Glossary
Data protection law from A to Z.
Data protection terms explained in clear language.
Contact person
Mag. Bernhard Brandauer, Rechtsanwalt
BRANDAUER Rechtsanwälte
Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.
C
- Communication to data subjects Communication to data subjects under Article 34 GDPR informs people without undue delay about a personal data breach where it is likely to result in a high risk to their rights and freedoms.
- Consent Consent is a freely given, informed and unambiguous agreement to the processing of specified personal data for a stated purpose.
- Controller The natural or legal person, public authority or other body that alone or jointly decides the purposes and means of processing personal data.
D
- Data portability The right to data portability under Article 20 GDPR allows data subjects, under specific conditions, to receive certain data they provided in a structured, commonly used and machine-readable format and to transmit it to another controller.
- Data protection by default Data protection by default means that, by default, only the personal data necessary for the specific purpose is processed and made accessible.
- Data protection by design Data protection by design means that controllers build appropriate technical and organisational measures into a processing operation from the planning stage so that data protection principles and people’s rights are effectively protected.
- Data protection impact assessment A data protection impact assessment examines before processing starts whether a planned operation is likely to create a high risk to people’s rights and freedoms and how that risk can be reduced.
- Data protection officer A data protection officer advises and monitors an organisation on data protection compliance and must be appointed in certain cases under Article 37 GDPR.
- Data subject The natural person to whom personal data relate and who is therefore affected by the processing under data protection law.
L
- Legal basis A legal basis is the specific legal ground that makes processing personal data lawful. For most processing activities, one of the conditions in Article 6(1) GDPR must apply.
- Legitimate interests A legitimate interest under Article 6(1)(f) GDPR can support processing where a concrete interest exists, the processing is necessary for it and the data subject’s interests or fundamental rights do not override it.
P
- Personal data Any information relating to an identified or identifiable natural person, such as a name, customer number, location data or an online identifier.
- Personal data breach A personal data breach is a security breach that accidentally or unlawfully destroys, loses, alters, discloses or gives unauthorised access to personal data.
- Processing Any operation performed on personal data, including collection, storage, use, disclosure, restriction, erasure or destruction.
- Processor A natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller and under the controller’s instructions.
- Processor agreement A processor agreement governs the processing of personal data by a processor on behalf of a controller. Article 28 GDPR sets out the agreement’s essential content.
- Profiling Profiling is the automated processing of personal data used to evaluate or predict personal aspects, such as interests, behaviour, economic situation or location.
R
- Records of processing activities Records of processing activities document which personal data a business processes, for which purposes, with which recipients and under which safeguards.
- Restriction of processing Under Article 18 GDPR, restriction of processing limits the use of personal data to specific legally permitted purposes while one of the statutory grounds applies.
- Right of access Under Article 15 GDPR, the right of access allows data subjects to obtain their personal data and important information about how it is processed.
- Right to erasure Under Article 17 GDPR, the right to erasure allows data subjects, in specified circumstances, to require a controller to delete their personal data.
- Right to object The right to object under Article 21 GDPR allows data subjects to object at any time to certain processing based on their particular situation or to direct marketing.
- Right to rectification The right to rectification under Article 16 GDPR allows data subjects to obtain without undue delay the correction of inaccurate personal data and the completion of incomplete data.
S
- Special categories of personal data Particularly sensitive personal data protected by Article 9 GDPR, including health data, biometric data used to identify a person uniquely and information about political opinions.
- Standard contractual clauses Standard contractual clauses are Commission-approved clauses that provide appropriate safeguards for certain transfers of personal data to third countries. Their choice and completion must fit the specific transfer.
- Storage limitation Storage limitation is the principle that personal data should be kept in an identifiable form only for as long as necessary for the specified purposes of the processing.
T
- Technical and organisational measures Technical and organisational measures are safeguards used to protect personal data in proportion to risk and to review whether those safeguards remain effective.
- Transfer Impact Assessment A documented assessment of whether the law and practice of a third country could undermine the safeguards for a planned transfer of personal data and require supplementary measures.
- Transparency and information duty Under the GDPR, the information duty requires controllers to explain clearly how and why they process personal data.
General orientation, not individual advice.
Contact
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000