← Certified Information Privacy Professional/Europe (CIPP/E)
Test yourself →

European Data Protection Law and Regulation

## European Data Protection Law and Regulation: GDPR Core

The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is the cornerstone of European data protection law, directly applicable across all EU member states and the EEA. Its primary aim is to protect the fundamental rights and freedoms of natural persons, particularly their right to protection of personal data. The GDPR applies to organizations processing personal data of individuals in the EU/EEA, regardless of whether the processing takes place in the EU or not (extra-territorial scope via Article 3).

## Key Principles of Data Processing

Article 5 outlines the core principles that govern all personal data processing:

  • Lawfulness, fairness, and transparency: Data must be processed lawfully, fairly, and transparently.
  • Purpose limitation: Data collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
  • Data minimisation: Data must be adequate, relevant, and limited to what is necessary for the purposes.
  • Accuracy: Data must be accurate and, where necessary, kept up to date. Inaccurate data must be rectified or erased.
  • Storage limitation: Data must be kept for no longer than is necessary for the purposes for which it is processed.
  • Integrity and confidentiality: Data must be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and accidental loss, destruction, or damage, using appropriate technical or organisational measures.
  • Accountability: The data controller is responsible for, and must be able to demonstrate compliance with, these principles.

## Roles and Responsibilities

  • Data Controller: Determines the purposes and means of processing personal data.
  • Data Processor: Processes personal data on behalf of the controller.
  • Data Protection Officer (DPO): An independent expert appointed by some organizations to advise on GDPR compliance and act as a contact point for supervisory authorities and data subjects.

## Legal Bases for Processing

Article 6 specifies six lawful bases for processing personal data:

1. Consent of the data subject.

2. Contract: Necessary for the performance of a contract or to take steps at the data subject's request prior to entering a contract.

3. Legal obligation: Necessary for compliance with a legal obligation.

4. Vital interests: Necessary to protect the vital interests of the data subject or another natural person.

5. Public task: Necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

6. Legitimate interests: Necessary for the legitimate interests pursued by the controller or a third party, unless overridden by the interests or fundamental rights and freedoms of the data subject.

## Data Subject Rights

Individuals (data subjects) have several key rights under the GDPR:

  • Right to information (Articles 13-14)
  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure ('right to be forgotten') (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)
  • Rights in relation to automated decision-making and profiling (Article 22)

## International Data Transfers

Transfers of personal data outside the EU/EEA are restricted unless an adequate level of protection is ensured. Mechanisms include adequacy decisions, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and specific derogations (e.g., explicit consent, necessity for contract).

## Enforcement and Supervisory Authorities

Each EU/EEA member state has one or more independent Supervisory Authorities (SAs) responsible for monitoring and enforcing the GDPR. SAs have investigative, corrective, and advisory powers, including the power to impose significant fines for non-compliance (up to €20 million or 4% of global annual turnover, whichever is higher).

## ePrivacy Directive

The ePrivacy Directive (Directive 2002/58/EC, often called the 'cookie law') complements the GDPR, focusing on privacy in electronic communications. It mandates consent for storing or accessing information on a user's device (e.g., cookies) and regulates unsolicited direct marketing (spam).

  • The GDPR applies to organizations processing personal data of individuals in the EU/EEA, regardless of location (extra-territorial scope).
  • The seven core principles of data processing are lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and accountability.
  • A **Data Controller** determines processing purposes and means; a **Data Processor** processes data on behalf of the controller.
  • There are six lawful bases for processing personal data: consent, contract, legal obligation, vital interests, public task, and legitimate interests.
  • Data subjects have rights including access, rectification, erasure ('right to be forgotten'), and objection.
  • International data transfers require adequate protection, often via adequacy decisions, SCCs, or BCRs.
  • Supervisory Authorities (SAs) enforce the GDPR and can impose fines up to €20 million or 4% of global annual turnover.
  • The ePrivacy Directive complements GDPR, regulating cookies and direct marketing via electronic communications.
What is the primary aim of the GDPR?
To protect the fundamental rights and freedoms of natural persons, particularly their right to protection of personal data.
tap to reveal
Which GDPR Article outlines the core principles of data processing?
Article 5.
tap to reveal
What is the key difference between a Data Controller and a Data Processor?
A Data Controller determines the purposes and means of processing, while a Data Processor processes data on behalf of the controller.
tap to reveal
Name three lawful bases for processing personal data under GDPR Article 6.
Consent, contract, legal obligation, vital interests, public task, or legitimate interests (any three).
tap to reveal
What is the 'right to be forgotten' also known as?
The right to erasure (GDPR Article 17).
tap to reveal
What are two common mechanisms for lawful international data transfers under GDPR?
Adequacy decisions, Standard Contractual Clauses (SCCs), or Binding Corporate Rules (BCRs).
tap to reveal
What is the maximum potential fine for a serious GDPR violation?
€20 million or 4% of the organization's total worldwide annual turnover of the preceding financial year, whichever is higher.
tap to reveal
Which EU directive complements the GDPR by regulating cookies and direct marketing?
The ePrivacy Directive (also known as the 'cookie law').
tap to reveal

Principles and Lawful Bases for Processing

## Principles for Processing Personal Data

GDPR Article 5(1) sets out the core principles that govern all processing of personal data. These principles are fundamental and must be adhered to regardless of the lawful basis chosen.

  • Lawfulness, fairness, and transparency: Processing must be lawful, fair to the data subject, and transparent about how data is used.
  • Purpose limitation: Data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
  • Data minimisation: Personal data processed must be adequate, relevant, and limited to what is necessary for the purposes for which they are processed.
  • Accuracy: Personal data must be accurate and, where necessary, kept up to date. Inaccurate data must be erased or rectified without delay.
  • Storage limitation: Personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
  • Integrity and confidentiality (security): Personal data must be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.

Accountability (Article 5(2)): The controller is responsible for, and must be able to demonstrate compliance with, the principles outlined in Article 5(1). This is often considered the overarching seventh principle.

## Lawful Bases for Processing

For any processing of personal data to be lawful, it must be based on one of the six lawful bases specified in GDPR Article 6(1).

  • Consent (Art. 6(1)(a)): The data subject has given clear consent for processing their personal data for a specific purpose. Consent must be freely given, specific, informed, and unambiguous.
  • Contract (Art. 6(1)(b)): Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal Obligation (Art. 6(1)(c)): Processing is necessary for compliance with a legal obligation to which the controller is subject (e.g., tax law, employment law).
  • Vital Interests (Art. 6(1)(d)): Processing is necessary to protect the vital interests of the data subject or another natural person (typically used in life-or-death situations).
  • Public Task (Art. 6(1)(e)): Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (e.g., public authorities).
  • Legitimate Interests (Art. 6(1)(f)): Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. This requires a balancing test.

Special Categories of Data (Sensitive Data)

Processing special categories of personal data (e.g., health, racial origin, political opinions, religious beliefs, sexual orientation) is generally prohibited unless, in addition to an Article 6 lawful basis, one of the specific conditions under GDPR Article 9(2) is met (e.g., explicit consent, substantial public interest, legal claims, vital interests).

  • GDPR Article 5(1) outlines six core principles for processing personal data.
  • The Accountability principle (Art 5(2)) requires controllers to demonstrate compliance with GDPR.
  • All processing of personal data must have one of the six lawful bases under GDPR Article 6(1).
  • Valid consent must be freely given, specific, informed, and an unambiguous indication of wishes.
  • The Legitimate Interests basis requires a balancing test between the controller's interests and the data subject's rights.
  • Special Categories of Data (sensitive data) require both an Article 6 lawful basis and an Article 9(2) condition.
  • Public authorities cannot use Legitimate Interests when performing their tasks as a public authority.
  • Data Minimisation means collecting only data that is adequate, relevant, and necessary for the purpose.
What are the seven GDPR principles for processing personal data?
Lawfulness, fairness, transparency; Purpose limitation; Data minimisation; Accuracy; Storage limitation; Integrity & confidentiality; Accountability.
tap to reveal
What is the primary purpose of GDPR Article 6(1)?
To establish the six lawful bases required for processing personal data.
tap to reveal
Name the six lawful bases for processing under GDPR Article 6(1).
Consent, Contract, Legal Obligation, Vital Interests, Public Task, Legitimate Interests.
tap to reveal
When is 'Legitimate Interests' an appropriate lawful basis?
When processing is necessary for the legitimate interests of the controller (or third party), unless overridden by the data subject's fundamental rights and freedoms (requires a balancing test).
tap to reveal
What additional requirement applies when processing 'Special Categories of Data' (sensitive data)?
You need both a lawful basis under Article 6 AND a specific condition for processing special categories under Article 9(2).
tap to reveal
What does the 'Accountability' principle (Art 5(2)) require of controllers?
Controllers must be able to demonstrate compliance with the GDPR principles.
tap to reveal
What are the key characteristics of valid consent under GDPR?
Freely given, specific, informed, unambiguous indication of the data subject's wishes by statement or clear affirmative action.
tap to reveal
Can public authorities rely on 'Legitimate Interests' for processing?
No, not when performing their tasks as a public authority. They typically rely on Public Task or Legal Obligation.
tap to reveal

Transparency and Information Provision to Data Subjects

## Transparency and Information Provision to Data Subjects

The General Data Protection Regulation (GDPR) places a strong emphasis on transparency, a core principle articulated in Article 5(1)(a). This means personal data must be processed lawfully, fairly, and in a transparent manner in relation to the data subject. The goal is to empower individuals by ensuring they understand how their data is used, enabling them to exercise their rights effectively.

Key Information Requirements

The GDPR distinguishes between information provided when data is collected directly from the data subject (Article 13) and when it is obtained from other sources (Article 14).

Common information to be provided (Articles 13 & 14):

  • Identity and contact details of the controller and, where applicable, their representative.
  • Contact details of the Data Protection Officer (DPO), if appointed.
  • The purposes of processing and the legal basis for it (e.g., consent, contract, legitimate interest).
  • Where processing is based on legitimate interests, the specific interests pursued.
  • The recipients or categories of recipients of the personal data.
  • Details of international transfers (third countries or international organisations), including safeguards.
  • The retention periods for the data or the criteria used to determine them.
  • The existence of data subject rights: access, rectification, erasure, restriction of processing, objection, and data portability.
  • The right to withdraw consent at any time, if processing is based on consent.
  • The right to lodge a complaint with a supervisory authority.
  • Information on whether the provision of personal data is a statutory or contractual requirement and the consequences of not providing it.
  • The existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and envisaged consequences for the data subject.

Additional information for Article 14 (data not collected from data subject):

  • The categories of personal data concerned.
  • The source from which the personal data originated.

Form and Accessibility

The information must be provided in a concise, transparent, intelligible, and easily accessible form, using clear and plain language, especially when addressing children. It should be in writing or by other means, including electronically, and must be free of charge. Controllers often use layered privacy notices, just-in-time notifications, or icons to achieve this.

Exemptions and Limitations

While comprehensive, there are limited exceptions, primarily under Article 14. Information provision may not be required if the data subject already has the information, if providing it proves impossible or involves disproportionate effort, or if obtaining/disclosure is expressly laid down by Union or Member State law. Confidentiality obligations (e.g., professional secrecy) can also be a basis for exemption.

  • Transparency is a core GDPR principle, ensuring data subjects understand how their data is used (Article 5(1)(a)).
  • Controllers must provide specific information at the time of data collection (Article 13) or when data is not directly obtained from the data subject (Article 14).
  • Required information includes the controller's identity, processing purposes, legal basis, and data subject rights.
  • Data subjects must be informed of their right to lodge a complaint with a supervisory authority.
  • Information must be concise, transparent, intelligible, easily accessible, and in clear, plain language.
  • All required information must be provided free of charge to the data subject.
  • If processing relies on consent, the right to withdraw consent at any time must be communicated.
  • Exemptions for Article 14 include disproportionate effort or if the data subject already possesses the information.
What GDPR Article establishes transparency as a core principle?
Article 5(1)(a).
tap to reveal
When must information be provided to data subjects if data is collected directly from them?
At the time of data collection (Article 13).
tap to reveal
Name three pieces of information a controller must always provide to data subjects under GDPR.
Controller's identity, processing purposes, legal basis, data subject rights, DPO contact (any three).
tap to reveal
What are the key characteristics of the language used for information provision under GDPR?
Concise, transparent, intelligible, easily accessible, clear and plain language (especially for children).
tap to reveal
Under what circumstances might a controller be exempt from providing information when data is *not* collected directly from the data subject (Article 14)?
If the data subject already has the information, if it proves impossible or involves disproportionate effort, or if legally mandated confidentiality applies.
tap to reveal
What is the rule regarding charging data subjects for information provision?
It must be provided free of charge.
tap to reveal
What specific right related to consent must be communicated if processing is based on consent?
The right to withdraw consent at any time.
tap to reveal
What additional information must be provided under Article 14 (not collected from DS) compared to Article 13?
Categories of personal data concerned and the source of the personal data.
tap to reveal

