0% found this document useful (0 votes)
36 views10 pages

GDPR Compliance Cheat Sheet Guide

The GDPR is a comprehensive regulation consisting of 99 articles and 173 recitals that governs data protection and privacy for individuals within the EU and extends to non-EU companies interacting with EU citizens. It establishes core principles for data processing, individual rights, corporate obligations, and enforcement mechanisms, emphasizing accountability and transparency. Companies must integrate data protection into their operations and comply with legal bases for processing personal data while being aware of the regulation's extraterritorial reach and enforcement penalties.

Uploaded by

pdj0516
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
36 views10 pages

GDPR Compliance Cheat Sheet Guide

The GDPR is a comprehensive regulation consisting of 99 articles and 173 recitals that governs data protection and privacy for individuals within the EU and extends to non-EU companies interacting with EU citizens. It establishes core principles for data processing, individual rights, corporate obligations, and enforcement mechanisms, emphasizing accountability and transparency. Companies must integrate data protection into their operations and comply with legal bases for processing personal data while being aware of the regulation's extraterritorial reach and enforcement penalties.

Uploaded by

pdj0516
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

GDPR Deep-Dive Cheat Sheet

🎯 Core Structure
99 Articles + 173 Recitals (interpretive guidance)

Effective: May 25, 2018

Replaced: Data Protection Directive (DPD, 1995)

🌍 Where It Applies (Extraterritorial Reach)


Applies to:

1. Companies established in the EU (regardless of where data is processed)

2. Non-EU companies that:


Offer goods/services to EU persons, OR

Monitor behavior of EU persons

Red flags you're covered:

Website in EU language

Accepting EU currency

Mentioning EU customers

Not just having an accessible website

📊 What It Covers
Personal Data (Broad Definition)
ANY info relating to an identified or identifiable natural person

Includes: names, IDs, location data, online identifiers, genetic data, biometric data

NOT just "personally identifying information" (narrower US concept)

Processing (Extremely Broad)


Basically anything you do with data:
Collection, recording, storage, retrieval, use, disclosure, transmission, deletion, etc.

Special Category Data (Extra Protected)


Racial/ethnic origin

Political opinions

Religious/philosophical beliefs

Trade union membership

Genetic data

Biometric data (for identification)

Health data

Sex life/sexual orientation

⚖️ The Two Fundamental Rights


1. Privacy (Article 7 of Charter)
Right to private/family life, home, communications

Similar to US privacy concepts

About creating barriers and opacity

2. Data Protection (Article 8 of Charter)


Separate and distinct from privacy

About transparency and process

Rules for the game when data is processed

NOT absolute—balanced against other rights

🔑 Core Principles (Article 5)


1. Lawfulness - must have legal basis for processing

2. Transparency - clear about what you're doing

3. Purpose Limitation - collect for specific purposes only

4. Data Minimization - only collect what you need


5. Accuracy - keep data correct and current

6. Storage Limitation - don't keep data longer than necessary

7. Integrity & Confidentiality - keep it secure

8. Accountability - prove your compliance

✅ Six Legal Bases for Processing (Article 6)


NOT just consent! You need ONE of these:

1. Consent - freely given, specific, informed, unambiguous

2. Contract - necessary to perform a contract

3. Legal Obligation - required by law

4. Vital Interests - protect life of person

5. Public Interest - task in public interest/official authority

6. Legitimate Interest - your interests (balanced against individual rights)

Why companies prefer legitimate interest over consent:

Consent can be withdrawn anytime

Consent requirements are strict

More control with balancing tests

👤 Individual Rights (Articles 12-23)


Core Rights:
Right to be informed - transparency about processing

Right of access - see what data is held (Subject Access Request)

Right to rectification - correct inaccurate data

Right to erasure - "right to be forgotten" (with exceptions)

Right to restrict processing - limit what's done with data

Right to data portability - get data in usable format


Right to object - challenge processing

Rights re: automated decision-making - human review of automated decisions

Key Points:
Rights have exceptions (not absolute)

Often involve balancing tests

Apply to third-party data holders (not just direct relationships)

Can be exercised by NGOs on behalf of individuals (collective redress)

🏢 Corporate Obligations
Two Entity Types:
Data Controller

Determines purposes and means of processing

Most obligations fall here

Can be joint controllers

Data Processor

Processes on behalf of controller

Has obligations under GDPR (unlike DPD)

Must follow controller instructions

Major Corporate Requirements:

1. Accountability (Article 5(2))

Must demonstrate compliance

Not just comply, but prove it

2. Records of Processing (Article 30)

Maintain detailed records of all processing activities

3. Data Protection by Design & Default (Article 25)

Build data protection into tech and processes


Examples: pseudonymization, data minimization

Minimize data collected by default

4. Data Protection Impact Assessment (DPIA) (Article 35)

Required for "high-risk" processing:


Large-scale processing of special category data

Large-scale systematic monitoring of public places

Automated decision-making with legal effects

Must consult regulator for particularly risky processing

5. Data Protection Officer (DPO) (Article 37)

Required for:
Public authorities

Large-scale systematic monitoring

Large-scale processing of special category data

Must be independent expert

Reports to highest management level

Monitors compliance, advises, liaises with regulators

6. Breach Notification (Articles 33-34)

Notify DPA within 72 hours of becoming aware

Notify individuals if high risk to rights/freedoms

🌐 International Data Transfers (Articles 44-50)


