EU-Wide GDPR Reference
Table of Contents
- Legal Bases (Art. 6)
- Special Category Data (Art. 9)
- Data Subject Rights (Art. 15–22)
- International Transfers (Chapter V)
- AI & Automated Decision-Making
- Children's Data (Art. 8)
- Soft Opt-In for Direct Marketing
- Art. 13/14 Mandatory Disclosures Checklist
Legal Bases
Art. 6(1)(a) — Consent
- Free, specific, informed, unambiguous
- Withdrawable at any time; withdrawal must be as easy as giving consent
- Burden of proof on controller (Art. 7(1))
- No pre-ticked boxes (Planet49, C-673/17)
- Use for: Newsletter, marketing cookies, ad tracking, sharing with partners, non-essential profiling
Art. 6(1)(b) — Contract Performance
- Processing necessary for contract execution or pre-contractual steps at data subject's request
- Cannot be stretched to cover all processing a controller wants to do (EDPB Guidelines 2/2019)
- Use for: Order fulfilment, account creation/management, payment processing, customer support related to the contract
Art. 6(1)(c) — Legal Obligation
- Processing necessary for compliance with a legal obligation to which the controller is subject
- Must identify the specific legal provision
- Use for: Tax retention, AML/KYC, employment law obligations, regulatory reporting
Art. 6(1)(d) — Vital Interests
- Rarely applicable; only when data subject physically unable to consent
- Use for: Medical emergencies
Art. 6(1)(e) — Public Interest / Official Authority
- Requires basis in Union or Member State law
- Use for: Public sector tasks, official authority exercise
Art. 6(1)(f) — Legitimate Interest
- Requires documented balancing test (LIA): legitimate interest → necessity → balancing against rights
- Data subject has absolute right to object for direct marketing (Art. 21(2))
- Use for: Fraud prevention, network security, anonymized analytics, B2B prospecting, intra-group admin
Special Category Data (Art. 9)
What Qualifies as Special Category Data
Art. 9(1) GDPR prohibits processing of these 8 categories unless an Art. 9(2) exception applies:
| Category |
Examples |
| Racial or ethnic origin |
Nationality, ethnicity, photo (if revealing) |
| Political opinions |
Party membership, political donations |
| Religious or philosophical beliefs |
Church membership (church tax in DE), dietary requirements revealing beliefs |
| Trade union membership |
Union dues deducted from payroll |
| Genetic data |
DNA tests, genetic predisposition data |
| Biometric data (for identification) |
Fingerprint access, facial recognition, iris scan |
| Health data |
Sick certificates, disability status, occupational health, insurance data |
| Sex life or sexual orientation |
Marital status (in some contexts), partner benefits |
Art. 9(2) Exceptions (Legal Bases for Special Categories)
Processing special categories requires both an Art. 6 legal basis and an Art. 9(2) exception (dual legal basis requirement).
| Exception |
Art. 9(2) |
Typical Use Cases |
| Explicit consent |
(a) |
Voluntary health surveys, diversity monitoring (where not legally required) |
| Employment & social security law |
(b) |
Payroll (church tax, union dues, disability), sick leave, occupational health |
| Vital interests |
(c) |
Medical emergency when data subject incapacitated |
| Not-for-profit bodies |
(d) |
Processing by churches, unions, political parties for their members |
| Manifestly public |
(e) |
Data subject has clearly made the data public (e.g., public social media profile) |
| Legal claims |
(f) |
Establishing, exercising, or defending legal claims |
| Substantial public interest |
(g) |
Anti-discrimination monitoring, statutory equality duties |
| Preventive/occupational medicine |
(h) |
Pre-employment medicals, occupational health assessments, fitness-for-duty |
| Public health |
(i) |
Pandemic response, pharmacovigilance |
| Archiving / research / statistics |
(j) |
Scientific research with appropriate safeguards |
Dual Legal Basis Requirement
Every processing of special category data must cite two legal bases:
- Art. 6(1) basis — e.g., Art. 6(1)(b) contract, Art. 6(1)(c) legal obligation, Art. 6(1)(f) legitimate interest
- Art. 9(2) exception — e.g., Art. 9(2)(b) employment law, Art. 9(2)(a) explicit consent
Example: Processing church tax data for an employee:
- Art. 6(1)(c) GDPR (legal obligation — tax law) + Art. 9(2)(b) GDPR (employment/social security law)
What to Disclose in the Privacy Notice
For each special category processed, the notice must state:
- The specific category of sensitive data processed
- The purpose of processing
- The Art. 6 legal basis and the Art. 9(2) exception
- Any additional safeguards applied (e.g., restricted access, pseudonymization, DPO oversight)
- Specific legal provisions authorizing the processing (e.g., § 26(3) BDSG, Art. 9(2)(b) + national employment law)
Intake Questions When Special Categories Are Detected
If any Art. 9 data is identified during intake, ask:
- Which specific categories of sensitive data are processed?
- What is the purpose for each sensitive data category?
- Which Art. 9(2) exception applies to each? Is there a Member State law authorizing it?
- Is explicit consent obtained? If so, how is it documented and how can it be withdrawn?
- What additional safeguards are in place (access restrictions, encryption, DPO involvement)?
- Is a DPIA required or already conducted for this processing? (Art. 35(3)(b) — large-scale special category processing requires DPIA)
Data Subject Rights
| Right |
Article |
Conditions / Limits |
Response Time |
| Access |
Art. 15 |
Free first copy; may charge for additional |
1 month (extendable +2) |
| Rectification |
Art. 16 |
Inaccurate or incomplete data |
1 month |
| Erasure ("Right to be Forgotten") |
Art. 17 |
When consent withdrawn, no longer necessary, unlawful, etc. Exceptions: legal obligation, public interest, legal claims |
1 month |
| Restriction |
Art. 18 |
Accuracy contested, unlawful processing, controller no longer needs data but subject needs for claims |
1 month |
| Data Portability |
Art. 20 |
Only for consent/contract-based automated processing |
1 month |
| Object |
Art. 21 |
Legitimate interest: must demonstrate compelling grounds. Direct marketing: absolute right |
1 month |
| Not be subject to automated decisions |
Art. 22 |
Decisions producing legal/significant effects. Exceptions: contract, law, explicit consent |
1 month |
| Withdraw Consent |
Art. 7(3) |
At any time; as easy as giving consent |
Without undue delay |
Exercise Procedure (to include in notice)
- Dedicated email address (e.g., privacy@..., datenschutz@..., dpo@...)
- Postal address
- Identity verification method (proportionate — no excessive ID requests)
- Response timeline: 1 month, extendable by 2 months for complex/numerous requests
- Free of charge (except manifestly unfounded/excessive)
International Transfers
Transfer Mechanisms (Chapter V)
| Mechanism |
Article |
When to Use |
| Adequacy Decision |
Art. 45 |
Country on EU Commission's adequate list |
| Standard Contractual Clauses (SCCs) |
Art. 46(2)(c) |
Most common mechanism for US/non-adequate transfers |
| Binding Corporate Rules (BCRs) |
Art. 47 |
Intra-group transfers |
| Derogations |
Art. 49 |
Explicit consent, contract necessity, public interest (narrow) |
Adequacy Decisions (current as of 2025)
Andorra, Argentina, Canada (PIPEDA), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, UK, Uruguay, USA (EU-U.S. Data Privacy Framework — DPF).
US Transfers — Specifics
- EU-U.S. DPF (Adequacy Decision July 2023) — verify the recipient is on the DPF list
- If not DPF-certified: SCCs + Transfer Impact Assessment (TIA) required
- Mention Schrems II implications if relevant
- Common processors requiring US transfer disclosure: Google, Meta, AWS (if US region), Microsoft, Salesforce, Mailchimp/Intuit, HubSpot, Stripe
What to Disclose in the Notice
For each transfer:
- Country/countries of destination
- Transfer mechanism used
- Where to obtain a copy/info about safeguards (link or on-request)
AI & Automated Decision-Making
GDPR Art. 22 Requirements
If the service uses AI/ML for decisions that produce legal or similarly significant effects:
- Right not to be subject to solely automated decisions
- Must disclose: (1) existence of automated decision-making, (2) meaningful information about the logic involved, (3) significance and envisaged consequences
- Exceptions: contract, law, explicit consent — but even then, safeguards required (human intervention, express point of view, contest)
EU AI Act Interplay (Regulation 2024/1689)
Applicable from August 2025 onwards (phased):
Transparency obligations for AI systems (Art. 50 AI Act):
- AI-generated content must be disclosed (chatbots, deepfakes, synthetic text)
- Users must be informed they are interacting with an AI system
- High-risk AI systems: extensive documentation and transparency requirements
Privacy notice should address:
- Whether AI/ML is used in processing personal data
- Purpose of AI processing (recommendations, scoring, content generation, moderation)
- Whether decisions are purely automated or human-in-the-loop
- Meaningful explanation of logic (not source code, but understandable impact description)
- How to contest AI-driven decisions
- Data used for training (if applicable to the user's data)
Standard AI Disclosure Wording (adapt per jurisdiction language)
[AI / AUTOMATED PROCESSING]
We use automated processing technologies, including [machine learning / artificial intelligence], for the following purposes:
- [Purpose 1, e.g., personalized content recommendations]
- [Purpose 2, e.g., fraud detection]
[If Art. 22 applies:]
These processes may produce decisions that significantly affect you. You have the right to:
- Obtain human intervention
- Express your point of view
- Contest the decision
To exercise these rights, contact [DPO/privacy contact].
[If AI Act applies:]
In accordance with the EU AI Act (Regulation 2024/1689), we inform you that [specific AI transparency disclosure].
Children's Data
Age Thresholds by Member State (Art. 8 GDPR)
| Country |
Age |
Source |
| Austria |
14 |
§ 4(4) DSG |
| Belgium |
13 |
Art. 7 loi du 30 juillet 2018 |
| Croatia |
16 |
default |
| Czech Republic |
15 |
§ 7 Zákon č. 110/2019 |
| Denmark |
13 |
§ 6 Databeskyttelsesloven |
| Estonia |
13 |
§ 8 IKS |
| Finland |
13 |
§ 5 Tietosuojalaki |
| France |
15 |
Art. 45 LIL |
| Germany |
16 |
§ 2 Nr. 17 TDDDG |
| Greece |
15 |
Art. 21 Law 4624/2019 |
| Hungary |
16 |
default |
| Ireland |
16 |
Sec. 31 Data Protection Act 2018 |
| Italy |
14 |
Art. 2-quinquies D.lgs. 196/2003 |
| Latvia |
13 |
Art. 9 FPDP |
| Lithuania |
14 |
Art. 8 ADTAĮ |
| Luxembourg |
16 |
default |
| Malta |
13 |
Reg. 5 SL 586.08 |
| Netherlands |
16 |
default |
| Poland |
16 |
default |
| Portugal |
13 |
Art. 16 Lei n.º 58/2019 |
| Romania |
16 |
default |
| Slovakia |
16 |
default |
| Slovenia |
16 |
default |
| Spain |
14 |
Art. 7 LOPDGDD |
| Sweden |
13 |
2 § Kompletterande dataskyddslag |
If the service may be used by children, include:
- Age-appropriate language in the notice
- Description of parental consent mechanism
- How parental consent is verified
- What data is collected from minors
- Whether profiles are created for minors
Soft Opt-In for Direct Marketing
Common 3-Condition Test
Most EU/EEA jurisdictions allow email marketing to existing customers without prior consent ("soft opt-in") if all three conditions are met:
- Existing customer relationship: The contact details were obtained in the context of a sale or service
- Similar products/services: The marketing concerns the controller's own similar products or services
- Easy opt-out: The customer was given a clear opportunity to object at the time of collection and in every subsequent message
Jurisdiction Comparison
| Jurisdiction |
Legal Provision |
Key Differences |
| Germany |
§ 7(3) UWG |
Strict: own similar products only; opt-out at collection + every email; no third-party marketing |
| France |
Art. L.34-5 CPCE |
Similar to DE; CNIL enforces strictly; B2B prospecting has separate, more permissive regime |
| Italy |
Art. 130(4) D.lgs. 196/2003 |
Soft opt-in recognized; Garante recommends clear disclosure at collection point |
| UK |
Regulation 22 PECR |
Similar to EU; ICO guidance: "similar products" interpreted reasonably |
| Spain |
Art. 21 LSSI |
Soft opt-in available; must clearly identify as commercial communication |
5-Step Decision Tree
- Was data collected during a sale/service? → No: consent required (Art. 6(1)(a))
- Is the marketing about your own similar products/services? → No: consent required
- Was an opt-out offered at the point of collection? → No: consent required (and remediate)
- Is an opt-out included in every message? → No: add it (legally required regardless)
- All conditions met → Soft opt-in applies; legal basis: Art. 6(1)(f) GDPR + national implementing provision
What to Disclose in the Notice
- State that existing customers may receive marketing about similar products/services
- Cite the specific national provision (e.g., § 7(3) UWG, Art. L.34-5 CPCE)
- Explain the right to opt out at any time
- Distinguish from consent-based marketing (newsletters, third-party offers)
Children's Data — Applicability Decision Logic
Decision Tree for Determining Applicability
Step 1: Is the service directed at children?
- Marketing, content, or design targets minors → children's data rules apply
- Examples: educational platforms, gaming, toy stores, children's apps
Step 2: Is the service likely to be accessed by children?
- General audience services accessible without age gate → consider children's rules
- Social media, entertainment, free online games → likely accessed by minors
Step 3: Is the service exclusively B2B or adult-only?
- Corporate SaaS, professional services, age-restricted products (alcohol, gambling) → children's rules generally not applicable
- Document the rationale for excluding children's data provisions
Multi-jurisdiction rule: When the service operates across multiple Member States, apply the lowest applicable age threshold across all target markets. See the age threshold table above.
Intake trigger conditions — Ask about children's data when:
- The service is publicly accessible (no B2B gating)
- The target audience includes families or education
- The platform allows user-generated content without age verification
- Products or services are marketed to or commonly used by minors
Mandatory Disclosures Checklist
Art. 13 (Data Collected from Data Subject)
Art. 14 (Data NOT Collected from Data Subject)
All of the above, PLUS:
1---2name: eu-wide-gdpr-reference3description: Processing special categories requires both an Art. 6 legal basis and an Art. 9(2) exception (dual legal basis requirement).4---5# EU-Wide GDPR Reference67## Table of Contents81. [Legal Bases (Art. 6)](#legal-bases)92. [Special Category Data (Art. 9)](#special-category-data-art-9)103. [Data Subject Rights (Art. 15–22)](#data-subject-rights)114. [International Transfers (Chapter V)](#international-transfers)125. [AI & Automated Decision-Making](#ai--automated-decision-making)136. [Children's Data (Art. 8)](#childrens-data)147. [Soft Opt-In for Direct Marketing](#soft-opt-in-for-direct-marketing)158. [Art. 13/14 Mandatory Disclosures Checklist](#mandatory-disclosures-checklist)1617---1819## Legal Bases2021### Art. 6(1)(a) — Consent22- Free, specific, informed, unambiguous23- Withdrawable at any time; withdrawal must be as easy as giving consent24- Burden of proof on controller (Art. 7(1))25- No pre-ticked boxes (Planet49, C-673/17)26- **Use for**: Newsletter, marketing cookies, ad