← REGULATIONS & COMPLIANCE

GDPR

EU General Data Protection Regulation — privacy, automated decisions, and the tension with immutable records

Regulation reference

Regulation (EU) 2016/679 governs personal-data processing in the EU/EEA; for this corpus it is a key external floor for contestability, transparency, and erasure — not a substitute for epistemic ethics.

EUR-Lex — Regulation (EU) 2016/679 (GDPR)

The General Data Protection Regulation (GDPR) is EU law on processing personal data. This site is not legal advice; this entry records how GDPR intersects with the judgment-infrastructure model — especially contestability, automated decision-making, and immutability of facts.

Official text: EUR-Lex — Regulation (EU) 2016/679

Why GDPR matters here

GDPR is one of the few regulations that names rights aligned with this corpus:

  • Transparency and information — data subjects should know what is decided and on what basis (supports honest tier and evidence at bind).
  • Automated decision-makingArticle 22 sets floors for significant purely automated decisions — related to, but not identical with, our contestability principle.
  • Erasure and rectification — Articles 16–17 tension with naive append-only design — see GDPR, immutability, and erasure.

Regulatory minimum bars do not exhaust moral requirements. Article 20 Mechanism 7 applies contestability broadly; GDPR applies where personal data and EU law reach.

Corpus stance

Context A2 — we cite GDPR as external constraint and partial alignment, not as epistemic canon. The published regulation on EUR-Lex is external T1 source text; our operational mapping here is site stance, not legal advice. Implementation requires qualified legal review in your jurisdiction.

Provisions in this reference

EntryTopic
Article 22Automated decisions with legal or similarly significant effects
Immutability and erasureAppend-only logs vs right to erasure and rectification