The Problem:
Cannot transfer data to countries without "adequate" data protection

Solutions:
1. Adequacy Decision - EU Commission approves country
Approved: Argentina, Canada (commercial), Israel, Japan, New Zealand, Switzerland, Uruguay, UK
(post-Brexit), others
2. Appropriate Safeguards:
Standard Contractual Clauses (SCCs)

Binding Corporate Rules (BCRs) - within same company group

Certifications

US-EU Situation:
Safe Harbor (2000-2015) - invalidated in Schrems I

Privacy Shield (2016-2020) - invalidated in Schrems II

Current: Must use SCCs or other mechanisms, but complicated by US surveillance laws

💰 Enforcement & Penalties


Fines (Article 83):
Up to €20 million OR 4% of global annual turnover (whichever is higher)

Lower tier: €10 million or 2%

Factors Considered:
Nature, gravity, duration of infringement

Intentional or negligent

Actions taken to mitigate damage

Cooperation with authorities

Previous infringements

Data Protection Authorities (DPAs):


Each Member State has one

Investigate complaints

Conduct audits

Issue guidance

Coordinate through European Data Protection Board (EDPB)

🔍 How to Interpret the GDPR


Hierarchy of Sources:
1. GDPR Text (99 Articles) - the actual law

2. Recitals (173) - interpretive guidance (not law itself)

3. EDPB Guidelines - coordinated regulator opinions


Formerly Article 29 Working Party Guidelines

Not hard law but highly influential

4. National DPA Guidance - country-specific interpretation


UK ICO is particularly detailed

France CNIL, Irish DPC, Dutch AP, etc.

5. CJEU Cases - Court of Justice of the European Union


Final word on EU law

Interprets GDPR and Charter rights

6. National Court Cases - implementing GDPR domestically

Important CJEU Cases:


Google Spain (2014) - established right to be forgotten under DPD

Schrems I (2015) - invalidated Safe Harbor

Schrems II (2020) - invalidated Privacy Shield

Google v. CNIL (2019) - right to be forgotten is territorial, not global

❌ Common Misconceptions
Myth vs. Reality:
MYTH: GDPR is all about consent REALITY: Consent is 1 of 6 legal bases; legitimate interest is often
preferred

MYTH: GDPR is just notice-and-choice REALITY: It's a comprehensive compliance regime with corporate
governance requirements

MYTH: Individuals have absolute control REALITY: Rights are balanced against other interests through
proportionality analysis
MYTH: GDPR creates property rights in data REALITY: It creates fundamental human rights protections, not
property ownership

MYTH: You can use a checklist for compliance REALITY: GDPR is a process requiring ongoing risk
assessment and balancing

MYTH: GDPR only applies to EU companies REALITY: Extraterritorial reach covers many non-EU
companies

📚 Related EU Laws (Not GDPR)


ePrivacy Directive (2002/2009)
Cookie consent rules

Communications privacy

Being replaced by ePrivacy Regulation (still in draft)

Law Enforcement Directive (LED)


Data protection in criminal justice context

Separate from GDPR

Consumer Rights Directive


Business-to-consumer contracts

Cancellation rights, pre-purchase info

e-Commerce Directive
Intermediary liability

Electronic contracts

🎓 Key Differences: US vs. EU Approach


Aspect US Approach EU/GDPR Approach

Coverage Sectoral (HIPAA, COPPA, etc.) Omnibus (all personal data)

Basis Notice & choice, consumer protection Fundamental rights, data protection

Scope Direct consumer relationships Follows the data (includes 3rd parties)

Rights Mostly negative (restrict govt) Positive & negative (services + restrictions)
Aspect US Approach EU/GDPR Approach

Consent Often sufficient One of six bases, strictly defined

Enforcement FTC, state AGs, sectoral DPAs + courts + private actions

🔧 Practical Tips for Compliance


1. Don't rely only on consent - explore legitimate interest

2. Document everything - accountability requires proof

3. Conduct DPIAs for high-risk processing

4. Appoint a DPO if required (and maybe even if not)

5. Build in data protection from the start (by design)

6. Train your staff - compliance is organization-wide

7. Have breach response plan ready (72-hour deadline)

8. Review third-party processors - you're still responsible

9. Check national laws - GDPR allows Member State variations

10. Stay updated - follow EDPB guidelines and DPA guidance

📖 Essential Resources
Official Sources:
GDPR Text: [Link]

EDPB Guidelines: [Link]

UK ICO Guide: [Link]

CJEU Cases: [Link]

Organizations:
IAPP (International Association of Privacy Professionals)

European Data Protection Board (EDPB)

National DPAs (each Member State)


Publications:
European Data Protection Law Review

International Data Privacy Law Journal

Handbook of European Data Protection Law (annual, free download)

🎯 Bottom Line
The GDPR is:

A fundamental rights-based regulation

About corporate accountability as much as individual rights

A process, not a checklist

Vague by design (collaborative governance)

Backed by serious enforcement mechanisms

The GDPR is NOT:

Primarily consent-based

Just about individual control

Creating property rights in data

Easy to automate or checklist

Going away anytime soon

Strategic takeaway: Companies must build data protection into their culture, infrastructure, and decision-
making processes—not just bolt on compliance measures.

You might also like