tracking, sharing with partners, non-essential profiling2728### Art. 6(1)(b) — Contract Performance29- Processing necessary for contract execution or pre-contractual steps at data subject's request30- Cannot be stretched to cover all processing a controller wants to do (EDPB Guidelines 2/2019)31- **Use for**: Order fulfilment, account creation/management, payment processing, customer support related to the contract3233### Art. 6(1)(c) — Legal Obligation34- Processing necessary for compliance with a legal obligation to which the controller is subject35- Must identify the specific legal provision36- **Use for**: Tax retention, AML/KYC, employment law obligations, regulatory reporting3738### Art. 6(1)(d) — Vital Interests39- Rarely applicable; only when data subject physically unable to consent40- **Use for**: Medical emergencies4142### Art. 6(1)(e) — Public Interest / Official Authority43- Requires basis in Union or Member State law44- **Use for**: Public sector tasks, official authority exercise4546### Art. 6(1)(f) — Legitimate Interest47- Requires documented balancing test (LIA): legitimate interest → necessity → balancing against rights48- Data subject has absolute right to object for direct marketing (Art. 21(2))49- **Use for**: Fraud prevention, network security, anonymized analytics, B2B prospecting, intra-group admin5051## Special Category Data (Art. 9)5253### What Qualifies as Special Category Data54Art. 9(1) GDPR prohibits processing of these 8 categories unless an Art. 9(2) exception applies:5556| Category | Examples |57|---|---|58| **Racial or ethnic origin** | Nationality, ethnicity, photo (if revealing) |59| **Political opinions** | Party membership, political donations |60| **Religious or philosophical beliefs** | Church membership (church tax in DE), dietary requirements revealing beliefs |61| **Trade union membership** | Union dues deducted from payroll |62| **Genetic data** | DNA tests, genetic predisposition data |63| **Biometric data** (for identification) | Fingerprint access, facial recognition, iris scan |64| **Health data** | Sick certificates, disability status, occupational health, insurance data |65| **Sex life or sexual orientation** | Marital status (in some contexts), partner benefits |6667### Art. 9(2) Exceptions (Legal Bases for Special Categories)6869Processing special categories requires **both** an Art. 6 legal basis **and** an Art. 9(2) exception (dual legal basis requirement).7071| Exception | Art. 9(2) | Typical Use Cases |72|---|---|---|73| **Explicit consent** | (a) | Voluntary health surveys, diversity monitoring (where not legally required) |74| **Employment & social security law** | (b) | Payroll (church tax, union dues, disability), sick leave, occupational health |75| **Vital interests** | (c) | Medical emergency when data subject incapacitated |76| **Not-for-profit bodies** | (d) | Processing by churches, unions, political parties for their members |77| **Manifestly public** | (e) | Data subject has clearly made the data public (e.g., public social media profile) |78| **Legal claims** | (f) | Establishing, exercising, or defending legal claims |79| **Substantial public interest** | (g) | Anti-discrimination monitoring, statutory equality duties |80| **Preventive/occupational medicine** | (h) | Pre-employment medicals, occupational health assessments, fitness-for-duty |81| **Public health** | (i) | Pandemic response, pharmacovigilance |82| **Archiving / research / statistics** | (j) | Scientific research with appropriate safeguards |8384### Dual Legal Basis Requirement85Every processing of special category data must cite **two** legal bases:861. **Art. 6(1)** basis — e.g., Art. 6(1)(b) contract, Art. 6(1)(c) legal obligation, Art. 6(1)(f) legitimate interest872. **Art. 9(2)** exception — e.g., Art. 9(2)(b) employment law, Art. 9(2)(a) explicit consent8889Example: Processing church tax data for an employee:90- Art. 6(1)(c) GDPR (legal obligation — tax law) **+** Art. 9(2)(b) GDPR (employment/social security law)9192### What to Disclose in the Privacy Notice93For each special category processed, the notice must state:94- The specific category of sensitive data processed95- The purpose of processing96- The Art. 6 legal basis **and** the Art. 9(2) exception97- Any additional safeguards applied (e.g., restricted access, pseudonymization, DPO oversight)98- Specific legal provisions authorizing the processing (e.g., § 26(3) BDSG, Art. 9(2)(b) + national employment law)99100### Intake Questions When Special Categories Are Detected101If any Art. 9 data is identified during intake, ask:1021. Which specific categories of sensitive data are processed?1032. What is the purpose for each sensitive data category?1043. Which Art. 9(2) exception applies to each? Is there a Member State law authorizing it?1054. Is explicit consent obtained? If so, how is it documented and how can it be withdrawn?1065. What additional safeguards are in place (access restrictions, encryption, DPO involvement)?1076. Is a DPIA required or already conducted for this processing? (Art. 35(3)(b) — large-scale special category processing requires DPIA)108109## Data Subject Rights110111| Right | Article | Conditions / Limits | Response Time |112|-------|---------|---------------------|---------------|113| **Access** | Art. 15 | Free first copy; may charge for additional | 1 month (extendable +2) |114| **Rectification** | Art. 16 | Inaccurate or incomplete data | 1 month |115| **Erasure ("Right to be Forgotten")** | Art. 17 | When consent withdrawn, no longer necessary, unlawful, etc. Exceptions: legal obligation, public interest, legal claims | 1 month |116| **Restriction** | Art. 18 | Accuracy contested, unlawful processing, controller no longer needs data but subject needs for claims | 1 month |117| **Data Portability** | Art. 20 | Only for consent/contract-based automated processing | 1 month |118| **Object** | Art. 21 | Legitimate interest: must demonstrate compelling grounds. Direct marketing: absolute right | 1 month |119| **Not be subject to automated decisions** | Art. 22 | Decisions producing legal/significant effects. Exceptions: contract, law, explicit consent | 1 month |120| **Withdraw Consent** | Art. 7(3) | At any time; as easy as giving consent | Without undue delay |121122### Exercise Procedure (to include in notice)123- Dedicated email address (e.g., privacy@..., datenschutz@..., dpo@...)124- Postal address125- Identity verification method (proportionate — no excessive ID requests)126- Response timeline: 1 month, extendable by 2 months for complex/numerous requests127- Free of charge (except manifestly unfounded/excessive)128129## International Transfers130131### Transfer Mechanisms (Chapter V)132| Mechanism | Article | When to Use |133|-----------|---------|-------------|134| **Adequacy Decision** | Art. 45 | Country on EU Commission's adequate list |135| **Standard Contractual Clauses (SCCs)** | Art. 46(2)(c) | Most common mechanism for US/non-adequate transfers |136| **Binding Corporate Rules (BCRs)** | Art. 47 | Intra-group transfers |137| **Derogations** | Art. 49 | Explicit consent, contract necessity, public interest (narrow) |138139### Adequacy Decisions (current as of 2025)140Andorra, Argentina, Canada (PIPEDA), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, UK, Uruguay, **USA (EU-U.S. Data Privacy Framework — DPF)**.141142### US Transfers — Specifics143- EU-U.S. DPF (Adequacy Decision July 2023) — verify the recipient is on the DPF list144- If not DPF-certified: SCCs + Transfer Impact Assessment (TIA) required145- Mention Schrems II implications if relevant146- Common processors requiring US transfer disclosure: Google, Meta, AWS (if US region), Microsoft, Salesforce, Mailchimp/Intuit, HubSpot, Stripe147148### What to Disclose in the Notice149For each transfer:1501. Country/countries of destination1512. Transfer mechanism used1523. Where to obtain a copy/info about safeguards (link or on-request)153154## AI & Automated Decision-Making155156### GDPR Art. 22 Requirements157If the service uses AI/ML for decisions that produce legal or similarly significant effects:158- **Right not to be subject** to