Skip to content
VibeFormer
38 min

The GDPR

Regulation 2016/679, and the instrument that pulls hardest against collecting data to train a model. Wisman's field, and the home of SCHUFA — the case that decides whether a human reviewer is really deciding.

Listen

1. The basics

Regulation (EU) 2016/679. Adopted 27 April 2016, applicable from 25 May 2018. It replaced Directive 95/46/EC.

It is a Regulation, so directly applicable in every Member State with no transposition needed. But it contains roughly 70 opening clauses letting Member States legislate detail, which is why national data protection acts still exist and why practice diverges.

Stated purpose: harmonise data protection across the single market, strengthen individual control, and enable lawful data flows by creating trust. That last aim matters — the instrument is framed as a facilitator, not a prohibition, and saying so signals you have read it rather than absorbed its reputation.

2. Who the actors are

ActorWho they are
Data subjectAn identified or identifiable natural person. Living individuals only. Not companies
Controller, Article 4(7)Determines the purposes and means of processing. Carries the primary obligations
Processor, Article 4(8)Processes on the controller's behalf, governed by a mandatory contract under Article 28
Joint controllers, Article 26Two or more controllers jointly determining purposes, who must allocate responsibilities transparently
Data Protection Officer, Articles 37 to 39Mandatory for public authorities, and for large-scale systematic monitoring or large-scale special category processing
Supervisory authority, Articles 51 to 59The national data protection authority. The Autoriteit Persoonsgegevens in the Netherlands
Lead supervisory authority, Article 56The one-stop-shop. For cross-border processing, the authority of the main establishment leads
EDPB, Articles 68 to 76European Data Protection Board. Guidelines, and dispute resolution between authorities
EDPSEuropean Data Protection Supervisor. Supervises EU institutions under Regulation 2018/1725, not the GDPR

3. Scope, and the three carve-outs that matter

Material scope, Article 2: processing of personal data wholly or partly by automated means, or manual processing of data forming part of a filing system.

Excluded: purely personal or household activity; matters outside the scope of Union law; criminal law enforcement, which is covered instead by the Law Enforcement Directive (EU) 2016/680; and EU institutions and bodies, covered instead by Regulation (EU) 2018/1725.

Territorial scope, Article 3: controllers and processors established in the EU, regardless of where the processing happens; and non-EU controllers who offer goods or services to, or monitor the behaviour of, people in the EU. That second limb is the extraterritorial reach, and the source of the Brussels effect.

4. Definitions you need, Article 4

  • Personal data — any information relating to an identified or identifiable natural person. Very broad: IP addresses, device identifiers and metadata all qualify.
  • Processing — essentially any operation. Collection, recording, storage, alteration, retrieval, consultation, use, disclosure, erasure.
  • Pseudonymisation, Article 4(5) — replacing identifiers so that re-identification needs additional information. Pseudonymised data is still personal data. People get this wrong constantly, and it is the most common fatal flaw in a research data plan.
  • Anonymous data — falls outside the GDPR entirely, under Recital 26. But the bar is that the person is no longer identifiable by any reasonably likely means, and genuine anonymisation is hard.
  • Profiling, Article 4(4) — automated processing to evaluate personal aspects, in particular to analyse or predict performance, behaviour, location or reliability.

5. The seven principles, Article 5

PrincipleMeaning
Lawfulness, fairness, transparency5(1)(a). A lawful basis is required, and people must know what is happening
Purpose limitation5(1)(b). Collected for specified, explicit, legitimate purposes; no incompatible further processing
Data minimisation5(1)(c). Adequate, relevant, and limited to what is necessary
Accuracy5(1)(d). Accurate and kept up to date; inaccurate data erased or rectified
Storage limitation5(1)(e). Kept no longer than necessary
Integrity and confidentiality5(1)(f). Appropriate security
Accountability5(2). The controller is responsible and must be able to demonstrate compliance

Note that purpose limitation and data minimisation are the same idea as Article 18's necessity test and Article 28's use limitation in Regulation 1/2003, arriving from a different direction. Two regimes, one constraint, and both of them argue with exploratory model training.

6. Lawful bases, Article 6(1)

You need at least one. They are alternatives, not a hierarchy.

BasisNote
(a) ConsentConditions in Article 7: freely given, specific, informed, unambiguous, demonstrable, withdrawable at any time
(b) ContractNecessary for performance of a contract with the data subject
(c) Legal obligationImposed on the controller by law
(d) Vital interestsLife-or-death situations
(e) Public interest or official authorityThe main basis for a regulator — but the task must have a basis in law
(f) Legitimate interestsA balancing test, and not available to public authorities in the performance of their tasks

Article 8 covers children: the digital age of consent is 16, and Member States may lower it to 13.

7. Special categories, Articles 9 and 10

Article 9 processing is prohibited unless an Article 9(2) exception applies: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for unique identification, health data, and sex life or sexual orientation. Exceptions include explicit consent and substantial public interest with a basis in law.

Article 10 covers criminal convictions and offences: only under the control of official authority, or where authorised by law.

8. Data subject rights, Chapter III

ArticleRightKey detail
12Transparency and modalitiesRespond within one month, extendable by two for complex requests
13Information where data is collected from the subjectAt the time of collection
14Information where data is obtained elsewhereWithin a month, or at first communication
15AccessA copy of the data, plus purposes, recipients and retention — and the existence of automated decision-making with meaningful information about the logic involved
16RectificationCorrect inaccurate data
17Erasure, the right to be forgottenNot absolute; several exceptions
18Restriction of processingA pause rather than a deletion
20Data portabilityStructured, commonly used, machine-readable format. Only where the basis is consent or contract and processing is automated
21ObjectionAbsolute for direct marketing; a balancing test otherwise
22Automated individual decision-makingSee the next section
23RestrictionsUnion or Member State law may restrict these rights

9. Article 22 and SCHUFA — the centrepiece

22(1) gives the data subject a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them.

22(2) permits it where it is necessary for a contract, authorised by Union or Member State law with suitable safeguards, or based on explicit consent. 22(3) requires, for the contract and consent routes, at minimum the right to human intervention, to express a point of view, and to contest the decision. 22(4) restricts reliance on special category data.

Recital 71 goes further, saying safeguards should include specific information, human intervention, and the right to obtain an explanation of the decision reached.

10. Controller obligations, Chapter IV

  • Article 24 — overall responsibility, with appropriate measures
  • Article 25 — data protection by design and by default
  • Article 28 — processor contracts, with mandatory content
  • Article 30 — records of processing activities
  • Article 32 — security of processing, including pseudonymisation and encryption
  • Article 33 — breach notification to the supervisory authority within 72 hours
  • Article 34 — notification to data subjects without undue delay where the risk is high
  • Article 35 — data protection impact assessment, required where processing is likely to result in high risk. 35(3) expressly lists systematic and extensive automated evaluation including profiling with legal effects, large-scale special category processing, and large-scale systematic monitoring of public areas
  • Article 36 — prior consultation where the assessment shows unmitigated high risk

11. International transfers — skim only

Transfers outside the EEA need an adequacy decision under Article 45, appropriate safeguards under Articles 46 and 47 such as standard contractual clauses or binding corporate rules, or a derogation under Article 49.

One case to know by name: Schrems II, case C-311/18, 2020, invalidated the EU–US Privacy Shield. The EU–US Data Privacy Framework replaced it in July 2023. Low priority for you.

12. Enforcement, remedies and fines

Remedies for individuals: Article 77 complaint to an authority, Article 78 judicial remedy against an authority, Article 79 judicial remedy against a controller or processor, Article 80 representation by non-profit bodies, and Article 82 compensation for material and non-material damage.

Corrective powers, Article 58(2): warnings, reprimands, orders to comply, ordering erasure, temporary or definitive limitation including a ban on processing, and suspending data flows.

TierMaximum, whichever is higherCovers
Lower, Article 83(4)10 million euro or 2 percent of total worldwide annual turnoverController and processor obligations — Articles 8, 11, 25 to 39, 42, 43
Upper, Article 83(5)20 million euro or 4 percent of total worldwide annual turnoverThe basic principles and consent (Articles 5, 6, 7, 9), data subject rights (Articles 12 to 22), and transfers (Articles 44 to 49)

Article 83(6) puts non-compliance with an authority's order in the upper tier too. Article 83(2) sets the factors: nature, gravity and duration; whether intentional or negligent; mitigation; degree of responsibility; previous infringements; cooperation; categories of data; and how the authority found out.

13. Benefits, criticisms, and the tension that is yours

What it achieved: harmonisation with one-stop-shop supervision; enforceable individual rights; a shift from notifying regulators to demonstrating compliance; a risk-based and technology-neutral structure; and global influence through Article 3(2).

Standing criticisms: compliance burden on small organisations; consent fatigue and cookie banners; slow enforcement through the one-stop-shop; and uneven national implementation.

The GDPR requiresMachine learning wants
Purpose limitation — specify the purpose up frontExploratory analysis: collect first, discover what matters later
Data minimisation — only what is necessaryRepresentative training data, including about subjects you never pursue
Accuracy — data must be accurateProbabilistic outputs that are calibrated rather than true or false
Storage limitation — delete when doneRetained datasets, for reproducibility and audit

14. How this connects to ATLANTIS

Of the project's three strands, the GDPR sits mainly on the first: the data problem. Schrepel's framing is that computational tools are only as good as the data that feeds them, that the appetite of those tools exceeds what the current framework was designed to deliver, and that the strain shows on both sides — agencies wanting representative datasets run into proportionality limits, business secrecy, data protection law, and the privilege against self-incrimination, while firms receiving sweeping requests cannot tell where necessity ends.

Data protection is named explicitly in that list. It is one of the four forces pulling against the collection that screening requires.

15. What the panel brings to this chapter

Panel memberWhy the GDPR is their territory
Tijmen WismanThis is his field. Assistant Professor of Internet Law at VU, working on privacy, data protection and state surveillance. He worked on the SyRI case, where the Hague District Court struck down the Dutch welfare fraud detection system under Article 8 ECHR, partly for insufficient transparency and verifiability. Earlier work on RFID and the internet of things, smart meters and eCall. He teaches the necessity and proportionality analysis under the Convention
Thibault SchrepelMeta v Bundeskartellamt is the case where competition enforcement and data protection formally met: a national competition authority may assess GDPR compliance when establishing abuse of dominance, subject to cooperating with the data protection authority
Catalina GoantaLawful access to data held by someone who would rather not share it, which is the DSA Article 40 problem and also yours with agency data
Georgiana MirzaCommon EU data spaces, at the intersection of fundamental rights, competition and innovation

16. What is unexplored, and six projects you could run

17. Your CV, mapped onto this chapter

What you haveWhere it landsWhy it fits
Causal inference — directed acyclic graphs, Bayesian belief networks, do-calculus, Bayesian structural time series over 22 years of administrative dataProject 1, measuring whether a human reviewer really decidedSeparating a model's effect on a decision from mere correlation with it is a causal identification problem, and a flag threshold is a discontinuity
The reporting-shock finding — measuring a change in detection caused by a 2013 legal amendment rather than a change in conductProjects 1 and 3You have already separated a real signal from an artefact of how data was collected. Agency data has the identical pathology
Model evaluation methodology — calibration, interval estimation at small n, agreement reporting, deterministic parsing where no model is neededProject 3, mapping the privacy and utility trade-offA trade-off curve is only as good as the evaluation protocol underneath it
Adversarial evaluation and the Mens Rea harnessProject 1 and the Article 22 question generallyYour finding that a steered system's self-account is true and incomplete is why human review can fail even with a willing reviewer
Legal training in evidence, procedure and administrative lawProjects 4, 5 and 6These are doctrinal and comparative, and need the legal half done properly rather than gestured at
The 2022 IoT and cybersecurity legal analysisCredibility with WismanConnected devices and the data they generate is where his earlier work sits
Production experience with guardrails, consent flows and user data at 28,000 monthly usersReading a compliance obligation as an operational constraint rather than a sentenceYou have had to satisfy these rules, not only cite them

18. If you remember ten things

  1. Regulation 2016/679, applicable May 2018, directly applicable, replaced the 1995 Directive.
  2. It protects natural persons, not companies — but personal data is all over competition evidence.
  3. The Commission is under Regulation 2018/1725 and the EDPS; national authorities are under the GDPR and their own supervisors.
  4. Seven principles; purpose limitation and data minimisation are the ones that bite.
  5. Six lawful bases. A public authority needs legal obligation or official authority, and cannot use legitimate interests.
  6. Rights sit in Articles 12 to 22, and Article 23 lets law restrict them for regulatory and investigative functions.
  7. Article 22 restricts solely automated decisions, and after SCHUFA a rubber-stamp human may not count.
  8. Article 35 impact assessments are the ancestor of the AI Act's Article 27.
  9. Fines are 2 percent or 10 million and 4 percent or 20 million, whichever is higher — but Article 83(7) means public authorities may be unfinable, so the real remedy against an agency is a processing ban or annulment.
  10. The four-way tension: purpose limitation against exploration, minimisation against representativeness, accuracy against probability, storage limitation against reproducibility.