3 4 5 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

What is GDPR

GDPRDefinition:

The General Data Protection Regulation or GDPR is Regulation (EU) 2016/679, which establishes rules concerning the processing of personal data and the free movement of such data in the European Union. It entered into force in 2016 and has applied since 25 May 2018.

It protects information relating to an identified or identifiable natural person. It applies to automated processing and to non-automated processing when the data form or are intended to form part of a filing system. The official GDPR text defines its scope, principles, rights, obligations and penalty regime.

What the GDPR involves

Processing must have a legal basis and comply with the principles established by the Regulation, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. The organisation must be able to demonstrate compliance.

  • Information and transparency: The person must know, among other matters, who processes their data, why, for how long and how to exercise their rights.
  • Legal bases: Consent is one possible basis, together with a contract, legal obligation, vital interests, a task in the public interest and legitimate interests subject to their conditions.
  • Rights: The Regulation recognises access, rectification, erasure, restriction, portability and objection, as well as safeguards concerning certain automated decisions.
  • Data protection by design and by default: Protective measures must be built into systems and initially limit data to what is necessary.
  • Security: Controllers and processors must apply measures appropriate to the risk and manage personal-data breaches in accordance with notification and communication requirements.
  • Processors and transfers: The use of providers and transfers outside the European Economic Area require appropriate contracts, safeguards and controls.
  • Data Protection Officer: Appointment is mandatory in the circumstances defined by the Regulation and applicable laws, not for every organisation without exception.
  • Impact assessment: It is required when a type of processing is likely to result in a high risk to rights and freedoms.

In marketing and web analytics, the GDPR may affect forms, databases, audiences, identifiers and cookies. Consent is not automatically required for all processing, but when it is used it must be freely given, specific, informed and unambiguous, and it must be possible to withdraw it.

GDPR scope

The GDPR applies to organisations established in the Union and may also apply to organisations outside it that offer goods or services to people in the Union or monitor their behaviour. Its application does not depend solely on whether an entity has legal personality.

Some processing falls outside its scope or is subject to specific rules:

  • Personal or household activity: Processing by a natural person in the course of a purely personal or household activity may be excluded.
  • Deceased persons: The Regulation does not directly apply to their data, although national law may establish rules.
  • National security and foreign policy: Certain activities outside the scope of Union law are not governed by the GDPR.
  • Criminal-law authorities: Prevention, investigation and prosecution by competent authorities are governed by a specific framework.
  • Freedom of expression and information: Member States must reconcile data protection with these rights, including journalistic processing.
  • Research, archiving and statistics: Specific adaptations and safeguards may apply, but there is no general exemption from compliance.

The so-called right to be forgotten is an application of the right to erasure and, for search engines, the removal of certain results associated with a person’s name. It is not an absolute right and must be balanced with legal obligations, public interest, freedom of expression and other rights.

Penalties arising from data protection

Surveillance camera

Supervisory authorities can adopt corrective measures such as warnings, reprimands, orders to satisfy rights, processing restrictions or fines. The amount is determined by factors including severity, duration, intent, measures taken, cooperation and previous infringements.

  • Lower tier: Up to EUR 10 million or, for an undertaking, up to 2% of its total worldwide annual turnover for the preceding financial year, whichever is higher.
  • Higher tier: Up to EUR 20 million or, for an undertaking, up to 4% of its total worldwide annual turnover for the preceding financial year, whichever is higher.

These are maximum limits for categories of infringement, not automatic amounts. Liability claims and other consequences under national law may also apply. Applying the rules to a particular case requires examination of the facts and current legislation.