1. Overview of GDPR
Key definitions
A handful of terms come up constantly in data protection. Get comfortable with these and the rest of the course will make much more sense.
Personal data
Any information relating to an identified or identifiable living individual. This is broader than people expect: a name, an email address, an IP address, a photo, a job title combined with an employer, or a CCTV image can all be personal data if they can identify someone, directly or indirectly.
Special category data
A subset of personal data that needs extra protection because misuse could cause serious harm: health data, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, genetic and biometric data.
Processing
Anything you do with personal data: collecting, recording, storing, organising, adapting, retrieving, using, disclosing, or deleting it. Almost every interaction with personal data counts as "processing."
Data subject
The individual the personal data is about, for example a customer, employee, or website visitor.
Data controller
The organisation (or person) that decides why and how personal data is processed. Controllers carry the primary legal responsibility.
Data processor
An organisation that processes personal data on behalf of a controller, following the controller's instructions, for example a payroll provider or a cloud hosting company.
› Course contents
Principles
Rights of the individual
Legal bases for processing