Articles
da Rosa Lazarotto, B., Stalla-Bourdillon, S., & Trigo Kramcsák, P. (2025). Giving EU Data Governance Law a Second Life? From Rebranding to Real-World Impact. Working Paper. Brussels Privacy Hub.
Stalla-Bourdillon, S. (2025). Déjà vu in data protection law: the risks of rewriting what counts as personal data. Privacy and Data Protection , 26(2), 9-13.
Stalla-Bourdillon, S. (2025). Between Nuance and Caution: How to Read the CJEU in EDPS v SRB. Privacy and Data Protection , 26(1), 6-10.
Stalla-Bourdillon, S. (2025). A GDPR Lens on the Draft Article 28 DSA Guidelines and Their Approach to Age Assurance. European Data Protection Law Review, 2025(2), 207-
Stalla-Bourdillon, S., Rossi, A. (2025). A Critical Assessment of EDPB Opinion 28/2024: Towards a Principle-Based Approach to Innovation?. Privacy and Data Protection, 25(6).
Stalla-Bourdillon, S. (2025). A Critical Assessment of the EDPB 01/2025 Guidelines on Pseudonymisation. European Data Protection Law Review, 11(1), 64-69.
Stalla-Bourdillon, S. (2025). The state of pseudonymisation in the EU: Where do we stand today?. Privacy and Data Protection, 18(2).
Stalla-Bourdillon, S. (2025). Identifiability as a data risk: Is a Uniform Approach to Anonymisation About to Emerge in the EU?. The European Journal of Risk Regulation.
Tsakalakis, N., Stalla-Bourdillon, S., Huynh, T. D., Moreau, L. (2025). A typology of explanations for Explainability-by-Design. ACM The Journal of Responsible Innovation, 2(1).
Stalla-Bourdillon, S. (2023). The UK Data Protection Digital Information Bill and the identifiability test. Privacy and Data Protection, 23(5).
Stalla-Bourdillon, S., Rossi, A. Hassan, H. (2022). What are Trusted Third Parties? (Part 2). Privacy and Data Protection, 22(1).
Boniface, M., Carmichael, L., Hall, W., Pickering, B., Stalla-Bourdillon, S., & Taylor, S. (2022). The Social Data Foundation model: Facilitating health and social care transformation through datatrust services. Data & Policy, 4(e6).
Stalla-Bourdillon, S., Rossi, A., Hassan, H. (2021). What are Trusted Third Parties? (Part 1). Privacy and Data Protection, 21(8).
Stalla-Bourdillon, S. (2021). A maturity spectrum for data institutions. IEEE Security and Privacy, 19(5), 90-94. [9529231]. https://doi.org/10.1109/MSEC.2021.3094985
Stalla-Bourdillon, S., Rossi, A. (2021). The technical fix for international data transfers: a word of caution. Privacy and Data Protection, 21(4).
Stalla-Bourdillon, S. (2021). Brexit: An opportunity to depart from the GDPR?. Revue des affaires européennes, 2021(1), p. 75.
Huynh, T. D., Tsakalakis, N., Helal, A., Stalla-Bourdillon, S., & Moreau, L. (2021). Addressing regulatory requirements on explanations for automated decisions with provenance – a case study. Digital Government: Research and Practice, [16e]. https://doi.org/10.1145/3436897
Stalla-Bourdillon, S., Carmichael, L., & Wintour, A. (2021). Fostering trustworthy data sharing: Establishing data foundations in practice. Data & Policy, 3(e4). https://doi.org/10.1017/dap.2020.24
Tsakalakis, N., Stalla-Bourdillon, S., Carmichael, L., Huynh, T. D., Moreau, L., & Helal, A. (2021). The dual function of explanations: Why it is useful to compute explanations. Computer Law and Security Review: The International Journal of Technology Law and Practice, 41, [105527]. https://doi.org/10.1016/j.clsr.2020.105527
Stalla-Bourdillon, S., Thuermer, G., Walker, J., Carmichael, L., & Simperl, E. (2020). Data protection by design: building the foundations of trustworthy data sharing. Data & Policy, 1(1).
