GDPR Law
Regulation (EU) 2016/679, with UK GDPR, the Data Protection Act 2018 and PECR alongside it. This is an honest stub. There is substantial GDPR work in this project — 32,802 words of it — and none of it is a GDPR graph. This page says what exists, what does not, and why this instrument is harder than the one that is modelled.
- Kind
- Law — and in the UK, a law plus a domestic implementation plus a separate ePrivacy instrument
- Issuer
- The European Parliament and the Council · and, for the UK GDPR and DPA 2018, the UK Parliament
- In force since
- 25 May 2018
- Republishable
- YES — EU legislative text, freely reusable
- Vault
- None. Verified against eight independent sources
- Graph
- Does not exist. Zero nodes, zero provisions, zero crosswalks
- Status
- Method, not artefact. Two finished white papers describe how to build it; nothing is assembled
There is no GDPR vault
index.md, llms.txt, llms-full.txt, the demos index, the catalogue index, the graph API's vault listing, and web search. GDPR appears nowhere as a vault.
The description that produced the belief — “it consolidates all the stuff” — is accurate, but it describes the AI Act vault, which composes Regulation (EU) 2024/1689 with its 2026 amendment because no official consolidation exists. That vault is excellent. It is not this instrument.
What does exist
| Asset | What it is | Is it a GDPR page? |
|---|---|---|
| Two finished white papers | A method for representing GDPR as a graph — the modelling approach, the file-path form for provisions, the concept layer | No. It is method, and the method now lives at /method/ where it belongs |
| An assessment design | How an organisation's GDPR posture would be assessed against the graph | No — and see the caution below |
| An article-by-article pass | The only one in the corpus, covering Articles 6, 7, 17, 27, 28, 30, 33–35, 5(1)(e) and PECR 5(3) | No, and it cannot be published. Why → |
| Two worked fragments | Article 32 → encryption → a control; Recital 83 on ciphertext and breach notification | Partly — the closest thing to a crosswalk anywhere on this estate |
Why this is harder than the AI Act
GDPR cannot be taken at face value — the rulings, the regulator guidance and the per-country variation are the graph.
That sentence is the whole difficulty, and it is worth being precise about why it does not apply equally to the AI Act. The AI Act is new: there is very little case law, guidance is thin, and the operative text is nearly all there is. GDPR is eight years old. Its operative text is the smallest part of what it means in practice — Article 6(1)(f) is four lines of text and a shelf of jurisprudence, and a graph containing only the four lines will confidently give you the wrong answer about legitimate interests.
So modelling GDPR properly means modelling three more layers the current method has never been asked to hold:
| Layer | What it needs | Does the method hold it? |
|---|---|---|
| Rulings | CJEU and national decisions as nodes, bridging to the provisions they interpret, with dates and precedential weight | Untested. Amendment exists; interpretation does not |
| Regulator guidance | EDPB and national authority guidance — persuasive, not binding, and it changes | Untested, and the binding/persuasive distinction has no place in the grammar yet |
| Per-country variation | The same article, different in Germany and Ireland, because the Regulation leaves room | Untested. Would need jurisdiction as a first-class property of an edge |
All three ghosted. This is the instrument that tests the acceptance criterion — whether the same structure holds something that is not a fresh EU regulation, without special cases. It very possibly does not, and publishing the special cases will be more useful than pretending otherwise.
The one near-crosswalk
The closest thing to a real bridge anywhere in this project's material, and it is a fragment rather than an artefact:
Article 32 GDPR --requires--> Encryption of Personal Data | is a v Security Control | mitigates v Confidentiality Risk
Three edges, and the third one — into ISO/IEC 27002's encryption control — is the one that cannot be published as text and can be published as a reference. That is the ISO pattern in miniature. The ISO folder → · how a bridge is built →
One argument that needs handling carefully
That is an argument about a recital, not a determination, and this site presents it as the reading it is. A vault-native project has an obvious interest in that reading being correct, which is exactly the reason to state it carefully rather than confidently: it is the “implying regulatory readiness” trap with this project's name on it. Any page that ships it will ship the counter-position beside it and attribute both. Participant disclosure →
What will not be published from the existing material
The structure is reusable; the findings are not. What a GDPR folder takes from it is the shape — which articles a controller has to be able to answer for, in what order, with what evidence — and none of the content. That distinction is the whole of the redaction policy on this site.
If this gets built
- Retrieve the operative text from CELLAR as Formex XML, with a retrieval record, exactly as the AI Act was. This part is mechanical and already proven.
- Build the taxonomy — 99 articles, 173 recitals, the paragraph-as-folder tree. Also mechanical.
- Stop, and decide how interpretation is modelled. This is where GDPR stops being a bigger AI Act. Rulings and guidance are not amendments and are not provisions; they are a third node class the grammar does not have. Do not skip this to reach a demo.
- Then the first crosswalk — AI Act ↔ GDPR, which is the natural first pair because the two apply concurrently. It is also the precondition that unblocks the crosswalk browser.