HomeKnowledge Hub › Publications

Knowledge Hub

Key Publications & Reports

Specific, authoritative privacy and data-protection publications worth knowing exist — regulator and expert-body guidance, opinions and recommendations, and recognised research. Grouped by domain. Know one we should add or retire? Tell us.

What's listed: official guidance, opinions and recommendations from regulators and recognised bodies, plus research with a disclosed methodology. What isn't: legislation (see Regulators), standards and frameworks (see Standards & Frameworks), and vendor marketing. Time-sensitive reports are kept for about two years; older editions are retired.

EU/UK GDPR Core Guidance (20)
IssuerTitleReferenceYear
EDPBGuidelines on personal data breach notificationGuidelines 01/20212021
EDPBGuidelines on the concepts of controller and processorGuidelines 07/20202021
EDPBGuidelines on transparency under Regulation 2016/679Guidelines 2/20182018
EDPBGuidelines on the right to data portabilityGuidelines 5/20192019
EDPBGuidelines on the territorial scope of the GDPRGuidelines 3/20182019
EDPBGuidelines on data protection by design and by defaultGuidelines 4/20192020
EDPBGuidelines on the right to erasureGuidelines 5/20182019
EDPBGuidelines on processing of personal data through video devicesGuidelines 3/20192020
EDPBGuidelines on purpose limitationWP2032013
EDPBGuidelines on Data Protection OfficersWP243 rev.012017
EDPBGuidelines on consent under Regulation 2016/679WP259 rev.012018
EDPBOpinion on the notion of legitimate interestsWP2172014
EDPBGuidelines on the right of accessGuidelines 01/20222023
EDPBGuidelines on the interplay between Article 3 and Chapter VGuidelines 05/20212022
ICOGuide to the UK GDPR2021
ICOAccountability and Governance guidance2020
ICOData Protection Impact Assessments guidance2021
ICORecords of Processing Activities guidance2021
EDPBGuidelines on codes of conduct as tools for transfersGuidelines 04/20212022
EDPBAnnual Report 2023 (published 2024)2024
International Data Transfers (12)
IssuerTitleReferenceYear
EDPBRecommendations on measures that supplement transfer toolsRecommendations 01/20202021
ICOInternational data transfer agreement (IDTA)2022
ICOInternational data transfer addendum to EU SCCs2022
ICOTransfer Risk Assessment guidance2022
EDPBRecommendations on the European Essential GuaranteesRecommendations 02/20202020
EDPBOpinion on the UK adequacy decisionsOpinion 14/20212021
EDPBAdequacy referentialWP254 rev.012018
EDPBGuidelines on binding corporate rules for processorsGuidelines 07/20222022
EDPBGuidelines on binding corporate rules for controllersGuidelines 05/20222022
OECDDeclaration on Government Access to Personal Data held by Private Sector Entities2022
EDPBInformation note on data transfers to the US post-Schrems II2020
EDPBGuidelines on the interplay between Article 3 and Chapter V GDPRGuidelines 05/20212022
Data Breach & Security (10)
IssuerTitleReferenceYear
EDPBGuidelines on personal data breach notification under GDPRGuidelines 01/20212021
EDPBGuidelines on personal data breach notificationWP250 rev.012018
ENISAThreat Landscape 20242024
ENISAData pseudonymisation: Advanced implementation guide2022
ENISATechnical guidelines for the implementation of minimum security measures for DSPs2017
NISTGuide to Protecting the Confidentiality of PIISP 800-1222010
ICOGuidance on security of personal data2022
UK NCSCCyber Security Toolkit for Boards2023
IBM / Ponemon InstituteCost of a Data Breach Report 20242024
VerizonData Breach Investigations Report 2024DBIR 20242024
AI & Automated Decision-Making (10)
IssuerTitleReferenceYear
EDPBGuidelines on automated individual decision-making and profilingGuidelines 5/20172018
EDPBGuidelines on Artificial Intelligence and data protectionGuidelines 02/20242024
ICOGuidance on AI and data protection2023
ICO / Alan Turing InstituteExplaining decisions made with AI2020
OECDRecommendation of the Council on Artificial IntelligenceOECD/LEGAL/04492019
ICOData protection and AI auditing framework2022
Ada Lovelace InstituteAlgorithmic Impact Assessment: A Case Study in Healthcare2022
Ada Lovelace InstituteExamining the Black Box: Tools for Assessing Algorithmic Systems2020
FPFUnderstanding Automated Decisions2019
ENISAArtificial Intelligence Cybersecurity Challenges2021
Children's Privacy (9)
IssuerTitleReferenceYear
ICOAge Appropriate Design Code (Children's Code)2021
ICOChildren's code guidance and resources2022
EDPBOpinion on age verification and parental consentWP1812011
UNICEFChildren's Online Privacy and Freedom of Expression2018
FPFStudent Privacy Compass resources2023
5Rights FoundationRisky Business: Children and Online Privacy2021
ICOChildren's privacy — regulatory approach and strategy2022
OFCOMChildren's safety online technology guide2023
EDPBOpinion on age assuranceOpinion 08/20242024
Health & Biometric Data (10)
IssuerTitleReferenceYear
EDPBGuidelines on processing of health data for researchGuidelines 03/20192019
