0% found this document useful (0 votes)
27 views3 pages

Key GDPR Definitions Explained

This document provides key definitions related to the General Data Protection Regulation (GDPR), including terms such as Personal Data, Data Subject, Data Controller, and Data Processor. It also highlights Special Categories of Personal Data that require extra safeguards and mentions the role of Supervisory Authorities in enforcing GDPR compliance. Additionally, it defines profiling and its implications under GDPR.

Uploaded by

mavenmj
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
27 views3 pages

Key GDPR Definitions Explained

This document provides key definitions related to the General Data Protection Regulation (GDPR), including terms such as Personal Data, Data Subject, Data Controller, and Data Processor. It also highlights Special Categories of Personal Data that require extra safeguards and mentions the role of Supervisory Authorities in enforcing GDPR compliance. Additionally, it defines profiling and its implications under GDPR.

Uploaded by

mavenmj
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

GDPR Key Definitions

INTRODUCTION
This document contains key definitions for some of the terms and jargon

you might come across in a GDPR context. This is not intended to be an

exhaustive list of GDPR definitions and, where technical terms are

explained in the course lectures, they are not generally duplicated here.

Personal Data (also Personally Identifiable Data)​ - any information that

is to do with an identifiable person. The definition of Personal Data under

the GDPR is wide. For example, personal data might include a wide range

of information such as names, addresses, social media “likes”, hair colour,

voting records and images of the person.

Data Subject ​- any person to whom Personal Data may relate.

Data Controller ​- any person or organisation that decides that personal

data is to to be processed, and determines how and why that processing

should take place is considered a Data Controller. Any Data Controller may

process personal data itself or may instruct Data Processors to work on

1 © Innovation Works UK Ltd


their behalf; in either case, the Data Controller is responsible for ensuring

that processing is in line with the GDPR.

Data Processor ​- any person or organisation who processes personal data

on behalf of a Data Controller will be considered a Data Processor. The

GDPR considers that Data Processors are always working under the

instruction of a Data Controller.

Special Categories of Personal Data ​- specific categories of personal data

that are considered to have extra sensitivity and therefore require

additional safeguards. Special Personal Data includes information such as

health, sexual preferences and behaviour, political allegiances, criminal

convictions and trade union membership. This was previously defined as

sensitive personal data under the Data Protection Act.

Supervisory Authority ​- regulatory organisations that exist in each EU

member state to enforce the correct implementation of the GDPR. In the

UK, the Information Commissioner's Office (ICO) is the Supervisory

Authority.

Profiling ​- the use of automated data processing to determine or predict

characteristics that relate to individuals from their data. Any activity that

compares personal data against a checklist in order to allocate them to a

group of similar people, such as identifying marketing segments, is likely to

count as profiling. Profiling is subject to specific safeguards where this

2 © Innovation Works UK Ltd


produces legal or significant effects on the data subject.

3 © Innovation Works UK Ltd

Common questions

Powered by AI

Under GDPR, Personal Data encompasses much more than traditional identifiers like names or addresses. It includes any information related to an identifiable person, such as social media 'likes', hair color, and images, making the scope of what constitutes personal data broad and encompassing various modern data types.

GDPR classifies Special Categories of Personal Data based on their sensitivity, which includes data related to health, sexual preferences, political allegiances, and more. These require additional safeguards because they could lead to discrimination or affect an individual's privacy more significantly if mismanaged.

GDPR expands on the concepts from traditional Data Protection Acts by introducing 'Special Categories of Personal Data', requiring stricter safeguards than previously defined sensitive data. This includes more rigorous consent requirements and additional measures for data handling and processing transparency.

A Data Controller is responsible for determining the purposes and means of processing personal data. They must ensure that all processing activities are in line with GDPR regulations. This includes managing data protection measures, obtaining necessary consents from data subjects, and overseeing any data processors they engage to ensure compliance.

Supervisory Authorities in each EU member state are responsible for enforcing the correct implementation of GDPR. They serve as the regulatory bodies ensuring compliance and addressing grievances. The Information Commissioner's Office (ICO) serves this role in the UK.

Obtaining consent is crucial under GDPR as it legalizes the processing of personal data. It must be informed, specific, freely given, and unambiguous to protect data subjects' rights and ensure they have control over their personal data. This prevents unauthorized data usage and fosters transparency.

Data Controllers decide the purposes and methods of data processing, while Data Processors handle the data as per the controllers' instructions. GDPR makes Data Controllers responsible for ensuring processors comply with regulations, necessitating detailed contracts and strict oversight mechanisms to manage data privacy risks.

Profiling under GDPR involves automated processing of personal data to evaluate certain aspects of an individual. It is subject to specific safeguards, particularly when it produces legal or significant effects on individuals. This presents challenges such as ensuring fairness, avoiding discrimination, and protecting against breaches of privacy.

You might also like