Regulation: EU 2016/679
Effective: Ongoing (since 25.5.2018)
Scope: Personal data protection
What is GDPR?
GDPR (General Data Protection Regulation) is the EU regulation on the protection of natural persons with regard to the processing of personal data. It applies to all organisations processing data of EU residents.
Key Terms
| Term | Definition |
|---|
| Personal data | Any information identifying a natural person |
| Data subject | Natural person whose data you process |
| Controller | Determines the purposes and means of processing |
| Processor | Processes data on behalf of the controller |
| DPO | Data Protection Officer |
| DSAR | Data Subject Access Request |
| DPIA | Data Protection Impact Assessment |
Legal Bases for Processing
| # | Legal Basis | Description | Examples |
|---|
| 1 | CONSENT (Consent) | Explicit opt-in, revocable at any time | Marketing, cookies, newsletter |
| 2 | CONTRACT (Contract) | Necessary for contract performance | Product/service delivery |
| 3 | LEGAL OBLIGATION (Legal obligation) | Law requires processing | Tax, accounting, regulatory reports |
| 4 | LEGITIMATE INTEREST (Legitimate interest) | Your interest vs. subject’s rights (LIA assessment) | Analytics, fraud prevention, direct marketing |
| 5 | VITAL INTEREST (Vital interest) | Protecting the subject’s life | Medical emergency |
| 6 | PUBLIC INTEREST (Public task) | Exercise of official authority | Government |
Data Subject Rights
| Right | Article | SLA | Description |
|---|
| Access | Art. 15 | 30 days | Export of all data about the subject |
| Rectification | Art. 16 | 30 days | Correction of inaccurate data |
| Erasure | Art. 17 | 30 days | ”Right to be forgotten” |
| Restriction | Art. 18 | 30 days | Suspension of processing |
| Portability | Art. 20 | 30 days | Export in machine-readable format |
| Objection | Art. 21 | 30 days | Objection to processing |
| Automated decision-making | Art. 22 | 30 days | Right to human review |
DSAR Workflow
Data Breach Notification
Timeline
When to Notify?
| Situation | Notify DPA | Notify subjects |
|---|
| Encrypted data stolen | No | No |
| Unencrypted PII stolen | Yes (72h) | Yes (asap) |
| Health data breach | Yes (72h) | Yes (asap) |
| Internal access without authorisation | Depends on scope | Depends on risk |
Penalties
| Category | Penalty |
|---|
| Severe violation | up to EUR 20M or 4% of global annual turnover |
| Medium violation | up to EUR 10M or 2% of turnover |
Examples:
- Meta: EUR 1.2B (2023) --- data transfer to the US
- Amazon: EUR 746M (2021) --- cookies
- Google: EUR 90M (2022) --- cookies in France
Next Steps
- Review data mapping
- Set up DSAR workflow
- Go through the checklist
Resources