Methodology
How GDPRI Works
Data Protection Regulatory Intelligence began as an internal data producer for other Ramparts monitors; this public front end is a new addition. This page states plainly what exists today, what the pipeline does, and what is still being built.
An honest starting point
GDPRI did not start life as a public website. It was built and run for over a year as a producer — a structured, source-cited data feed consumed by other Ramparts regulatory-intelligence monitors, with no reader-facing surface of its own. This public front end is new. The Renderer and Publisher pipeline stages that turn producer output into a published page did not exist before this build, and no jurisdiction page has been published on this site yet. Where this site has no content to show, it says so plainly — "pipeline onboarding in progress," "not yet populated," "coming soon" — rather than fabricating a count, a finding, or a status.
Pipeline stages
GDPRI's producer pipeline runs five stages. The first four are the established producer path; the fifth and sixth are new, added specifically to support this public front end.
- Registry — tracks which jurisdictions and modules are in scope, and their onboarding tranche.
- DR (baseline research) — gathers primary and secondary source material per jurisdiction and module.
- Interpreter — extracts structured claims from that research, each tied to a cited source.
- Composer — assembles interpreted claims into the module-level analysis GDPRI's other consumers read.
- Applier — writes composed output to persistent per-jurisdiction state. This is the terminus of the established producer pipeline — everything up to here has been running for other Ramparts monitors.
- Renderer & Publisher new — turn Applier's persistent state into a published page on this site. These two stages are new as of this build; they did not exist before the operator's decision to give GDPRI its own front end.
The producer→consumer contract that other Ramparts monitors depend on is unchanged by adding a front end — GDPRI's producer role is unaffected; the Renderer/Publisher stages read from the same Applier output without altering it.
The ten-module grammar
Every jurisdiction GDPRI covers is analysed against the same ten parent modules, so jurisdictions are comparable to each other:
Each parent module decomposes into sub-modules under GDPRI's internal doctrine (57 in total across the ten parents). The per-jurisdiction template page uses these same ten module names as its section headings, so the site's structure matches the pipeline's own taxonomy rather than a separately invented one.
Free-jurisdiction policy
Seven jurisdictions are available on the free tier without a subscription: the European Union,
United States, and Canada (each scoped to the federal/supranational level only — member-state, state,
or provincial jurisdictions within them are gated separately), plus China, Nigeria, the United
Kingdom, and Gibraltar at national scope. This allowlist is declared in GDPRI's own
consumer.config.json and is shared byte-for-byte with the equivalent crypto
regulatory consumer in the same fleet, so a reader who knows one free-tier list knows the other.
Scope and current status
GDPRI's overall jurisdiction scope is 31 jurisdictions. Onboarding proceeds in tranches: a first tranche of 30 jurisdictions was dispatched for research, with the remaining jurisdictions held back pending capacity — this is a capacity decision, not a reflection of those jurisdictions' importance. A pilot research corpus already exists inside the producer pipeline for 10 jurisdictions — AE, BR, CN, DE, FR, GB, IE, SG, US-CA, and ZA — though even that corpus may not yet be publication-ready by the standard this site holds itself to. As of this build, no jurisdiction page has been published; the jurisdiction template shows the page shape a published jurisdiction will use, with an explicit honest-empty state in place of real analysis.
AI-generated content disclosure
Every page on this site that carries substantive analysis marks itself content: ai_generated in a visible trust bar. GDPRI's claims are assembled by an AI research pipeline from cited public sources; they are general information, not legal advice, and individual claims have not each been independently verified by a human reviewer. Where the pipeline has not yet produced content for a page, that page says so — it does not fall back to a generic disclaimer in place of an honest empty state.