## European Data Protection Law and Regulation: GDPR Core
The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is the cornerstone of European data protection law, directly applicable across all EU member states and the EEA. Its primary aim is to protect the fundamental rights and freedoms of natural persons, particularly their right to protection of personal data. The GDPR applies to organizations processing personal data of individuals in the EU/EEA, regardless of whether the processing takes place in the EU or not (extra-territorial scope via Article 3).
## Key Principles of Data Processing
Article 5 outlines the core principles that govern all personal data processing:
## Roles and Responsibilities
## Legal Bases for Processing
Article 6 specifies six lawful bases for processing personal data:
1. Consent of the data subject.
2. Contract: Necessary for the performance of a contract or to take steps at the data subject's request prior to entering a contract.
3. Legal obligation: Necessary for compliance with a legal obligation.
4. Vital interests: Necessary to protect the vital interests of the data subject or another natural person.
5. Public task: Necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
6. Legitimate interests: Necessary for the legitimate interests pursued by the controller or a third party, unless overridden by the interests or fundamental rights and freedoms of the data subject.
## Data Subject Rights
Individuals (data subjects) have several key rights under the GDPR:
## International Data Transfers
Transfers of personal data outside the EU/EEA are restricted unless an adequate level of protection is ensured. Mechanisms include adequacy decisions, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and specific derogations (e.g., explicit consent, necessity for contract).
## Enforcement and Supervisory Authorities
Each EU/EEA member state has one or more independent Supervisory Authorities (SAs) responsible for monitoring and enforcing the GDPR. SAs have investigative, corrective, and advisory powers, including the power to impose significant fines for non-compliance (up to €20 million or 4% of global annual turnover, whichever is higher).
## ePrivacy Directive
The ePrivacy Directive (Directive 2002/58/EC, often called the 'cookie law') complements the GDPR, focusing on privacy in electronic communications. It mandates consent for storing or accessing information on a user's device (e.g., cookies) and regulates unsolicited direct marketing (spam).
## Principles for Processing Personal Data
GDPR Article 5(1) sets out the core principles that govern all processing of personal data. These principles are fundamental and must be adhered to regardless of the lawful basis chosen.
Accountability (Article 5(2)): The controller is responsible for, and must be able to demonstrate compliance with, the principles outlined in Article 5(1). This is often considered the overarching seventh principle.
## Lawful Bases for Processing
For any processing of personal data to be lawful, it must be based on one of the six lawful bases specified in GDPR Article 6(1).
Processing special categories of personal data (e.g., health, racial origin, political opinions, religious beliefs, sexual orientation) is generally prohibited unless, in addition to an Article 6 lawful basis, one of the specific conditions under GDPR Article 9(2) is met (e.g., explicit consent, substantial public interest, legal claims, vital interests).
## Transparency and Information Provision to Data Subjects
The General Data Protection Regulation (GDPR) places a strong emphasis on transparency, a core principle articulated in Article 5(1)(a). This means personal data must be processed lawfully, fairly, and in a transparent manner in relation to the data subject. The goal is to empower individuals by ensuring they understand how their data is used, enabling them to exercise their rights effectively.
The GDPR distinguishes between information provided when data is collected directly from the data subject (Article 13) and when it is obtained from other sources (Article 14).
Common information to be provided (Articles 13 & 14):
Additional information for Article 14 (data not collected from data subject):
The information must be provided in a concise, transparent, intelligible, and easily accessible form, using clear and plain language, especially when addressing children. It should be in writing or by other means, including electronically, and must be free of charge. Controllers often use layered privacy notices, just-in-time notifications, or icons to achieve this.
While comprehensive, there are limited exceptions, primarily under Article 14. Information provision may not be required if the data subject already has the information, if providing it proves impossible or involves disproportionate effort, or if obtaining/disclosure is expressly laid down by Union or Member State law. Confidentiality obligations (e.g., professional secrecy) can also be a basis for exemption.
## Data Subjects' Rights under GDPR
The GDPR grants individuals (data subjects) specific, enforceable rights regarding their personal data. Controllers are legally obliged to facilitate the exercise of these rights transparently and promptly.
## Core Rights
## Controller Obligations & Key Considerations
Controllers must respond to data subject requests within one month (extendable by two months for complex cases). Requests are generally free of charge, but a reasonable fee may apply for manifestly unfounded or excessive requests. Controllers must verify the data subject's identity. These rights are not absolute and are subject to limitations (Article 23) for reasons like national security, public health, or crime prevention.
## Accountability under GDPR
Accountability is a cornerstone of the General Data Protection Regulation (GDPR), explicitly stated in Article 5(2). It mandates that data controllers are not only responsible for complying with the data processing principles (lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality) but must also be able to demonstrate that compliance. This proactive approach requires organisations to implement robust internal governance and processes.
## Key Mechanisms for Demonstrating Accountability
## International Data Transfers
The General Data Protection Regulation (GDPR) restricts transfers of personal data to countries outside the European Economic Area (EEA) and the UK (collectively, "third countries") to ensure that the level of protection afforded to data subjects is not undermined. Article 44 GDPR states that any transfer must only occur if the conditions laid down in Chapter V (Articles 44-50) are met.
## Mechanisms for Lawful Transfers
There are three primary mechanisms for legitimizing international data transfers:
An adequacy decision is made by the European Commission (or the UK Secretary of State for UK transfers) when a third country, a territory, or a specific sector within a third country is deemed to provide an adequate level of data protection essentially equivalent to that within the EEA/UK. If an adequacy decision exists, data can flow freely to that country without requiring further safeguards. Examples include Japan, New Zealand, and Switzerland. Adequacy decisions are regularly reviewed and can be revoked if the level of protection changes (e.g., the invalidation of the EU-US Privacy Shield by the Schrems II ruling).
In the absence of an adequacy decision, transfers can proceed if the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. The most common safeguards include:
When neither an adequacy decision nor appropriate safeguards are in place, transfers can occur based on derogations for specific situations. These are exceptions and must be used sparingly, typically for infrequent and non-repetitive transfers. Key derogations include:
The "compelling legitimate interests" derogation (Art. 49(1) second subparagraph) is highly restrictive and rarely applicable.
## Security of Processing (Article 32 GDPR)
GDPR Article 32 mandates that controllers and processors implement appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk. This requires a risk-based approach, considering the nature, scope, context, and purposes of processing, as well as the likelihood and severity of the risk to individuals' rights and freedoms.
Key considerations for TOMs include:
Examples of TOMs include pseudonymisation, encryption, access controls, and regular security audits. Processors are contractually obligated to assist controllers in meeting these security requirements.
## Data Breach Notification (Articles 33 & 34 GDPR)
A personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
## Supervisory Authorities (SAs)
Supervisory Authorities (SAs) are independent public authorities established by each Member State to monitor the application of the GDPR. Their primary role is to protect fundamental rights and freedoms of natural persons in relation to processing and to facilitate the free flow of personal data within the Union. SAs must act with complete independence, free from external influence.
SAs are endowed with significant powers to ensure compliance with the GDPR:
For cross-border processing, the one-stop shop mechanism designates a single lead SA to be the main point of contact for the controller or processor. This lead SA cooperates with other concerned SAs (where data subjects are affected in other Member States) to reach a joint decision, streamlining enforcement and ensuring consistent application of the GDPR.
## European Data Protection Board (EDPB)
The European Data Protection Board (EDPB) is an independent European body that contributes to the consistent application of the GDPR across the EU/EEA. It provides general guidance, opinions, and advice on data protection matters. The EDPB plays a crucial role in resolving disputes between SAs through the consistency mechanism, ensuring a harmonised interpretation and application of the GDPR.
## Administrative Fines and Remedies
GDPR introduces a two-tiered system for administrative fines:
When imposing fines, SAs consider factors like the nature, gravity, and duration of the infringement, intentionality, mitigation efforts, and prior infringements.
Data subjects have several avenues for redress: