🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi

Methodology

How the Data Protection Monitor Works

Data Protection Regulatory Intelligence began as an internal data producer for other Ramparts monitors; this public front end is a new addition. This page states plainly what exists today, what the pipeline does, and what is still being built.

An honest starting point

The Data Protection Monitor did not start life as a public website. It was built and run for over a year as a producer — a structured, source-cited data feed consumed by other Ramparts regulatory-intelligence monitors, with no reader-facing surface of its own. This public front end is new. The Renderer and Publisher pipeline stages that turn producer output into a published page did not exist before this build; the site now carries 155 published jurisdiction pages, counted at build time. Where this site has no content to show, it says so plainly — "pipeline onboarding in progress," "not yet populated," "coming soon" — rather than fabricating a count, a finding, or a status.

Pipeline stages

The Data Protection Monitor's producer pipeline runs five stages. The first four are the established producer path; the fifth and sixth are new, added specifically to support this public front end.

  • Registry — tracks which jurisdictions and modules are in scope, and their onboarding tranche.
  • DR (baseline research) — gathers primary and secondary source material per jurisdiction and module.
  • Interpreter — extracts structured claims from that research, each tied to a cited source.
  • Composer — assembles interpreted claims into the module-level analysis the Data Protection Monitor's other consumers read.
  • Applier — writes composed output to persistent per-jurisdiction state. This is the terminus of the established producer pipeline — everything up to here has been running for other Ramparts monitors.
  • Renderer & Publisher new — turn Applier's persistent state into a published page on this site. These two stages are new as of this build; they did not exist before the operator's decision to give the Data Protection Monitor its own front end.

The producer→consumer contract that other Ramparts monitors depend on is unchanged by adding a front end — the Data Protection Monitor's producer role is unaffected; the Renderer/Publisher stages read from the same Applier output without altering it.

The ten-module grammar

Every jurisdiction the Data Protection Monitor covers is analysed against the same ten parent modules, so jurisdictions are comparable to each other:

Regulator & FrameworkM1
Lawful Processing & Special DataM2
Data Subject RightsM3
Controller / Processor DutiesM4
Cross-Border & AdequacyM5
Sectoral WatchM6
AdTech & Commercial PrivacyM7
Algorithmic, Biometric & Surveillance GovernanceM8
Children & Vulnerable GroupsM9
Enforcement & RedressM10

Each parent module decomposes into sub-modules under the Data Protection Monitor's internal doctrine (57 in total across the ten parents). The per-jurisdiction template page uses these same ten module names as its section headings, so the site's structure matches the pipeline's own taxonomy rather than a separately invented one.

Free-jurisdiction policy

Seven jurisdictions are available on the free tier without a subscription: the European Union, United States, and Canada (each scoped to the federal/supranational level only — member-state, state, or provincial jurisdictions within them are gated separately), plus China, Nigeria, the United Kingdom, and Gibraltar at national scope. This allowlist is declared in the Data Protection Monitor's own consumer.config.json and is shared byte-for-byte with the equivalent crypto regulatory consumer in the same fleet, so a reader who knows one free-tier list knows the other.

Scope and current status

The Data Protection Monitor tracks 155 jurisdictions in its registry. 155 of them have a published jurisdiction page. Both figures are counted from the registry and the published pages at build time, not typed in; the jurisdiction template shows the page shape, including the explicit honest-empty state a module carries where the pipeline has produced nothing.

Pipeline disclosure: how this content is produced

The Data Protection Monitor's claims are assembled by an AI research pipeline from cited public sources. The content: ai_generated mark means the analysis beside it was assembled by that pipeline, and it is general information, not legal advice. Facts are machine-assembled from cited public sources. Individual claims have not each been independently verified by a human reviewer. The pipeline roles are DR, Interpreter, Composer and Applier, run in that order after the registry. Where the pipeline has produced nothing, the page says so rather than substituting a generic disclaimer or a plausible estimate.