0% found this document useful (0 votes)
5 views6 pages

Understanding Personal Data Under GDPR

The Article 29 Working Party (WP29) outlines four building blocks defining personal data: any information, relating to an identified or identifiable natural person, and the concept of natural person itself. It emphasizes that personal data can include both objective and subjective information, and pseudonymisation is encouraged to reduce risks while still being under GDPR scope. The document also details the roles of data controllers and processors, their responsibilities, and the implications of joint controllership in data processing activities.

Uploaded by

ru testisa
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views6 pages

Understanding Personal Data Under GDPR

The Article 29 Working Party (WP29) outlines four building blocks defining personal data: any information, relating to an identified or identifiable natural person, and the concept of natural person itself. It emphasizes that personal data can include both objective and subjective information, and pseudonymisation is encouraged to reduce risks while still being under GDPR scope. The document also details the roles of data controllers and processors, their responsibilities, and the implications of joint controllership in data processing activities.

Uploaded by

ru testisa
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Article 29 Working Party (WP29)

Within Opinion 4/2007, the WP29 set out four building blocks that comprise
the meaning of personal data. ese are:
‘Any information’
‘Relating to’
‘An identified or identifable’
‘Natural person’

1. First Blocks of any information

a) Nature
Examples of an objective statement are ‘[the employee] has a degree
in computer science’ or ‘[the employee]is the head of IT’. Subjective statements
are those that express someone’s opinions or an assessment. An example of a
subjective statement is ‘[the employee]is a good worker and merits promotion’.
Information does not need to be true to be considered personal data.
b) Content
Refers to the actual information that identifies or relates to a natural person.

Examples: name, IP address, location data, browsing history, photos, videos, health
records, opinions, biometric identifiers

c) And format
Structured or unstructured
For example, it includes information kept on paper in a hospital
clinic’s history, in a computer memory that records someone’s electronic bank
records, on a tape kept by a travel agent’s customer services department that
records tele Sphone calls for training purposes, or images recorded on closed-circuit TV
(CCTV)

2. Second building block: ‘relating to’


To an individual
Information that relates to objects, processes, or events may constitute personal
data under certain circumstances. For example, objects may belong to an
individual (e.g., an individual owns a car)
3. Third building block: ‘identified or identifiable’
● A person is identifiable when it’s possible, using reasonable means, to determine their
identity, even if they aren’t directly named.

● This includes indirect data that, when combined with other information (like location data
+ purchase habits), could reveal who they are

WP29 has recognised that, when the possibility of singling out an individual ‘does not exist
or is negligible’, the person should not be considered as identiable, and the
information is not personal data.

Pseudonymisation is defined in Article 4(5) of the GDPR as the processing of personal data in
such a way that the data cannot be attributed to a specific person without additional
information, provided that such information is kept separately and secured i.

Examples include replacing names with codes, encrypting identifiers, or hashing personal data,
while storing the key or lookup table separately

Encouraged best practice: Though not removing the data from GDPR scope,
pseudonymisation reduces risk and supports stronger compliance (data minimisation, purpose
limitation, security by desig

Anonimisation

Unnder Recital 26 of the GDPR, information is exempt from data protection rules if:

1. It cannot be linked to an identified or identifiable person,

2. Or it has been rendered anonymous such that re-identification is no longer


possible, taking into account all reasonably likely means—including future technologies
and cost

Fourth block ( Natural person)

● The GDPR explicitly states that citizenship or nationality is irrelevant. What matters is
whether a person is in the EU when their data is processed, and where the processing
occurs
● GDPR protects all individuals present in the EU, whether EU nationals, tourists,
business travelers, or refugees.
● Recital 27 states the GDPR does not
● apply to the personal data of deceased persons,
Let us look at Aggregation of data for statistical purposes is likely to result in non-
personal data.

Deintification data

What does the GDPR say

Sestive data are ‘personal data

revealing racial or ethnic origin,

political opinions,

religious or philosophical beliefs,

or trade union membership,

and the processing of genetic data,

biometric data for the purpose of uniquely

identifying a natural person,

data concerning health or data concerning a natural

person’s sexlife or sexual orientation’.

Genetic data

A medical photograph showing a patient's skin condition could be considered health


data, while a facial image processed using facial recognition technology could be
considered biometric data.

Controller and processor


● A data controller is the natural or legal person, public authority, agency, or any
● other body which alone or jointly with others determines the purposes and means
● of the processing of personal data.
● In other words, the data controller is the key decision maker with regard to
personal data. As a result, most of the responsibilities for compliance with the
GDPR fall on the data controller’s shoulders.
● For example, the data controller is responsible for providing information to the
data subject,
● ensuring processing has a legitimate basis
● and the data subject’s rights are honoured,
● carrying out data protection impact assessments (DPIA) in the case of high-risk
processing
● Ensuring there is appropriate security for data, and determining whether
notification to data protection authorities (DPAs) or data subjects is necessary in
case of a personal

Processor

● processor has some obligations under the GDPR


● (e.g., ensuring its international data transfers comply with the GDPR,
● having appropriate security in place,
● and notifying data controllers if there is a data breach),
● but it remains required by contract to process personal data only
● on documented instructions from the controller, who retains most liability under
● the GDPR.

How to identify them

Why is the processing taking place? Who has initiated it?

Alone or jointly with others’

● It is not unusual for companies to cooperate on projects and make decisions jointly,
particularly if they belong to the same corporate group.
● Several dierent entities may be controllers for the same processing, if they are all
involved in the relevant decision-making.
● It is also possible for an organisation to be a controller even if it is not making all the
decisions as to purposes and means.

Definition of processor

● existence of a data processor depends upon a decision by the controller to


delegate all or part of a processing activity to an external organisation or
Individuals.
● In the case of an organisation, it must be a separate legal entity.
Subsidiary can be a processor for another company in the same corporate group,
● but a department cannot be a data processor for another department in the same
company.
● Individuals acting under the direct authority of the controller, such as
temporary employees, are also not to be seen as data processors, as their
processing activity is viewed as part of the controller’s own organisation.

The GDPR requires the processor processes personal data only on the
controller’s instructions and a contract or a binding legal act regulating the

Guidelines also promote a more proactive approach to due diligence by


controllers to satisfy the requirement in Article 28

Consequences of joint controllership

arrangement’ between the controllers ‘should be made


● Should be available to the data subject’.
● DPR does not specify the type of contracts
● Data subjects should be clearly informed as to how to exercise their data subject rights.
● As a maer of good practice and administrative convenience, it can be useful for
joint controllers to designate one controller as a single point of contact for data protection
enquiries,
● However, if either a data subject or a DPA chooses to contact a dierent controller, they
still have the right to do so
● Guidelines 07/2020 recommend controllers use a contract or other legal binding act as
this will provide certainty
● GDpr recommend that is documents

What is processing

Any operation or set of operations which is performed on personal data or on sets


of personal data, whether or not by automated means, such as collection,
● recording,
● organisation,
● 7structuring,
● storage,
● adaptation or
● Alteration,
● retrieval,
● consultation,
● Use,
● disclosure byt ransmission,
● dissemination or otherwise making
● available,
● alignment or combination, r
● estriction,
● erasure or
● Destruction.

What is a data subjects

You might also like