GDPR
Also known as: General Data Protection Regulation, Regulation (EU) 2016/679
The EU law that protects personal data and gives people rights over how it is used.
Draft - this entry has not been reviewed yet.
Formal
Regulation (EU) 2016/679, applying directly in every member state since 25 May 2018, which sets principles, legal grounds, rights and security duties for processing data about identifiable people, with fines of up to 20 million euro or 4% of global turnover.
In plain English
Information about you is treated as yours - others may borrow it only for a fair reason, must look after it and must tell you what they do with it.
In practice
When a laptop holding customer lists is stolen from the owner's car, a Danish web shop has 72 hours to report the breach to Datatilsynet and must decide whether the customers themselves need to be told.
Why it matters
Before it, data protection rules differed from country to country and were weakly enforced; GDPR gave people the same rights across the EU and made breaking them costly.
How to put it into practice
The usual steps, in order. Adapt them to your organisation.
- Name an owner for data protection with a mandate from management, and check whether Art. 37 requires you to designate a data protection officer (DPO).
- Map every processing activity in a record of processing (Art. 30) with purposes, data and people, recipients, transfers, retention and security; the under-250 exemption is narrow, so keep one anyway.
- Document a legal basis under Art. 6(1) for each purpose, plus an Art. 9(2) exception for special categories, and tell people about it in privacy notices (Arts. 13-14).
- Screen new and changed processing for high risk and complete a DPIA (Art. 35) before it starts where one is required.
- Sign a data processing agreement meeting Art. 28(3) with every supplier that handles personal data for you, and cover transfers outside the EU/EEA under Chapter V.
- Set risk-based security measures (Art. 32) such as access control, encryption, logging and tested backups, and build privacy by design and by default into new systems (Art. 25).
- Log every personal data breach internally (Art. 33(5)), report it to Datatilsynet via virk.dk within 72 hours where feasible unless it is unlikely to pose a risk, and tell those affected when the risk is high (Art. 34).
- Set up a process for data subject requests (access, rectification, erasure, restriction, portability, objection) that answers within one month, extendable by two months for complex cases (Art. 12(3)).
- Review the record, legal bases, agreements and procedures at least yearly and after major changes, and train the staff who handle personal data.
Common pitfalls
- Relying on consent where another legal basis fits, especially for employees, where the imbalance of power means consent is rarely freely given.
- Treating the record of processing as a one-off document that nobody updates when systems and suppliers change.
- Waiting for the full picture before reporting a breach, so the 72-hour deadline is missed.
- Assuming an ordinary supplier contract covers data protection without a separate Art. 28 agreement.
Good guides
- Fortegnelse(opens in a new tab) · Datatilsynet (in Danish)
- Hvornår må du behandle personoplysninger(opens in a new tab) · Datatilsynet (in Danish)
- Håndtering af brud på persondatasikkerheden(opens in a new tab) · Datatilsynet (in Danish)
- De registreredes rettigheder(opens in a new tab) · Datatilsynet (in Danish)
- Lov nr. 502 af 23. maj 2018 (databeskyttelsesloven)(opens in a new tab) · Retsinformation (in Danish)
Technical deep dive
Regulation (EU) 2016/679 has 99 articles and 173 recitals; it entered into force on 24 May 2016 and has applied since 25 May 2018, replacing Directive 95/46/EC. Its material scope (Art. 2) is the processing of personal data wholly or partly by automated means, or in a filing system, excluding purely household activity and law-enforcement processing, which falls under the separate Directive (EU) 2016/680. Territorial scope (Art. 3) follows either an establishment in the EU or, for non-EU organisations, the targeting of goods or services at people in the EU or the monitoring of their behaviour. Personal data (Art. 4(1)) covers any information relating to an identified or identifiable natural person, including online identifiers; pseudonymised data remains personal data (recital 26), while only truly anonymised data falls outside the regulation, a distinction regularly misapplied to hashed identifiers and device IDs.
The regulation is principle-driven. Art. 5(1) sets the six processing principles and Art. 5(2) adds accountability, which is operationalised through records of processing (Art. 30), data protection by design and by default (Art. 25), security of processing (Art. 32), DPIAs (Art. 35) and, where Art. 37 applies, a data protection officer. Every processing operation needs one of the six legal bases in Art. 6(1); consent is neither preferred nor usually appropriate for employers or public authorities because of the power imbalance. Special categories under Art. 9, such as health, biometric data used for identification and trade-union membership, are prohibited by default and need an Art. 9(2) exception in addition to an Art. 6 basis.
Enforcement is decentralised but coordinated. Each member state has an independent supervisory authority; for cross-border processing the one-stop-shop mechanism (Art. 56 and Art. 60) makes the authority of the main establishment lead, and disagreements go to the European Data Protection Board under the consistency mechanism (Arts. 63-65). Chapter V restricts transfers to third countries: adequacy decisions (Art. 45), appropriate safeguards such as standard contractual clauses (Art. 46), or narrow derogations (Art. 49). After the CJEU invalidated Privacy Shield in Schrems II (C-311/18, July 2020), transfers to the US have relied on SCCs with transfer impact assessments or, since the adequacy decision of 10 July 2023, on the EU-US Data Privacy Framework for certified recipients.
Denmark supplements the regulation with databeskyttelsesloven (lov nr. 502 af 23. maj 2018), which uses the opening clauses, for example setting the age for consent to information society services at 13 and regulating CPR numbers. Because Danish law does not allow administrative fines against private companies, Art. 83(9) applies: Datatilsynet reports cases to the police and the courts impose fines. Data subjects can also claim compensation for material or non-material damage under Art. 82. In security practice, GDPR does not prescribe specific controls; Art. 32 is risk-based and technology-neutral, so frameworks such as ISO 27001 or the CIS Controls are used to demonstrate that measures are appropriate.
What to learn first
Everything this builds on, foundations first.
Relationships
Sources & further reading
Standards & official texts
- Regulation (EU) 2016/679 (GDPR) · European Union
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…