Data Subjects' Rights

## Data Subjects' Rights under GDPR

The GDPR grants individuals (data subjects) specific, enforceable rights regarding their personal data. Controllers are legally obliged to facilitate the exercise of these rights transparently and promptly.

## Core Rights

  • Right to Information (Articles 13 & 14): Data subjects must be informed about data collection and use, including controller identity, processing purposes, legal basis, and retention periods.
  • Right of Access (Article 15): Individuals can request confirmation of processing, access to their data, and supplementary information (e.g., data categories, processing purposes).
  • Right to Rectification (Article 16): Data subjects can demand correction of inaccurate data or completion of incomplete data without undue delay.
  • Right to Erasure ("Right to be Forgotten") (Article 17): Individuals can request data deletion under specific conditions (e.g., data no longer necessary, consent withdrawn). This right is not absolute.
  • Right to Restriction of Processing (Article 18): Data subjects can request temporary cessation of processing, for instance, during accuracy verification or if processing is unlawful.
  • Right to Data Portability (Article 20): Allows individuals to receive their personal data (provided by them, processed by automated means based on consent/contract) in a structured, machine-readable format, and to transmit it to another controller.
  • Right to Object (Article 21): Individuals can object to processing based on legitimate interests or for direct marketing.
  • Rights related to Automated Decision-Making and Profiling (Article 22): Right not to be subject to decisions based solely on automated processing that significantly affect them, unless specific exceptions apply.

## Controller Obligations & Key Considerations

Controllers must respond to data subject requests within one month (extendable by two months for complex cases). Requests are generally free of charge, but a reasonable fee may apply for manifestly unfounded or excessive requests. Controllers must verify the data subject's identity. These rights are not absolute and are subject to limitations (Article 23) for reasons like national security, public health, or crime prevention.

  • Controllers must respond to data subject requests within one month, extendable by two months.
  • Data subjects generally do not pay a fee to exercise their rights.
  • The "Right to be Forgotten" (Erasure) is not an absolute right; exceptions apply.
  • Data Portability allows transfer of personal data provided by the data subject to another controller.
  • Controllers must always verify the identity of the data subject making a request.
  • Data subjects can complain to a supervisory authority if their rights are infringed.
  • The Right to Object is particularly strong for direct marketing purposes.
  • Limitations to data subjects' rights exist for reasons like national security or crime prevention.
What is the standard time limit for a controller to respond to a data subject request under GDPR?
One month from receipt, extendable by two further months for complex requests.
tap to reveal
Which GDPR right is also known as the "Right to be Forgotten"?
The Right to Erasure (Article 17).
tap to reveal
Under what conditions does the Right to Data Portability apply?
When processing is based on consent or contract, carried out by automated means, and applies to data provided by the data subject.
tap to reveal
Can a controller charge a fee for a data subject request?
Generally no, but a reasonable fee can be charged for manifestly unfounded or excessive requests.
tap to reveal
What crucial step must a controller take before fulfilling a data subject request?
Verify the identity of the data subject making the request.
tap to reveal
Which GDPR Article outlines the Right to Object?
Article 21.
tap to reveal
Name two common reasons why a data subject's right might be limited.
National security, public health, crime prevention, or protecting the rights and freedoms of others (Article 23).
tap to reveal
What is the purpose of the Right to Restriction of Processing?
To temporarily halt processing of personal data, for instance, while accuracy is verified or if processing is unlawful.
tap to reveal

Accountability

## Accountability under GDPR

Accountability is a cornerstone of the General Data Protection Regulation (GDPR), explicitly stated in Article 5(2). It mandates that data controllers are not only responsible for complying with the data processing principles (lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality) but must also be able to demonstrate that compliance. This proactive approach requires organisations to implement robust internal governance and processes.

## Key Mechanisms for Demonstrating Accountability

  • Data Protection Officer (DPO): Under Article 37, a DPO must be appointed by public authorities, organisations whose core activities involve large-scale systematic monitoring of individuals, or large-scale processing of special categories of data or criminal conviction data. The DPO's role (Article 39) includes informing and advising on GDPR obligations, monitoring compliance, cooperating with the supervisory authority, and acting as a contact point.
  • Records of Processing Activities (RoPA): Article 30 requires controllers and processors to maintain detailed records of their processing activities. This documentation typically includes the purposes of processing, categories of data subjects and personal data, recipients, international transfers, retention periods, and security measures. It is mandatory for organisations with 250+ employees, or if processing is likely to risk rights/freedoms, not occasional, or involves special categories/criminal convictions data.
  • Data Protection Impact Assessments (DPIAs): Article 35 mandates a DPIA when a type of processing is likely to result in a high risk to the rights and freedoms of natural persons. This typically applies to new technologies, large-scale processing of special categories of data, or systematic monitoring of public areas. A DPIA assesses the necessity, proportionality, risks, and measures to mitigate those risks. If a DPIA indicates an unmitigated high risk, prior consultation with the supervisory authority (Article 36) is required before processing.
  • Security of Processing and Breach Notification: Article 32 requires controllers and processors to implement appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk. This includes pseudonymisation, encryption, confidentiality, integrity, availability, and resilience. In the event of a personal data breach, controllers must notify the supervisory authority without undue delay, and where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals' rights and freedoms (Article 33). If the breach is likely to result in a high risk to individuals, they must also be notified without undue delay (Article 34).
  • Data Protection by Design and by Default: Article 25 requires organisations to implement appropriate technical and organisational measures, both at the time of determining the means for processing and at the time of the processing itself. This ensures that data protection principles are met from the outset (by design) and that, by default, only necessary data is processed.
  • GDPR Article 5(2) establishes the core principle of accountability: controllers must demonstrate compliance.
  • Data Protection Officers (DPOs) are mandatory for public authorities, large-scale systematic monitoring, or special category data processing.
  • Records of Processing Activities (RoPA) are required by Article 30 to document data processing operations.
  • Data Protection Impact Assessments (DPIAs) are mandatory for processing likely to result in a high risk to individuals' rights and freedoms.
  • Data breaches must be reported to the Supervisory Authority within 72 hours, unless unlikely to pose a risk.
  • Data Protection by Design and by Default (Article 25) requires proactive integration of data protection into systems and processes.
  • Prior consultation with the Supervisory Authority is necessary if a DPIA indicates an unmitigated high risk.
  • Appropriate Technical and Organisational Measures (TOMs) are essential for ensuring security of processing (Article 32).
What is the core principle of accountability under GDPR?
Article 5(2) states that the controller shall be responsible for, and be able to demonstrate compliance with, the data processing principles.
tap to reveal
When is a Data Protection Officer (DPO) mandatory?
For public authorities, organisations whose core activities involve large-scale systematic monitoring, or large-scale processing of special categories of data or criminal conviction data.
tap to reveal
What is the purpose of a Record of Processing Activities (RoPA)?
To document an organisation's data processing operations, demonstrating compliance with GDPR Article 30.
tap to reveal
When is a Data Protection Impact Assessment (DPIA) required?
When a type of processing is likely to result in a high risk to the rights and freedoms of natural persons (Article 35).
tap to reveal
What is the deadline for notifying the Supervisory Authority of a data breach?
Without undue delay, and where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk.
tap to reveal
Explain 'Data Protection by Design and by Default'.
Implementing appropriate technical and organisational measures to ensure data protection principles are met from the outset (by design) and that, by default, only necessary data is processed (Article 25).
tap to reveal
What is 'prior consultation' in the context of DPIAs?
If a DPIA indicates a high risk that cannot be mitigated, the controller must consult the supervisory authority before processing (Article 36).
tap to reveal

International Data Transfers

## International Data Transfers

The General Data Protection Regulation (GDPR) restricts transfers of personal data to countries outside the European Economic Area (EEA) and the UK (collectively, "third countries") to ensure that the level of protection afforded to data subjects is not undermined. Article 44 GDPR states that any transfer must only occur if the conditions laid down in Chapter V (Articles 44-50) are met.

## Mechanisms for Lawful Transfers

There are three primary mechanisms for legitimizing international data transfers:

1. Adequacy Decisions (Article 45)

An adequacy decision is made by the European Commission (or the UK Secretary of State for UK transfers) when a third country, a territory, or a specific sector within a third country is deemed to provide an adequate level of data protection essentially equivalent to that within the EEA/UK. If an adequacy decision exists, data can flow freely to that country without requiring further safeguards. Examples include Japan, New Zealand, and Switzerland. Adequacy decisions are regularly reviewed and can be revoked if the level of protection changes (e.g., the invalidation of the EU-US Privacy Shield by the Schrems II ruling).

2. Appropriate Safeguards (Article 46)

In the absence of an adequacy decision, transfers can proceed if the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. The most common safeguards include:

  • Standard Contractual Clauses (SCCs): These are pre-approved contractual clauses issued by the European Commission (or the UK Information Commissioner's Office for UK transfers). Data exporters and importers must sign these clauses, committing to protect data. Following Schrems II, organisations using SCCs must conduct a Transfer Impact Assessment (TIA) to evaluate the legal framework of the recipient country and determine if supplementary measures (e.g., encryption, pseudonymisation) are needed to ensure adequate protection against government access.
  • Binding Corporate Rules (BCRs): These are internal codes of conduct approved by supervisory authorities for multinational groups of undertakings or enterprises. They allow for intra-group transfers to third countries, provided they include all essential GDPR principles and are legally binding and enforceable.
  • Codes of Conduct (Art. 40) and Certification Mechanisms (Art. 42): These can also serve as appropriate safeguards if they include binding and enforceable commitments by the controller or processor in the third country.

3. Derogations for Specific Situations (Article 49)

When neither an adequacy decision nor appropriate safeguards are in place, transfers can occur based on derogations for specific situations. These are exceptions and must be used sparingly, typically for infrequent and non-repetitive transfers. Key derogations include:

  • The data subject has given explicit consent to the proposed transfer after being informed of the risks.
  • The transfer is necessary for the performance of a contract between the data subject and the controller, or for pre-contractual measures taken at the data subject's request.
  • The transfer is necessary for important reasons of public interest.
  • The transfer is necessary for the establishment, exercise, or defence of legal claims.
  • The transfer is necessary to protect the vital interests of the data subject or other persons, where the data subject is physically or legally incapable of giving consent.

The "compelling legitimate interests" derogation (Art. 49(1) second subparagraph) is highly restrictive and rarely applicable.

  • GDPR Articles 44-50 govern international data transfers to third countries.
  • Data transfers to third countries require an adequate level of protection for personal data.
  • Adequacy decisions by the European Commission (or UK) allow free data flow to approved countries.
  • Standard Contractual Clauses (SCCs) are the most common appropriate safeguard for transfers.
  • The Schrems II ruling mandates Transfer Impact Assessments (TIAs) for SCCs and BCRs.
  • Binding Corporate Rules (BCRs) are internal codes for intra-group data transfers within multinational companies.
  • Derogations under Article 49 are exceptions for specific, infrequent, and non-repetitive transfers.
  • Explicit consent is a common derogation, requiring the data subject to be informed of risks.
What GDPR articles govern international data transfers?
Articles 44-50.
tap to reveal
What is an 'adequacy decision' in the context of data transfers?
A decision by the European Commission (or UK) that a third country provides an adequate level of data protection, allowing free data flow.
tap to reveal
What are SCCs and why are they commonly used for data transfers?
Standard Contractual Clauses; pre-approved contract terms used as appropriate safeguards when no adequacy decision exists.
tap to reveal
What is a TIA, and what ruling made it essential for SCCs/BCRs?
Transfer Impact Assessment; a risk assessment of the recipient country's laws, mandated by the Schrems II ruling.
tap to reveal
What are BCRs and for what type of data transfer are they primarily used?
Binding Corporate Rules; internal codes of conduct for intra-group transfers within multinational companies.
tap to reveal
When can derogations under Article 49 be used for data transfers?
Only in specific, infrequent, and non-repetitive situations where no adequacy decision or appropriate safeguards apply.
tap to reveal
Name two specific derogations for data transfers under Article 49.
Explicit consent from the data subject; necessity for the performance of a contract with the data subject.
tap to reveal
What was a key impact of the Schrems II ruling on international data transfers?
It invalidated the EU-US Privacy Shield and emphasized the need for TIAs and supplementary measures when using SCCs/BCRs.
tap to reveal

Security of Processing and Data Breach Notification

## Security of Processing (Article 32 GDPR)

GDPR Article 32 mandates that controllers and processors implement appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk. This requires a risk-based approach, considering the nature, scope, context, and purposes of processing, as well as the likelihood and severity of the risk to individuals' rights and freedoms.

