Files
awesome-awesomeness/html/gdpr.html
2025-07-18 22:22:32 +02:00

247 lines
11 KiB
HTML
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<h1 id="awesome-gdpr-awesome">Awesome GDPR <a
href="https://awesome.re"><img src="https://awesome.re/badge-flat.svg"
alt="Awesome" /></a></h1>
<p><a
href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679"><img src="GDPR.png" align="right" width="300"></a></p>
<p>The General Data Protection Regulation (GDPR) is a regulation on data
protection and privacy for all individuals within the European Union and
the European Economic Area. The regulation has increased the focus on
privacy in companies and strengthened the data subjects influence.</p>
<h2 id="contents">Contents</h2>
<ul>
<li><a href="#legal-text">Legal text</a></li>
<li><a href="#Guidelines">Guidelines</a></li>
<li><a href="#rights-of-the-data-subject-art-12---23">Rights of the data
subject (art. 12 - 23)</a></li>
<li><a href="#privacy-by-design---guides-for-developers-art-25">Privacy
by Design - Guides for developers (art. 25)</a></li>
<li><a href="#records-of-processing-art-30">Records of Processing (art.
30)</a></li>
<li><a href="#security-art-32">Security (art. 32)</a></li>
<li><a href="#incident-management-art-33-and-34">Incident management
(art. 33 and 34)</a></li>
<li><a href="#data-protection-impact-assessments-dpia-art-35">Data
Protection Impact Assessments (DPIA, art. 35)</a></li>
<li><a href="#tools">Tools</a></li>
<li><a href="#data-protection-authorities-art-51--59">Data Protection
Authorities</a></li>
<li><a href="#organisations--projects">Organisations / Projects</a></li>
<li><a href="#Publications">Publications</a></li>
<li><a href="#Solutions-providers">Solutions providers</a></li>
<li><a href="#Related">Related</a></li>
</ul>
<h2 id="legal-text">Legal text</h2>
<ul>
<li><a
href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&amp;from=EN">GDPR
(2016/679)</a> - Official version of GDPR.</li>
<li><a href="https://gdpr-info.eu/">GDPR-info</a> - GDPR linked to
relevant articles and section in the preamble (Non-official site).</li>
<li><a
href="https://www.gdpr-expert.com/home.html?mid=5">GDPR-expert</a> -
Compare the Regulation, Directive and National legislation. Linked to
relevant section in preamble (Non-official site).</li>
<li><a
href="https://gdprhub.eu/index.php?title=Category:GDPR_Articles">GDPRhub
-&gt; GDPR Articles</a> - GDPR articles included commentary.</li>
</ul>
<h2 id="guidelines">Guidelines</h2>
<ul>
<li><a
href="https://edpb.europa.eu/our-work-tools/general-guidance/gdpr-guidelines-recommendations-best-practices_en">Guidelines</a>
&amp; <a
href="https://edpb.europa.eu/our-work-tools/consistency-findings/opinions_en">Opinions</a>
from the European Data Protection Board (EDPB).</li>
<li><a
href="https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/">ICO:
Guide to GDPR</a></li>
<li><a
href="https://publications.europa.eu/en/publication-detail/-/publication/5b0cfa83-63f3-11e8-ab9c-01aa75ed71a1">Handbook
on European data protection law</a> - Handbook issued by EU.</li>
<li><a
href="https://edps.europa.eu/data-protection/our-work/our-work-by-type/factsheets_en">Factsheets</a>
- Factsheets from EU Data Protection Supervisor.</li>
</ul>
<h2 id="rights-of-the-data-subject-art.-12---23">Rights of the data
subject (art. 12 - 23)</h2>
<ul>
<li><a href="https://github.com/juro-privacy/free-privacy-notice">Open
source privacy notice template (Juro)</a></li>
</ul>
<h2 id="privacy-by-design---guides-for-developers-art.-25">Privacy by
Design - Guides for developers (art. 25)</h2>
<ul>
<li><a href="https://github.com/LINCnil/GDPR-Developer-Guide">CNIL -
GDPR Developer Guide</a></li>
<li><a
href="https://www.datatilsynet.no/en/about-privacy/virksomhetenes-plikter/data-protection-by-design-and-by-default/">Norwegian
DPA - Software development with Data Protection by Design and by
Default</a></li>
<li><a
href="https://www.enisa.europa.eu/publications/data-pseudonymisation-advanced-techniques-and-use-cases/">Data
Pseudonymisation: Advanced Techniques and Use Cases</a> - Report on
pseudonymisation techniques from ENISA.</li>
<li><a
href="https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/ico-call-for-views-anonymisation-pseudonymisation-and-privacy-enhancing-technologies-guidance/">Anonymisation,
pseudonymisation and privacy enhancing technologies guidance -
ICO</a></li>
</ul>
<h2 id="records-of-processing-art.-30">Records of Processing (art.
30)</h2>
<ul>
<li><a
href="https://www.iubenda.com/en/internal-privacy-management">Iubenda -
Register of data processing activities</a></li>
</ul>
<h2 id="security-art.-32">Security (art. 32)</h2>
<ul>
<li><a href="https://owasp.org/www-project-top-ten/">OWASP Top 10</a> -
Top 10 Web Application Security Risks.</li>
<li><a href="https://cheatsheetseries.owasp.org/">OWASP Cheat Sheet
Series</a> - Concise collection of high value information on specific
application security topics.</li>
<li><a
href="https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/ico-call-for-views-anonymisation-pseudonymisation-and-privacy-enhancing-technologies-guidance/">Anonymisation,
pseudonymisation and privacy enhancing technologies guidance</a></li>
</ul>
<h2 id="incident-management-art.-33-and-34">Incident management (art. 33
and 34)</h2>
<ul>
<li><a
href="https://www.enisa.europa.eu/publications/dbn-severity">ENISA:
Recommendations for a methodology of the assessment of severity of
personal data breaches</a></li>
<li><a
href="https://landing.google.com/sre/sre-book/chapters/managing-incidents/">Google,
SRE: Managing Incidents</a></li>
<li><a
href="https://www.troyhunt.com/data-breach-disclosure-101-how-to-succeed-after-youve-failed/">Troy
Hunt: Data breach disclosure 101</a></li>
<li><a
href="https://github.com/meirwah/awesome-incident-response">Awesome
Incident Response</a></li>
<li><a href="http://www.enforcementtracker.com/">GDPR Enforcement
Tracker</a> - Overview of fines and penalties.</li>
</ul>
<h2 id="data-protection-impact-assessments-dpia-art.-35">Data Protection
Impact Assessments (DPIA, art. 35)</h2>
<ul>
<li><a
href="https://www.cnil.fr/en/open-source-pia-software-helps-carry-out-data-protection-impact-assesment">Open-source
DPIA software from the French DPA</a></li>
<li><a
href="https://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=611236">Guidelines
on Data Protection Impact Assessment (WP29)</a></li>
<li><a href="https://www.iso.org/standard/86012.html">ISO-standard:
Guidelines for privacy impact assessment</a></li>
<li><a
href="https://iapp.org/resources/article/sample-dpia-template/">DPIA
template from ICO</a></li>
<li><a
href="https://www.rijksoverheid.nl/documenten/publicaties/2022/02/21/public-dpia-teams-onedrive-sharepoint-and-azure-ad">Public
DPIA Teams OneDrive SharePoint and Azure AD</a> - DPIA of Microsoft
Teams in combination with OneDrive, SharePoint Online and the Azure
Active Directory.</li>
</ul>
<h2 id="tools">Tools</h2>
<ul>
<li><a
href="https://github.com/EU-EDPS/website-evidence-collector">Website
Evidence Collector (WEC)</a> - EDPS Inspection Software.</li>
<li><a
href="https://www.cnil.fr/en/data-protection-around-the-world">Data
protection around the world</a> - (CNIL) Map of the level of data
protection in each country.</li>
<li><a href="https://www.dlapiperdataprotection.com/">Data Protection
Laws of the world</a> - (DLA Piper) Compare data protection laws around
the world.</li>
</ul>
<h2 id="data-protection-authorities-art.-51--59">Data Protection
Authorities (art. 51 -59)</h2>
<ul>
<li><a href="https://edpb.europa.eu/">European Data Protection Board</a>
- EDPB.</li>
<li><a href="https://edps.europa.eu/">European Data Protection
Supervisor</a> - EDPS.</li>
<li><a
href="https://www.enisa.europa.eu/topics/data-protection">European Union
Agency for Network and Information Security (ENISA)</a> - ENISA.</li>
<li><a href="https://pdpecho.com/the-list/">List of Data Protection
Authorities</a></li>
</ul>
<h2 id="organisations-projects">Organisations / Projects</h2>
<ul>
