Notes

← Back to home

A collection of fragments of understanding in the pursuit of deeper questions.

The General Data Protection Regulation - General Principles

EU GDPR - Timeline

  • January 2012, Commission Proposals
  • March 2014, EU Parliament, First Reading
  • June 2015, Council released its general approach
  • December 2015, EU General Data Protection Regulation was agreed
  • 2018 General Data Protection Regulation came into force.

An Overview

  • Directly applicable in all the Member States
  • Replaces the 1955 Data Protection Directive
  • Replaces, to the relevant extent, the national laws transposing the 1995 Directive
  • National laws applied until 25 May 2018; later, kept in force only in the provisions not covered nor replaced by the GDPR.

From a Directive to a Regulation?

  • From Harmonization there was a shift to uniformity.
  • Broad margins of maneuver for Member States.

(There are some specific areas of GDPR where States have margin to adopt some more specific provisions.) Lawfulness of processing - Article 6(2) GDPR

*Member States may **maintain or introduce more specific provisions to adapt the application of the rules of this Regulation with regard to processing for compliance with points (c) and (e) ***[see below] by determining more precisely specific requirements for the processing and other measures to ensure lawful and fair processing including for other specific processing situations.

(c) processing is necessary for compliance with a legal obligation to which the controller is subject; (e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

  • Conditions applicable to child's consent in relation to information society services (Art. 8 GDPR).

Member States may provide by law for a lower age for those purposes (16) provided that such lower age is not below 13 years. (Member States can lower the age of 16, but they can't go under 13).

  • Processing of special categories of personal data (Art. 9(2)(g) GDPR).

Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited.

Paragraph 1 shall not apply if one of the following applies: processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject;

Scope of Application

  • Material Scope (Art. 2 GDPR)

    • The GDPR applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.
    • There are some exceptions, from which the most important: by a natural person in the course of a purely personal or household activity. (The GDPR doesn't cover a situation like the citated).
  • Territorial Scope (Art. 3 GDPR) The GDPR applies:

  • to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not [Google Spain].

  • to the processing of data of data subjects located in the EU by a controller or processor not established in the EU, where the processing activities are related to:

    • the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
    • the monitoring of their behaviour as far as their behaviour takes place within the Union.
  • by a controller not established in the Union, but in a place where Member States' national law applies by virtue of public international law.

Personal and Non-Personal Data Personal Data: any information relating to an identified or identifiable natural person (Data Subject). Processing of Personal Data: any operation performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, storage, ... .

The principles of data protection should apply to any information concerning an identified or identifiable natural person. (The GDPR is applicable not only to information directly related to an identified person, but also to information that makes the person identifiable, such as IP Address).

Personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person.

To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used either by the controller or by another person to identify the natural person directly or indirectly.

To ascertain whether means are reasonably likely to be used to identify the natural person, account should be taken of all objective factors, such as the costs of and the amount of time required for identification, taking into consideration the available technology at the time of the processing and technological developments.

Pseudonymisation (Even with pseudonymization the GDPR is still applicable)

  • 'Pseudonymisation' means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that thepersonal data are not attributed to an identified or identifiable natural person.
  • WP29: Pseudonymisation consists of replacing one attribute (typically a unique attribute) in a record by another. The natural person is therefore still likely to be identified indirectly; accordingly, pseudonymisation when used alone will not result in an anonymous dataset.

Anonymization (GDPR is not applicable)

  • The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable.
  • The GDPR does not therefore concern the processing of such anonymous information, including for statistical or research purposes.

Controller: the natural or legal person, public authority, agency or any other body which determines the purposes and means of the processing of personal data. Processor: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller. (Processor is not acting by himself, but he is following the decisions of the controllers).

Principles

  • Lawfulness, fairness and transparency
  • Purpose limitation (limit to those necessary to the purposes).
  • Data minimization (limit to those necessary to the purposes).
  • Accuracy (Accurate data, up to date).
  • Storage limitation (data to be kept permitting identification of data subject no longer that the time needed for the purpose agreed).
  • Integrity and confidentiality
  • Accountability (Data Controller should be accountable and responsible, being able to show that treated data in compliance with the GDPR principles).

Lawfulness of Processing Main legal basis to process personal data is the Consent, which consists of:

  • Freely given
  • Specific and Informed
  • Unambiguous
  • Revocable
  • Provable

Consent is not required when the processing is necessary to:

  • The performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
  • Comply with a legal obligation to which the controller is subject.
  • The performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
  • Protect the vital interests of the data subject or of another natural person.
  • For the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.