
GDPR Data Processing Agreement (DPA): Article 28 Explained (2026)
GDPR Article 28 requires a written DPA with every processor. Learn the 8 mandatory clauses, sub-processor rules, and consequences of non-compliance.
Loading...
433 articles · page 3 of 8

GDPR Article 28 requires a written DPA with every processor. Learn the 8 mandatory clauses, sub-processor rules, and consequences of non-compliance.

The eight GDPR data subject rights under Chapter III: access, rectification, erasure, restriction, portability, objection, automated-decision rights, and the right to be informed. Timelines, exemptions, and 2026 enforcement.

GDPR Article 35 requires a DPIA before high-risk processing. Learn when it is mandatory, what it must contain, and when to consult your supervisory authority.

GDPR Articles 37-39 explained: the 3 mandatory DPO triggers, tasks, independence rules, conflict-of-interest bar, and fines for non-compliance.

GDPR fines explained: the two-tier Article 83 structure, EDPB fine-calculation methodology, the Deutsche Wohnen corporate-liability ruling, every major fine and its current appeal status, non-monetary consequences, and how to reduce your exposure.

Practical GDPR compliance guide for small businesses: what applies, the Article 30(5) records derogation, when you need a DPO, the 2025 Digital Omnibus simplification proposal, sector examples, and low-cost steps.

GDPR Chapter V bars EU data transfers abroad without a valid mechanism. Learn adequacy, SCCs, BCRs, derogations, and Schrems II in plain English.

GDPR Article 17 gives you the right to demand erasure of personal data in 6 grounds. Learn the exceptions, Google Spain ruling, and how to make a request.

Learn how to respond to a GDPR DSAR under Article 15: the one-month deadline, what data to provide, fees, refusals, and a step-by-step response workflow.
Side-by-side comparison of GDPR and CCPA/CPRA: scope, consent models, consumer rights, sensitive data, penalties, CPPA enforcement, and the 2025 ADMT/cybersecurity regulations.
Side-by-side comparison of the EU GDPR and Brazil's LGPD: legal bases (6 vs 10), penalties, data subject rights, the ANPD vs EU DPAs, breach notification, and the January 2026 mutual adequacy decision.
Side-by-side comparison of GDPR and China's PIPL: scope, legal bases, individual rights, penalties, cross-border transfers, and 2025-2026 regulatory updates.
The EU GDPR and UK GDPR started identical after Brexit. The Data (Use and Access) Act 2025—in force February 2026—has introduced recognised legitimate interests, new ADM rules, SAR stop-the-clock, and cookie exemptions. The EU renewed UK adequacy through December 2031.
Generac's $15M PWRcell SnapRS settlement has preliminary approval. Claims are open through Aug. 24, 2026. See who's covered and how much you may get.

Georgia has no biometric privacy law. Learn what the Personal Identity Protection Act covers, how SB 111 could change protections, and what rights you have in 2026.

Georgia's data breach notification law requires notice without unreasonable delay but sets no deadline, no AG reporting, and no penalties. Full breakdown of Ga. Code 10-1-912.

Georgia data privacy laws explained: breach notification under O.C.G.A. 10-1-912, Computer Systems Protection Act, failed consumer privacy bills, and federal protections.

Germany enforces the EU GDPR through the BDSG, 17 supervisory authorities, and a constitutional right to informational self-determination. Full guide to compliance, DPO rules, employee data, AI Act overlay, and enforcement.

Complete guide to Ghana data privacy laws: Data Protection Act 2012 (Act 843), the Data Protection Commission, mandatory registration, data subject rights, cross-border transfer rules, penalties, and the pending Data Protection Bill 2025 that would modernize the framework.
Google's $68M Assistant privacy settlement is open as of July 2026. Claim deadline Aug. 27; see who qualifies, how payouts work, and where to file.
Google's $8.25M Google Play COPPA settlement claim deadline is Sept. 14, 2026. See who's eligible, how parents file, and what pro rata pay means.

There's no Google privacy settlement claim form as of July 2026. The $440M verdict is contested and AG settlements paid states, not consumers.

Greece data privacy laws explained: GDPR implementation via Law 4624/2019, Hellenic Data Protection Authority enforcement, Clearview AI fine, Predatorgate, EU AI Act, cookies, and compliance tips.
GRIPA's $2.15M MOVEit data breach settlement is open. File by September 3, 2026 for cash or documented-loss reimbursement plus free identity protection.

The $14M Hard Rock Stadium Copa America settlement is open; claims are due Aug. 11, 2026. Ticketholders denied entry or full access may be eligible.

Hawaii covers biometric data through its breach notification law (HRS Ch. 487N) and constitutional privacy rights. Learn what fingerprint, voiceprint, and iris data protections apply.

Hawaii requires breach notification without unreasonable delay under HRS 487N. Learn about penalties up to $2,500, private right of action, and what triggers notice.

Guide to Hawaii data privacy laws including constitutional privacy rights, data breach notification under HRS 487N, SSN protections, and 2026 legislative updates.

Complete guide to Hong Kong's Personal Data (Privacy) Ordinance (PDPO, Cap. 486): six Data Protection Principles, 2021 anti-doxxing regime, breach handling, cross-border transfer rules, AI guidance, and 2026 reform proposals.

How to complain to the UK ICO about a data breach: raise it with the organisation first, ICO timescales and powers, and why compensation comes from court.

Step-by-step guide to filing a data privacy complaint in 2026: California CPPA and AG, state AGs for VCDPA/CPA/CTDPA/TDPSA, the FTC, HHS OCR for HIPAA (180-day deadline), and EU/GDPR supervisory authorities.

A credit freeze is free at Equifax, Experian, and TransUnion by federal law. Step-by-step for all three, plus freeze vs. fraud alert vs. lock.

How to make a privacy complaint to the OAIC in Australia: complain to the organisation first, lodge with the OAIC, conciliation, and s 52 compensation.

How to make a UK subject access request: how to ask, the one-month deadline, the free-of-charge rule, exemptions, refusals, and complaining to the ICO.

Step-by-step guide to opting out of data brokers in 2026: use California's DROP platform, enable Global Privacy Control, check CA, VT, OR, and TX registries, and submit per-broker CCPA requests.

Step-by-step guide to submitting a data deletion request under CCPA, US state privacy laws, and GDPR:including timelines, identity verification, authorized agents, exceptions, and how to escalate if a company refuses.

Hungary data privacy law explained: GDPR + Info Act CXII of 2011, NAIH enforcement, AI Act overlay, cross-border transfers, DPO rules, penalties up to EUR 20 million.
The Hyundai-Kia ACU settlement is open, with a $62.1M fund and a claim deadline of April 8, 2027. See who may be eligible and how to file.

A practical Iowa Code 715D compliance checklist: thresholds, privacy notice, sale opt-out, processor contracts, the 90-day cure, and $7,500 penalties.

Under Iowa Code 715D.3, Iowans can access, delete, port, and opt out of data sales. There is no right to correct, targeted-ad opt-out, or profiling opt-out.

Iceland applies the GDPR through the EEA Agreement and Act No. 90/2018. Learn how Persónuvernd enforces data protection, what fines apply, and how businesses must comply.

Idaho has no dedicated biometric privacy law as of 2026. Learn what current statutes cover, pending legislation like H0744, and how Idaho compares to other states.

Learn Idaho data breach notification rules, the 24-hour agency reporting deadline, protected data categories, encryption safe harbor, and penalties up to $25,000.

Idaho data privacy laws explained: breach notification rules under Idaho Code 28-51-105, identity theft penalties, student data protections, and federal privacy coverage.

Illinois BIPA (740 ILCS 14) requires written consent before collecting fingerprints, face scans, or other biometrics. Violations carry $1,000-$5,000 in damages per violation.

Learn Illinois data breach notification rules under 815 ILCS 530, including reporting timelines, AG notification thresholds, encryption safe harbor, and penalties.

Illinois leads the nation in biometric privacy through BIPA, with penalties up to $5,000 per violation. Learn about BIPA settlements, data breach rules, and employee protections.

An INCDPA compliance checklist: IC 24-15 thresholds, privacy notice, opt-in sensitive data, 45-day requests, assessments, and the permanent 30-day cure before Jan. 1, 2026.

Indiana's INCDPA (IC 24-15-3-1) gives residents access, correction, deletion, portability, and opt-out rights starting Jan. 1, 2026, with a 45-day response window.

India's Digital Personal Data Protection Act 2023 and the DPDP Rules notified November 2025 form the country's first comprehensive data protection regime. This guide covers consent, Data Principal rights, the Data Protection Board, penalties up to INR 250 crore, cross-border transfers, and the phased compliance timeline to May 2027.

India's DPDP Act is mostly not yet operative. Full commencement timeline, Consent Managers, rights gaps, and CERT-In vs DPDP breach rules vs GDPR.

Indiana's ICDPA classifies biometric data as sensitive, requiring opt-in consent for fingerprints, voiceprints, and iris scans. Learn consent rules, penalties, and exemptions.

Indiana requires data breach notification within 45 days. Learn who must be notified, what personal information triggers the law, penalties up to $150,000, and the biometric data gap.

Learn about Indiana data privacy laws including the ICDPA consumer rights, business obligations, enforcement penalties, and data breach notification requirements.

Indonesia's Personal Data Protection Law (UU PDP, Law 27/2022) is fully in force since October 2024. Guide covers supervisory authority status, data subject rights, breach notification, cross-border transfers, criminal and administrative penalties, and compliance steps.

Indonesia's UU PDP is fully in force, but its supervisory authority and PP regulation are not yet built. GDPR comparison, penalties, breach rules.

Iowa classifies biometric data as sensitive under the ICDPA (effective Jan 2025). Learn about opt-out requirements, breach notification rules, and penalties.

Iowa requires breach notification in the most expedient time possible under Code 715C. Learn about biometric data coverage, AG reporting rules, and penalties.

Iowa's ICDPA grants consumers access, deletion, portability, and opt-out rights under Iowa Code Ch. 715D. Learn thresholds, the 90-day cure period, penalties up to $7,500, and breach notification rules.

Ireland's DPC enforces GDPR for Meta, Google, TikTok and more. Learn about the Data Protection Act 2018, record fines exceeding 4 billion euros, the three commissioners, AI Act obligations, cross-border transfer rules, and your rights.