GDPR Overview
Theodora Baxevani
Alexander TEI of Thessaloniki
Department of Information Technology
Thessaloniki, Greece.
it144268@[Link]
Abstract— The General Data Protection Regulation (GDPR) - how it is being used, why it is being used and ultimately the
a set of rules designed to give European citizens more control right to be forgotten upon request.
over their personal data- is undeniably the most consequential
change in European Union’s (EU) data privacy regulation in the III. GDPR COMPONENTS
last two decades. It replaced the outdated Data Protection
Directive (DPD) 95/46/EC which was introduced in 1995, in order to A. Personal data
empower the data privacy by being applied to all companies The term ‘personal data’ is the entryway to the application
processing personal data of European citizens, regardless of the of the GDPR. Only if a processing of data concerns personal
company’s location. In this article, the most significant parts and data, the General Data Protection Regulation applies. Personal
topics about this regulation are being presented as well as an data is defined as any information relating to an identified or
assessment about its results and actual impact. identifiable person. An identifiable natural person is one who
can be identified, directly or indirectly, in particular by
Keywords—GDPR, Privacy, Personal Data, Data Processing reference to information. For example, the telephone, credit
card or identity number of a person, account data, number of
I. INTRODUCTION plate, appearance, customer number or address are all personal
Over the last 15 years, technology has entered and data [3].
transformed our lives tremendously. Most abilities of today’s Some personal data may be considered “sensitive” and
Internet lead to everyday transactions which demand some require special care such as encryption. Anyone collecting
personal data from the users, even for the simplest applications. sensitive personal data must consider the need for the
As a result, huge amount of data is being collected and collection, processing, and storage of that data, and determine
synthesized by service providers and spying entities on daily whether it is truly necessary. Sensitive data includes categories
basis. When users disclose these digital footprints about such as:
themselves, they often have no control as to what companies Racial or ethnic origin
will do with them which results in a huge information Political opinions
asymmetry. The concern about the methods that all these data Religious or philosophical beliefs
should be collected, stored and transferred became the main Trade union membership
reasons for the creation of the GDPR with the intent of giving Genetic data
to individuals more control of their personal data. A collateral Biometric data for the purpose of uniquely identifying
aim was to make it easier and cheaper for companies in the a natural person
digital market to comply with data protection rules, as it applies Data concerning health or a natural person’s sex life
directly without needing to be turned into law, creating fewer and/or sexual orientation
variations in interpretation between member states.
When data is requested from an individual and is explicitly
provided, such as in a web form, the means of data collection
II. THE PRIVACY PARADOX is self-evident. But increasingly, the bulk of the data gathered
The Privacy Paradox describes people’s intention versus about individuals is collected through a variety of passive
their behavior: people say they care about privacy but behave means, or is acquired from third parties, and these sources
as if they don’t. In [1] Barnes noted the phenomenon among must be disclosed in each company’s privacy statement.
young adults in social media who described concerns about Privacy policies have emerged to be the de facto transparency
privacy and yet willingly entered vital personal information boards that service providers use to communicate their
into social networks (address, phone number, photos of information processing practices. Moreover, privacy policies
children etc.). Internet psychologist Anders Colding Jorgensen also serve as binding legal agreements between website
suggests that people are ambivalent about social media because operators and their users [4]. For example, privacy statements
their greater concern is not being noticed, and therefore users that cover websites or online services need to include a
tradeoff their privacy concerns versus being known [2]. The detailed discussion of how data is collected passively through
same phenomenon appears in other websites like blogs, the use of cookies [5]. Cookies are small text files that
forums, recruitment agencies etc. Whilst users may still be websites and online services can store on the computer or
willing to share their data, GDPR gives them the right to know other device that connects to the site or service in order to
remember information. This piece of legislation has caused place between the parties. Similarly, if a processor uses
websites across the EU to display cookie consent notices, often another organization (i.e. a sub-processor) to help it process
referred to as cookie banners – boxes or banners informing personal data for a controller, it needs to have a written
users about the use of cookies by the website and associated contract in place with that sub-processor [6].
third parties. These notices may explicitly ask users for their Contracts must define:
consent or interpret a user’s continued website use as implied the subject matter and duration of the processing
consent. This action applies to any kind of information stored the nature and purpose of the processing
on the user’s system even if it does not contain any personal the type of personal data and categories of data
information. In case it does, consent according to GDPR rules subject
is also required, though the two types then may be merged. the controller’s obligations and rights
B. Data Processing
Contracts must also include specific terms or clauses
According to Article 4, data processing includes any
regarding:
operation or set of operations which is performed on personal
data or on sets of personal data, whether or not by automated appropriate security measures
means, such as collection, recording, organization, structuring, any use of sub-processors
storage, adaptation or alteration, retrieval, consultation, use, data subjects’ rights
disclosure by transmission, dissemination or otherwise making end-of-contract provisions
available, alignment or combination, restriction, erasure or audit and inspection reports
destruction[3]. The regulation introduces seven principles,
listed in Table1, to be followed when processing personal data.
E. Data Protection Officer (DPO)
1) Table 1. The seven basic principles in the GDPR
When the “core activities” of an organization consist of
“processing operations which, by virtue of their nature, their
scope and/or their purposes, require regular and systematic
monitoring of data subjects on a large scale” or “processing on
a large scale of special categories of data pursuant to Article 9
and personal data relating to criminal convictions and offences
referred to in Article 10, the GDPR requires from those
organizations to appoint a data protection officer (DPO). The
C. Data Controllers DPO may be an employee or contractor. Where a DPO is
appointed, that person’s contact information must also be
The privacy statement must identify the data controller,
included in the privacy statement. DPO’s tasks include
which is the entity that ultimately determines how the data
advising the organization about the GDPR, monitoring
will be used [3]. For example, if a vendor hosts a website on
compliance and training staff. A DPO must report to the
behalf of an organization, the organization will be the data
highest level of management, operate independently, and have
controller and the vendor will be a data processor. Thus, the
adequate resources to carry out their tasks [6].
privacy statement for that website must identify the
organization as the controller (although it may also state that IV. GDPR MAIN CHANGES
the vendor is hosting the website on behalf of the
Although the key principles of data privacy still hold true to
organization). Within a corporate family of a parent
the previous directive, many changes have been proposed to
corporation and a number of controlled subsidiaries and
the regulatory policies.
affiliates, the parent will typically be the data controller.
However, there are some cases in which a subsidiary will be A. Data protection by design and default
the data controller and the corporate parent will be a data The GDPR requires from companies to put in place
processor. Regardless, the privacy statement should describe appropriate technical and organizational measures to
those relationships and clarify the role that each one plays. As implement the data protection principles and safeguard
an example, in the context of an acquisition, the acquired individual rights. This is ‘data protection by design and by
company’s privacy statement should be updated promptly to default’. In essence, this means integrating data protection into
disclose the identity of the new corporate parent [5]. processing activities and business practices, from the design
D. Contracts stage right through the lifecycle. But this concept is not new.
Previously known as ‘privacy by design’, it has have always
The GDPR makes written contracts between controllers
been part of data protection law. The key change with the
and processors a requirement. These contracts must now
GDPR is that it is now a legal requirement. Data protection by
include specific minimum terms. These terms are designed to
design is about considering data protection and privacy issues
ensure that processing carried out by a processor meets all the
upfront in everything action. This provision means that
GDPR requirements, not just those related to keeping personal
companies will process only the absolutely necessary data for
data secure. Whenever a controller uses a processor to process
the completion of its business and limit access to personal data
personal data on their behalf, a written contract needs to be in
to only those employees needing the information to complete not having their records in order (Article 28), not notifying the
the process consented to by the data subject. This helps to supervising authority and data subject about a breach or not
ensure that companies comply with the GDPR’s fundamental conducting impact assessment. It is important to note that these
principles and requirements, and forms part of the focus on rules apply to both controllers and processors which mean that
accountability [6]. ‘clouds’ are not exempt from GDPR enforcement Some have
gone so far as to conclude that analytical and other secondary
B. Increased Territorial Application Scope uses of data are impractical, if not impossible or illegal, under
Arguably the biggest change to the regulatory landscape of the GDPR .
data privacy comes with the extended jurisdiction of the E. Controlled Linkable Data and the GDPR
GDPR, as it applies to all companies processing the personal
The onset of the GDPR regime creates a significant
data of data subjects residing in the Union, regardless of the
dilemma for all global data controllers and processors: either
company’s location. Previously, territorial applicability of the
comply with the GDPR and its “data protection by default,” but
directive was ambiguous and referred to data process ‘in endure significant limits on data use and data value – or subject
context of an establishment’. This topic has arisen in a number oneself to the possibility of debilitating fines as mentioned in
of high profile court cases. GDPR makes its applicability very the previous paragraph. In [11] the authors describe and how a
clear – it applies to the processing of personal data by new technical approach to de-identification – “Controlled
controllers and processors in the EU, regardless of whether the Linkable Data” – allows data use and the unlocking of data
processing takes place in the EU or not. The GDPR also value in a way that enables compliance with the GDPR, all
applies to the processing of personal data of data subjects in the while enhancing individual data subject privacy.
EU by a controller or processor not established in the EU,
where the activities relate to: offering goods or services to EU F. Data Analytics under the GDPR
citizens (irrespective of whether payment is required) and the Gartner predicts that by 2020, more than 40% of enterprise
monitoring of behavior that takes place within the EU. Non-EU revenue will come from digital business. Similarly, IDC
businesses processing the data of EU citizens also have to forecasts that by 2020, 50% of the Global 2000 will see a
appoint a representative in the EU [7]. majority of their business come from their ability to create
digitally-enhanced products, services, and experiences. Yet
C. Breach notifications many data-driven operations underlying these projections rely
A ‘personal data breach’ means a breach of security leading on data analytics that are increasingly subject to restrictions on
to the accidental or unlawful destruction, loss, alteration, lawful data use such as contained in the GDPR and similar
unauthorized disclosure of, or access to, personal data evolving regulations. The GDPR is much more than a law
transmitted, stored or otherwise processed under the pertaining to EU personal data – it is the leading wave of
responsibility of the European University Institute (EUI) as a transformational data processing restrictions evolving around
controller [1]. Every personal data breach is a security incident the globe and its three key points are [10]:
and depending on the circumstances, it can concern a breach of
confidentiality, integrity or availability of personal data, as well 1. The GDPR Increases Options for Organizations to
as any combination of these. A personal data breach could, if Process Data: Legitimate Interest is an available legal
not addressed in an appropriate and timely manner, result in basis to enable GDPR compliant data analytics,
physical, material or non-material damage to natural persons. artificial intelligence (AI), machine learning and digital
Among the causes of data breaches are negligence, accident or transformation.
technical failure, and intentional acts by internal or external 2. Support for Global Data-Driven Business Beyond
actors [8]. Compliance with the GDPR requires companies to GDPR Compliance: Pseudonymisation, as newly
notify all data subjects that a security breach has occurred defined under the GDPR, supports the separation of the
within 72 hours of first discovering it [1]. The method of this information value of data from the re-identifiability of
notification will include as many forms as deemed necessary to individuals as necessary to support innovation for data-
disseminate the information in a timely manner, including driven businesses
email, telephone message, and public announcement. 3. Controlled Re-Linking of Data Increases the Value
D. Penalties of Data Analytics: The ability of pseudonymisation to
help support re-linking of data about individuals under
It is prescribed that organizations that fail to comply with controlled conditions distinguishes it from
GDPR can be fined up to 4% of annual global turnover or €20 anonymisation, general statistical analysis, or complete
Million (whichever is greater) plus additional significant
de-Identification, which are not designed to support re-
obligations, liability, and exposure [3][10]. This is the
linkability of data.
maximum fine that can be imposed for the most serious
infringements e.g. not having sufficient customer consent to
process data or violating the core of Privacy by Design G. Protection of children
concepts. Fines depend on the severity of the breach and on
The GDPR contains provisions intended to enhance the
whether the company is deemed to have taken compliance and
regulations around security in a serious enough manner. There protection of children’s personal data and to ensure that
is a tiered approach to fines e.g. a company can be fined 2% for children are addressed in plain clear language that they can
understand. Information related to children should be treated [2] Anders Colding‐Jørgensen, “Er Det OK at vi Lige Giver USA’s
Efterretningstjeneste Adgang Til Dine Børns DNA Profiler?”, 2015
with utmost caution, because they may be less aware of the
[3] The European Parliament and the Council of the Europeann Union,
risks involved. Children merit specific protection when their General Data Protection Regulation (EU) 2016/679, April 2016
personal data are being used for marketing purposes or creating [4] S. Wilson, F. Schaub, A. A. Dara, F. Liu, S. Cherivirala, P. G. Leon, M.
user profiles [6]. For children under the age of 16, consent can S. Andersen, S. Zimmeck, K. M. Sathyendra, N. C. Russell, “The
only be given by the holder of parental responsibility but Creation and Analysis of a Website Privacy Policy Corpus”, 2016
Member States may provide by law for a lower age, provided [5] Mike Hintze, “Privacy Statements Under the GDPR”, 42 SEATTLE U.
that such lower age is not below 13 years (Article 8). L. REV. 1129 , 2019
[6] “Guide to the General Data Protection Regulation (GDPR)”,
V. CONCLUSION Information Commissioner’s Office (ico), 2018
[7] Retrieved from [Link]
Taking into consideration all the above traits, the GDPR
[8] European Data Protection Supervisor (EDPS), “Guidelines on personal
turns out to be a major step forward for enhancing the privacy data breach notification For the European Union Institutions and
of EU citizens, harmonizing data protection rules across Bodies”, 2018
Member States, and promoting privacy and security as core [9] European Symposium on Security and Privacy Workshops
aspects of the European online personal data industry with (EuroS&PW), London, 2018
overall positive effect on the transparency of websites. [10] G. Le Grand, J. Polonetsky, G. LaFever, “GDPR Data Analytics
Webinar”, Anonos, 2017
VI. REFERENCES [11] M. Hintze and G. LaFever, “Meeting Upcoming GDPR Requirements
While Maximizing the Full Value of Data Analytics”, January 2017
[1] Susan B. Barnes, “A Privacy Paradox: Social Networking in the United
States”, 2006