What Keel scores in GDPR, and what it does not
GDPR has 99 Articles. Keel scores 110 requirements. Neither number is wrong, and the distance between them is a set of deliberate calls. This page is all of them, so you can disagree with a specific line instead of with a total.
The two rules
- The leaf is the numbered paragraph, not the Article. Article 30(1) is the controller’s record of processing and Article 30(2) is the processor’s: different duties, different parties, separately enforceable. Counted as one requirement, one of them silently has no owner. Where an Article has no numbered paragraphs, the Article itself is the leaf.
- A provision is scored only if it binds a controller or a processor. Provisions addressed to Member States, the Commission, supervisory authorities, the Board, courts, and accreditation, certification or monitoring bodies are cited and left unscored — along with pure exemptions that impose no residual action, permissions contingent on circumstances a controller may never meet, and evidential clauses that merely say adherence to a code or certification may help demonstrate compliance.
Excluded is not the same as inapplicable. This is not a claim that the excluded provisions do not apply. A controller is bound by the whole Regulation. Scoring “the Commission shall publish a list of adequate third countries” would load every workspace’s readiness denominator with an item it cannot implement, deflating every score for no compliance benefit. Keel scores what is implementable, and says which provisions it left out.
Where the 110 sit
| Chapter | Articles | Covers | Scored |
|---|---|---|---|
| II | Arts 5–11 | Principles | 15 |
| III | Arts 12–22 | Rights of the data subject | 36 |
| IV | Arts 24–39 | Controller and processor | 49 |
| V | Arts 44–49 | Transfers to third countries | 9 |
| IX | Art 89(1) | Research and archiving safeguards | 1 |
| Total | 110 | ||
The register
Whole chapters 6
Six chapters place no duty on a controller or processor at all.
-
Ch. I — Arts 1–4Procedural, transitional or finalSubject matter, scope and definitionsSets out what the Regulation covers and defines its terms. Imposes no duty on anyone.
-
Ch. VI — Arts 51–59Binds someone other than a controller or processorSupervisory authoritiesStatus, competence, tasks and powers of the regulator. Duties on the supervisory authority, not on a controller.
-
Ch. VII — Arts 60–76Binds someone other than a controller or processorCooperation, consistency and the BoardDuties on regulators and on the European Data Protection Board.
-
Ch. VIII — Arts 77–84Procedural, transitional or finalRemedies, liability and penaltiesConsequences of infringement, not requirements to implement.
-
Ch. X — Arts 92–93Binds someone other than a controller or processorDelegated and implementing actsCommission procedure.
-
Ch. XI — Arts 94–99Procedural, transitional or finalFinal provisionsRepeal, relationship to other instruments, review and entry into force. Transitional and final.
Whole articles, inside otherwise in-scope chapters 6
These sit among provisions that are scored, which is why each one is named rather than summarised.
-
Art 23A mandate or option for Member State lawRestrictionsRestrictions enacted by Union or Member State legislative measure.
-
Arts 40, 41Permits rather than requiresCodes of conduct and their monitoringElective. The duties they create bind associations, accredited monitoring bodies and supervisory authorities; a controller’s involvement is voluntary adherence, recorded in the Regulation only as evidence — at 24(3), 28(5), 32(3) and 35(8), themselves excluded as evidential.
-
Arts 42, 43Permits rather than requiresCertification, seals and certification bodies42(3) states the mechanism is voluntary. 42(6)’s duty to give the certification body information arises only once a controller elects it.
-
Art 45Binds someone other than a controller or processorTransfers on the basis of an adequacy decisionCommission adequacy decisions. A controller relies on one; it cannot implement one.
-
Art 50Binds someone other than a controller or processorInternational cooperationCooperation by the Commission and supervisory authorities.
-
Arts 85–88, 90, 91A mandate or option for Member State lawSpecific processing situationsFree expression, public access to documents, national identification numbers, the employment context, obligations of secrecy, and pre-existing church rules. Each is a mandate or option for Member State law rather than a controller duty. Art 89(1) is the exception and IS scored: it imposes safeguards directly on whoever processes for research or archiving.
Individual paragraphs, inside in-scope articles 25
The finest-grained calls, and the ones most worth disagreeing with.
-
6(2), 6(3)A mandate or option for Member State lawMember State specification of the legal basisMember State law may specify, and must lay down, the legal basis.
-
8(3)Removes a duty rather than creating oneNational contract law unaffectedSavings clause for national contract law.
-
9(4)A mandate or option for Member State lawFurther conditions for special-category dataMember States may add conditions for genetic, biometric or health data.
-
11(1)Removes a duty rather than creating oneNo duty to keep identifying dataA relief from obtaining identifying data, not a duty.
-
12(6)Permits rather than requiresConfirming the requester’s identityPermissive — the controller *may* request identity confirmation.
-
12(7)Permits rather than requiresStandardised iconsPermissive — information *may* be combined with standard icons.
-
12(8)Binds someone other than a controller or processorDelegated acts on iconsCommission delegated acts.
-
13(4)Removes a duty rather than creating oneInformation already heldExemption where the data subject already has the information.
-
17(3)Removes a duty rather than creating oneExceptions to erasureExemptions to erasure — freedom of expression, a legal obligation, legal claims and others.
-
20(3)Removes a duty rather than creating onePortability and erasurePortability without prejudice to erasure, plus the public-task carve-out.
-
22(2)Removes a duty rather than creating oneWhen the automated-decision prohibition does not applyCases in which the prohibition does not apply.
-
24(3), 25(3)Evidential — says how compliance may be shownCodes and certification as evidenceEvidential — adherence may help demonstrate compliance.
-
27(2), 27(5)Removes a duty rather than creating oneRepresentative — exemption and savings27(2) exempts from the representative duty; 27(5) is a savings clause.
-
28(5)–(8), 28(10)Permits rather than requiresProcessor contracting mechanics28(5) evidential; 28(6) permissive use of standard contractual clauses; 28(7) Commission SCCs; 28(8) supervisory-authority SCCs; 28(10) the consequence of a processor determining purposes — it becomes a controller.
-
30(5)Removes a duty rather than creating oneSmall-organisation exemptionExemption for organisations under 250 people.
-
32(3)Evidential — says how compliance may be shownSecurity and certificationEvidential — adherence to an approved code or certification may be used to demonstrate that security measures are appropriate. It does not itself require a measure.
-
34(3), 34(4)Removes a duty rather than creating oneCommunicating a breach to individuals34(3) sets conditions removing the duty to communicate; 34(4) is the authority’s power to require communication anyway.
-
35(4)(5)(6), 35(8), 35(10)Binds someone other than a controller or processorDPIA lists, consistency and exemptionsSupervisory-authority DPIA lists and the consistency mechanism; 35(8) evidential; 35(10) exemption where a legislative DPIA already exists.
-
36(2), 36(4), 36(5)Binds someone other than a controller or processorPrior consultation mechanics36(2) the authority’s written advice and its deadlines; 36(4) Member State consultation on draft legislation; 36(5) Member State law may require prior authorisation.
-
37(2)(3)(4)(6)Permits rather than requiresHow a DPO may be designatedPermissive arrangements — group-wide, shared across public bodies, voluntary designation, and employed versus contracted.
-
38(4)Binds someone other than a controller or processorData subjects may contact the DPOAddressed to data subjects. The controller-facing counterpart, publishing the contact details, is scored at 37(7).
-
46(4), 46(5)Procedural, transitional or finalSafeguards — consistency and transition46(4) the consistency mechanism; 46(5) transitional validity of pre-GDPR authorisations.
-
47(1), 47(3)Binds someone other than a controller or processorBinding corporate rules — approval47(1) the authority approves BCRs; 47(3) Commission implementing acts.
-
49(3)(4)(5)A mandate or option for Member State lawDerogations — carve-outsThe public-authority carve-out, and the Union or Member State law that recognises the public interest or limits transfers.
-
89(2)(3)(4)A mandate or option for Member State lawResearch and archiving derogationsMember State derogations from data-subject rights for research and archiving.
Where the inventory came from
Think one of these belongs in scope? That is the point of publishing it — tell us which line. The full framework is at GDPR · 2016/679.