Cybersecurity Glossary

What is the GDPR?

The General Data Protection Regulation (GDPR) is Regulation (EU) 2016/679. It protects individuals when their personal data is processed while governing the free movement of that data in the EU. Personal data is any information relating directly or indirectly to a person, from a name and customer number to online identifiers or location data.

When does the GDPR apply?

It applies to automated processing and structured non-automated records. It covers organizations established in the EU and, under certain conditions, providers outside the EU when offering goods or services to people in the EU or monitoring their behavior. Purely personal or household activities may be exempt. Authorities, employment data, telecommunications and healthcare can be subject to additional national and sector-specific rules.

Which principles apply?

PrinciplePractical meaning
Lawfulness, fairness, transparencyProcessing needs a legal basis and must be explained clearly.
Purpose limitationData is collected for specified legitimate purposes and not reused arbitrarily.
Data minimizationOnly data necessary for the purpose is processed.
AccuracyInaccurate data is corrected or deleted.
Storage limitationDeletion periods and legal retention are actively managed.
Integrity and confidentialityAppropriate technical and organizational measures protect the data.
AccountabilityThe organization must be able to demonstrate compliance, not merely assert it.

Consent is only one possible legal basis. Depending on the processing, performance of a contract, legal obligation, vital interests, a public task or legitimate interests may apply. Consent collected as a precaution is not automatically valid and can be withdrawn.

Which roles does the GDPR distinguish?

A controller determines the purposes and means of processing. A processor handles data on the controller's documented instructions; this relationship generally requires an Article 28 contract. When parties jointly determine purposes and means, they may be joint controllers. Roles follow actual activities rather than the heading used in a contract.

Which rights do data subjects have?

Important rights include information and access, rectification, erasure, restriction, data portability and objection. Additional safeguards apply to solely automated decisions with significant effects. These rights are not absolute: identity, statutory retention, other people's rights and the applicable legal basis must be considered. Clear responsibilities and deadlines are needed to answer requests completely and securely.

What security does Article 32 require?

Controllers and processors must provide a level of security appropriate to risk. The state of the art, implementation cost, nature and scale of processing, and the likelihood and severity of possible harm to individuals are relevant. The GDPR therefore does not prescribe identical products for every organization.

  • Pseudonymization and encryption where appropriate.
  • Ongoing confidentiality, integrity, availability and resilience of systems.
  • Ability to restore availability and access after an incident in a timely manner.
  • Regular testing, assessment and evaluation of control effectiveness.

In practice, this includes access control, secure development, patch and vulnerability management, backups, logging, incident response, training and managed suppliers. A penetration test can support effectiveness testing but does not replace a complete privacy program.

When must a breach be reported?

A personal data breach includes accidental or unlawful destruction, loss, alteration, disclosure of, or access to personal data. The controller generally notifies the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware, unless the breach is unlikely to result in a risk to people's rights and freedoms. Where a high risk is likely, affected people generally need a clear notification as well. Processors notify the controller without undue delay.

Not every security incident is a personal data breach, and not every data breach is a cyberattack. Misdirected messages, lost devices and accidental deletion can qualify. The controller must document breaches and its risk assessment even when notification to the authority is not required.

What does practical implementation involve?

  1. Record processing activities, data flows, purposes, legal bases, recipients and deletion periods.
  2. Apply data protection by design and by default from the start of a project.
  3. Assess risk and conduct a data protection impact assessment where high risk is likely.
  4. Select processors and review contracts and international transfers.
  5. Run repeatable processes for rights requests, deletion, incidents and control testing.

What is commonly misunderstood?

Data protection is broader than information security. Technically well-protected data can still be processed without a legal basis, for too long or for an incompatible purpose. Conversely, a privacy notice does not make insecure processing lawful. Data is outside the scope as anonymous only when re-identification is not reasonably likely; pseudonymous data generally remains personal data. Concrete edge cases need legal assessment rather than a technical checklist alone.

Thank you for your feedback! We will review it and optimize this content.

Do you have feedback on GDPR? Tell us!