HomeSearch

Lenses
Business lenslens
Certifying body lenslens
End user / data subject lenslens
Front-line staff lenslens
Government lenslens
Human rights / privacy advocate lenslens
Policymaker (Government lens)lens
Regulator / enforcer (Government lens)lens
Africa
Egyptplanned
Ghanaplanned
Kenyaplanned
Moroccoplanned
Nigeriaplanned
Rwandaplanned
South Africaplanned
Asia-Pacific
Australiaplanned
Chinadrafting
Hong Kongplanned
Indiaplanned
Indonesiaplanned
Japanplanned
Malaysiaplanned
New Zealandplanned
Philippinesplanned
Singaporeplanned
South Koreaplanned
Thailandplanned
Vietnamplanned
Europe
European Uniondrafting
Switzerlandplanned
Türkiyeplanned
United Kingdomplanned
Latin America
Argentinaplanned
Brazilplanned
Chileplanned
Colombiaplanned
Peruplanned
Uruguayplanned
Middle East
Bahrainplanned
Israelplanned
Qatarplanned
Saudi Arabiaplanned
United Arab Emiratesplanned
North America
Canadaplanned
Mexicoplanned
United States (federal)drafting
United States
Californiadrafting
Coloradoplanned
Connecticutplanned
Delawareplanned
Floridaplanned
Indianaplanned
Iowaplanned
Kentuckyplanned
Marylandplanned
Minnesotaplanned
Montanaplanned
Nebraskaplanned
New Hampshireplanned
New Jerseyplanned
Ohioplanned
Oregonplanned
Rhode Islandplanned
Tennesseeplanned
Texasplanned
Utahplanned
Virginiaplanned
Menu

European Union

Coverage draftingAlso: EEA, Europe, GDPR, AI Act, Brussels

VERIFIED 2026-09-17 · REVIEW BY 2027-03-16

Europrivacy is the only Art. 42 certification approved as a transfer tool; other approved schemes, such as GDPR-CARPA and EuroPriSe, are not. SOC 2 and ISO/IEC 27001 carry no legal effect under the GDPR provisions assessed.

Instruments

  • Artificial Intelligence ActAI Act · Regulation (EU) 2024/1689
  • General Data Protection RegulationGDPR · Regulation (EU) 2016/679

Regulator

No regulator with a sourced address is recorded for European Union yet.

Exercisable rights

Directly exercisable against the controller, free of charge, with a right to complain to the supervisory authority where you live, work or where the infringement took place

Through each lens

End user / data subject

What can I actually do about this today, and what does it cost me.

No end user / data subject analysis for European Union yet.

Business

What does this obligate us to build, and by when.

No business analysis for European Union yet.

Government

Government is one lens carrying two sub-lenses, each with judicial reviewability analysis.

No government analysis for European Union yet.

Policymaker

What did the drafters intend, and what did the text achieve.

No policymaker analysis for European Union yet.

Regulator / enforcer

What can this authority make stick on appeal.

No regulator / enforcer analysis for European Union yet.

Certifying body

What is the scope of what we are attesting to.

No certifying body analysis for European Union yet.

Front-line staff

What do I do when this lands on my desk.

No front-line staff analysis for European Union yet.

Human rights / privacy advocate

Who does this regime fail, and can that be shown.

No human rights / privacy advocate analysis for European Union yet.

Sources

  1. Regulation (EU) 2016/679 (GDPR), Arts. 12(5), 15-22 and 77(1) · retrieved 2026-09-17 · https://eur-lex.europa.eu/eli/reg/2016/679/oj
  2. EDPB register of certification mechanisms, seals and marks, 17 entries; one usable as a tool for transfers (Europrivacy extension); GDPR-CARPA and EuroPriSe listed · retrieved 2026-09-17 · https://www.edpb.europa.eu/registers/register-of-consistency-and-of-accountability-tools/certification-mechanisms-and-data_en