A collection of fragments of understanding in the pursuit of deeper questions.
(Risk base approach, depending on the entity processing data (Hospitals, social networks, small online shops, the control has to be different according to the quantity and risk assessed).
Processing of Personal Data
Data Subject - Rights
Data Controller/Processor - Obligations
Right to Access
Right to Rectification (and Integration)
Right to Erasure The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay.
Right to Restriction of Processing (You're not interested in the erasure of information, but you are asking for a restriction of information) The data subject shall have the right to obtain from the controller restriction of processing where:
But: with the exception of storage, personal data shall only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest.
Right to Object (Similar to the right to erasure, you object that there has never been the consent to process data). The data subject shall have the right to object, on ground relating to his or her particular situation, at any time to the processing of personal data concerning him or her where processing is necessary for:
The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
Right to Object, the case of direct marketing Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.
Right to Data Portability (Important) The data subject shall have the right to receive the personal data concerning him or her, in a structured, commonly used and machine-readable format and have the right to transmit those data from the controller to a new controller, without hindrance (Without suffering any negative effect/obstacle), where:
Automated Individual Decision-Making, including Profiling The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
The right does not apply where the processing:
Risk-Based Approach
Data Protection by Design and by Default - Art. 25 GDPR Controllers must ensure that, both in the planning phase of processing activities and the implementation phase of any new product or service, data protection principles, and appropriate safeguards, are addressed and implemented.
Compliance with data protection law should not be an after-thought, but should be treated as a key issue in the planning and implementation of any new product or service that affects personal data.
Security of Processing Must be taken into account:
The controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia:
![]() |
![]() |
|---|
In assessing the appropriate level of security, account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful:
Data Breach
Data Breach Notification In the case of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it the controller shall notify the personal data breach to the competent supervisory authority. Unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken.
Data Breach Communication In the case of a personal data breach without undue delay and, where feasible**, not later than 72 hours** after becoming aware of it the controller shall notify the personal data breach to the competent supervisory authority and, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. The controller shall communicate the personal data breach to the data subject without undue delay.
Records of Processing Activities Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. Each processor and, where applicable, the processor's representative shall maintain a record of all categories of processing activities carried out on behalf of a controller.
Exemptions from the obligation to keep record of processing activities The obligation does not apply to an enterprise or an organization employing fewer than 250 persons, unless:
DPIA (Data Protection Impact Assessment) A DPIA is a process designed to:
DPIAs are important tools for accountability, as they help controllers to comply with GDPR requirments and to demonstrate that appropriate measures have been taken to ensure compliance (a process for building and demonstrating compliance).
(You conduct an assessment to define which is the risk, if you realize that the specific data processing has high risk, you have to ask to the supervisory authority consultation on the process of data processing).
Supervisory authorities shall establish and make public a list of the kind of processing operations which are subject to the requirement for a DPIA and of the kind of processing operations for which no DPIA is required.
Where a DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk, the controller shall consult the supervisory authority prior to processing. If the supervisory authority finds that the intended processing would infringe the GDPR, in particular where the controller has insufficiently identified or mitigated the risk, it shall, within up to eight weeks of receipt of the request for consultation (extended by six weeks, taking into account the complexity of the intended processing), provide written advice to the controller and, where applicable, to the processor. Those periods may be suspended until the supervisory authority has obtained information it has requested for the purposes of the consultation. Member State may in any case require controllers to consult with, and obtain prior authorisation from, the supervisory authority in relation to processing by a controller for the performance of a task carried out by the controller in the public interest, including processing in relation to social protection and public health.
Designation of the DPO (Data Protection Officer) The controller and the processor shall designate a data protection officer in any case where:
Who is the DPO? The DPO shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks provided by Article 39 GDPR. The DPO may be a staff member of the controller or processor, or fulfill the tasks on the basis of a service contract. The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority. (Contact point between data controllers/processors and supervisory authorities)
Position of the DPO
Transfer of Personal Data to Third Countries (Nothing changed from the Directive 95/46 to the GDPR)
Penalties "In order to strengthen the enforcement of the rules of this Regulation, penalties including administrative fines should be imposed for any infringement of this Regulation, in addition to, or instead of appropriate measures imposed by the supervisory authority pursuant to this Regulation. In a case of a minor infringement or if the fine likely to be imposed would constitute a disproportionate burden to a natural person, a reprimand may be issued instead of a fine". "Member States should be able to lay down the rules on criminal penalties for infringements of this Regulation, including for infringements of national rules adopted pursuant to and within the limits of this Regulation. Those criminal penalties may also allow for the deprivation of the profits obtained through infringements of this Regulation. However, the imposition of criminal penalties for infringements of such national rules and of administrative penalties should not lead to a breach of the principle of ne bis in idem, as interpreted by the Court of Justice".
Three possible "layers"
There exist two types of administrative fines: