Ramparts · Regulatory Intelligence
Data Protection & Privacy, Jurisdiction by Jurisdiction
GDPRI tracks how data protection and privacy law is enforced, interpreted, and reformed across jurisdictions — regulator posture, lawful-processing rules, data subject rights, cross-border transfer regimes, sectoral watch, and the fast-moving edge of algorithmic and biometric governance. Built for counsel, DPOs, and engineering teams who need a working picture of a jurisdiction's regime, not a restated version of the statute.
What's in scope
- 10 parent modules tracked per jurisdiction
- 31 jurisdictions in scope
- 7 jurisdictions on the free tier
What is GDPRI?
GDPRI gives counsel, DPOs, and engineering teams a working picture of data protection and privacy law in 31 jurisdictions — search by module or by right, see regulator posture and enforcement trends at a glance, and export the underlying citations instead of re-deriving them from primary sources yourself. Seven jurisdictions are available now on the free tier.
Coverage is organised into GDPRI's own ten-module grammar — regulator & framework, lawful processing & special data, data subject rights, controller/processor duties, cross-border & adequacy, sectoral watch, adtech & commercial privacy, algorithmic/biometric/surveillance governance, children & vulnerable groups, and enforcement & redress — applied consistently across every tracked jurisdiction. GDPRI began life as an internal data producer feeding other Ramparts monitors; see the methodology page for that history and the honest account of what exists today versus what is still being built.
Explore
This site is an early-stage public front end for an internal regulatory intelligence pipeline. Content is AI-assisted and cited to public primary and secondary sources; it is general information, not legal advice, and has not been independently verified for every claim. See methodology for scope and limitations.