Regime and Abuse of Dominant Position
Fundamental CJEU ruling of 4 July 2023 (ECLI:EU:C:2023:537): strict limitations on contractual necessity (Art. 6.1.b) and legitimate interest for personalized advertising.
CJEU C-300/21 Österreichische Post: Right to Compensation and Non-Material Damage Under Art. 82
CJEU judgment of 4 May 2023 (ECLI:EU:C:2023:370): compensation conditions under Article 82, absence of a de minimis threshold for non-material damage, and burden of proof.
CJEU C-621/22 KNLTB: Lawfulness of Commercial Interest Under Art. 6(1)(f)
Fundamental CJEU ruling of 4 October 2024 (ECLI:EU:C:2024:858): lawful commercial interest is not excluded as a legitimate interest subject to strict necessity and balancing.
CJEU C-199/24 Legal Newsdesk Sweden: Criminal Convictions Data and Article 85 GDPR
CJEU judgment of 9 July 2026 (ECLI:EU:C:2026:564): commercial publication of criminal conviction records does not fall, in principle, within the journalistic purposes of Article 85 GDPR.
Public Disclosure of Data and Proportionality
CJEU judgment of 3 September 2026 (ECLI:EU:C:2026:679): unrestricted online disclosure of minority shareholders' personal data is contrary to the GDPR.
🇪🇺 EDPB Doctrine & Guidelines (4)
European guidelines, opinions, and enforcement doctrine:
EDPB Guidelines 05/2020: Criteria for Valid Consent under the GDPR
EDPB Guidelines 05/2020 and Planet49 case law: the 4 cumulative criteria of valid consent (freely given, specific, informed, unambiguous) and cookie wall prohibitions.
EDPB Opinion 08/2024: Framework for 'Consent or Pay' Models on Digital Platforms
EDPB Opinion 08/2024 under Article 64(2) GDPR: strict conditions for 'Consent or Pay' models on large platforms, equivalent free alternatives, and genuine choice.
EDPB Guidelines 02/2025: Blockchain, Governance, and GDPR Compliance
EDPB Guidelines 02/2025 on blockchain technologies: Data Protection by Design and by Default (Art. 25), off-chain storage, smart contracts, and governance.
EDPB Guidelines 03/2026: Web Scraping for Generative AI
Legal analysis of EDPB Guidelines 03/2026 (Draft Version 1.0 open for consultation until 30 Oct 2026): lawful grounds for AI web scraping, Art. 6, Art. 9, and Art. 14 transparency.