EU Data Protection Guidance (EDPB)
European Union · actualizaciones: monthly · eu-data-protection-guidance
The European Data Protection Board’s guidelines, recommendations, statements and other guidance — the GDPR interpretation an EU data-protection compliance question is answered against — collected from edpb.europa.eu with no API key and no login. One record is one adopted document at its current version, keyed by the EDPB citation (Guidelines 02/2025, Recommendations 01/2025, Statement 1/2025) where the document has one, so a buyer retrieves by the reference a practitioner actually cites. The as-of axis is the publisher’s own: the adoption date and version number printed on the document’s first page, with the in-document version history carried verbatim — because the file name and the landing page both go stale and the printed page does not. The scope is the Board’s guidance, deliberately: its Article 64 opinions on draft national decisions and its Article 65 binding decisions are excluded by document type before anything is fetched, because they recite the facts of individual complaints — 269 of the 531 documents the index lists, refused and counted on every run. Each document’s identity is proved twice, from the landing page and from the document’s own first page, and one that does not corroborate the title it is served under is refused rather than released under a name it does not carry. Only born-digital PDF text layers are read: there is no OCR, and a document whose text cannot be extracted is refused and counted with an attestation rather than shipped as an empty record. Chunking is deliberately conservative — one record is one whole document, split only on the document’s own paragraph boundaries, and every chunk carries the document title, citation, type, adoption date and version — because the EDPB’s reuse notice authorises commercial reuse on condition that the original meaning is not distorted, and the source acknowledgement that notice requires rides on every record. Every record carries its source URL, fetch timestamp, HTTP status and the SHA-256 of both the raw response and the extracted record. Every release ships a manifest with every file’s SHA-256 and a Merkle root over every chunk hash, which the buyer can recompute from the downloaded files. record_id and chunk_id are stable across releases. Personal data is screened out inside the pipeline before any hash is computed.