Bundle catalog

compliance bundle

GDPR

A free, open-source set of 15 Markdown files for triaging GDPR (General Data Protection Regulation) questions against current sources and the facts of a specific situation.

Use this bundle to scope GDPR (General Data Protection Regulation) questions to the relevant source, case facts, and review owner; it does not provide a final legal or compliance conclusion. The page previews an overview, a workflow, a template, and a quality rubric; the intended output is source-aware GDPR compliance brief. Start source review with EUR-Lex Regulation (EU) 2016/679.

Project-reviewed beta

15 Markdown files · 2,166 words · no signup · CC-BY-4.0

Professional review status

No professional domain review recorded

This bundle covers legal, privacy subject matter. It is a source-aware research aid, not professional advice, and should not be the sole basis for consequential decisions.

Review before reliance: A qualified data-protection or legal professional appropriate to the question and jurisdiction.

Maintainer, editorial, or technical review addresses the bundle as a published artifact. It does not constitute legal, medical, financial, accounting, or other regulated professional approval.

Inspect before downloading

See what is inside

These previews come from the published bundle files, so you can judge the method and writing before using it.

Example task

A SaaS company asks: "We have EU customers and use an US analytics vendor. Are we GDPR compliant if the vendor says it has a DPA?" Create a short answer. Assume no direct access to the company's contracts, data map, transfer mechanism, security measures, or notices.

Without the bundle

If the vendor has a DPA, the company is likely GDPR compliant for that vendor relationship. The company should keep the DPA on file and ensure the vendor follows GDPR requirements. This is weak because it treats one claimed document as enough, does not inspect the legal source or contract, and ignores transfer, role, notice, security, and evidence gaps.

Using the bundle

The company cannot conclude GDPR compliance from the vendor's statement that it has a DPA. That is one relevant fact, but the conclusion is provisional until the contract, transfer mechanism, processing role, data categories, purpose, security measures, notices, and applicable guidance are reviewed. Source note: The answer needs the official GDPR legal text, relevant EDPB or national supervisory authority guidance for transfers and processor contracts, the vendor DPA, transfer documentation, and the company's processing records. None of those user documents were provided in this task.

Why this is better: The baseline output fails because it treats a vendor statement as enough to conclude compliance. It omits source note, evidence gaps, transfer analysis, and professional review. The bundle-assisted output is stronger because it gives a direct but cautious answer, separates missing evidence from conclusions, names required source categories, and gives next steps for document review. See GDPR source-awareness check.

Inspect this example in the repository

Is this bundle right for your task?

Who it is for

  • Compliance, legal, risk, security, operations, and product teams assessing GDPR (General Data Protection Regulation)
  • Teams working in cross-industry

When to use it

  • A GDPR (General Data Protection Regulation) question needs to be scoped to the correct rule, guidance, regulator, date, and affected entity.
  • A draft conclusion needs its stated facts, missing evidence, source citations, and professional-review handoff checked.

What you need to provide

  • The jurisdiction, entity and relationship facts, applicable dates, exact question, and accountable professional reviewer.
  • Current official sources plus the policies, contracts, records, system evidence, and missing facts relevant to the situation.

Tasks and expected outputs

Questions it helps answer

  • triage GDPR applicability and obligation questions without inventing legal conclusions
  • separate official law, regulator guidance, user-provided facts, assumptions, and missing evidence
  • produce source-aware GDPR compliance briefs for professional review

What it helps produce

  • source-aware GDPR compliance brief

Practical example

Use it with an agent

Load the bundle as context, provide the evidence named above, then adapt this example to your situation.

Provide the jurisdiction, entity and relationship facts, applicable dates, exact question, and accountable professional reviewer. Ask the agent to assess GDPR (General Data Protection Regulation) and draft source-aware GDPR compliance brief that separates stated facts, assumptions, missing evidence, relevant source sections, and actions requiring professional approval. Begin with EUR-Lex Regulation (EU) 2016/679, then confirm that the reference is current and applicable. Inspect GDPR Overview before drafting.

Context path: bundles/compliance/gdpr

What the bundle includes

Frameworks

  • source-evidence matrix
  • controller-processor role triage

Evaluations

  • GDPR source-awareness check

Sources used to build this bundle

These are the public references behind the role definition and operating guidance. The bundle does not replace current documentation or evidence from your site.

Limitations and safe use

Do not use this for

  • Final legal or compliance conclusions, filings, notices, or operational changes without current source review and accountable professional approval.

Known limitations

  • This bundle is a compliance hub, not legal advice or a full article-by-article GDPR treatise.
  • Scenario-specific answers require current legal text, regulator guidance, jurisdiction facts, and user-provided processing evidence.
  • Measured evaluation is planned but not complete.

Safety notes

  • Require qualified legal or privacy professional review before relying on outputs for regulatory, enforcement, contractual, or incident-response decisions.
  • Do not request, expose, or publish personal data beyond what is necessary for the user-approved analysis.
  • Require explicit confirmation before submitting notices, contacting regulators, changing policies, or sending legal communications.

Next step

Inspect it before relying on it

Download the bundle for use, review its source files and evidence, or read the agent guidance. If the project is useful, starring the repository helps others discover it.