Skip to content
TECHNOMATON | Docs SAI Certified Trainers

GDPR: Overview

Regulation: EU 2016/679 Effective: Ongoing (since 25.5.2018) Scope: Personal data protection


What is GDPR?

GDPR (General Data Protection Regulation) is the EU regulation on the protection of natural persons with regard to the processing of personal data. It applies to all organisations processing data of EU residents.

Key Terms

TermDefinition
Personal dataAny information identifying a natural person
Data subjectNatural person whose data you process
ControllerDetermines the purposes and means of processing
ProcessorProcesses data on behalf of the controller
DPOData Protection Officer
DSARData Subject Access Request
DPIAData Protection Impact Assessment
#Legal BasisDescriptionExamples
1CONSENT (Consent)Explicit opt-in, revocable at any timeMarketing, cookies, newsletter
2CONTRACT (Contract)Necessary for contract performanceProduct/service delivery
3LEGAL OBLIGATION (Legal obligation)Law requires processingTax, accounting, regulatory reports
4LEGITIMATE INTEREST (Legitimate interest)Your interest vs. subject’s rights (LIA assessment)Analytics, fraud prevention, direct marketing
5VITAL INTEREST (Vital interest)Protecting the subject’s lifeMedical emergency
6PUBLIC INTEREST (Public task)Exercise of official authorityGovernment

Data Subject Rights

RightArticleSLADescription
AccessArt. 1530 daysExport of all data about the subject
RectificationArt. 1630 daysCorrection of inaccurate data
ErasureArt. 1730 days”Right to be forgotten”
RestrictionArt. 1830 daysSuspension of processing
PortabilityArt. 2030 daysExport in machine-readable format
ObjectionArt. 2130 daysObjection to processing
Automated decision-makingArt. 2230 daysRight to human review

DSAR Workflow

Data Breach Notification

Timeline

When to Notify?

SituationNotify DPANotify subjects
Encrypted data stolenNoNo
Unencrypted PII stolenYes (72h)Yes (asap)
Health data breachYes (72h)Yes (asap)
Internal access without authorisationDepends on scopeDepends on risk

Penalties

CategoryPenalty
Severe violationup to EUR 20M or 4% of global annual turnover
Medium violationup to EUR 10M or 2% of turnover

Examples:

  • Meta: EUR 1.2B (2023) --- data transfer to the US
  • Amazon: EUR 746M (2021) --- cookies
  • Google: EUR 90M (2022) --- cookies in France

Next Steps

  1. Review data mapping
  2. Set up DSAR workflow
  3. Go through the checklist

Resources