Professional review status
No professional domain review recorded
This bundle covers legal, privacy subject matter. It is a source-aware research aid, not professional advice, and should not be the sole basis for consequential decisions.
Review before reliance: A qualified data-protection or legal professional appropriate to the question and jurisdiction.
Maintainer, editorial, or technical review addresses the bundle as a published artifact. It does not constitute legal, medical, financial, accounting, or other regulated professional approval.
Inspect before downloading
See what is inside
These previews come from the published bundle files, so you can judge the method and writing before using it.
Example task
A SaaS company asks: "We have EU customers and use an US analytics vendor. Are we GDPR compliant if the vendor says it has a DPA?" Create a short answer. Assume no direct access to the company's contracts, data map, transfer mechanism, security measures, or notices.
Without the bundle
If the vendor has a DPA, the company is likely GDPR compliant for that vendor relationship. The company should keep the DPA on file and ensure the vendor follows GDPR requirements. This is weak because it treats one claimed document as enough, does not inspect the legal source or contract, and ignores transfer, role, notice, security, and evidence gaps.
Using the bundle
The company cannot conclude GDPR compliance from the vendor's statement that it has a DPA. That is one relevant fact, but the conclusion is provisional until the contract, transfer mechanism, processing role, data categories, purpose, security measures, notices, and applicable guidance are reviewed. Source note: The answer needs the official GDPR legal text, relevant EDPB or national supervisory authority guidance for transfers and processor contracts, the vendor DPA, transfer documentation, and the company's processing records. None of those user documents were provided in this task.
Why this is better: The baseline output fails because it treats a vendor statement as enough to conclude compliance. It omits source note, evidence gaps, transfer analysis, and professional review. The bundle-assisted output is stronger because it gives a direct but cautious answer, separates missing evidence from conclusions, names required source categories, and gives next steps for document review. See GDPR source-awareness check.
Inspect this example in the repositoryOverview
GDPR Overview
Defines the source scope, applicability framing, and safety boundaries for GDPR compliance work.
Read the fileWorkflow
GDPR Obligation Triage
Source-aware workflow for turning a GDPR question into an evidence-backed compliance brief.
Read the fileTemplate
Source-Aware GDPR Compliance Brief
Output format for GDPR answers that must separate legal sources, regulator guidance, user evidence, assumptions, and missing verification.
Read the fileQuality rubric
GDPR Source-Awareness Check
Rubric for checking whether a GDPR answer is source-aware, cautious, and suitable for professional review.
Read the fileIs this bundle right for your task?
Who it is for
- Compliance, legal, risk, security, operations, and product teams assessing GDPR (General Data Protection Regulation)
- Teams working in cross-industry
When to use it
- A GDPR (General Data Protection Regulation) question needs to be scoped to the correct rule, guidance, regulator, date, and affected entity.
- A draft conclusion needs its stated facts, missing evidence, source citations, and professional-review handoff checked.
What you need to provide
- The jurisdiction, entity and relationship facts, applicable dates, exact question, and accountable professional reviewer.
- Current official sources plus the policies, contracts, records, system evidence, and missing facts relevant to the situation.
Tasks and expected outputs
Questions it helps answer
- triage GDPR applicability and obligation questions without inventing legal conclusions
- separate official law, regulator guidance, user-provided facts, assumptions, and missing evidence
- produce source-aware GDPR compliance briefs for professional review
What it helps produce
- source-aware GDPR compliance brief
Practical example
Use it with an agent
Load the bundle as context, provide the evidence named above, then adapt this example to your situation.
Provide the jurisdiction, entity and relationship facts, applicable dates, exact question, and accountable professional reviewer. Ask the agent to assess GDPR (General Data Protection Regulation) and draft source-aware GDPR compliance brief that separates stated facts, assumptions, missing evidence, relevant source sections, and actions requiring professional approval. Begin with EUR-Lex Regulation (EU) 2016/679, then confirm that the reference is current and applicable. Inspect GDPR Overview before drafting.
Context path: bundles/compliance/gdpr
What the bundle includes
Frameworks
- source-evidence matrix
- controller-processor role triage
Evaluations
- GDPR source-awareness check
Sources used to build this bundle
These are the public references behind the role definition and operating guidance. The bundle does not replace current documentation or evidence from your site.
Limitations and safe use
Do not use this for
- Final legal or compliance conclusions, filings, notices, or operational changes without current source review and accountable professional approval.
Known limitations
- This bundle is a compliance hub, not legal advice or a full article-by-article GDPR treatise.
- Scenario-specific answers require current legal text, regulator guidance, jurisdiction facts, and user-provided processing evidence.
- Measured evaluation is planned but not complete.
Safety notes
- Require qualified legal or privacy professional review before relying on outputs for regulatory, enforcement, contractual, or incident-response decisions.
- Do not request, expose, or publish personal data beyond what is necessary for the user-approved analysis.
- Require explicit confirmation before submitting notices, contacting regulators, changing policies, or sending legal communications.