solely automated decisions159- Must disclose: (1) existence of automated decision-making, (2) meaningful information about the logic involved, (3) significance and envisaged consequences160- Exceptions: contract, law, explicit consent — but even then, safeguards required (human intervention, express point of view, contest)161162### EU AI Act Interplay (Regulation 2024/1689)163Applicable from August 2025 onwards (phased):164165**Transparency obligations for AI systems (Art. 50 AI Act)**:166- AI-generated content must be disclosed (chatbots, deepfakes, synthetic text)167- Users must be informed they are interacting with an AI system168- High-risk AI systems: extensive documentation and transparency requirements169170**Privacy notice should address**:171- Whether AI/ML is used in processing personal data172- Purpose of AI processing (recommendations, scoring, content generation, moderation)173- Whether decisions are purely automated or human-in-the-loop174- Meaningful explanation of logic (not source code, but understandable impact description)175- How to contest AI-driven decisions176- Data used for training (if applicable to the user's data)177178### Standard AI Disclosure Wording (adapt per jurisdiction language)179```180[AI / AUTOMATED PROCESSING]181182We use automated processing technologies, including [machine learning / artificial intelligence], for the following purposes:183- [Purpose 1, e.g., personalized content recommendations]184- [Purpose 2, e.g., fraud detection]185186[If Art. 22 applies:]187These processes may produce decisions that significantly affect you. You have the right to:188- Obtain human intervention189- Express your point of view190- Contest the decision191192To exercise these rights, contact [DPO/privacy contact].193194[If AI Act applies:]195In accordance with the EU AI Act (Regulation 2024/1689), we inform you that [specific AI transparency disclosure].196```197198## Children's Data199200### Age Thresholds by Member State (Art. 8 GDPR)201202| Country | Age | Source |203|---------|-----|--------|204| Austria | 14 | § 4(4) DSG |205| Belgium | 13 | Art. 7 loi du 30 juillet 2018 |206| Croatia | 16 | default |207| Czech Republic | 15 | § 7 Zákon č. 110/2019 |208| Denmark | 13 | § 6 Databeskyttelsesloven |209| Estonia | 13 | § 8 IKS |210| Finland | 13 | § 5 Tietosuojalaki |211| France | 15 | Art. 45 LIL |212| Germany | 16 | § 2 Nr. 17 TDDDG |213| Greece | 15 | Art. 21 Law 4624/2019 |214| Hungary | 16 | default |215| Ireland | 16 | Sec. 31 Data Protection Act 2018 |216| Italy | 14 | Art. 2-quinquies D.lgs. 196/2003 |217| Latvia | 13 | Art. 9 FPDP |218| Lithuania | 14 | Art. 8 ADTAĮ |219| Luxembourg | 16 | default |220| Malta | 13 | Reg. 5 SL 586.08 |221| Netherlands | 16 | default |222| Poland | 16 | default |223| Portugal | 13 | Art. 16 Lei n.º 58/2019 |224| Romania | 16 | default |225| Slovakia | 16 | default |226| Slovenia | 16 | default |227| Spain | 14 | Art. 7 LOPDGDD |228| Sweden | 13 | 2 § Kompletterande dataskyddslag |229230If the service may be used by children, include:231- Age-appropriate language in the notice232- Description of parental consent mechanism233- How parental consent is verified234- What data is collected from minors235- Whether profiles are created for minors236237## Soft Opt-In for Direct Marketing238239### Common 3-Condition Test240Most EU/EEA jurisdictions allow email marketing to existing customers without prior consent ("soft opt-in") if **all three** conditions are met:2411. **Existing customer relationship**: The contact details were obtained in the context of a sale or service2422. **Similar products/services**: The marketing concerns the controller's own similar products or services2433. **Easy opt-out**: The customer was given a clear opportunity to object at the time of collection and in every subsequent message244245### Jurisdiction Comparison246247| Jurisdiction | Legal Provision | Key Differences |248|---|---|---|249| **Germany** | § 7(3) UWG | Strict: own similar products only; opt-out at collection + every email; no third-party marketing |250| **France** | Art. L.34-5 CPCE | Similar to DE; CNIL enforces strictly; B2B prospecting has separate, more permissive regime |251| **Italy** | Art. 130(4) D.lgs. 196/2003 | Soft opt-in recognized; Garante recommends clear disclosure at collection point |252| **UK** | Regulation 22 PECR | Similar to EU; ICO guidance: "similar products" interpreted reasonably |253| **Spain** | Art. 21 LSSI | Soft opt-in available; must clearly identify as commercial communication |254255### 5-Step Decision Tree2561. **Was data collected during a sale/service?