EDPBOpinion on the European Health Data SpaceOpinion 03/20212021
EDPBGuidelines on the use of location data in the context of COVID-19Guidelines 04/20202020
EDPBGuidelines on processing of genetic dataGuidelines 05/20232023
EDPBGuidelines on scientific research under GDPRGuidelines 1/20262026
ICOSpecial category data guidance2021
ICOGuidance on processing health data2022
ENISAPseudonymisation techniques and best practices2019
WHOEthics and Governance of Artificial Intelligence for Health2021
ENISAData protection engineering — from theory to practice2022
Consent & Legitimate Interests (10)
IssuerTitleReferenceYear
EDPBGuidelines on consent under Regulation 2016/679Guidelines 05/20202020
EDPBGuidelines on consent under Regulation 2016/679WP259 rev.012018
EDPBOpinion on legitimate interest of the data controllerWP2172014
EDPBGuidelines on the interplay of PSD2 and GDPRGuidelines 06/20202020
ICOLawful basis for processing guidance2022
ICOConsent guidance2022
ICOLegitimate interests guidance2023
EDPBGuidelines on data protection by design and by defaultGuidelines 04/20192019
EDPBOpinion on the notion of personal dataWP1362007
EDPBGuidelines on automated individual decision-making and profilingWP251 rev.012018
Data Subject Rights (12)
IssuerTitleReferenceYear
EDPBGuidelines on the right of accessGuidelines 01/20222023
EDPBGuidelines on restrictions under Article 23 of the GDPRGuidelines 10/20202021
EDPBGuidelines on the right to erasureGuidelines 05/20182019
EDPBGuidelines on the right to data portabilityGuidelines 05/20192019
ICORight of access (subject access request) guidance2022
ICORight to erasure guidance2021
ICORight to data portability guidance2021
ICORight to object guidance2021
ICOExemptions guidance — data subject access requests2021
EDPBGuidelines on the right to data portabilityWP242 rev.012017
EDPBGuidelines on the right to be forgotten in search enginesGuidelines 5/20192019
EDPBInterplay of ePrivacy and GDPR concerning individual rights2021
Privacy by Design & Engineering (7)
IssuerTitleReferenceYear
EDPBGuidelines on data protection by design and by defaultGuidelines 4/20192020
ENISAData protection engineering — from theory to practice2022
ENISAPseudonymisation techniques and best practices2019
ENISAPrivacy and data protection in mobile applications2021
ICOPrivacy by design and default guidance2021
ICOGuidance on Data Protection Impact Assessments (DPIAs)2021
FPFPrivacy by Design: Essential Building Blocks2022
International Frameworks & Instruments (7)
IssuerTitleReferenceYear
OECDGuidelines Governing the Protection of Privacy and Transborder Flows of Personal Data2013
UNResolution on the right to privacy in the digital ageA/RES/68/1672013
OECDRecommendation on Health Data GovernanceOECD/LEGAL/04332017
CoE / FRA / EDPSHandbook on European Data Protection Law2018
OECDDeclaration on Government Access to Personal Data2022
G7Data Free Flow with Trust (DFFT) — Osaka Track2019
UNESCORecommendation on the Ethics of Artificial Intelligence2021
Research, Statistics & Archiving (8)
IssuerTitleReferenceYear
EDPBGuidelines on processing of personal data for scientific researchGuidelines 03/20192019
EDPBGuidelines on scientific research under GDPR (updated)Guidelines 1/20262026
ICOResearch, public task and official authority guidance2021
ICOAnonymisation, pseudonymisation and privacy enhancing technologies guidance2022
ONSData Access and Research — UK statistics authority guidance2022
UKRIPolicy on open access and research data2021
EDPBOpinion on the concept of personal dataWP1362007
ENISARecommendations on shaping technology according to GDPR provisions2018
Marketing, Tracking & Cookies (13)
IssuerTitleReferenceYear
EDPBGuidelines on the use of location data and contact tracing toolsGuidelines 04/20202020
EDPBGuidelines on consent for online analytics and trackingGuidelines 05/20202020
EDPBOpinion on cookie consent exemptionWP1942012
ICOGuidance on cookies and similar technologies2020
ICODirect marketing guidance2021
ICOGuide to Privacy and Electronic Communications Regulations (PECR)2021
ICOLive chat and online messaging guidance2022
EDPBGuidelines on the use of dark patterns in social mediaGuidelines 03/20222022
CNILCookie depositing conditions2020
CNILGDPR guides for professionals2022
FPFUnderstanding the Digital Advertising Ecosystem2021
EDPBGuidelines on the use of personal data in the electoral processGuidelines 03/20192019
EDPBOpinion on online behavioural advertisingWP1882010
Benchmarks & Profession Reports (8)
IssuerTitleReferenceYear
IAPPPrivacy Tech Vendor Report 20242024
IAPPOrganizational Digital Governance Report 20242024
IAPPAI Governance Profession Report 20242024
IAPP-EYAnnual Privacy Governance Report 20242024
CiscoData Privacy Benchmark Study 20242024
TrustArcGlobal Privacy Benchmarks Report 20242024
ISACAState of Privacy 20242024
OneTrust DataGuidanceGlobal Privacy Laws and Regulations Guide2024

← Back to the Knowledge Hub