<li><a href="https://www.eff.org/">Electronic Frontier Foundation</a> -
Nonprofit defending digital privacy, free speech, and innovation.</li>
<li><a href="https://iapp.org/">International Association of Privacy
Professionals</a> - A resource for privacy professionals.</li>
<li><a href="https://www.privacyinternational.org">Privacy
International</a> - Charity that challenges the governments and
companies that want to know everything about individuals, groups, and
whole societies.</li>
<li><a href="https://noyb.eu/">NOYB</a> - Organisation that brings
important issues to the attention of DPAs, enforces the law in civil
court or directly engages with companies.</li>
<li><a href="https://gdpr.eu/">GDPR.eu</a> - Resource for organisations
and individuals researching the GDPR (Not official website).</li>
<li><a href="https://cups.cs.cmu.edu/">CyLab Usable Privacy and Security
Laboratory</a> - Research related to understand and improving the
usability of privacy and security.</li>
<li><a href="https://epic.org/">EPIC</a> - Electronic Privacy
Information Center.</li>
<li><a href="https://fpf.org/">Future of Privacy Forum</a> - Catalyst
for privacy leadership and scholarship, advancing principled data
practices in support of emerging technologies.</li>
<li><a href="https://www.w3.org/Privacy/">W3C Privacy Interest Group</a>
- Leading the web to its full potential.</li>
<li><a href="https://www.codeofconduct.cloud/">CISPE Code of Conduct</a>
- Pan-European sector-specific code for cloud infrastructure service
providers under Article 40.</li>
</ul>
<h2 id="publications">Publications</h2>
<ul>
<li><a href="https://www.gdprtoday.org/">GDPR Today</a> - Privacy news
from the Open Rights Group.</li>
<li><a href="https://spreadprivacy.com/">Spread Privacy</a> - DuckDuckGo
Blog.</li>
<li><a href="https://freedom-to-tinker.com/">Freedom To Tinker</a> -
Blog from Princetons CITP, a research center that studies digital
technologies in public life.</li>
<li><a href="https://pdpecho.com/">pdpEcho</a> - All about personal data
protection and privacy, by Gabriela Zanfir-Fortuna.</li>
<li><a href="https://gdprhub.eu/">GDPRhub</a> - Free and open wiki that
allows anyone to find and share GDPR insights across Europe.</li>
</ul>
<h2 id="related">Related</h2>
<ul>
<li><a
href="https://github.com/nikitavoloboev/privacy-respecting">Privacy
Respecting</a></li>
<li><a href="https://github.com/sindresorhus/awesome#security">Awesome:
Security</a></li>
<li><a
href="https://github.com/humanetech-community/awesome-humane-tech#readme">Awesome:
Humane Tech</a></li>
<li><a href="https://github.com/pluja/awesome-privacy#readme">Awesome:
Privacy</a> - List of free, open source and privacy respecting services
and alternatives to privative services.</li>
<li><a
href="https://github.com/truevault/hipaa-compliance-developers-guide">Developers
Guide to HIPAA Compliance</a></li>
<li><a href="https://www.gocookieless.com/">Analytics without
cookies</a></li>
<li><a
href="https://european-alternatives.eu/category/web-analytics-services">European
web analytics services</a></li>
<li><a href="https://dasprive.be/eu-alternatives/">EU
Alternatives</a></li>
</ul>
<h2 id="license">License</h2>
<p><a href="https://creativecommons.org/publicdomain/zero/1.0/"><img
src="http://mirrors.creativecommons.org/presskit/buttons/88x31/svg/cc-zero.svg"
alt="CC0" /></a></p>
<p>To the extent possible under law, Harald O. Bakke has waived all
copyright and related or neighboring rights to this work.</p>
<p><a href="https://github.com/bakke92/awesome-gdpr">gdpr.md
Github</a></p>