Skip to content
TECHNOMATON | Docs SAI Certified Trainers

GDPR | Data Processing

Guide for proper processing of personal data under GDPR.


Key Terms

TermDefinitionExample
Personal dataAny information identifying a natural personName, email, IP address
Data subjectNatural person whose data you processCustomer, employee
ControllerDetermines the purposes and means of processingYour company
ProcessorProcesses data on behalf of the controllerCloud provider
ProcessingAny operation performed on dataCollection, storage, use, deletion

Categories of Personal Data

Standard Personal Data

CategoryExamples
IdentificationName, surname, date of birth, national ID number
ContactEmail, phone, address
Online identifiersIP address, cookies, device ID
FinancialBank account number, payment card
ProfessionalEmployer, position, CV
BehaviouralPurchase history, browsing history

Special Categories (Art. 9)

Processing requires explicit consent or a legal exemption:

CategoryExamplesLegal basis
Racial/ethnic originNationality, ethnicityExplicit consent
Political opinionsPolitical party membershipExplicit consent
Religious beliefsFaith, churchExplicit consent
Trade union membershipTrade unionExplicit consent
Genetic dataDNA, genetic testsHealth purposes
Biometric dataFingerprint, face IDSecurity
Health dataDiagnoses, treatmentHealthcare
Sexual orientationSexual preferencesExplicit consent

Data Mapping (ROPA)

Records of Processing Activities

GDPR requires maintaining records of processing (Art. 30):

ROPA Table Example

#PurposeLegal basisSubjectsDataRecipientsRetention
1E-commerceContractCustomersName, address, paymentsCourier, payment gateway10 years
2NewsletterConsentSubscribersEmailEmail service providerUntil revocation
3HRContract + Legal obligationEmployeesAllAccountant, social security30 years
4AnalyticsLegitimate interestVisitorsIP, cookiesAnalytics provider2 years

#Legal basisWhenExampleCaveat
1CONSENT (Art. 6.1.a)Marketing, cookies, newsletterVoluntary, specific, informedRevocable at any time
2CONTRACT (Art. 6.1.b)Performance of a contract with the subjectGoods delivery, service provisionOnly necessary data
3LEGAL OBLIGATION (Art. 6.1.c)Law requires processingTax, accounting, social securityA specific law must exist
4VITAL INTEREST (Art. 6.1.d)Protecting the subject’s lifeMedical emergencyExceptional situations
5PUBLIC INTEREST (Art. 6.1.e)Exercise of official authorityGovernmentOnly public authorities
6LEGITIMATE INTEREST (Art. 6.1.f)Your legitimate interest outweighs rightsFraud prevention, direct marketingLIA (balancing test) required

Valid consent must be:

RequirementDescriptionWrong exampleCorrect example
Freely givenWithout coercion”You cannot use the service without consent”Service works without consent
SpecificFor a clear purpose”I agree to everything""I agree to the newsletter”
InformedSubject knows whatNo explanationClear description of purpose
UnambiguousActive actionPre-ticked checkboxEmpty checkbox
RevocableEasy withdrawalHidden or complicatedLink in every email

Legitimate Interest --- LIA

Legitimate Interest Assessment (balancing test):


Processing Principles

GDPR Principles (Art. 5)

PrincipleDescriptionImplementation
LawfulnessHave a legal basisDocument in ROPA
Purpose limitationOnly for the defined purposeDo not share for other purposes
Data minimisationOnly necessary dataAudit, delete unnecessary data
AccuracyData must be correctValidation, corrections
Storage limitationNot longer than necessaryRetention policy
IntegrityData securityEncryption, access control
AccountabilityDemonstrate complianceDocumentation, audit trail

Data Transfers Outside the EU

Transfer Mechanisms

MechanismWhen to use
Adequacy decisionCountries with an EC decision (UK, Switzerland, Canada, Japan…)
SCCsStandard Contractual Clauses --- most common
BCRBinding Corporate Rules --- for corporations
DerogationsExplicit consent, contract performance (limited)

US Transfers (post-Schrems II)

  • EU-US Data Privacy Framework (2023+) --- for certified US companies
  • Must verify whether the vendor is on the DPF list
  • Alternatively SCCs + TIA (Transfer Impact Assessment)

Data Processing Agreements

Mandatory DPA Content (Art. 28)

ItemDescription
Subject of processingWhat the processor processes
DurationHow long
Nature and purposeWhy
Types of dataWhat data
Categories of subjectsAbout whom
Rights and obligationsController vs. Processor
Sub-processorsList + approval process
Security measuresTechnical + organisational
Breach notificationSLA for reporting
Audit rightsRight to audit
DeletionAfter termination of the agreement
AssistanceHelp with DSAR, DPIA

Retention Policy

Retention Schedule Example

Data categoryRetentionBasisAuto-delete
Customer dataContract duration + 3 yearsBusiness need[ ] Yes
Employee dataEmployment duration + 30 yearsLaw[ ] No
Financial records10 yearsAccounting regulations[ ] Yes
Marketing consentUntil revocationConsent[ ] Yes
Log data1 yearSecurity[ ] Yes
Backup data30 days after deletionTechnical[ ] Yes
CCTV72 hoursLegitimate interest[ ] Yes

Next Steps

  1. Data processing understood
  2. Data subject rights (DSAR)
  3. Compliance checklist