GDPR
EU General Data Protection Regulation — privacy, automated decisions, and the tension with immutable records
Regulation (EU) 2016/679 governs personal-data processing in the EU/EEA; for this corpus it is a key external floor for contestability, transparency, and erasure — not a substitute for epistemic ethics.
The General Data Protection Regulation (GDPR) is EU law on processing personal data. This site is not legal advice; this entry records how GDPR intersects with the judgment-infrastructure model — especially contestability, automated decision-making, and immutability of facts.
Official text: EUR-Lex — Regulation (EU) 2016/679
Why GDPR matters here
GDPR is one of the few regulations that names rights aligned with this corpus:
- Transparency and information — data subjects should know what is decided and on what basis (supports honest tier and evidence at bind).
- Automated decision-making — Article 22 sets floors for significant purely automated decisions — related to, but not identical with, our contestability principle.
- Erasure and rectification — Articles 16–17 tension with naive append-only design — see GDPR, immutability, and erasure.
Regulatory minimum bars do not exhaust moral requirements. Article 20 Mechanism 7 applies contestability broadly; GDPR applies where personal data and EU law reach.
Corpus stance
Context A2 — we cite GDPR as external constraint and partial alignment, not as epistemic canon. The published regulation on EUR-Lex is external T1 source text; our operational mapping here is site stance, not legal advice. Implementation requires qualified legal review in your jurisdiction.