** → No: consent required (Art. 6(1)(a))2572. **Is the marketing about your own similar products/services?** → No: consent required2583. **Was an opt-out offered at the point of collection?** → No: consent required (and remediate)2594. **Is an opt-out included in every message?** → No: add it (legally required regardless)2605. **All conditions met** → Soft opt-in applies; legal basis: Art. 6(1)(f) GDPR + national implementing provision261262### What to Disclose in the Notice263- State that existing customers may receive marketing about similar products/services264- Cite the specific national provision (e.g., § 7(3) UWG, Art. L.34-5 CPCE)265- Explain the right to opt out at any time266- Distinguish from consent-based marketing (newsletters, third-party offers)267268## Children's Data — Applicability Decision Logic269270### Decision Tree for Determining Applicability271272**Step 1: Is the service directed at children?**273- Marketing, content, or design targets minors → children's data rules apply274- Examples: educational platforms, gaming, toy stores, children's apps275276**Step 2: Is the service likely to be accessed by children?**277- General audience services accessible without age gate → consider children's rules278- Social media, entertainment, free online games → likely accessed by minors279280**Step 3: Is the service exclusively B2B or adult-only?**281- Corporate SaaS, professional services, age-restricted products (alcohol, gambling) → children's rules generally not applicable282- Document the rationale for excluding children's data provisions283284**Multi-jurisdiction rule**: When the service operates across multiple Member States, apply the **lowest applicable age threshold** across all target markets. See the age threshold table above.285286**Intake trigger conditions** — Ask about children's data when:287- The service is publicly accessible (no B2B gating)288- The target audience includes families or education289- The platform allows user-generated content without age verification290- Products or services are marketed to or commonly used by minors291292## Mandatory Disclosures Checklist293294### Art. 13 (Data Collected from Data Subject)295- [ ] Controller identity and contact details296- [ ] DPO contact details (if appointed)297- [ ] Processing purposes + legal basis for each298- [ ] Legitimate interests pursued (if Art. 6(1)(f))299- [ ] Recipients or categories of recipients300- [ ] Transfer to third countries + safeguards301- [ ] Retention period or criteria to determine it302- [ ] Right to: access, rectification, erasure, restriction, portability, object303- [ ] Right to withdraw consent (if Art. 6(1)(a))304- [ ] Right to lodge complaint with supervisory authority305- [ ] Whether provision of data is statutory/contractual requirement + consequences of non-provision306- [ ] Existence of automated decision-making including profiling (Art. 22) + meaningful info about logic + significance + envisaged consequences307- [ ] If special categories (Art. 9): specific Art. 9(2) exception identified, dual legal basis disclosed (Art. 6 + Art. 9(2)), additional safeguards mentioned308- [ ] If data to be further processed for another purpose: info about that purpose before further processing309310### Art. 14 (Data NOT Collected from Data Subject)311All of the above, PLUS:312- [ ] Categories of personal data concerned313- [ ] Source of the data (and whether publicly accessible)314- [ ] Must be provided within 1 month / at first communication / at first disclosure to recipient