Compilation of Guidances on the EU General Data Protection Regulation

July 24, 2018

  1. If you are new to the General Data Protection Regulation, you may want to review the text of the regulation to familiarize yourself with basic GDPR concepts and terminology: https://gdpr-info.eu/ exit disclaimer icon  Keep in mind that the scope of the GDPR is broader than U.S. privacy laws such as HIPAA.
  2. The names and website addresses of each country’s data protection authority are seen in Columns B and C.
  3. General GDPR Guidance documents are listed in Column D. If the information is not available in English, an online translation program can be helpful.
  4. The table lists guidances specific to Research (Column E), Legal Basis (Column F), Consent (Column G), and International Data Transfer (Column H). Country-level interpretations and procedures are likely to evolve over time, and data protection authorities may release new guidances.
 
A B C D E F G H
Country Name of Data Protection Authority Website General Guidance Research Legal Basis Consent International Data Transfer
European Union European Data Protection Board  https://edpb.europa.eu exit disclaimer icon http://ec.europa.eu/newsroom/article29/news.cfm?item_type=1360 exit disclaimer icon     http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=623051 exit disclaimer icon  
Austria Data Protection Authority http://www.dsb.gv.at/ exit disclaimer icon          
Belgium Data Protection Authority https://www.autoriteprotectiondonnees.be/ exit disclaimer icon     https://www.autoriteprotectiondonnees.be/fondement-legal-pour-le-traitement-de-donnees-a-caractere-personnel exit disclaimer icon https://www.autoriteprotectiondonnees.be/consentement exit disclaimer icon https://www.autoriteprotectiondonnees.be/international-0 exit disclaimer icon
Bulgaria Commission for Personal Data Protection https://www.cpdp.bg/ exit disclaimer icon https://www.cpdp.bg/index.php?p=element&aid=1163 exit disclaimer icon https://www.cpdp.bg/en/index.php?p=element&aid=1162 exit disclaimer icon   https://www.cpdp.bg/en/index.php?p=element&aid=1162 exit disclaimer icon  
Croatia Personal Data Protection Agency http://www.azop.hr/ exit disclaimer icon http://azop.hr/info-servis/detaljnije/opca-uredba-o-zastiti-podataka-gdpr exit disclaimer icon        
Cyprus Commissioner for Personal Data Protection http://www.dataprotection.gov.cy/          
Czech Republic Office for Personal Data Protection http://www.uoou.cz/ exit disclaimer icon https://www.uoou.cz/gdpr-strucne/ds-4843/p1=4843 exit disclaimer icon        
Denmark Data Protection Agency http://www.datatilsynet.dk/ exit disclaimer icon https://www.datatilsynet.dk/ exit disclaimer icon        
Estonia Data Protection Inspectorate http://www.aki.ee/ exit disclaimer icon   http://www.aki.ee/sites/www.aki.ee/files/elfinder/article_files/When%20do%20I%20need%20permission%20for%20conducting%20scientific%20research.pdf - PDF exit disclaimer icon     http://www.aki.ee/en/guidelines/transfer-personal-data-foreign-country exit disclaimer icon
Finland Office of the Data Protection Ombudsman http://www.tietosuoja.fi/en/ exit disclaimer icon          
France National Commission of Information Processing and Freedoms http://www.cnil.fr/ exit disclaimer icon https://www.cnil.fr/fr/recherches-dans-le-domaine-de-la-sante-la-cnil-adopte-de-nouvelles-mesures-de-simplification exit disclaimer icon https://www.cnil.fr/fr/declaration/mr-001-recherches-dans-le-domaine-de-la-sante-avec-recueil-du-consentement exit disclaimer icon and https://www.cnil.fr/sites/default/files/atoms/files/guide-cnom-cnil.pdf - PDF exit disclaimer icon https://www.cnil.fr/fr/recherches-dans-le-domaine-de-la-sante-ce-qui-change-avec-les-nouvelles-methodologies-de-reference exit disclaimer icon https://www.cnil.fr/fr/declaration/mr-001-recherches-dans-le-domaine-de-la-sante-avec-recueil-du-consentement exit disclaimer icon https://www.cnil.fr/fr/declaration/mr-001-recherches-dans-le-domaine-de-la-sante-avec-recueil-du-consentement exit disclaimer icon
Germany Federal Commissioner for Data Protection and Freedom of Information http://www.bfdi.bund.de/  exit disclaimer icon https://www.bfdi.bund.de/DE/Datenschutz/DatenschutzGVO/Aktuelles/Aktuelles_Artikel/DSGVO_Kurzpapiere.html exit disclaimer icon       https://www.bfdi.bund.de/SharedDocs/Downloads/DE/Datenschutz/Kurzpapier_DatenschutzFolgeabschaetzung.pdf?__blob=publicationFile&v=2 - PDF exit disclaimer icon
Greece Hellenic Data Protection Authority http://www.dpa.gr/ exit disclaimer icon          
Hungary National Authority for Data Protection and Freedom of Information http://www.naih.hu/ exit disclaimer icon http://www.naih.hu/felkeszueles-az-adatvedelmi-rendelet-alkalmazasara.html exit disclaimer icon        
Iceland Data Protection Authority https://www.personuvernd.is/information-in-english/ exit disclaimer icon https://www.personuvernd.is/ny-personuverndarloggjof-2018/ exit disclaimer icon        
Ireland Data Protection Commissioner http://www.dataprotection.ie/ exit disclaimer icon http://gdprandyou.ie/ exit disclaimer icon   http://gdprandyou.ie/gdpr-12-steps/#what-we-mean-when-we-talk-about-a-legal-basis exit disclaimer icon http://gdprandyou.ie/gdpr-12-steps/#using-customer-consent-as-a-grounds-to-process-data exit disclaimer icon https://www.dataprotection.ie/docs/Transfers-Abroad/y/37.htm exit disclaimer icon
Italy Guarantor for the Protection of Personal Data http://www.garanteprivacy.it/ exit disclaimer iconhttps://www.garanteprivacy.it/regolamentoue exit disclaimer icon     https://www.garanteprivacy.it/home/doveri#2 exit disclaimer icon    
Latvia Data State Inspectorate http://www.dvi.gov.lv/ http://www.dvi.gov.lv/lv/        
Liechten-stein Data Protection Office https://www.llv.li/#/1758/datenschutzstelle exit disclaimer icon          
Lithuania State Data Protection Inspectorate http://www.ada.lt/ exit disclaimer icon          
Luxem-bourg National Commission for Data Protection http://www.cnpd.lu/ exit disclaimer icon https://cnpd.public.lu/fr/dossiers-thematiques/Reglement-general-sur-la-protection-des-donnees/responsabilite-accrue-des-responsables-du-traitement/guide-preparation-rgpd.html exit disclaimer icon        
Malta Office of the Information and Data Protection Commissioner http://www.idpc.org.mt/ exit disclaimer icon https://idpc.org.mt/en/Pages/gdpr.aspx exit disclaimer icon        
Nether-lands Personal Data Authority https://autoriteitpersoonsgegevens.nl/nl exit disclaimer icon https://autoriteitpersoonsgegevens.nl/nl/onderwerpen/avg-europese-privacywetgeving exit disclaimer icon        
Nether-lands Central Committee on Research Involving Human Subjects http://www.ccmo.nl exit disclaimer icon   http://www.ccmo.nl/en/algemene-verordening-gegevensbescherming?5ad0a79c-a970-44d7-8c78-6de7c35ff8ba exit disclaimer icon   http://www.ccmo.nl/nl/nieuwsarchief/aanpassingen-pif-vanwege-nieuwe-europese-privacywetgeving exit disclaimer icon  
Norway Data Protection Authority https://www.datatilsynet.no/en/ exit disclaimer icon          
Poland Personal Data Protection Office https://uodo.gov.pl/          
Portugal National Commission for Data Protection https://www.cnpd.pt/ exit disclaimer icon https://www.cnpd.pt/bin/rgpd/rgpd.htm exit disclaimer icon   https://www.cnpd.pt/bin/faqs/faqs.htm exit disclaimer icon    
Romania National Supervisory Authority for Personal Data Processing http://www.dataprotection.ro/ exit disclaimer icon http://www.dataprotection.ro/?page=Regulamentul_nr_679_2016 exit disclaimer icon        
Slovakia Office for Personal Data Protection http://www.dataprotection.gov.sk/ https://dataprotection.gov.sk/uoou/sk/main-content/nariadenie-gdpr        
Slovenia Information Commissioner https://www.ip-rs.si/ exit disclaimer icon https://www.ip-rs.si/varstvo-osebnih-podatkov/projekti/rapidsi/ exit disclaimer icon        
Spain Agency for Data Protection https://www.agpd.es/ exit disclaimer icon https://www.servicios.agpd.es/AGPD/view/form/MDAwMDAwMDAwMDAwMDE3NjUwNzcxNTMyNDU2MTM5ODQ2?updated=true exit disclaimer icon        
Spain Department of Medications for Human Use https://www.aemps.gob.es/ exit disclaimer icon   https://www.aemps.gob.es/investigacionClinica/medicamentos/docs/anexo8c-Ins-AEMPS-EC.pdf - PDF exit disclaimer icon   https://www.aemps.gob.es/investigacionClinica/medicamentos/docs/anexo8c-Ins-AEMPS-EC.pdf - PDF exit disclaimer icon https://www.aemps.gob.es/investigacionClinica/medicamentos/docs/anexo8c-Ins-AEMPS-EC.pdf - PDF exit disclaimer icon
Sweden Data Inspection Board http://www.datainspektionen.se/ exit disclaimer icon https://www.datainspektionen.se/lagar--regler/dataskyddsforordningen/ exit disclaimer icon       https://www.datainspektionen.se/lagar--regler/dataskyddsforordningen/tredjelandsoverforing/ exit disclaimer icon
United Kingdom (Data Protection Act of 2018) Information Commissioner’s Office https://ico.org.uk exit disclaimer icon https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/ exit disclaimer icon   Legitimate Interests: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/legitimate-interests/ exit disclaimer icon https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/consent/ exit disclaimer icon https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/international-transfers/ exit disclaimer icon
United Kingdom (Data Protection Act of 2018) NHS Health Research Authority https://www.hra.nhs.uk exit disclaimer icon     https://www.hra.nhs.uk/planning-and-improving-research/policies-standards-legislation/data-protection-and-information-governance/gdpr-guidance/what-law-says/consent-research/ exit disclaimer icon https://www.hra.nhs.uk/planning-and-improving-research/policies-standards-legislation/data-protection-and-information-governance/gdpr-guidance/what-law-says/consent-research/ exit disclaimer icon  

 

Disclaimer: Though this Compilation contains information of a legal nature, it has been developed for informational purposes only and does not constitute legal advice or opinions as to the current operative guidelines of any jurisdiction. In addition, because new guidelines are issued on a continuing basis, this Compilation is not an exhaustive source of all current applicable guidelines relating to the General Data Protection Regulation. While reasonable efforts have been made to assure the accuracy and completeness of the information provided, researchers and other individuals should check with local authorities and/or research ethics committees before starting research activities.

Content created by Office for Human Research Protections (OHRP)
Content last reviewed