Live Founding Cohort open, limited seats remaining Back to main site →

The primary-source pack every GDPR practitioner must bookmark

Every claim in this course is anchored to a primary source. This lesson gives you the exact URLs and search discipline for the six sources you will use every week.

Free preview 6 min read Verified
Legal basis
GDPR primary-source stack current to 10 August 2026. Core: Regulation (EU) 2016/679 (GDPR), in force 25 May 2018. EDPB Guidelines: 3/2018 (territorial scope, endorsed 12 November 2019), 05/2020 (consent, adopted 4 May 2020 v1.1), 07/2020 (controller/processor, adopted 7 July 2021 v2.1), 9/2022 (breach notification, v2.0 adopted 28 March 2023), 1/2024 (legitimate interests, adopted 8 October 2024), draft 02/2026 (Anonymisation, published for consultation 7 July 2026), 02/2025 v2.0 (Blockchain, adopted 7 July 2026). Cross-border: Commission Implementing Decision (EU) 2021/914 SCCs (4 June 2021); EU-US Data Privacy Framework Adequacy Decision C(2023) 4745 final (10 July 2023, Latombe C-703/25 P appeal pending at CJEU); adequacy list including Brazil mutual (Implementing Decision 2026/179, 26 January 2026), UK renewal (19 December 2025 with sunset 27 December 2031). Adjacent EU: Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), Data Governance Act (Regulation 2022/868), Data Act (Regulation 2023/2854), AI Act (Regulation 2024/1689) as amended by Regulation (EU) 2026/1744 Digital Omnibus on AI (OJ 24 July 2026, in force 27 July 2026, postponing high-risk AI to 2 December 2027 and 2 August 2028), NIS2 Directive (Directive 2022/2555). Landmark CJEU: Schrems II (C-311/18, 16 Jul 2020), Meta v Bundeskartellamt (C-252/21, 4 Jul 2023), IAB Europe (C-604/22, 7 Mar 2024), Lindenapotheke (C-21/23, 4 Oct 2024). India crosswalk: DPDP Act 2023 (No. 22 of 2023, assented 11 Aug 2023), DPDP Rules 2025 (notified 13 Nov 2025, operative Rules commencement expected 13 May 2027), RBI Payment Data Storage Direction (DPSS.CO.OD.No.2785 dated 6 Apr 2018), CERT-In Directions (No. 20(3)/2022-CERT-In dated 28 Apr 2022).

Every claim in this course is anchored to a primary source. When a claim you rely on turns out to be wrong (a Guideline is superseded, an adequacy decision is added, a fine is set aside on appeal), you need to be able to re-verify from the primary source in ten minutes. Bookmark these six.

1. eur-lex.europa.eu

The official EU legal database. Every Regulation, Directive, Implementing Decision, and Delegated Act is here in every EU official language with CELEX numbers. For GDPR: CELEX 32016R0679. Bookmark the direct GDPR consolidated view: https://eur-lex.europa.eu/eli/reg/2016/679/oj.

2. edpb.europa.eu

The European Data Protection Board publishes Guidelines, Opinions, and Coordinated Enforcement Announcements. Every Guideline has a version number and adoption date. Never quote a Guideline without pulling the current version from the EDPB documents register. Bookmark: https://www.edpb.europa.eu/our-work-tools/general-guidance/guidelines-recommendations-best-practices_en.

3. curia.europa.eu

The Court of Justice of the European Union case-law database. Every judgment has a case number (C-311/18 for Schrems II, C-252/21 for Meta v Bundeskartellamt, C-604/22 for IAB Europe). The database includes Advocate General opinions, orders, and pending-case dockets. When you cite a CJEU judgment, cite the case number and paragraph. Bookmark: https://curia.europa.eu.

4. ec.europa.eu adequacy decisions page

The Commission maintains the adequacy list. Any new adequacy decision, renewal, or withdrawal appears here first. As of Aug 2026 the list includes Brazil (mutual, 26 January 2026, Implementing Decision 2026/179), UK (renewed 19 December 2025, sunset 27 December 2031), plus Andorra, Argentina, Canada (commercial), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, Uruguay, European Patent Organisation, and the US Data Privacy Framework [L5-C1]. Bookmark: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en.

5. DPA press releases (your Member-State DPA, plus DPC Ireland and CNIL France as the most-cited)

Enforcement lives in DPA press releases. DPC Ireland (https://www.dataprotection.ie) is the lead DPA for many US-headquartered platforms under the One-Stop-Shop mechanism and issues the largest fines (Meta EUR 1.2B, TikTok EUR 530M, LinkedIn EUR 310M, WhatsApp EUR 225M). CNIL France (https://www.cnil.fr) is the most active on adtech and cookie-consent. Netherlands AP (https://www.autoriteitpersoonsgegevens.nl) handled the Uber transfer-coverage-gap case. For a running enforcement view, cross-reference with enforcementtracker.com but always cross-check numbers against the issuing DPA\'s primary release.

6. meity.gov.in

The Ministry of Electronics and Information Technology publishes the DPDP Act, DPDP Rules, notifications, and (when they land) the Data Protection Board of India Chairperson appointment and adjudication orders. Bookmark: https://www.meity.gov.in/data-protection-framework.

Search discipline

When you need to check whether a claim is still current, go in this order:

  1. Primary source (eur-lex, edpb, curia, ec.europa.eu, DPA site, meity)
  2. The primary source\'s latest publication date
  3. Any pending amendment or appeal that would change the reading

Never rely on a secondary summary as the sole basis for advice. If the secondary source (a law-firm blog, a training slide deck) says something that matters, follow the link and read the primary.

What this course commits to

Every lesson in this course carries citations back to the primary source in the same style you just saw in this lesson: a bracketed reference (like [L5-C1]) that you can click through to the citation register on the course Trust page. When the course is updated, the citation register is refreshed. When a citation becomes wrong (a Guideline is superseded, a case is overturned), the citation is marked and the lesson prose is corrected within our stated update-SLA.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview complete You've read every free lesson in Module 1

Ready for the rest of GDPR for Indian Companies (with DPDP Crosswalk) Practitioner?

  • All 8 paid modules (30 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹14,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
EU Adequacy Decisions, Adequacy List Aug 2026 (EU Commission Adequacy Decisions in force (as of Aug 2026)) L5-C1
Third countries and international organisations recognised by the European Commission as ensuring an adequate level of protection: Andorra, Argentina, Brazil (mutual adequacy adopted 26 January 2026), Canada (commercial organisations only), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, United Kingdom (adequacy renewed 19 December 2025), Uruguay, European Patent Organisation. United States: adequacy applies only to organisations self-certified to the EU-US Data Privacy Framework. India is NOT on the adequacy list; all EU-to-India personal-data transfers require an Art 46 mechanism (SCCs, BCRs, certification, code of conduct) plus a Schrems II Transfer Impact Assessment.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: why GDPR reaches you as an Indian practitioner
Module 2: Lawful basis and consent
  • The six Article 6 lawful bases and why consent is overused
  • Legitimate interests: the three-part test (Guidelines 1/2024)
  • Article 7 consent standards and Guidelines 05/2020
  • Article 9 special categories and the ten Art 9(2) gateways
Module 3: Data subject rights end-to-end
  • The rights inventory and the one-month response clock
  • Article 15 access requests: the practitioner playbook
  • Article 17 erasure: six triggers, ten exceptions
  • Articles 20, 21, 22: portability, objection, automated decisions
Module 4: Controller vs processor, contracts, subprocessing
  • Determining the role: factually, not contractually
  • Article 28 processor contract: the eight mandatory clauses
  • Joint controllership under Article 26 and the transparency obligation
  • Article 30 records of processing: what an Indian processor's ROPA must show
Module 5: DPO office, DPIA, records of processing
  • Article 37 DPO trigger: when a DPO must be appointed
  • Articles 38-39: DPO independence, resources, tasks
  • Article 35 DPIA: when and how
  • One DPO office serving GDPR and DPDP in parallel
Module 6: Breach notification and the triple clock
  • Article 33: when the 72-hour clock actually starts
  • Article 34 data-subject notification: the high-risk test
  • The triple clock: CERT-In 6h, DPDP 72h, GDPR 72h
  • Worked scenario: ransomware at an Indian SaaS with EU customers
Module 7: Cross-border transfers: SCCs, adequacy, DPF, Transfer Impact Assessment
  • Chapter V architecture: adequacy, Article 46, Article 49 derogations
  • Commission SCCs 2021/914: four modules walkthrough
  • Schrems II TIA obligation: the practitioner working reference
  • EU-US Data Privacy Framework: read as fragile additional layer
  • DPDP Section 16 + Rule 15: the negative-list mirror
Module 8: Adjacent EU instruments + enforcement pattern + capstone
  • DSA, DMA, Data Act, AI Act, NIS2: what reaches an Indian entity
  • Top-15 GDPR fines 2018-2026: practitioner lessons
  • Reading the 2024-2026 enforcement pattern
  • AI Act plus GDPR for Indian AI providers: DPIA plus FRIA overlap
  • Capstone: dual-regime compliance programme for an Indian IT services firm
Module 9: Final Exam and Certificate