General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) is a comprehensive legal framework enacted by the European Union to strengthen and unify data protection for all individuals within the EU. It grants citizens significant control over their personal data, including rights of access, rectification, and erasure, fundamentally influencing the field of computer science by mandating principles like "privacy by design" and "privacy by default" in software architecture and data processing systems. From a cybersecurity perspective, GDPR imposes strict obligations on organizations to implement robust technical and organizational security measures to protect personal data from breaches and requires the prompt reporting of such incidents, making data security not just a technical best practice but a critical legal requirement with significant financial penalties for non-compliance.

  1. Foundations of GDPR
    1. Introduction to Data Protection Law
      1. Historical Context and Predecessors
        1. Early Data Protection Laws in Europe
          1. Data Protection Directive 95/46/EC
            1. Limitations of Previous Frameworks
            2. Rationale and Objectives of the GDPR
              1. Harmonisation of Data Protection Laws Across the EU
                1. Strengthening Data Subject Rights
                  1. Enhancing Accountability and Governance
                    1. Facilitating the Digital Single Market
                      1. Addressing Technological Developments
                    2. Key Terminology and Definitions
                      1. Personal Data
                        1. Definition and Scope
                          1. Examples of Personal Data
                            1. Identifiers and Identification Factors
                              1. Online Identifiers
                                1. Location Data
                                  1. Biometric Data
                                  2. Special Categories of Personal Data
                                    1. Racial or Ethnic Origin
                                      1. Political Opinions
                                        1. Religious or Philosophical Beliefs
                                          1. Trade Union Membership
                                            1. Genetic Data
                                              1. Biometric Data for Identification
                                                1. Health Data
                                                  1. Sex Life and Sexual Orientation
                                                    1. Additional Protections Required
                                                    2. Processing
                                                      1. Definition of Processing Activities
                                                        1. Collection
                                                          1. Recording
                                                            1. Organisation
                                                              1. Structuring
                                                                1. Storage
                                                                  1. Adaptation or Alteration
                                                                    1. Retrieval
                                                                      1. Consultation
                                                                        1. Use
                                                                          1. Disclosure by Transmission
                                                                            1. Dissemination
                                                                              1. Alignment or Combination
                                                                                1. Restriction
                                                                                  1. Erasure or Destruction
                                                                                  2. Controller
                                                                                    1. Definition and Role
                                                                                      1. Determining Controller Status
                                                                                        1. Decision-Making Authority
                                                                                          1. Purposes and Means of Processing
                                                                                          2. Processor
                                                                                            1. Definition and Role
                                                                                              1. Processing on Behalf of Controller
                                                                                                1. Processor vs. Controller Distinction
                                                                                                  1. Sub-Processor Relationships
                                                                                                  2. Data Subject
                                                                                                    1. Definition and Rights
                                                                                                      1. Natural Persons
                                                                                                        1. Deceased Persons
                                                                                                        2. Pseudonymisation
                                                                                                          1. Definition and Purpose
                                                                                                            1. Technical Implementation
                                                                                                              1. Differences from Anonymisation
                                                                                                                1. Benefits for Compliance
                                                                                                                2. Anonymisation
                                                                                                                  1. Definition and Irreversibility
                                                                                                                    1. Techniques and Methods
                                                                                                                      1. Testing for Effective Anonymisation
                                                                                                                      2. Profiling
                                                                                                                        1. Definition and Examples
                                                                                                                          1. Automated Processing
                                                                                                                            1. Evaluation of Personal Aspects
                                                                                                                              1. Risks Associated with Profiling
                                                                                                                              2. Personal Data Breach
                                                                                                                                1. Definition and Types of Breaches
                                                                                                                                  1. Confidentiality Breaches
                                                                                                                                    1. Integrity Breaches
                                                                                                                                      1. Availability Breaches
                                                                                                                                      2. Supervisory Authority
                                                                                                                                        1. Role and Structure
                                                                                                                                          1. Independence Requirements
                                                                                                                                            1. One-Stop-Shop Mechanism
                                                                                                                                              1. Lead Supervisory Authority
                                                                                                                                            2. Scope of the GDPR
                                                                                                                                              1. Material Scope
                                                                                                                                                1. Types of Data and Processing Covered
                                                                                                                                                  1. Wholly or Partly Automated Processing
                                                                                                                                                    1. Non-Automated Processing in Filing Systems
                                                                                                                                                      1. Exclusions and Exemptions
                                                                                                                                                        1. Household Activities
                                                                                                                                                          1. Law Enforcement Processing
                                                                                                                                                            1. National Security
                                                                                                                                                              1. Activities Outside EU Law Scope
                                                                                                                                                            2. Territorial Scope
                                                                                                                                                              1. Establishment in the EU
                                                                                                                                                                1. Processing by EU-Based Organisations
                                                                                                                                                                  1. Main Establishment
                                                                                                                                                                    1. Other Establishments
                                                                                                                                                                    2. Targeting of Data Subjects in the EU
                                                                                                                                                                      1. Offering Goods or Services
                                                                                                                                                                        1. Monitoring Behaviour
                                                                                                                                                                          1. Representative Requirements
                                                                                                                                                                          2. Application to Non-EU Organisations
                                                                                                                                                                            1. Designation of Representatives
                                                                                                                                                                              1. Compliance Obligations