GDPR¶

Regulation (EU) 2016/679: the baseline of the EU digital-regulation stack, in application since 25 May 2018. This branch treats GDPR as an operating discipline, not a legal topic: the registers, assessments and processes that make compliance demonstrable.
Planned branches¶
| Area | Planned artefacts |
|---|---|
| Accountability (Art. 5(2), 24, 30) | Records-of-processing starter structure · document inventory |
| DPIAs (Art. 35) | When-is-a-DPIA-required checklist · DPIA template walk-through |
| Processors & transfers (Art. 28, Ch. V) | Processor due-diligence checklist · DPA clause review list |
| Breach handling (Art. 33–34) | 72-hour notification runbook · severity assessment reference |
| GDPR × AI | How GDPR obligations interact with AI Act obligations (see also cross-mappings) |
Under construction
This branch fills in gradually. GDPR artefacts often ship as the "third leg" of cross-regulation mappings. Announcements on the blog.
From my library¶
Links from my reading library that help with GDPR work.
Running a GDPR project, step by step
A practitioner's guide to scoping and running a GDPR programme, written by someone who has clearly done it.
github.comPowerbrain, a GDPR-native context engine
Very young project: OPA policies, a sealed vault and pseudonymization for LLM context. Interesting direction for privacy-preserving AI plumbing.
github.comPII-Shield
Local PII anonymization with reversible placeholders, so you can send text to an LLM without sending the personal data. Small and practical.
european-alternatives.euEuropean Alternatives
A directory of EU-based alternatives to common US cloud services. Handy when data-transfer questions make a European provider the easier answer.
Primary sources¶
- Regulation (EU) 2016/679 on EUR-Lex
- EDPB guidelines (linked per artefact)