A collection of fragments of understanding in the pursuit of deeper questions.
EU GDPR - Timeline
An Overview
From a Directive to a Regulation?
(There are some specific areas of GDPR where States have margin to adopt some more specific provisions.) Lawfulness of processing - Article 6(2) GDPR
*Member States may **maintain or introduce more specific provisions to adapt the application of the rules of this Regulation with regard to processing for compliance with points (c) and (e) ***[see below] by determining more precisely specific requirements for the processing and other measures to ensure lawful and fair processing including for other specific processing situations.
(c) processing is necessary for compliance with a legal obligation to which the controller is subject; (e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
Member States may provide by law for a lower age for those purposes (16) provided that such lower age is not below 13 years. (Member States can lower the age of 16, but they can't go under 13).
Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited.
Paragraph 1 shall not apply if one of the following applies: processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject;
Scope of Application
Material Scope (Art. 2 GDPR)
Territorial Scope (Art. 3 GDPR) The GDPR applies:
to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not [Google Spain].
to the processing of data of data subjects located in the EU by a controller or processor not established in the EU, where the processing activities are related to:
by a controller not established in the Union, but in a place where Member States' national law applies by virtue of public international law.
Personal and Non-Personal Data Personal Data: any information relating to an identified or identifiable natural person (Data Subject). Processing of Personal Data: any operation performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, storage, ... .
The principles of data protection should apply to any information concerning an identified or identifiable natural person. (The GDPR is applicable not only to information directly related to an identified person, but also to information that makes the person identifiable, such as IP Address).
Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person.
To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used either by the controller or by another person to identify the natural person directly or indirectly.
To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments.
Pseudonymisation (Even with pseudonymization the GDPR is still applicable)
Anonymization (GDPR is not applicable)
Controller: the natural or legal person, public authority, agency or any other body which determines the purposes and means of the processing of personal data. Processor: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller. (Processor is not acting by himself, but he is following the decisions of the controllers).
Principles
Lawfulness of Processing Main legal basis to process personal data is the Consent, which consists of:
Consent is not required when the processing is necessary to: