GDPR for beginners


RGPD - Regulamento Geral Proteção Dados

Demystifying the GDPR (General Data Protection Regulation)

(GDPR )

Ever since the announced roll-out of the GDPR on 25 May 2018 came to the attention of business owners and company directors, we have watched a rush to market for solutions that deliver the necessary compliance and avoid the fines (hefty ones, it must be said) set out by the European Commission. Starting with the fine, it can reach €20 million or up to 4% of the company's turnover. Now that we have set the scene, let's clear up the typical, immediate questions we all have about the GDPR.

What is the General Data Protection Regulation (GDPR) for?

The GDPR sets out the rules on the processing, by a person, a company or an organisation, of personal data relating to people/citizens of the European Union. In that sense, it serves to protect people from the misuse of their personal data by other entities, while also giving them the right to access their data (free of charge) in order to view, update or delete it (the right to deletion depends on the context: if there is a legal obligation, for example, the entity is not required to delete the person's data).

It does not apply to the processing of personal data of deceased persons or of legal persons.

An answer that seems obvious to a question that seems basic:

What is personal data?

Personal data is information relating to a living person who is identified or identifiable. A set of separate pieces of information that can lead to the identification of a particular person also constitutes personal data.

Personal data that has been de-identified, encrypted or pseudonymised but can still be used to re-identify a person remains personal data and falls within the scope of the GDPR.

Personal data that has been made anonymous in such a way that the person is not or is no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.

The GDPR protects personal data regardless of the technology used to process it — it is technology-neutral and applies to both automated and manual processing, provided the data is organised according to pre-defined criteria (for example, in alphabetical order). It is also irrelevant how the data is stored — in an IT system, through video surveillance, or on paper; in all these cases, personal data is subject to the protection requirements set out in the GDPR.

Examples of data considered personal

  • first name and surname;
  • home address;
  • an email address such as name.surname@company.com;
  • identity card number;
  • location data (for example, the location data function on a mobile phone)*;
  • IP (internet protocol) address;
  • cookies;
  • your phone's advertising identifier;
  • data held by a hospital or doctor that uniquely identifies a person.

Who does data protection law apply to?

The GDPR applies to companies or entities that process personal data as part of the activities of one of their branches established in the EU, regardless of where the data is processed; or to a company set up outside the EU that offers goods/services (paid or free) or monitors the behaviour of people in the European Union. If processing personal data is not a core part of your business and your activity does not create risks for individuals, then some GDPR obligations do not apply to you (for example, appointing a data protection officer (DPO)).

Speaking of which…

Does my company/organisation need a data protection officer (DPO)?

Your company/organisation must appoint a DPO, whether it is a controller or a processor, if its core activities involve the large-scale processing of sensitive data, or if its core activities involve the regular and systematic monitoring of people on a large scale. In this context, monitoring people's behaviour includes all forms of tracking and profiling on the internet, in particular for behavioural advertising purposes.

Public authorities are always required to appoint a DPO (with the exception of courts acting in their judicial capacity).

The DPO can be an employee of your organisation or can be hired externally under a service contract. The DPO can be an individual or an organisation.

Do data protection rules apply to data about companies?

No, the rules only apply to personal data about natural persons. They therefore do not cover data about companies or other legal entities. However, information about sole traders may constitute personal data where it allows a natural person to be identified. The rules also apply to all personal data relating to natural persons in a professional context, such as the employees of a company/organisation, including work email addresses like "name.surname@company.eu" or employees' work phone numbers.

We hope we have helped clear up some of the most basic and fundamental questions about the GDPR. If you would like further clarification, get in touch at dpo@jelly.pt

The content of this article was based on and transcribed from https://ec.europa.eu JTNDZGl2JTIwY2xhc3MlM0QlMjJmYi1jb21tZW50cyUyMiUyMGRhdGEtaHJlZiUzRCUyMmh0dHBzJTNBJTJGJTJGd3d3LmplbGx5Y29kZS5wdCUyRnJncGQtaW5pY2lhZG9zLXJlc3Bvc3Rhcy1hcy1xdWVzdG9lcy1lbGVtZW50YXJlcyUyRiUyMiUyMGRhdGEtd2lkdGglM0QlMjIxMDAlMjUlMjIlMjBkYXRhLW51bXBvc3RzJTNEJTIyMTAlMjIlM0UlM0MlMkZkaXYlM0U=

Get what we write

No fixed calendar: only when there is something worth your time.

Your email, nothing else. We do not ask for a name or a company.

You will receive it in English.

RelatedAll articles