247 lines
11 KiB
HTML
247 lines
11 KiB
HTML
<h1 id="awesome-gdpr-awesome">Awesome GDPR <a
|
||
href="https://awesome.re"><img src="https://awesome.re/badge-flat.svg"
|
||
alt="Awesome" /></a></h1>
|
||
<p><a
|
||
href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679"><img src="GDPR.png" align="right" width="300"></a></p>
|
||
<p>The General Data Protection Regulation (GDPR) is a regulation on data
|
||
protection and privacy for all individuals within the European Union and
|
||
the European Economic Area. The regulation has increased the focus on
|
||
privacy in companies and strengthened the data subjects influence.</p>
|
||
<h2 id="contents">Contents</h2>
|
||
<ul>
|
||
<li><a href="#legal-text">Legal text</a></li>
|
||
<li><a href="#Guidelines">Guidelines</a></li>
|
||
<li><a href="#rights-of-the-data-subject-art-12---23">Rights of the data
|
||
subject (art. 12 - 23)</a></li>
|
||
<li><a href="#privacy-by-design---guides-for-developers-art-25">Privacy
|
||
by Design - Guides for developers (art. 25)</a></li>
|
||
<li><a href="#records-of-processing-art-30">Records of Processing (art.
|
||
30)</a></li>
|
||
<li><a href="#security-art-32">Security (art. 32)</a></li>
|
||
<li><a href="#incident-management-art-33-and-34">Incident management
|
||
(art. 33 and 34)</a></li>
|
||
<li><a href="#data-protection-impact-assessments-dpia-art-35">Data
|
||
Protection Impact Assessments (DPIA, art. 35)</a></li>
|
||
<li><a href="#tools">Tools</a></li>
|
||
<li><a href="#data-protection-authorities-art-51--59">Data Protection
|
||
Authorities</a></li>
|
||
<li><a href="#organisations--projects">Organisations / Projects</a></li>
|
||
<li><a href="#Publications">Publications</a></li>
|
||
<li><a href="#Solutions-providers">Solutions providers</a></li>
|
||
<li><a href="#Related">Related</a></li>
|
||
</ul>
|
||
<h2 id="legal-text">Legal text</h2>
|
||
<ul>
|
||
<li><a
|
||
href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679&from=EN">GDPR
|
||
(2016/679)</a> - Official version of GDPR.</li>
|
||
<li><a href="https://gdpr-info.eu/">GDPR-info</a> - GDPR linked to
|
||
relevant articles and section in the preamble (Non-official site).</li>
|
||
<li><a
|
||
href="https://www.gdpr-expert.com/home.html?mid=5">GDPR-expert</a> -
|
||
Compare the Regulation, Directive and National legislation. Linked to
|
||
relevant section in preamble (Non-official site).</li>
|
||
<li><a
|
||
href="https://gdprhub.eu/index.php?title=Category:GDPR_Articles">GDPRhub
|
||
-> GDPR Articles</a> - GDPR articles included commentary.</li>
|
||
</ul>
|
||
<h2 id="guidelines">Guidelines</h2>
|
||
<ul>
|
||
<li><a
|
||
href="https://edpb.europa.eu/our-work-tools/general-guidance/gdpr-guidelines-recommendations-best-practices_en">Guidelines</a>
|
||
& <a
|
||
href="https://edpb.europa.eu/our-work-tools/consistency-findings/opinions_en">Opinions</a>
|
||
from the European Data Protection Board (EDPB).</li>
|
||
<li><a
|
||
href="https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/">ICO:
|
||
Guide to GDPR</a></li>
|
||
<li><a
|
||
href="https://publications.europa.eu/en/publication-detail/-/publication/5b0cfa83-63f3-11e8-ab9c-01aa75ed71a1">Handbook
|
||
on European data protection law</a> - Handbook issued by EU.</li>
|
||
<li><a
|
||
href="https://edps.europa.eu/data-protection/our-work/our-work-by-type/factsheets_en">Factsheets</a>
|
||
- Factsheets from EU Data Protection Supervisor.</li>
|
||
</ul>
|
||
<h2 id="rights-of-the-data-subject-art.-12---23">Rights of the data
|
||
subject (art. 12 - 23)</h2>
|
||
<ul>
|
||
<li><a href="https://github.com/juro-privacy/free-privacy-notice">Open
|
||
source privacy notice template (Juro)</a></li>
|
||
</ul>
|
||
<h2 id="privacy-by-design---guides-for-developers-art.-25">Privacy by
|
||
Design - Guides for developers (art. 25)</h2>
|
||
<ul>
|
||
<li><a href="https://github.com/LINCnil/GDPR-Developer-Guide">CNIL -
|
||
GDPR Developer Guide</a></li>
|
||
<li><a
|
||
href="https://www.datatilsynet.no/en/about-privacy/virksomhetenes-plikter/data-protection-by-design-and-by-default/">Norwegian
|
||
DPA - Software development with Data Protection by Design and by
|
||
Default</a></li>
|
||
<li><a
|
||
href="https://www.enisa.europa.eu/publications/data-pseudonymisation-advanced-techniques-and-use-cases/">Data
|
||
Pseudonymisation: Advanced Techniques and Use Cases</a> - Report on
|
||
pseudonymisation techniques from ENISA.</li>
|
||
<li><a
|
||
href="https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/ico-call-for-views-anonymisation-pseudonymisation-and-privacy-enhancing-technologies-guidance/">Anonymisation,
|
||
pseudonymisation and privacy enhancing technologies guidance -
|
||
ICO</a></li>
|
||
</ul>
|
||
<h2 id="records-of-processing-art.-30">Records of Processing (art.
|
||
30)</h2>
|
||
<ul>
|
||
<li><a
|
||
href="https://www.iubenda.com/en/internal-privacy-management">Iubenda -
|
||
Register of data processing activities</a></li>
|
||
</ul>
|
||
<h2 id="security-art.-32">Security (art. 32)</h2>
|
||
<ul>
|
||
<li><a href="https://owasp.org/www-project-top-ten/">OWASP Top 10</a> -
|
||
Top 10 Web Application Security Risks.</li>
|
||
<li><a href="https://cheatsheetseries.owasp.org/">OWASP Cheat Sheet
|
||
Series</a> - Concise collection of high value information on specific
|
||
application security topics.</li>
|
||
<li><a
|
||
href="https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/ico-call-for-views-anonymisation-pseudonymisation-and-privacy-enhancing-technologies-guidance/">Anonymisation,
|
||
pseudonymisation and privacy enhancing technologies guidance</a></li>
|
||
</ul>
|
||
<h2 id="incident-management-art.-33-and-34">Incident management (art. 33
|
||
and 34)</h2>
|
||
<ul>
|
||
<li><a
|
||
href="https://www.enisa.europa.eu/publications/dbn-severity">ENISA:
|
||
Recommendations for a methodology of the assessment of severity of
|
||
personal data breaches</a></li>
|
||
<li><a
|
||
href="https://landing.google.com/sre/sre-book/chapters/managing-incidents/">Google,
|
||
SRE: Managing Incidents</a></li>
|
||
<li><a
|
||
href="https://www.troyhunt.com/data-breach-disclosure-101-how-to-succeed-after-youve-failed/">Troy
|
||
Hunt: Data breach disclosure 101</a></li>
|
||
<li><a
|
||
href="https://github.com/meirwah/awesome-incident-response">Awesome
|
||
Incident Response</a></li>
|
||
<li><a href="http://www.enforcementtracker.com/">GDPR Enforcement
|
||
Tracker</a> - Overview of fines and penalties.</li>
|
||
</ul>
|
||
<h2 id="data-protection-impact-assessments-dpia-art.-35">Data Protection
|
||
Impact Assessments (DPIA, art. 35)</h2>
|
||
<ul>
|
||
<li><a
|
||
href="https://www.cnil.fr/en/open-source-pia-software-helps-carry-out-data-protection-impact-assesment">Open-source
|
||
DPIA software from the French DPA</a></li>
|
||
<li><a
|
||
href="https://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=611236">Guidelines
|
||
on Data Protection Impact Assessment (WP29)</a></li>
|
||
<li><a href="https://www.iso.org/standard/86012.html">ISO-standard:
|
||
Guidelines for privacy impact assessment</a></li>
|
||
<li><a
|
||
href="https://iapp.org/resources/article/sample-dpia-template/">DPIA
|
||
template from ICO</a></li>
|
||
<li><a
|
||
href="https://www.rijksoverheid.nl/documenten/publicaties/2022/02/21/public-dpia-teams-onedrive-sharepoint-and-azure-ad">Public
|
||
DPIA Teams OneDrive SharePoint and Azure AD</a> - DPIA of Microsoft
|
||
Teams in combination with OneDrive, SharePoint Online and the Azure
|
||
Active Directory.</li>
|
||
</ul>
|
||
<h2 id="tools">Tools</h2>
|
||
<ul>
|
||
<li><a
|
||
href="https://github.com/EU-EDPS/website-evidence-collector">Website
|
||
Evidence Collector (WEC)</a> - EDPS Inspection Software.</li>
|
||
<li><a
|
||
href="https://www.cnil.fr/en/data-protection-around-the-world">Data
|
||
protection around the world</a> - (CNIL) Map of the level of data
|
||
protection in each country.</li>
|
||
<li><a href="https://www.dlapiperdataprotection.com/">Data Protection
|
||
Laws of the world</a> - (DLA Piper) Compare data protection laws around
|
||
the world.</li>
|
||
</ul>
|
||
<h2 id="data-protection-authorities-art.-51--59">Data Protection
|
||
Authorities (art. 51 -59)</h2>
|
||
<ul>
|
||
<li><a href="https://edpb.europa.eu/">European Data Protection Board</a>
|
||
- EDPB.</li>
|
||
<li><a href="https://edps.europa.eu/">European Data Protection
|
||
Supervisor</a> - EDPS.</li>
|
||
<li><a
|
||
href="https://www.enisa.europa.eu/topics/data-protection">European Union
|
||
Agency for Network and Information Security (ENISA)</a> - ENISA.</li>
|
||
<li><a href="https://pdpecho.com/the-list/">List of Data Protection
|
||
Authorities</a></li>
|
||
</ul>
|
||
<h2 id="organisations-projects">Organisations / Projects</h2>
|
||
<ul>
|
||
<li><a href="https://www.eff.org/">Electronic Frontier Foundation</a> -
|
||
Nonprofit defending digital privacy, free speech, and innovation.</li>
|
||
<li><a href="https://iapp.org/">International Association of Privacy
|
||
Professionals</a> - A resource for privacy professionals.</li>
|
||
<li><a href="https://www.privacyinternational.org">Privacy
|
||
International</a> - Charity that challenges the governments and
|
||
companies that want to know everything about individuals, groups, and
|
||
whole societies.</li>
|
||
<li><a href="https://noyb.eu/">NOYB</a> - Organisation that brings
|
||
important issues to the attention of DPAs, enforces the law in civil
|
||
court or directly engages with companies.</li>
|
||
<li><a href="https://gdpr.eu/">GDPR.eu</a> - Resource for organisations
|
||
and individuals researching the GDPR (Not official website).</li>
|
||
<li><a href="https://cups.cs.cmu.edu/">CyLab Usable Privacy and Security
|
||
Laboratory</a> - Research related to understand and improving the
|
||
usability of privacy and security.</li>
|
||
<li><a href="https://epic.org/">EPIC</a> - Electronic Privacy
|
||
Information Center.</li>
|
||
<li><a href="https://fpf.org/">Future of Privacy Forum</a> - Catalyst
|
||
for privacy leadership and scholarship, advancing principled data
|
||
practices in support of emerging technologies.</li>
|
||
<li><a href="https://www.w3.org/Privacy/">W3C Privacy Interest Group</a>
|
||
- Leading the web to its full potential.</li>
|
||
<li><a href="https://www.codeofconduct.cloud/">CISPE Code of Conduct</a>
|
||
- Pan-European sector-specific code for cloud infrastructure service
|
||
providers under Article 40.</li>
|
||
</ul>
|
||
<h2 id="publications">Publications</h2>
|
||
<ul>
|
||
<li><a href="https://www.gdprtoday.org/">GDPR Today</a> - Privacy news
|
||
from the Open Rights Group.</li>
|
||
<li><a href="https://spreadprivacy.com/">Spread Privacy</a> - DuckDuckGo
|
||
Blog.</li>
|
||
<li><a href="https://freedom-to-tinker.com/">Freedom To Tinker</a> -
|
||
Blog from Princeton’s CITP, a research center that studies digital
|
||
technologies in public life.</li>
|
||
<li><a href="https://pdpecho.com/">pdpEcho</a> - All about personal data
|
||
protection and privacy, by Gabriela Zanfir-Fortuna.</li>
|
||
<li><a href="https://gdprhub.eu/">GDPRhub</a> - Free and open wiki that
|
||
allows anyone to find and share GDPR insights across Europe.</li>
|
||
</ul>
|
||
<h2 id="related">Related</h2>
|
||
<ul>
|
||
<li><a
|
||
href="https://github.com/nikitavoloboev/privacy-respecting">Privacy
|
||
Respecting</a></li>
|
||
<li><a href="https://github.com/sindresorhus/awesome#security">Awesome:
|
||
Security</a></li>
|
||
<li><a
|
||
href="https://github.com/humanetech-community/awesome-humane-tech#readme">Awesome:
|
||
Humane Tech</a></li>
|
||
<li><a href="https://github.com/pluja/awesome-privacy#readme">Awesome:
|
||
Privacy</a> - List of free, open source and privacy respecting services
|
||
and alternatives to privative services.</li>
|
||
<li><a
|
||
href="https://github.com/truevault/hipaa-compliance-developers-guide">Developers
|
||
Guide to HIPAA Compliance</a></li>
|
||
<li><a href="https://www.gocookieless.com/">Analytics without
|
||
cookies</a></li>
|
||
<li><a
|
||
href="https://european-alternatives.eu/category/web-analytics-services">European
|
||
web analytics services</a></li>
|
||
<li><a href="https://dasprive.be/eu-alternatives/">EU
|
||
Alternatives</a></li>
|
||
</ul>
|
||
<h2 id="license">License</h2>
|
||
<p><a href="https://creativecommons.org/publicdomain/zero/1.0/"><img
|
||
src="http://mirrors.creativecommons.org/presskit/buttons/88x31/svg/cc-zero.svg"
|
||
alt="CC0" /></a></p>
|
||
<p>To the extent possible under law, Harald O. Bakke has waived all
|
||
copyright and related or neighboring rights to this work.</p>
|
||
<p><a href="https://github.com/bakke92/awesome-gdpr">gdpr.md
|
||
Github</a></p>
|