GDPR Deep-Dive Cheat Sheet
🎯 Core Structure
99 Articles + 173 Recitals (interpretive guidance)
Effective: May 25, 2018
Replaced: Data Protection Directive (DPD, 1995)
🌍 Where It Applies (Extraterritorial Reach)
Applies to:
1. Companies established in the EU (regardless of where data is processed)
2. Non-EU companies that:
Offer goods/services to EU persons, OR
Monitor behavior of EU persons
Red flags you're covered:
Website in EU language
Accepting EU currency
Mentioning EU customers
Not just having an accessible website
📊 What It Covers
Personal Data (Broad Definition)
ANY info relating to an identified or identifiable natural person
Includes: names, IDs, location data, online identifiers, genetic data, biometric data
NOT just "personally identifying information" (narrower US concept)
Processing (Extremely Broad)
Basically anything you do with data:
Collection, recording, storage, retrieval, use, disclosure, transmission, deletion, etc.
Special Category Data (Extra Protected)
Racial/ethnic origin
Political opinions
Religious/philosophical beliefs
Trade union membership
Genetic data
Biometric data (for identification)
Health data
Sex life/sexual orientation
⚖️ The Two Fundamental Rights
1. Privacy (Article 7 of Charter)
Right to private/family life, home, communications
Similar to US privacy concepts
About creating barriers and opacity
2. Data Protection (Article 8 of Charter)
Separate and distinct from privacy
About transparency and process
Rules for the game when data is processed
NOT absolute—balanced against other rights
🔑 Core Principles (Article 5)
1. Lawfulness - must have legal basis for processing
2. Transparency - clear about what you're doing
3. Purpose Limitation - collect for specific purposes only
4. Data Minimization - only collect what you need
5. Accuracy - keep data correct and current
6. Storage Limitation - don't keep data longer than necessary
7. Integrity & Confidentiality - keep it secure
8. Accountability - prove your compliance
✅ Six Legal Bases for Processing (Article 6)
NOT just consent! You need ONE of these:
1. Consent - freely given, specific, informed, unambiguous
2. Contract - necessary to perform a contract
3. Legal Obligation - required by law
4. Vital Interests - protect life of person
5. Public Interest - task in public interest/official authority
6. Legitimate Interest - your interests (balanced against individual rights)
Why companies prefer legitimate interest over consent:
Consent can be withdrawn anytime
Consent requirements are strict
More control with balancing tests
👤 Individual Rights (Articles 12-23)
Core Rights:
Right to be informed - transparency about processing
Right of access - see what data is held (Subject Access Request)
Right to rectification - correct inaccurate data
Right to erasure - "right to be forgotten" (with exceptions)
Right to restrict processing - limit what's done with data
Right to data portability - get data in usable format
Right to object - challenge processing
Rights re: automated decision-making - human review of automated decisions
Key Points:
Rights have exceptions (not absolute)
Often involve balancing tests
Apply to third-party data holders (not just direct relationships)
Can be exercised by NGOs on behalf of individuals (collective redress)
🏢 Corporate Obligations
Two Entity Types:
Data Controller
Determines purposes and means of processing
Most obligations fall here
Can be joint controllers
Data Processor
Processes on behalf of controller
Has obligations under GDPR (unlike DPD)
Must follow controller instructions
Major Corporate Requirements:
1. Accountability (Article 5(2))
Must demonstrate compliance
Not just comply, but prove it
2. Records of Processing (Article 30)
Maintain detailed records of all processing activities
3. Data Protection by Design & Default (Article 25)
Build data protection into tech and processes
Examples: pseudonymization, data minimization
Minimize data collected by default
4. Data Protection Impact Assessment (DPIA) (Article 35)
Required for "high-risk" processing:
Large-scale processing of special category data
Large-scale systematic monitoring of public places
Automated decision-making with legal effects
Must consult regulator for particularly risky processing
5. Data Protection Officer (DPO) (Article 37)
Required for:
Public authorities
Large-scale systematic monitoring
Large-scale processing of special category data
Must be independent expert
Reports to highest management level
Monitors compliance, advises, liaises with regulators
6. Breach Notification (Articles 33-34)
Notify DPA within 72 hours of becoming aware
Notify individuals if high risk to rights/freedoms
🌐 International Data Transfers (Articles 44-50)
The Problem:
Cannot transfer data to countries without "adequate" data protection
Solutions:
1. Adequacy Decision - EU Commission approves country
Approved: Argentina, Canada (commercial), Israel, Japan, New Zealand, Switzerland, Uruguay, UK
(post-Brexit), others
2. Appropriate Safeguards:
Standard Contractual Clauses (SCCs)
Binding Corporate Rules (BCRs) - within same company group
Certifications
US-EU Situation:
Safe Harbor (2000-2015) - invalidated in Schrems I
Privacy Shield (2016-2020) - invalidated in Schrems II
Current: Must use SCCs or other mechanisms, but complicated by US surveillance laws
💰 Enforcement & Penalties
Fines (Article 83):
Up to €20 million OR 4% of global annual turnover (whichever is higher)
Lower tier: €10 million or 2%
Factors Considered:
Nature, gravity, duration of infringement
Intentional or negligent
Actions taken to mitigate damage
Cooperation with authorities
Previous infringements
Data Protection Authorities (DPAs):
Each Member State has one
Investigate complaints
Conduct audits
Issue guidance
Coordinate through European Data Protection Board (EDPB)
🔍 How to Interpret the GDPR
Hierarchy of Sources:
1. GDPR Text (99 Articles) - the actual law
2. Recitals (173) - interpretive guidance (not law itself)
3. EDPB Guidelines - coordinated regulator opinions
Formerly Article 29 Working Party Guidelines
Not hard law but highly influential
4. National DPA Guidance - country-specific interpretation
UK ICO is particularly detailed
France CNIL, Irish DPC, Dutch AP, etc.
5. CJEU Cases - Court of Justice of the European Union
Final word on EU law
Interprets GDPR and Charter rights
6. National Court Cases - implementing GDPR domestically
Important CJEU Cases:
Google Spain (2014) - established right to be forgotten under DPD
Schrems I (2015) - invalidated Safe Harbor
Schrems II (2020) - invalidated Privacy Shield
Google v. CNIL (2019) - right to be forgotten is territorial, not global
❌ Common Misconceptions
Myth vs. Reality:
MYTH: GDPR is all about consent REALITY: Consent is 1 of 6 legal bases; legitimate interest is often
preferred
MYTH: GDPR is just notice-and-choice REALITY: It's a comprehensive compliance regime with corporate
governance requirements
MYTH: Individuals have absolute control REALITY: Rights are balanced against other interests through
proportionality analysis
MYTH: GDPR creates property rights in data REALITY: It creates fundamental human rights protections, not
property ownership
MYTH: You can use a checklist for compliance REALITY: GDPR is a process requiring ongoing risk
assessment and balancing
MYTH: GDPR only applies to EU companies REALITY: Extraterritorial reach covers many non-EU
companies
📚 Related EU Laws (Not GDPR)
ePrivacy Directive (2002/2009)
Cookie consent rules
Communications privacy
Being replaced by ePrivacy Regulation (still in draft)
Law Enforcement Directive (LED)
Data protection in criminal justice context
Separate from GDPR
Consumer Rights Directive
Business-to-consumer contracts
Cancellation rights, pre-purchase info
e-Commerce Directive
Intermediary liability
Electronic contracts
🎓 Key Differences: US vs. EU Approach
Aspect US Approach EU/GDPR Approach
Coverage Sectoral (HIPAA, COPPA, etc.) Omnibus (all personal data)
Basis Notice & choice, consumer protection Fundamental rights, data protection
Scope Direct consumer relationships Follows the data (includes 3rd parties)
Rights Mostly negative (restrict govt) Positive & negative (services + restrictions)
Aspect US Approach EU/GDPR Approach
Consent Often sufficient One of six bases, strictly defined
Enforcement FTC, state AGs, sectoral DPAs + courts + private actions
🔧 Practical Tips for Compliance
1. Don't rely only on consent - explore legitimate interest
2. Document everything - accountability requires proof
3. Conduct DPIAs for high-risk processing
4. Appoint a DPO if required (and maybe even if not)
5. Build in data protection from the start (by design)
6. Train your staff - compliance is organization-wide
7. Have breach response plan ready (72-hour deadline)
8. Review third-party processors - you're still responsible
9. Check national laws - GDPR allows Member State variations
10. Stay updated - follow EDPB guidelines and DPA guidance
📖 Essential Resources
Official Sources:
GDPR Text: [Link]
EDPB Guidelines: [Link]
UK ICO Guide: [Link]
CJEU Cases: [Link]
Organizations:
IAPP (International Association of Privacy Professionals)
European Data Protection Board (EDPB)
National DPAs (each Member State)
Publications:
European Data Protection Law Review
International Data Privacy Law Journal
Handbook of European Data Protection Law (annual, free download)
🎯 Bottom Line
The GDPR is:
A fundamental rights-based regulation
About corporate accountability as much as individual rights
A process, not a checklist
Vague by design (collaborative governance)
Backed by serious enforcement mechanisms
The GDPR is NOT:
Primarily consent-based
Just about individual control
Creating property rights in data
Easy to automate or checklist
Going away anytime soon
Strategic takeaway: Companies must build data protection into their culture, infrastructure, and decision-
making processes—not just bolt on compliance measures.