Kwasny, S., Mantelero, A., & Stalla-Bourdillon, S. (2020). The role of the Council of Europe on the 40th anniversary of Convention 108. Computer Law & Security Review, [105501]. https://doi.org/10.1016/j.clsr.2020.105501
Stalla-Bourdillon, S. (2019). Data protection by design and data analytics: can we have both? Privacy and Data Protection , 19(5).
Stalla-Bourdillon, S. (2019). Anonymising personal data: where do we stand now? Privacy and Data Protection , 19(4).
Pearce, H., & Stalla-Bourdillon, S. (2019). Rethinking the “release and forget” ethos of the Freedom of Information Act 2000: why developments in the field of anonymisation necessitate the development of a new approach to disclosing data. European Journal of Law and Technology , 10(1). http://ejlt.org/article/view/671/906
Stalla-Bourdillon, S., Pearce, H., & Tsakalakis, N. (2018). The GDPR: A game changer for electronic identification schemes? The case study of Gov.UK Verify. Computer Law and Security Review: The International Journal of Technology Law and Practice, 34(4), 784-805. https://doi.org/10.1016/j.clsr.2018.05.012
Zhang, P., Stalla-Bourdillon, S., & Gilbert, L. (2017). A Content-Linking-Context Model for automatic assessment of web resources in “Notice-and-take-down” Procedures. The Journal of Web Science, 3(1). http://www.webscience-journal.net/webscience/article/view/42
Stalla-Bourdillon, S., Rosati, E., Turk, K., Angelopoulos, C., Kuczerawy, A., Peguera, M., & Husovec, M. (2017). An academic perspective on the copyright reform. Computer Law & Security Review, 33(1), 3-13. https://doi.org/10.1016/j.clsr.2016.12.003
Stalla-Bourdillon, S., & Knight, A. (2017). Anonymous data v. personal data – a false debate: an EU perspective on anonymization, pseudonymization and personal data. Wisconsin International Law Journal, 34(2), 284-322. https://repository.law.wisc.edu/s/uwlaw/item/77050
Thorburn, R., Stalla-Bourdillon, S., & Rosati, E. (2017). iCLIC Data Mining and Data Sharing workshop: the present and future of data mining and data sharing in the EU. Computer Law & Security Review, 33(1), 129-137. https://doi.org/10.1016/j.clsr.2016.12.004
Tsakalakis, N., Stalla-Bourdillon, S., & O’Hara, K. (2017). Identity Assurance in the UK: technical implementation and legal implications under eIDAS. The Journal of Web Science, 3(3), 32-46. https://doi.org/10.1561/106.00000010
Cradock, E., Stalla-Bourdillon, S., & Millard, D. (2017). Nobody puts data in a corner? Why a new approach to categorising personal data is required for the obligation to inform. Computer Law & Security Review, 33(2), 142-158. https://doi.org/10.1016/j.clsr.2016.11.005
Cradock, E., Millard, D., & Stalla-Bourdillon, S. (2016). An extended investigation of the similarity between privacy policies of social networking sites as a precursor for standardization. The Journal of Web Science, 2(3), 31-44. https://doi.org/10.1561/106.00000006
Carmichael, L., Stalla-Bourdillon, S., & Staab, S. (2016). Data mining and automated discrimination: a mixed legal/technical perspective. IEEE Intelligent Systems, 31(6), 51-55. https://doi.org/10.1109/MIS.2016.96
Stalla-Bourdillon, S. (2015). ‘Safe harbour’ court ruling could prevent US firms from reaching European users. The Conversation.
Sullivan, C., & Stalla-Bourdillon, S. (2015). Digital identity and French personality rights – a way forward in recognizing and protecting an individual’s rights in his/her digital identity. Computer Law and Security Review: The International Journal of Technology Law and Practice, 31, 268-279.
Fryer, H., Stalla-Bourdillon, S., & Chown, T. (2015). Malicious web pages: what if hosting providers could actually do something… Computer Law and Security Review: The International Journal of Technology Law and Practice, 31, 490-505. https://doi.org/10.1016/j.clsr.2015.05.011
Stalla-Bourdillon, S., Papadaki, E., & Chown, T. (2014). From porn to cybersecurity passing by copyright: how mass surveillance technologies are gaining legitimacy… the case of Deep Packet inspection technologies. Computer Law & Security Review, 30(6), 670-686. https://doi.org/10.1016/j.clsr.2014.09.006
Stalla-Bourdillon, S. (2014). Tackling online trolls doesn’t need a bigger stick – just a more effective one. The Conversation.
