No history yet

Introduction to GDPR

What is GDPR?

In our digital world, personal information is constantly being collected, shared, and used. The General Data Protection Regulation, or GDPR, is a landmark privacy law from the European Union designed to give individuals control over their own personal data. It sets the rules for how organizations must handle this information.

Lesson image

Think of it as a bill of rights for the digital age. It harmonizes data privacy laws across Europe, protecting all EU citizens from privacy and data breaches. Before GDPR, each country in the EU had its own set of rules, creating a confusing patchwork of regulations. GDPR replaced these with a single, unified framework, making it simpler for businesses to comply and strengthening the rights of individuals.

Its main objective is to give citizens and residents control over their personal data, in addition to simplifying and unifying the regulation of international business.

Who Does It Apply To?

One of the most significant aspects of GDPR is its wide reach. The regulation doesn't just apply to organizations based in the EU. It applies to any company, anywhere in the world, that processes the personal data of people residing in the European Union.

This means an online store in Canada that ships products to a customer in Germany, or a tech startup in Brazil with an app used by people in Sweden, must both comply with GDPR. If you offer goods or services to EU residents or monitor their behavior (like using web cookies to track their activity), the rules apply to you.

GDPR's reach is global. It's not about where your company is located, but whose data you handle.

Key GDPR Terms

To understand how GDPR works, you need to know the language it uses. The regulation defines a few key terms that are central to its rules. Let's break down the most important ones.

Personal Data

noun

Any information that can be used to identify a living person, either directly or indirectly. This includes obvious identifiers like a name or email address, but also less obvious ones like an IP address, location data, or cookie ID.

This broad definition is a cornerstone of the GDPR. It acknowledges that in the digital economy, many different pieces of information can be pieced together to identify someone.

Data Subject

noun

The individual whose personal data is being collected, held, or processed. In simple terms, if a company has your information, you are the data subject.

The regulation also defines the two main roles involved in handling data: the controller and the processor. These roles clarify who is responsible for protecting personal data.

Data Controller

noun

The organization or individual that determines the purposes and means of processing personal data. They decide 'why' and 'how' the data should be processed and have the main responsibility for ensuring it's handled correctly.

Think of the data controller as the one in the driver's seat. They make the important decisions about the data.

Data Processor

noun

The organization or individual that processes personal data on behalf of the data controller. A processor acts on the controller's instructions.

For example, a hospital (the controller) might use a third-party company (the processor) to manage its patient scheduling software. The hospital decides what information to collect, while the software company processes it according to the hospital's directions.

Understanding these core concepts is the first step in grasping the world of data privacy under GDPR.