Skip to content
← Services

GDPR

Regulation (EU) 2016/679 — General Data Protection Regulation

Data ProtectionEuropean UnionIn force: May 25, 2018

What it is

The General Data Protection Regulation governs the processing of personal data of EU residents. Eight years in, it is the most influential data protection framework globally, shaping national regimes from Brazil's LGPD to Nigeria's NDPA.

What it requires

Any organisation processing personal data of EU residents, regardless of where the organisation is established. Mandates lawful basis, data subject rights (access, rectification, erasure, portability, objection), accountability, privacy by design, breach notification within 72 hours, DPO appointment for certain processors, and prior consultation for high-risk processing.

Key facts

Supervisor
National Data Protection Authority per member state (BfDI, CNIL, Garante, IMY, AEPD, etc.), coordinated through the EDPB
Maximum fine
EUR 20 million or 4% of global annual turnover (whichever is higher) for the most serious infringements

DSI services for GDPR

DSI Advisory Services helps covered entities translate GDPR obligations into evidence a supervisor, auditor, or board can sign off on — gap assessment, control mapping, and documentation that survives review.

See the service →

Related briefings

The Architecture of the Watched World
Chokepoint DoctrineJuly 14, 2026
The Architecture of the Watched World

I saw The Lives of Others in 2011, and it shook me to my core — not the cruelty of the Stasi, but the ordinariness of it: a life catalogued by professionals simply doing their jobs. I have spent the years since watching a version of that filing system being rebuilt, not by a police state but by democracies, for reasons that are mostly good, using tools most people carry willingly in their pockets. This DSI assessment maps the six-layer identity-and-surveillance stack now in deployment across the EU, UK, Australia and beyond — identity wallets, age verification, message scanning, biometric driver monitoring, ambient audio, and behavioural data — each introduced with a genuine justification, and ungoverned in combination. It corrects the viral misreading of what Von der Leyen actually said, sets the 1984 Stasi against the 2026 stack, and closes with five dated, falsifiable forecasts and the risks I would put on any register I was responsible for. The Stasi needed forty years, 91,000 staff and 175,000 informants. The equivalent capability now needs an app, a camera, and a terms-of-service agreement — and there is no wall to tear down.

Free tier18 min read
The Ship and the Iceberg
Chokepoint DoctrineJuly 12, 2026
The Ship and the Iceberg

Pavel Durov says the ship of our personal freedoms has hit the iceberg and is sinking without us realising it. He is partly right, partly wrong, and entirely worth taking seriously. This GISI assessment evaluates his argument against the evidence: the UK's 30 online-speech arrests a day, Germany's platform-fining model, France's crypto-kidnapping wave, the EU's Chat Control revival on 9 July 2026, and the online-safety regimes of Australia and New Zealand. What is accurate survives scrutiny. What is exaggerated — the collapse of the distinction between Western democracies and Russia, China, and Iran — does not. The right question is not whether the West is becoming authoritarian. It is whether the architecture being built in the name of safety — age verification, identity wallets, bulk collection, biometric mandates — creates the conditions under which essential liberty becomes, in practice, optional, regardless of who governs it. The series has been asking that question. The answer, so far, is not consistently yes.

Free tier13 min read
No Means No. Except When It Does.
Regulatory ForesightJuly 9, 2026
No Means No. Except When It Does.

On 9 July 2026 the European Parliament revived Chat Control 1.0 — three months after rejecting it. A majority of MEPs still voted against (314 to 276, 17 abstentions), but under the second-reading procedure the EPP engineered, blocking it required an absolute majority of 361. Opponents fell 47 short. The vote count is not the story. The procedure that inverted the burden of proof — timed for the last day before recess — is.

Free tier9 min read
The Sixth Attempt
EU Regulatory LandscapeJuly 8, 2026
The Sixth Attempt

The EU's 'Chat Control' is back for the sixth time - and the way it is coming back matters more than whether it passes. Chat Control 1.0, the interim derogation letting US platforms voluntarily scan unencrypted messages for CSAM, expired on 3 April 2026 after Parliament rejected an extension 311-228 (not, as claimed, by a single vote). The Council is reviving it through a formally 'new' law with identical content: an urgent-procedure vote cleared the way 331-304 on 7 July, with the substantive vote on Thursday 10 July - the last sitting day before recess, when 361 members (an absolute majority) would be needed to stop it. Whose interest does this serve? Several at once: a genuine child-protection case; institutional pressure (four Commissioners lobbied MEPs); the EPP closing a 'legal gap' while dodging the Chat Control 2.0 vote its members are blocking; and - the interest nobody names - legal-cover restoration for Meta, Google, Microsoft and Snap, who have scanned without authorisation since April. My assessment: this is not the EU overriding democracy but circumventing it through procedure while keeping formal cover - harder to name, and harder to stop. And the surveillance architecture (EUDI Wallet, age verification, ADDW cameras) keeps building regardless of Thursday's vote. Every box is governed; the intersection is no one's job.

Free tier8 min read
The Camera That Cannot Be Turned Off
Chokepoint DoctrineJuly 8, 2026
The Camera That Cannot Be Turned Off

Since 7 July 2026, every new car and van registered in the EU must carry an infrared camera aimed at the driver's face - the Advanced Driver Distraction Warning (ADDW), specified under the General Safety Regulation. It tracks gaze, warns after 3.5 seconds' distraction above 50 km/h, and cannot be permanently turned off. The safety case is real (the wider package is projected to save 25,000+ lives by 2038) and the rule prohibits facial recognition. But the regulation mandates the hardware while leaving the data surface unanswered - retention, sharing, insurer and law-enforcement access - and the same automakers now installing it have already been documented collecting, sharing, and losing connected-vehicle data. The stronger concern is structural: the camera is always-on infrastructure, and the Commission has committed to further ADDW requirements by July 2027. My assessment: this is 'every box is governed, the space between is no one's job' arriving on the road. The camera cannot be turned off - and who benefits from what it sees, beyond the driver, is still being answered by the parties with the most incentive to answer it in their own favour.

Free tier10 min read
The Credential You Can't Change
Chokepoint DoctrineJuly 7, 2026
The Credential You Can't Change

Your voiceprint is not a password. A password can be changed; your voice cannot. In January 2021 Walmart settled for $10M over palm scans of 22,000 Illinois employees; by July it was sued over warehouse-headset voiceprints, then over uploading shoppers' faces to a Clearview AI database - three biometric systems, one company, all under Illinois's Biometric Information Privacy Act, the only US law that lets individuals sue. McDonald's, Chipotle, Verizon, Microsoft Teams face the same claims; 107 BIPA class actions were filed in Illinois in 2025 alone. In 47 of 50 states, collecting your fingerprint, face, or voiceprint needs no consent, no disclosure, and carries no consequence. Under GDPR Article 9 it is special-category data requiring explicit consent, with fines to EUR 20M or 4% of turnover - and the EU AI Act bans workplace emotion inference from 2 August 2026. My assessment: this is not a regulatory gap but a policy choice, applied to the one category of data that is permanent. If the database holding your voiceprint is breached, the credential is compromised for life - and in 47 states no one is obliged to tell you.

Free tier8 min read

Read more on this

Other data protection frameworks in the DSI registry: