What Keel scores in GDPR, and what it does not

GDPR has 99 Articles. Keel scores 110 requirements. Neither number is wrong, and the distance between them is a set of deliberate calls. This page is all of them, so you can disagree with a specific line instead of with a total.

110scored requirements
6chapters excluded
6article groups excluded
25paragraph groups excluded

The two rules

  1. The leaf is the numbered paragraph, not the Article. Article 30(1) is the controller’s record of processing and Article 30(2) is the processor’s: different duties, different parties, separately enforceable. Counted as one requirement, one of them silently has no owner. Where an Article has no numbered paragraphs, the Article itself is the leaf.
  2. A provision is scored only if it binds a controller or a processor. Provisions addressed to Member States, the Commission, supervisory authorities, the Board, courts, and accreditation, certification or monitoring bodies are cited and left unscored — along with pure exemptions that impose no residual action, permissions contingent on circumstances a controller may never meet, and evidential clauses that merely say adherence to a code or certification may help demonstrate compliance.

Excluded is not the same as inapplicable. This is not a claim that the excluded provisions do not apply. A controller is bound by the whole Regulation. Scoring “the Commission shall publish a list of adequate third countries” would load every workspace’s readiness denominator with an item it cannot implement, deflating every score for no compliance benefit. Keel scores what is implementable, and says which provisions it left out.

Where the 110 sit

ChapterArticlesCoversScored
II Arts 5–11 Principles 15
III Arts 12–22 Rights of the data subject 36
IV Arts 24–39 Controller and processor 49
V Arts 44–49 Transfers to third countries 9
IX Art 89(1) Research and archiving safeguards 1
Total 110

The register

Whole chapters 6

Six chapters place no duty on a controller or processor at all.

  • Ch. I — Arts 1–4 Procedural, transitional or final
    Subject matter, scope and definitions

    Sets out what the Regulation covers and defines its terms. Imposes no duty on anyone.

  • Ch. VI — Arts 51–59 Binds someone other than a controller or processor
    Supervisory authorities

    Status, competence, tasks and powers of the regulator. Duties on the supervisory authority, not on a controller.

  • Ch. VII — Arts 60–76 Binds someone other than a controller or processor
    Cooperation, consistency and the Board

    Duties on regulators and on the European Data Protection Board.

  • Ch. VIII — Arts 77–84 Procedural, transitional or final
    Remedies, liability and penalties

    Consequences of infringement, not requirements to implement.

  • Ch. X — Arts 92–93 Binds someone other than a controller or processor
    Delegated and implementing acts

    Commission procedure.

  • Ch. XI — Arts 94–99 Procedural, transitional or final
    Final provisions

    Repeal, relationship to other instruments, review and entry into force. Transitional and final.

Whole articles, inside otherwise in-scope chapters 6

These sit among provisions that are scored, which is why each one is named rather than summarised.

  • Art 23 A mandate or option for Member State law
    Restrictions

    Restrictions enacted by Union or Member State legislative measure.

  • Arts 40, 41 Permits rather than requires
    Codes of conduct and their monitoring

    Elective. The duties they create bind associations, accredited monitoring bodies and supervisory authorities; a controller’s involvement is voluntary adherence, recorded in the Regulation only as evidence — at 24(3), 28(5), 32(3) and 35(8), themselves excluded as evidential.

  • Arts 42, 43 Permits rather than requires
    Certification, seals and certification bodies

    42(3) states the mechanism is voluntary. 42(6)’s duty to give the certification body information arises only once a controller elects it.

  • Art 45 Binds someone other than a controller or processor
    Transfers on the basis of an adequacy decision

    Commission adequacy decisions. A controller relies on one; it cannot implement one.

  • Art 50 Binds someone other than a controller or processor
    International cooperation

    Cooperation by the Commission and supervisory authorities.

  • Arts 85–88, 90, 91 A mandate or option for Member State law
    Specific processing situations

    Free expression, public access to documents, national identification numbers, the employment context, obligations of secrecy, and pre-existing church rules. Each is a mandate or option for Member State law rather than a controller duty. Art 89(1) is the exception and IS scored: it imposes safeguards directly on whoever processes for research or archiving.

Individual paragraphs, inside in-scope articles 25

The finest-grained calls, and the ones most worth disagreeing with.

  • 6(2), 6(3) A mandate or option for Member State law
    Member State specification of the legal basis

    Member State law may specify, and must lay down, the legal basis.

  • 8(3) Removes a duty rather than creating one
    National contract law unaffected

    Savings clause for national contract law.

  • 9(4) A mandate or option for Member State law
    Further conditions for special-category data

    Member States may add conditions for genetic, biometric or health data.

  • 11(1) Removes a duty rather than creating one
    No duty to keep identifying data

    A relief from obtaining identifying data, not a duty.

  • 12(6) Permits rather than requires
    Confirming the requester’s identity

    Permissive — the controller *may* request identity confirmation.

  • 12(7) Permits rather than requires
    Standardised icons

    Permissive — information *may* be combined with standard icons.

  • 12(8) Binds someone other than a controller or processor
    Delegated acts on icons

    Commission delegated acts.

  • 13(4) Removes a duty rather than creating one
    Information already held

    Exemption where the data subject already has the information.

  • 17(3) Removes a duty rather than creating one
    Exceptions to erasure

    Exemptions to erasure — freedom of expression, a legal obligation, legal claims and others.

  • 20(3) Removes a duty rather than creating one
    Portability and erasure

    Portability without prejudice to erasure, plus the public-task carve-out.

  • 22(2) Removes a duty rather than creating one
    When the automated-decision prohibition does not apply

    Cases in which the prohibition does not apply.

  • 24(3), 25(3) Evidential — says how compliance may be shown
    Codes and certification as evidence

    Evidential — adherence may help demonstrate compliance.

  • 27(2), 27(5) Removes a duty rather than creating one
    Representative — exemption and savings

    27(2) exempts from the representative duty; 27(5) is a savings clause.

  • 28(5)–(8), 28(10) Permits rather than requires
    Processor contracting mechanics

    28(5) evidential; 28(6) permissive use of standard contractual clauses; 28(7) Commission SCCs; 28(8) supervisory-authority SCCs; 28(10) the consequence of a processor determining purposes — it becomes a controller.

  • 30(5) Removes a duty rather than creating one
    Small-organisation exemption

    Exemption for organisations under 250 people.

  • 32(3) Evidential — says how compliance may be shown
    Security and certification

    Evidential — adherence to an approved code or certification may be used to demonstrate that security measures are appropriate. It does not itself require a measure.

  • 34(3), 34(4) Removes a duty rather than creating one
    Communicating a breach to individuals

    34(3) sets conditions removing the duty to communicate; 34(4) is the authority’s power to require communication anyway.

  • 35(4)(5)(6), 35(8), 35(10) Binds someone other than a controller or processor
    DPIA lists, consistency and exemptions

    Supervisory-authority DPIA lists and the consistency mechanism; 35(8) evidential; 35(10) exemption where a legislative DPIA already exists.

  • 36(2), 36(4), 36(5) Binds someone other than a controller or processor
    Prior consultation mechanics

    36(2) the authority’s written advice and its deadlines; 36(4) Member State consultation on draft legislation; 36(5) Member State law may require prior authorisation.

  • 37(2)(3)(4)(6) Permits rather than requires
    How a DPO may be designated

    Permissive arrangements — group-wide, shared across public bodies, voluntary designation, and employed versus contracted.

  • 38(4) Binds someone other than a controller or processor
    Data subjects may contact the DPO

    Addressed to data subjects. The controller-facing counterpart, publishing the contact details, is scored at 37(7).

  • 46(4), 46(5) Procedural, transitional or final
    Safeguards — consistency and transition

    46(4) the consistency mechanism; 46(5) transitional validity of pre-GDPR authorisations.

  • 47(1), 47(3) Binds someone other than a controller or processor
    Binding corporate rules — approval

    47(1) the authority approves BCRs; 47(3) Commission implementing acts.

  • 49(3)(4)(5) A mandate or option for Member State law
    Derogations — carve-outs

    The public-authority carve-out, and the Union or Member State law that recognises the public interest or limits transfers.

  • 89(2)(3)(4) A mandate or option for Member State law
    Research and archiving derogations

    Member State derogations from data-subject rights for research and archiving.

Where the inventory came from

Official Journal text, EUR-Lex CELEX 32016R0679, OJ L 119, 4.5.2016, p. 1. The parse reproduces 99 Articles and 372 numbered paragraphs; the per-chapter and per-article leaf counts are pinned by test, because a correct total can hide a paragraph filed under the wrong Article.

Think one of these belongs in scope? That is the point of publishing it — tell us which line. The full framework is at GDPR · 2016/679.