GDPR Guides

Clear, primary-source guides to the EU General Data Protection Regulation. Each guide is written in plain English and grounded in Regulation (EU) 2016/679 itself and European Data Protection Board guidance — built to help you actually understand the rules, whether you’re preparing for a data protection officer (DPO) certification exam or just need a reliable reference.

Deep dive7 min read

GDPR Right to Object: Article 21 Marketing Stop vs Qualified Objection

When the GDPR right to object is absolute for direct marketing under Article 21(2), when Article 21(1) is only qualified, and how objection, restriction and erasure fit together — cited to the Regulation and EDPB Guidelines 1/2024.

Read the guide →
Deep dive7 min read

GDPR Article 13 vs Article 14: Information Obligations Explained

A side-by-side comparison of Articles 13 and 14 -- scope, staggered timing, the categories-of-data and source-of-data disclosures unique to Article 14, and why Article 14 has four exemptions where Article 13 has only one.

Read the guide →
DPO essentials8 min read

When is a Data Protection Officer (DPO) required under GDPR?

Learn exactly when appointing a Data Protection Officer (DPO) is mandatory under Article 37 of the GDPR, what their tasks are, and who is allowed to take on the role without a conflict of interest.

Read the guide →
Reference12 min read

The EU GDPR Explained: A Complete Guide

A plain-English walkthrough of Regulation (EU) 2016/679 — scope, the seven principles, six lawful bases, data subject rights, controller and processor duties, the DPO role, breaches, transfers and fines. Every claim tied to the regulation.

Read the guide →
Deep dive8 min read

Legitimate Interest Under GDPR: The Three-Part Test Explained

A deep dive into Article 6(1)(f) — the three cumulative conditions, the EDPB’s 2024 balancing-test factors, direct marketing rules, the right to object and children’s data, grounded in EDPB Guidelines 1/2024.

Read the guide →
Deep dive7 min read

GDPR Compensation Claims: When Does Non-Material Damage Qualify?

A practical guide to Article 82 compensation claims, built on the 2025 CJEU ruling in IP v Quirin Privatbank (C-655/23) and 2023’s Österreichische Post case: no seriousness threshold, fault-irrelevant amounts, controller vs. processor liability and a claim checklist.

Read the guide →
Deep dive7 min read

How to Handle a GDPR Subject Access Request: Deadlines and Refusal Grounds

Article 15 access requests explained: the one-month deadline, what must be disclosed, when a fee applies, the Article 12(5) refusal grounds, and the March 2026 CJEU ruling on abusive first-time requests (Case C-526/24, Brillen Rottler).

Read the guide →
Deep dive8 min read

International Data Transfers Under GDPR: Adequacy, SCCs and the EU-US Data Privacy Framework

The three Chapter V transfer mechanisms explained — adequacy decisions, Standard Contractual Clauses with a Transfer Impact Assessment, and Article 49 derogations — plus what the General Court’s September 2025 Latombe ruling (Case T-553/23) and the pending CJEU appeal mean for the EU-US Data Privacy Framework.

Read the guide →
Guide8 min read

When is a Data Protection Impact Assessment (DPIA) required under the GDPR?

Learn when a Data Protection Impact Assessment (DPIA) is mandatory under Article 35 of the GDPR, what triggers a high risk, and who is responsible for conducting it.

Read the guide →
Guide8 min read

GDPR Anonymisation vs Pseudonymisation: The 2026 EDPB Test

An exam-focused guide to GDPR anonymisation vs pseudonymisation, the EDPB Guidelines 02/2026 three-criterion test, hashes and recipient perspective.

Read the guide →
Guide8 min read

GDPR Data Breach Notification: Articles 33 & 34 Explained

A complete practitioner guide to GDPR data breach notification requirements under Articles 33 & 34: the 72-hour rule, risk vs. high-risk thresholds, processor duties, DPA reporting contents, CJEU C-340/21, and EDPB Guidelines.

Read the guide →
Guide8 min read

How Are GDPR Fines Calculated? Article 83 & EDPB Guidelines 04/2022

A structured guide to GDPR fine calculation, covering Article 83 statutory maximums and the EDPB 5-step methodology used by supervisory authorities.

Read the guide →
Guide8 min read

Record of Processing Activities (RoPA) GDPR Article 30 Requirements

Learn what a Record of Processing Activities (RoPA) is, what it must include, and why the Article 30(5) exemption for under 250 employees rarely applies.

Read the guide →
Practice questions15 min practice

GDPR Exam Practice Questions

18 free multiple-choice GDPR exam practice questions across principles, data subject rights, RoPA, breach notification, DPIAs, DPO rules and fines — every answer cited to its exact article.

Read the guide →
Cost comparison7 min read

How Much Does DPO / GDPR Certification Cost?

A cost comparison of IAPP (CIPP/E, CIPM), BCS, PECB CDPO and Germany’s TÜV/DEKRA DSB certification paths, with verified official pricing and clearly flagged approximate figures.

Read the guide →
Deep dive7 min read

GDPR Article 17: Right to Erasure Explained

Article 17 explained: the six erasure grounds, the five Article 17(3) exceptions, and the Article 17(2) vs Article 19 distinction that trips up most exam candidates.

Read the guide →
Deep dive8 min read

Joint Controllers Under GDPR Article 26: The Facebook Fan Page Ruling

What Article 26 requires of joint controllers, and how the CJEU’s Facebook fan page ruling (Case C-210/16) established that platform users configuring third-party analytics can be joint controllers -- with a worked example.

Read the guide →
Deep dive8 min read

GDPR Data Portability: Article 20 Explained

A practical comparison of Article 20 portability and Article 15 access: qualifying legal bases, automated processing, machine-readable formats, direct controller-to-controller transfer and the limits that matter in exams.

Read the guide →
Deep dive8 min read

GDPR Processor Agreement: What Article 28 Requires

A primary-source guide to GDPR processor agreements under Article 28: who is a processor, the mandatory contract clauses, sub-processors, Commission SCCs and when a processor becomes a controller.

Read the guide →
Deep dive8 min read

GDPR Article 22: Automated Decision-Making and Profiling

Article 22 GDPR explained: the three-part test for automated decisions, the SCHUFA scoring ruling, and the 2025 Dun & Bradstreet right to an explanation.

Read the guide →
Deep dive8 min read

GDPR Article 9 Special Category Data: The Lindenapotheke Test

GDPR Article 9 special category data explained: the prohibition, the ten Article 9(2) exceptions, Recital 51 on photographs, and CJEU C-21/23 Lindenapotheke on pharmacy-only order data as health data.

Read the guide →

Turn knowledge into a pass

Practise everything in these guides with hundreds of realistic multiple-choice questions, chapter training and a timed exam simulation — with AI explanations for every answer.

Start freeTry 30 questions free — no time limit, no credit card.