Key considerations for TOMs include:

  • The state of the art and cost of implementation.
  • Ensuring the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
  • The ability to restore availability and access to personal data in a timely manner in the event of a physical or technical incident.
  • A process for regularly testing, assessing, and evaluating the effectiveness of TOMs.

Examples of TOMs include pseudonymisation, encryption, access controls, and regular security audits. Processors are contractually obligated to assist controllers in meeting these security requirements.

## Data Breach Notification (Articles 33 & 34 GDPR)

A personal data breach is defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Controller to Supervisory Authority (SA) - Article 33

  • When to notify: The controller must notify the relevant SA without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach.
  • Exception: Notification is not required if the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
  • What to include: The notification must describe the nature of the breach, categories of data subjects and data involved, contact details of the DPO/contact point, likely consequences, and measures taken or proposed to address the breach.
  • Documentation: Controllers must document all personal data breaches, including the facts, effects, and remedial action taken, regardless of whether they were notified.

Processor to Controller - Article 33(2)

  • The processor must notify the controller of a personal data breach without undue delay after becoming aware of it.

Controller to Data Subject - Article 34

  • When to notify: The controller must communicate the breach to the data subject without undue delay if the breach is likely to result in a high risk to the rights and freedoms of natural persons.
  • Exceptions: Communication is *not* required if:
  • The controller has implemented appropriate technical protection measures (e.g., encryption) that render the data unintelligible.
  • The controller has taken subsequent measures to ensure the high risk is no longer likely to materialise.
  • It would involve disproportionate effort (public communication may be used instead).
  • What to include: The communication must be in clear and plain language, describing the nature of the breach, DPO contact, likely consequences, and measures taken or proposed.
  • Article 32 GDPR mandates a **risk-based approach** for implementing security measures (TOMs).
  • TOMs must ensure the **confidentiality, integrity, availability, and resilience** of processing systems.
  • A personal data breach is any security incident leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure/access of personal data.
  • Controllers must notify the Supervisory Authority (SA) of a breach within **72 hours** of awareness, unless it's unlikely to pose a risk.
  • Processors must notify controllers of a personal data breach **without undue delay**.
  • Controllers must notify data subjects **without undue delay** if a breach is likely to result in a **high risk** to their rights and freedoms.
  • Effective **encryption** of data is a key exception to the requirement to notify data subjects of a high-risk breach.
  • All personal data breaches, regardless of notification status, must be **documented** by the controller.
What is the primary principle guiding security measures under GDPR Article 32?
A **risk-based approach**, implementing appropriate technical and organisational measures (TOMs) proportionate to the risk.
tap to reveal
What is the GDPR definition of a 'personal data breach'?
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
tap to reveal
What is the deadline for a controller to notify the Supervisory Authority (SA) of a personal data breach?
Without undue delay and, where feasible, not later than **72 hours** after becoming aware of it.
tap to reveal
Under what condition is a controller *not* required to notify the SA of a breach?
If the personal data breach is **unlikely to result in a risk to the rights and freedoms of natural persons**.
tap to reveal
What is a processor's obligation upon discovering a personal data breach?
To notify the controller **without undue delay**.
tap to reveal
When must a controller communicate a personal data breach directly to the affected data subjects?
When the personal data breach is **likely to result in a high risk to the rights and freedoms of natural persons**.
tap to reveal
Name two exceptions where a controller might *not* need to notify data subjects of a high-risk breach.
If data was rendered unintelligible (e.g., **encrypted**), or if subsequent measures ensure the high risk is no longer likely to materialise.
tap to reveal
What documentation requirement does GDPR Article 33 impose on controllers regarding data breaches?
Controllers must **document all personal data breaches**, including facts, effects, and remedial actions, regardless of notification status.
tap to reveal

Supervision and Enforcement

## Supervisory Authorities (SAs)

Supervisory Authorities (SAs) are independent public authorities established by each Member State to monitor the application of the GDPR. Their primary role is to protect fundamental rights and freedoms of natural persons in relation to processing and to facilitate the free flow of personal data within the Union. SAs must act with complete independence, free from external influence.