Stalla-Bourdillon, S. (2013). Online monitoring, filtering, blocking … what is the difference? Where to draw the line? Computer Law & Security Review, 29, 702-712.
Stalla-Bourdillon, S. (2011). Uniformity v. diversity of internet intermediaries’ liability regimes: where does the ECJ stand? Journal of International Commercial Law and Technology, 6(1), 51-61.
Stalla-Bourdillon, S. (2010). Chilling ISPs… when private regulators act without adequate public framework. Computer Law & Security Review, 26(3), 290-297. https://doi.org/10.1016/j.clsr.2010.03.006
Stalla-Bourdillon, S. (2010). Regulating the electronic marketplace through extraterritorial legislation: Google and eBay in the line of fire of French judges. Internation Review of Law, Computers and Technology, 24(1), 39-49. https://doi.org/10.1080/13600860903570152
Stalla-Bourdillon, S. (2010). Should search engines begin to worry? Journal of Internet Law, 14, 3-9.
Stalla-Bourdillon, S. (2010). The flip side of ISP’s liability regimes : the ambiguous protection of fundamental rights and liberties in private digital spaces. Computer Law & Security Review, 26(5), 492-501. https://doi.org/10.1016/j.clsr.2010.07.004
Stalla-Bourdillon, S. (2009). Making intermediary Internet service providers participate in the regulatory process through tort law: a comparative analysis. Internation Review of Law, Computers and Technology, 23(1-2), 153-165. https://doi.org/10.1080/13600860902742521
Books
Sénéchal, J., & Stalla-Bourdillon, S. (2028). Rôle et responsabilité juridiques des plateformes en ligne: approche(s) transversale(s) ou approches sectorielles? IRJS Editions .
Stalla-Bourdillon, S. (2017). Responsabilité civile et stratégie de régulation: Essai sur la responsabilité civile des prestataires intermédiaires de service en ligne. Editions Universitaires Europeennes.
Stalla-Bourdillon, S., Phillips, J., & Ryan, M. D. (2014). Privacy vs security. (Springer Briefs in Cybersecurity). Springer.
Book Chapters
Carmichael, L., Cradock, E., & Stalla-Bourdillon, S. (2023). Article 11 of the General Data Protection Regulation. In I. Spiecker Döhmann, V. Papakonstantinou, G. Hornung, & P. de Hert (Eds.), Commentary on the General Data Protection Regulation Nomos.
Carmichael, L., Cradock, E., & Stalla-Bourdillon, S. (2023). Article 21 of the General Data Protection Regulation. In I. Spiecker Döhmann, V. Papakonstantinou, G. Hornung, & P. de Hert (Eds.), Commentary on the General Data Protection Regulation Nomos.
Carmichael, L., Cradock, E., & Stalla-Bourdillon, S. (2023). Article 30 of the General Data Protection Regulation. In I. Spiecker Döhmann, V. Papakonstantinou, G. Hornung, & P. de Hert (Eds.), Commentary on the General Data Protection Regulation Nomos.
Papadaki, E., & Stalla-Bourdillon, S. (2023). Article 32 of the General Data Protection Regulation. In I. Spiecker Döhmann, V. Papakonstantinou, G. Hornung, & P. de Hert (Eds.), Commentary on the General Data Protection Regulation Nomos.
Tsakalakis, N., & Stalla-Bourdillon, S. (2023). Article 87 of the General Data Protection Regulation. In I. Spiecker Döhmann, V. Papakonstantinou, G. Hornung, & P. de Hert (Eds.), Commentary on the General Data Protection Regulation Nomos.
Carmichael, L., Cradock, E., & Stalla-Bourdillon, S. (2023). Article 89 of the General Data Protection Regulation. In I. Spiecker Döhmann, V. Papakonstantinou, G. Hornung, & P. de Hert (Eds.), Commentary on the General Data Protection Regulation Nomos.
Stalla-Bourdillon, S., & Rossi, A. (2023). Pseudonymous data. In M. Finck (Ed.), Encyclopedia of EU Law Oxford University Press, Oxford.
Tsakalakis, N., Stalla-Bourdillon, S., Carmichael, L., Huynh, D., Moreau, L., & Helal, A. (2022). The dual function of explanations: Why computing explanations is of value. In D. Hallinan , R. Leenes & P. De Hert (Eds.). Data Protection and Privacy: Enforcing Rights in a Changing World (pp. 127–156). Oxford: Hart Publishing.
Stalla-Bourdillon, S., & Rossi, A. (2021). Aggregation, synthesization and anonymization: a call for a risk-based assessment of anonymization approaches. In D. Hallinan, R. Leenes & P. De Hert (Eds.). Data Protection and Privacy: Data Protection and Artificial Intelligence (pp. 111–144). Oxford: Hart Publishing.
Stalla-Bourdillon, S., & Thorburn, R. H. (2020). The scandal of intermediary: Acknowledging the both/and dispensation for regulating hybrid actors. In B. Petkova, & T. Ojanen (Eds.), Fundamental Rights Protection Online: the Future Regulation of Intermediaries Edward Elgar.
Stalla-Bourdillon, S. (2019). Anonymisation. In N. Martial-Braz, & J. Rochfeld (Eds.), Droit des Données Personnelles Dalloz.
Stalla-Bourdillon, S., & Knight, A. M. (2019). Data analytics and the GDPR: friends or foes? A call for a dynamic approach to data protection law. In R. Leenes, R. van Brakel, S. Gutwirth, & P. De Hert (Eds.), Data Protection and Privacy: the Internet of Bodies (pp. 249–276). Hart. https://doi.org/10.5040/9781509926237.ch-011
Hu, R., Stalla-Bourdillon, S., Yang, M., Schiavo, V., & Sassone, V. (2017). Bridging policy, regulation and practice? A techno-legal analysis of three types of data in the GDPR. In R. Leenes, R. van Brakel, S. Gutwirth, & P. De Hert (Eds.), Data Protection and Privacy: the Age of Intelligent Machines (Computers, Privacy and Data Protection; Vol. 10). Hart.
Stalla-Bourdillon, S. (2017). Internet intermediaries as responsible actors? Why it is time to rethink the e-Commerce Directive as well… In M. Taddeo, & L. Floridi (Eds.), The Responsibilities of Online Service Providers (Law, Governance and Technology Series; Vol. 31). Springer International Publishing. https://doi.org/10.1007/978-3-319-47852-4_15
Stalla-Bourdillon, S. (2018). Qui sonne le glas des intermédiaires de l’Internet. In J. Sénéchal, & S. Stalla-Bourdillon (Eds.), Rôle et Responsabilité Juridiques des Plateformes en Ligne: Approche(s) Transversale(s) ou Approches Sectorielles? IRJS Editions.
Stalla-Bourdillon, S., Papadaki, E., & Chown, T. (2016). Metadata, traffic data, communications data, service use information… What is the difference? Does the difference matter? An interdisciplinary view from the UK. In S. Gutwirth, R. Leenes, & P. De Hert (Eds.), Data Protection on the Move: Current Developments in ICT and Privacy/Data Protection Springer. https://doi.org/10.1007/978-94-017-7376-8_16
Stalla-Bourdillon, S. (2012). Liability exemptions wanted! Internet intermediaries’ liability under UK law. In S. Kierkegaard, & W. Grosheide (Eds.), Copyright Law in the Making – European and Chinese Perspectives (pp. 129-142). Co-Reach.
Stalla-Bourdillon, S. (2012). Sometimes one is not enough! Securing freedom of expression, encouraging private regulation, or subsidizing internet intermediaries or all three at the same time: the dilemma of internet intermediaries’ liability. In S. Kierkegaard, & W. Grosheide (Eds.), Copyright Law in the Making- European and Chinese Perspectives (pp. 95-122). Co-Reach.
Stalla-Bourdillon, S. (2011). Privacy is dead, long live privacy! Breach of confidence and information privacy: towards a more progressive action for breach of confidence? In S. Kierkegaard (Ed.), Law Across Nations: Governance, Policy & Statutes IAITL.
Stalla-Bourdillon, S. (2009). Re-allocating horizontal and vertical regulatory powers in the electronic marketplace: what to do with private international law. In F. Cafaggi, & H. Muir-Watt (Eds.), The Regulatory Function of European Private Law (pp. 290-342). Edward Elgar.
Aubert de Vincelles, C., Chardenoux, S., Grynbaum, L., Poillot, E., Rochfeld, J., Slim, H., Usunier, L., & Stalla-Bourdillon, S. (2007). Réponse de l’atelier français intégré aux recherches du groupe européen acquis communautaire. In Livre Vert sur le Droit Européen de la Consommation : Réponses Françaises Société de Législation Comparée.
Chardenoux, S., & Stalla-Bourdillon, S. (2006). L’agent de la sanction. In J. Rochfeld, & C. A. de Vincelles (Eds.), L’Acquis Communautaire: Les Sanctions de l’Inexécution du Contrat (Etudes Juridiques; No. 26). Économica.
Selected Conferences
Boniface, M., Hall, W., Stalla-Bourdillon, S., Pickering, B., Taylor, S., Carmichael, L., & Hardinges, J. (2021). HSCT 2021-Joined up data equals better care: facilitating health and social care transformation through trustworthy and collaborative data sharing: welcome and workshop summary. In WebSci 2021 – Proceedings of the 13th ACM Web Science Conference (Companion Volume) (pp. 44-45). (HSCT 2021-Joined up Data Equals Better Care). ACM. https://doi.org/10.1145/3462741.3466646
Stalla-Bourdillon, S., Carmichael, L., & Wintour, A. (2020). Fostering trustworthy data sharing: establishing data foundations in practice. In Data for Policy Proceedings Zenodo https://zenodo.org/record/3967690#.X1dkHYtS_cc
Tsakalakis, N., Stalla-Bourdillon, S., & O’hara, K. (2019). Data protection by design for cross-border electronic identification: Does the eIDAS Interoperability Framework need to be modernised? In E. Kosta, S. Fischer-Hübner, J. Pierson, D. Slamanig, & S. Krenn (Eds.), Privacy and Identity Management. Fairness, Accountability, and Transparency in the Age of Big Data: 13th IFIP WG 9.2, 9.6/11.7, 11.6/SIG 9.2.2 International Summer School, Vienna, Austria, August 20-24, 2018, Revised Selected Papers (pp. 255-274). (IFIP Advances in Information and Communication Technology; Vol. 547). Springer New York. https://doi.org/10.1007/978-3-030-16744-8_17
Stalla-Bourdillon, S., Thuermer, G., Walker, J. C., & Carmichael, L. (2019). Data protection by design: building the foundations of trustworthy data sharing. In Proceedings of Data for Policy Conference 2019 https://doi.org/10.5281/zenodo.3079895
Walker, J., Simperl, E., Stalla-Bourdillon, S., & O’Hara, K. (2019). Decision making processes for data sharing: a framework for data trusts. Abstract from ACM WomENcourage 2019, Rome, Italy. https://womencourage.acm.org/2019/wp-content/uploads/2019/07/womENcourage_2019_paper_41.pdf
Zhang, P., Stalla-Bourdillon, S., & Gilbert, L. (2016). A content-linking-context model for “notice-and-takedown” procedures. In WebSci ’16 Proceedings of the 8th ACM Conference on Web Science (pp. 161-165). ACM New York, NY, USA. https://doi.org/10.1145/2908131.2908171
Hühnlein, D., Frosch, T., Schwenk, J., Piswanger, C. M., Sel, M., Hühnlein, T., Wich, T., Nemmert, D., Lottes, R., Baszanowski, S., Zeuner, V., Rauh, M., Somorovsky, J., Mladenov, V., Condovici, C., Leitold, H., Stalla-Bourdillon, S., Tsakalakis, N., Eichholz, J., … Sazonov, A. (2016). Futuretrust-future trust services for trustworthy global transactions. In D. Huhnlein, M. Talamo, H. Rossnagel, & C. H. Schunck (Eds.), Open Identity Summit 2016, OID 2016 – Proceedings (pp. 27-41). Gesellschaft fur Informatik (GI).
Tsakalakis, N., O’hara, K., & Stalla-Bourdillon, S. (2016). Identity assurance in the UK: technical implementations and legal implications under the eIDAS regulation. 55-65. Paper presented at WebSci ’16 Proceedings of the 8th ACM Conference on Web Science, Hannover, Germany. https://doi.org/10.1145/2908131.2908152
Tsakalakis, N., Stalla-Bourdillon, S., & O’Hara, K. (2016). What’s in a name: the conflicting views of pseudonymisation under eIDAS and the General Data Protection Regulation. In D. Hühnlein, H. Roßnagel, C. H. Schunck, & M. Talamo (Eds.), Open Identity Summit 2016: October 13–14, 2016, Rome, Italy (Vol. P-264, pp. 167-174). (Lecture Notes in Informatics (LNI) – Proceedings ; Vol. P-264). Gesellschaft für Informatik. https://subs.emis.de/LNI/Proceedings/Proceedings264/P-264.pdf
Cradock, E., Millard, D., & Stalla-Bourdillon, S. (2015). Investigating similarity between privacy policies of social networking sites as a precursor for standardization. Paper presented at 24th International World Wide Web Conference, Florence, Italy.
Fryer, H., Stalla-Bourdillon, S., & Chown, T. (2014). Computer abuse legislation: a trap for the unwary?. Paper presented at The Web Science Cybercrime – Cyberwar Workshop: Research Methodologies for analyzing Cybercrime and Cyberwarfare, Bloomington, United States.
Selected White Papers, Reports and Deliverables
Stalla-Bourdillon, S. (2024). Cross-Border Data Transfer Tools v Privacy Enhancing Technologies: A False Debate. Cerre Publication. in S. Stalla-Bourdillon. (Ed). Global Governance of Data Flows. Cerre Publication.
Stalla-Bourdillon, S. (2024). Relational Trustworthiness for Cross-Border Data Flows: on Certification and Model Clauses. Cerre Publication. in S. Stalla-Bourdillon (Ed). Global Governance of Data Flows. Cerre Publication.
Stalla-Bourdillon, S. (Ed). (2004). Global Governance of Data Flows. Cerre Publication.
Boniface, M., Carmichael, L., Hall, W., Pickering, B., Stalla-Bourdillon, S., & Taylor, S. (2020). A blueprint for a social data foundation: Accelerating trustworthy and collaborative data sharing for health and social care transformation . (Web Science Institute White Papers; No. 4). University of Southampton. https://doi.org/10.5258/SOTON/WSI-WP004
Stalla-Bourdillon, S., Wintour, A., & Carmichael, L. (2019). Building trust through data foundations: a call for a data governance model to support trustworthy data sharing. (WSI White Papers; No. 2). University of Southampton. https://doi.org/10.5258/SOTON/WSI-WP002
Tsakalakis, N., & Stalla-Bourdillon, S. (2019). Legal evaluation of the FutureTrust architecture: D.5.3. FutureTrust. https://2e06f8c1-edcc-4de4-9e0f-222a5feadd60.filesusr.com/ugd/2844e6_6ee720db94a444b98f1cadafeefca1db.pdf
Huynh, T. D., Stalla-Bourdillon, S., & Moreau, L. (2019). Provenance-based explanations for automated decisions: final IAA project report. https://kclpure.kcl.ac.uk/portal/files/113483446/ico_iaa_report.v4.pdf
Tsakalakis, N., & Stalla-Bourdillon, S. (2018). Documentation of the legal foundations of trust and trustworthiness: Deliverable D2.8. FutureTrust.
Stalla-Bourdillon, S., & Knight, A. (2017). Legal and Privacy Toolkit v1.0. Data Pitch.
Tsakalakis, N., Stalla-Bourdillon, S., & Sel, M. (Ed.) (2017). State of the art in relation to privacy and data protection requirements (preliminary report): Deliverable 2.7. FutureTrust.
Staab, S., Stalla-Bourdillon, S., & Carmichael, L. (2016). Observing and recommending from a social web with biases. (Web Science Institute (WSI) Pump – Priming Project). University of Southampton.
German, L., Kalogiros, C., Kanakakis, M., Nasser, B., Stalla-Bourdillon, S., van der Graaf, S., Vanobberghen, W., & Wiegand, S. (2015). OPTET D2.4 Socio-economic evaluation of trust and trustworthiness. University of Southampton.
German, L., Kalagiros, C., Kanakakis, M., Nasser, B., Stalla-Bourdillon, S., van der Graaf, S., Vanobberghen, W., & Wiegand, S. (2015). OPTET D2.5 – Consolidated report on the socio-economic basis for trust and trustworthiness. University of Southampton.
