No history yet

Introduction to GDPR

What is GDPR?

The General Data Protection Regulation, or GDPR, is a landmark privacy law from the European Union. Its main goal is to give individuals control over their personal information. Think of it as a digital bill of rights for the modern age.

Its main objective is to give citizens and residents control over their personal data, in addition to simplifying and unifying the regulation of international business.

Even though GDPR is an EU regulation, its reach is global. It applies to any organization, anywhere in the world, that targets or collects data related to people in the EU. So, a U.S.-based company with customers in France or an Australian charity with donors in Germany must comply with GDPR.

Why Was It Created?

Before GDPR, Europe's data privacy rules were based on a directive from 1995. A lot has changed since then. The rise of the internet, social media, and big data created new challenges for privacy that the old rules couldn't handle.

Each EU country had its own version of the law, creating a confusing patchwork of regulations for businesses to navigate. GDPR replaced this fragmented system with a single, unified law for the entire EU. This move had two primary objectives: to strengthen individuals' fundamental rights to data protection and to make it easier for businesses to operate legally across the continent.

Lesson image

Key Terms to Know

To understand GDPR, you need to know the language it uses. The regulation defines several key roles and concepts that are central to its rules.

Personal Data

noun

Any information that can be used to identify a living person. This isn't just a name or email address; it also includes IP addresses, location data, cookie identifiers, and even biometric or genetic information.

This definition is intentionally broad to keep up with changing technology.

Data Subject

noun

The person whose data is being collected, held, or processed. In short, it's you, me, and anyone else whose information is being used.

Next are the two main roles responsible for handling that data.

Data Controller

noun

The organization that determines the purposes and means of processing personal data. It's the entity that decides why and how the data should be collected and used.

Think of the controller as the one in charge. But they often don't do all the work themselves.

Data Processor

noun

An organization that processes personal data on behalf of the data controller. The processor follows the controller's instructions.

For example, a hospital (the controller) might use a third-party company (the processor) to manage its patient billing system. The hospital decides what data is needed, while the company processes it accordingly.

Now that you know the basics, let's test your knowledge.

Quiz Questions 1/4

What is the primary goal of the General Data Protection Regulation (GDPR)?

Quiz Questions 2/4

A travel blog is based in Australia and writes about European destinations. It has a newsletter that people from Italy subscribe to, providing their email addresses. Does GDPR apply to this blog?

Understanding these fundamental concepts is the first step in grasping the full impact of GDPR on data privacy worldwide.