The GDPR
Regulation 2016/679, and the instrument that pulls hardest against collecting data to train a model. Wisman's field, and the home of SCHUFA — the case that decides whether a human reviewer is really deciding.
1. The basics
Regulation (EU) 2016/679. Adopted 27 April 2016, applicable from 25 May 2018. It replaced Directive 95/46/EC.
It is a Regulation, so directly applicable in every Member State with no transposition needed. But it contains roughly 70 opening clauses letting Member States legislate detail, which is why national data protection acts still exist and why practice diverges.
Stated purpose: harmonise data protection across the single market, strengthen individual control, and enable lawful data flows by creating trust. That last aim matters — the instrument is framed as a facilitator, not a prohibition, and saying so signals you have read it rather than absorbed its reputation.
2. Who the actors are
| Actor | Who they are |
|---|---|
| Data subject | An identified or identifiable natural person. Living individuals only. Not companies |
| Controller, Article 4(7) | Determines the purposes and means of processing. Carries the primary obligations |
| Processor, Article 4(8) | Processes on the controller's behalf, governed by a mandatory contract under Article 28 |
| Joint controllers, Article 26 | Two or more controllers jointly determining purposes, who must allocate responsibilities transparently |
| Data Protection Officer, Articles 37 to 39 | Mandatory for public authorities, and for large-scale systematic monitoring or large-scale special category processing |
| Supervisory authority, Articles 51 to 59 | The national data protection authority. The Autoriteit Persoonsgegevens in the Netherlands |
| Lead supervisory authority, Article 56 | The one-stop-shop. For cross-border processing, the authority of the main establishment leads |
| EDPB, Articles 68 to 76 | European Data Protection Board. Guidelines, and dispute resolution between authorities |
| EDPS | European Data Protection Supervisor. Supervises EU institutions under Regulation 2018/1725, not the GDPR |
3. Scope, and the three carve-outs that matter
Material scope, Article 2: processing of personal data wholly or partly by automated means, or manual processing of data forming part of a filing system.
Excluded: purely personal or household activity; matters outside the scope of Union law; criminal law enforcement, which is covered instead by the Law Enforcement Directive (EU) 2016/680; and EU institutions and bodies, covered instead by Regulation (EU) 2018/1725.
Territorial scope, Article 3: controllers and processors established in the EU, regardless of where the processing happens; and non-EU controllers who offer goods or services to, or monitor the behaviour of, people in the EU. That second limb is the extraterritorial reach, and the source of the Brussels effect.
4. Definitions you need, Article 4
- Personal data — any information relating to an identified or identifiable natural person. Very broad: IP addresses, device identifiers and metadata all qualify.
- Processing — essentially any operation. Collection, recording, storage, alteration, retrieval, consultation, use, disclosure, erasure.
- Pseudonymisation, Article 4(5) — replacing identifiers so that re-identification needs additional information. Pseudonymised data is still personal data. People get this wrong constantly, and it is the most common fatal flaw in a research data plan.
- Anonymous data — falls outside the GDPR entirely, under Recital 26. But the bar is that the person is no longer identifiable by any reasonably likely means, and genuine anonymisation is hard.
- Profiling, Article 4(4) — automated processing to evaluate personal aspects, in particular to analyse or predict performance, behaviour, location or reliability.
5. The seven principles, Article 5
| Principle | Meaning |
|---|---|
| Lawfulness, fairness, transparency | 5(1)(a). A lawful basis is required, and people must know what is happening |
| Purpose limitation | 5(1)(b). Collected for specified, explicit, legitimate purposes; no incompatible further processing |
| Data minimisation | 5(1)(c). Adequate, relevant, and limited to what is necessary |
| Accuracy | 5(1)(d). Accurate and kept up to date; inaccurate data erased or rectified |
| Storage limitation | 5(1)(e). Kept no longer than necessary |
| Integrity and confidentiality | 5(1)(f). Appropriate security |
| Accountability | 5(2). The controller is responsible and must be able to demonstrate compliance |
Note that purpose limitation and data minimisation are the same idea as Article 18's necessity test and Article 28's use limitation in Regulation 1/2003, arriving from a different direction. Two regimes, one constraint, and both of them argue with exploratory model training.
6. Lawful bases, Article 6(1)
You need at least one. They are alternatives, not a hierarchy.
| Basis | Note |
|---|---|
| (a) Consent | Conditions in Article 7: freely given, specific, informed, unambiguous, demonstrable, withdrawable at any time |
| (b) Contract | Necessary for performance of a contract with the data subject |
| (c) Legal obligation | Imposed on the controller by law |
| (d) Vital interests | Life-or-death situations |
| (e) Public interest or official authority | The main basis for a regulator — but the task must have a basis in law |
| (f) Legitimate interests | A balancing test, and not available to public authorities in the performance of their tasks |
Article 8 covers children: the digital age of consent is 16, and Member States may lower it to 13.
7. Special categories, Articles 9 and 10
Article 9 processing is prohibited unless an Article 9(2) exception applies: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for unique identification, health data, and sex life or sexual orientation. Exceptions include explicit consent and substantial public interest with a basis in law.
Article 10 covers criminal convictions and offences: only under the control of official authority, or where authorised by law.
8. Data subject rights, Chapter III
| Article | Right | Key detail |
|---|---|---|
| 12 | Transparency and modalities | Respond within one month, extendable by two for complex requests |
| 13 | Information where data is collected from the subject | At the time of collection |
| 14 | Information where data is obtained elsewhere | Within a month, or at first communication |
| 15 | Access | A copy of the data, plus purposes, recipients and retention — and the existence of automated decision-making with meaningful information about the logic involved |
| 16 | Rectification | Correct inaccurate data |
| 17 | Erasure, the right to be forgotten | Not absolute; several exceptions |
| 18 | Restriction of processing | A pause rather than a deletion |
| 20 | Data portability | Structured, commonly used, machine-readable format. Only where the basis is consent or contract and processing is automated |
| 21 | Objection | Absolute for direct marketing; a balancing test otherwise |
| 22 | Automated individual decision-making | See the next section |
| 23 | Restrictions | Union or Member State law may restrict these rights |
9. Article 22 and SCHUFA — the centrepiece
22(1) gives the data subject a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them.
22(2) permits it where it is necessary for a contract, authorised by Union or Member State law with suitable safeguards, or based on explicit consent. 22(3) requires, for the contract and consent routes, at minimum the right to human intervention, to express a point of view, and to contest the decision. 22(4) restricts reliance on special category data.
Recital 71 goes further, saying safeguards should include specific information, human intervention, and the right to obtain an explanation of the decision reached.
10. Controller obligations, Chapter IV
- Article 24 — overall responsibility, with appropriate measures
- Article 25 — data protection by design and by default
- Article 28 — processor contracts, with mandatory content
- Article 30 — records of processing activities
- Article 32 — security of processing, including pseudonymisation and encryption
- Article 33 — breach notification to the supervisory authority within 72 hours
- Article 34 — notification to data subjects without undue delay where the risk is high
- Article 35 — data protection impact assessment, required where processing is likely to result in high risk. 35(3) expressly lists systematic and extensive automated evaluation including profiling with legal effects, large-scale special category processing, and large-scale systematic monitoring of public areas
- Article 36 — prior consultation where the assessment shows unmitigated high risk
11. International transfers — skim only
Transfers outside the EEA need an adequacy decision under Article 45, appropriate safeguards under Articles 46 and 47 such as standard contractual clauses or binding corporate rules, or a derogation under Article 49.
One case to know by name: Schrems II, case C-311/18, 2020, invalidated the EU–US Privacy Shield. The EU–US Data Privacy Framework replaced it in July 2023. Low priority for you.
12. Enforcement, remedies and fines
Remedies for individuals: Article 77 complaint to an authority, Article 78 judicial remedy against an authority, Article 79 judicial remedy against a controller or processor, Article 80 representation by non-profit bodies, and Article 82 compensation for material and non-material damage.
Corrective powers, Article 58(2): warnings, reprimands, orders to comply, ordering erasure, temporary or definitive limitation including a ban on processing, and suspending data flows.
| Tier | Maximum, whichever is higher | Covers |
|---|---|---|
| Lower, Article 83(4) | 10 million euro or 2 percent of total worldwide annual turnover | Controller and processor obligations — Articles 8, 11, 25 to 39, 42, 43 |
| Upper, Article 83(5) | 20 million euro or 4 percent of total worldwide annual turnover | The basic principles and consent (Articles 5, 6, 7, 9), data subject rights (Articles 12 to 22), and transfers (Articles 44 to 49) |
Article 83(6) puts non-compliance with an authority's order in the upper tier too. Article 83(2) sets the factors: nature, gravity and duration; whether intentional or negligent; mitigation; degree of responsibility; previous infringements; cooperation; categories of data; and how the authority found out.
13. Benefits, criticisms, and the tension that is yours
What it achieved: harmonisation with one-stop-shop supervision; enforceable individual rights; a shift from notifying regulators to demonstrating compliance; a risk-based and technology-neutral structure; and global influence through Article 3(2).
Standing criticisms: compliance burden on small organisations; consent fatigue and cookie banners; slow enforcement through the one-stop-shop; and uneven national implementation.
| The GDPR requires | Machine learning wants |
|---|---|
| Purpose limitation — specify the purpose up front | Exploratory analysis: collect first, discover what matters later |
| Data minimisation — only what is necessary | Representative training data, including about subjects you never pursue |
| Accuracy — data must be accurate | Probabilistic outputs that are calibrated rather than true or false |
| Storage limitation — delete when done | Retained datasets, for reproducibility and audit |
14. How this connects to ATLANTIS
Of the project's three strands, the GDPR sits mainly on the first: the data problem. Schrepel's framing is that computational tools are only as good as the data that feeds them, that the appetite of those tools exceeds what the current framework was designed to deliver, and that the strain shows on both sides — agencies wanting representative datasets run into proportionality limits, business secrecy, data protection law, and the privilege against self-incrimination, while firms receiving sweeping requests cannot tell where necessity ends.
Data protection is named explicitly in that list. It is one of the four forces pulling against the collection that screening requires.
15. What the panel brings to this chapter
| Panel member | Why the GDPR is their territory |
|---|---|
| Tijmen Wisman | This is his field. Assistant Professor of Internet Law at VU, working on privacy, data protection and state surveillance. He worked on the SyRI case, where the Hague District Court struck down the Dutch welfare fraud detection system under Article 8 ECHR, partly for insufficient transparency and verifiability. Earlier work on RFID and the internet of things, smart meters and eCall. He teaches the necessity and proportionality analysis under the Convention |
| Thibault Schrepel | Meta v Bundeskartellamt is the case where competition enforcement and data protection formally met: a national competition authority may assess GDPR compliance when establishing abuse of dominance, subject to cooperating with the data protection authority |
| Catalina Goanta | Lawful access to data held by someone who would rather not share it, which is the DSA Article 40 problem and also yours with agency data |
| Georgiana Mirza | Common EU data spaces, at the intersection of fundamental rights, competition and innovation |
16. What is unexplored, and six projects you could run
17. Your CV, mapped onto this chapter
| What you have | Where it lands | Why it fits |
|---|---|---|
| Causal inference — directed acyclic graphs, Bayesian belief networks, do-calculus, Bayesian structural time series over 22 years of administrative data | Project 1, measuring whether a human reviewer really decided | Separating a model's effect on a decision from mere correlation with it is a causal identification problem, and a flag threshold is a discontinuity |
| The reporting-shock finding — measuring a change in detection caused by a 2013 legal amendment rather than a change in conduct | Projects 1 and 3 | You have already separated a real signal from an artefact of how data was collected. Agency data has the identical pathology |
| Model evaluation methodology — calibration, interval estimation at small n, agreement reporting, deterministic parsing where no model is needed | Project 3, mapping the privacy and utility trade-off | A trade-off curve is only as good as the evaluation protocol underneath it |
| Adversarial evaluation and the Mens Rea harness | Project 1 and the Article 22 question generally | Your finding that a steered system's self-account is true and incomplete is why human review can fail even with a willing reviewer |
| Legal training in evidence, procedure and administrative law | Projects 4, 5 and 6 | These are doctrinal and comparative, and need the legal half done properly rather than gestured at |
| The 2022 IoT and cybersecurity legal analysis | Credibility with Wisman | Connected devices and the data they generate is where his earlier work sits |
| Production experience with guardrails, consent flows and user data at 28,000 monthly users | Reading a compliance obligation as an operational constraint rather than a sentence | You have had to satisfy these rules, not only cite them |
18. If you remember ten things
- Regulation 2016/679, applicable May 2018, directly applicable, replaced the 1995 Directive.
- It protects natural persons, not companies — but personal data is all over competition evidence.
- The Commission is under Regulation 2018/1725 and the EDPS; national authorities are under the GDPR and their own supervisors.
- Seven principles; purpose limitation and data minimisation are the ones that bite.
- Six lawful bases. A public authority needs legal obligation or official authority, and cannot use legitimate interests.
- Rights sit in Articles 12 to 22, and Article 23 lets law restrict them for regulatory and investigative functions.
- Article 22 restricts solely automated decisions, and after SCHUFA a rubber-stamp human may not count.
- Article 35 impact assessments are the ancestor of the AI Act's Article 27.
- Fines are 2 percent or 10 million and 4 percent or 20 million, whichever is higher — but Article 83(7) means public authorities may be unfinable, so the real remedy against an agency is a processing ban or annulment.
- The four-way tension: purpose limitation against exploration, minimisation against representativeness, accuracy against probability, storage limitation against reproducibility.