Powers of SAs

SAs are endowed with significant powers to ensure compliance with the GDPR:

  • Investigative powers: To order controllers and processors to provide information, conduct data protection audits, obtain access to data and premises.
  • Corrective powers: To issue warnings, reprimands, order compliance, impose temporary or definitive limitations on processing, order rectification or erasure, and impose administrative fines.
  • Authorisation and advisory powers: To advise the controller, issue opinions, and authorise processing operations (e.g., data transfers).

One-Stop Shop Mechanism

For cross-border processing, the one-stop shop mechanism designates a single lead SA to be the main point of contact for the controller or processor. This lead SA cooperates with other concerned SAs (where data subjects are affected in other Member States) to reach a joint decision, streamlining enforcement and ensuring consistent application of the GDPR.

## European Data Protection Board (EDPB)

The European Data Protection Board (EDPB) is an independent European body that contributes to the consistent application of the GDPR across the EU/EEA. It provides general guidance, opinions, and advice on data protection matters. The EDPB plays a crucial role in resolving disputes between SAs through the consistency mechanism, ensuring a harmonised interpretation and application of the GDPR.

## Administrative Fines and Remedies

GDPR introduces a two-tiered system for administrative fines:

  • Tier 1: Up to €10 million, or 2% of the undertaking's total worldwide annual turnover of the preceding financial year, whichever is higher (e.g., for infringements related to technical and organisational measures, data protection by design/default).
  • Tier 2: Up to €20 million, or 4% of the undertaking's total worldwide annual turnover of the preceding financial year, whichever is higher (e.g., for infringements related to basic principles for processing, data subjects' rights, transfers).

When imposing fines, SAs consider factors like the nature, gravity, and duration of the infringement, intentionality, mitigation efforts, and prior infringements.

Data Subject Remedies

Data subjects have several avenues for redress:

  • Right to lodge a complaint with an SA.
  • Right to an effective judicial remedy against an SA decision or against a controller/processor.
  • Right to compensation for material or non-material damage suffered as a result of a GDPR infringement.
  • Supervisory Authorities (SAs) are independent bodies monitoring GDPR compliance in each Member State.
  • SAs possess investigative, corrective, authorisation, and advisory powers.
  • The one-stop shop mechanism designates a single lead SA for cross-border processing.
  • The European Data Protection Board (EDPB) ensures consistent GDPR application across the EU/EEA.
  • GDPR administrative fines can reach up to €20 million or 4% of global annual turnover.
  • Fines are tiered, with higher penalties for infringements of core principles and data subject rights.
  • Data subjects can lodge complaints with SAs and seek effective judicial remedies or compensation.
  • The EDPB's consistency mechanism resolves disputes between SAs to ensure uniform GDPR application.
What is the primary role of a Supervisory Authority (SA) under GDPR?
To monitor the application of the GDPR and protect data subjects' fundamental rights and freedoms.
tap to reveal
Name two types of powers an SA has under GDPR.
Investigative powers (e.g., audits) and Corrective powers (e.g., imposing fines, ordering compliance).
tap to reveal
What is the purpose of the 'one-stop shop' mechanism?
To designate a single lead SA for controllers/processors engaged in cross-border processing, streamlining enforcement.
tap to reveal
What is the maximum administrative fine for the most severe GDPR infringements?
Up to €20 million, or 4% of the undertaking's total worldwide annual turnover of the preceding financial year, whichever is higher.
tap to reveal
What body ensures the consistent application of GDPR across the EU/EEA?
The European Data Protection Board (EDPB).
tap to reveal
What right do data subjects have if they believe their GDPR rights have been infringed?
The right to lodge a complaint with a Supervisory Authority (SA).
tap to reveal
What is the EDPB's role in resolving disputes between SAs?
It uses the consistency mechanism to issue binding decisions or opinions, ensuring harmonised GDPR application.
tap to reveal