GDPR - notes
General Data Protection Regulation (GDPR)
The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by
the European Union (EU) that took effect on May 25, 2018. It aims to enhance the protection of
personal data for EU citizens and residents, and to unify data protection laws across Europe. Here’s
a detailed overview of GDPR:
Key Provisions
1. Scope and Applicability:
- Territorial Scope: GDPR applies to organizations operating within the EU and those outside the
EU if they offer goods or services to, or monitor the behavior of, EU residents.
- Personal Data: Any information that relates to an identified or identifiable individual, such as
names, email addresses, and IP addresses.
2. Principles:
GDPR sets out seven key principles for processing personal data:
- Lawfulness, Fairness, and Transparency: Data must be processed lawfully, fairly, and
transparently.
- Purpose Limitation: Data should be collected for specified, legitimate purposes and not further
processed in a way incompatible with those purposes.
- Data Minimization: Data should be adequate, relevant, and limited to what is necessary for the
purposes for which it is processed.
- Accuracy: Data must be accurate and kept up to date.
- Storage Limitation: Data should be kept in a form that allows identification of individuals for no
longer than necessary.
- Integrity and Confidentiality: Data must be processed securely, protecting it against
unauthorized or unlawful processing and against accidental loss, destruction, or damage.
- Accountability: The data controller is responsible for ensuring and demonstrating compliance
with these principles.
3. Rights of Data Subjects:
GDPR grants several rights to individuals regarding their personal data:
Pedro Lúa Leblanc – GRC notes
GDPR - notes
- Right to Access: Individuals can request access to their personal data and obtain information
about how it is processed.
- Right to Rectification: Individuals can request corrections to inaccurate or incomplete data.
- Right to Erasure (Right to be Forgotten): Individuals can request the deletion of their data under
certain conditions.
- Right to Restrict Processing: Individuals can request the restriction of processing their data
under certain circumstances.
- Right to Data Portability: Individuals can request their data in a structured, commonly used, and
machine-readable format and transfer it to another organization.
- Right to Object: Individuals can object to the processing of their data for specific purposes,
including direct marketing.
- Rights Related to Automated Decision-Making: Individuals are protected against decisions
based solely on automated processing, including profiling.
4. Data Protection Officer (DPO):
- Appointment: Organizations that process large amounts of personal data or handle sensitive data
must appoint a Data Protection Officer to oversee compliance with GDPR.
5. Data Breach Notification:
- Notification: Organizations must notify the relevant data protection authority and affected
individuals of data breaches that pose a risk to the rights and freedoms of individuals, usually within
72 hours of becoming aware of the breach.
6. Fines and Penalties:
- Administrative Fines: Organizations can face substantial fines for non-compliance, up to €20
million or 4% of the annual global turnover, whichever is higher.
7. Cross-Border Data Transfers:
- Transfer Mechanisms: GDPR regulates the transfer of personal data outside the EU to ensure
that the level of protection is not undermined. Approved mechanisms include Standard Contractual
Clauses (SCCs) and Binding Corporate Rules (BCRs).
Official Reference
Pedro Lúa Leblanc – GRC notes
GDPR - notes
For the official text and resources related to GDPR, visit:
- GDPR Official Text: [EUR-Lex Access to European Union Law]([Link]
content/EN/TXT/?uri=CELEX%3A32016R0679)
- This page provides the full text of the GDPR regulation.
- European Commission GDPR Page: [European Commission - Data
Protection]([Link]
- This page offers an overview of GDPR, including guidance, factsheets, and additional resources.
- European Data Protection Board (EDPB): [EDPB GDPR Guidance]([Link]
work-tools/our-documents/guidelines_en)
- The EDPB provides guidelines, opinions, and best practices related to GDPR compliance.
Pedro Lúa Leblanc – GRC notes