resources

GDPR Glossary: Key Data Protection Concepts

Essential definitions of the GDPR (Regulation (EU) 2016/679): controller, processor, legal bases, data subject rights, DPIA, DPO, international transfers and more. Legal reference with article sources.

GDPR Glossary · Data protection · GDPR · Personal data · DPO · DPIA · Privacy · Data subject rights

We help you identify the correct legal bases, draft privacy notices and DPAs, conduct DPIAs and design a data protection policy tailored to your sector.

This glossary collects the essential terms of the General Data Protection Regulation (EU) 2016/679 (GDPR), with definitions based directly on the regulatory text. Each entry includes the reference to the corresponding article or recital to facilitate direct consultation of the Regulation.

Personal data

Any information relating to an identified or identifiable natural person (the data subject). A person is identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier (IP address, cookie), or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity. Truly and irreversibly anonymised data falls outside the scope of the GDPR.

Source: Art. 4(1) GDPR · Regulation (EU) 2016/679 Related service →

Processing

Any operation or set of operations performed on personal data, whether by automated means or not. This includes collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. An AI system that processes personal data performs processing subject to the GDPR.

Source: Art. 4(2) GDPR · Regulation (EU) 2016/679 Related service →

Controller

The natural or legal person, public authority, agency or other body that, alone or jointly with others, determines the purposes (the why) and means (the how) of processing personal data. The controller bears primary responsibility under the GDPR: complying with all principles, ensuring data subjects' rights, and being accountable to the supervisory authority. Where two or more controllers jointly determine purposes and means, they are joint controllers and must define their respective responsibilities by agreement.

Source: Art. 4(7) GDPR · Art. 26 GDPR (joint controllers) · Regulation (EU) 2016/679 Related service →

Processor

The natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller and in accordance with its instructions. The relationship must be formalised through a Data Processing Agreement (DPA) containing the mandatory clauses of Art. 28 GDPR. Cloud providers, SaaS tools and marketing agencies that access client personal data typically act as processors. Processors may not engage sub-processors without prior written authorisation from the controller.

Source: Art. 4(8) GDPR · Art. 28 GDPR · Regulation (EU) 2016/679 Related service →

Data subject

The identified or identifiable natural person whose personal data are being processed. The GDPR grants data subjects a comprehensive set of rights: access, rectification, erasure (right to be forgotten), restriction of processing, data portability, objection, and the right not to be subject to solely automated decisions. Controllers must establish procedures to respond to the exercise of these rights within one month (extendable to three months in complex cases).

Source: Arts. 4(1), 12-22 GDPR · Regulation (EU) 2016/679 Related service →

Legal bases for processing

The six lawfulness conditions that must be met for personal data processing to be legitimate (Art. 6 GDPR): (1) consent of the data subject; (2) performance of a contract; (3) compliance with a legal obligation; (4) protection of vital interests; (5) performance of a task in the public interest or exercise of official authority; (6) legitimate interests of the controller or a third party. Each processing activity must be grounded in at least one legal basis, which must be identified before processing begins.

Source: Art. 6 GDPR · Regulation (EU) 2016/679 Related service →

Consent

Any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they signify agreement to the processing of their personal data by a statement or clear affirmative action. Consent cannot be bundled, implied, coerced or conditional on the provision of a service. It must be as easy to withdraw as to give. For children under 16 (or a lower age set by Member States, minimum 13), parental consent is required under Art. 8 GDPR.

Source: Arts. 4(11), 6(1)(a), 7 GDPR · Art. 8 GDPR (children) · Regulation (EU) 2016/679 Related service →

Legitimate interests

Legal basis allowing processing when necessary for the legitimate interests of the controller or a third party, provided those interests are not overridden by the data subject's interests, rights or fundamental freedoms (the balancing test). Relevant factors: nature of the interest, necessity of the processing, impact on the data subject and their reasonable expectations. Not applicable when the controller is a public authority acting in the public interest. The balancing test must be documented in advance.

Source: Art. 6(1)(f) GDPR · Recital 47 · Regulation (EU) 2016/679 Related service →

Special categories of data (sensitive data)

Categories of personal data whose processing is in principle prohibited unless an exception in Art. 9(2) GDPR applies. They require enhanced protection because their disclosure can cause discrimination or serious harm: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for unique identification, health data, sex life or sexual orientation. Processing requires both an Art. 9(2) exception and a lawful basis under Art. 6.

Source: Art. 9 GDPR · Regulation (EU) 2016/679 Related service →

Right of access

The right of the data subject to obtain from the controller confirmation as to whether personal data concerning them are being processed, and if so, access to the data and the following information: purposes, categories, recipients, retention periods, the source of data, and the existence of automated decision-making. The controller must provide a free copy of the data in an accessible format. Response deadline: one month, extendable to three months with justification.

Source: Art. 15 GDPR · Regulation (EU) 2016/679 Related service →

Right to rectification

The right of the data subject to obtain without undue delay the correction of inaccurate personal data concerning them, and the completion of incomplete personal data by providing a supplementary statement. The controller must communicate any rectification to each recipient to whom data has been disclosed, unless this proves impossible or involves disproportionate effort, and must inform the data subject about those recipients upon request.

Source: Art. 16 GDPR · Art. 19 GDPR · Regulation (EU) 2016/679 Related service →

Right to erasure (right to be forgotten)

The right of the data subject to obtain erasure of their personal data without undue delay. Grounds include: (i) the data are no longer necessary for the purposes for which they were collected; (ii) consent is withdrawn and no other legal basis applies; (iii) the data subject objects and no compelling legitimate grounds override; (iv) the data have been unlawfully processed; (v) erasure is required by law. If the controller has made data public, it must take reasonable steps to inform other controllers processing the data.

Source: Art. 17 GDPR · Regulation (EU) 2016/679 Related service →

Right to restriction of processing

The right of the data subject to obtain from the controller restriction of processing in certain circumstances: when the data subject contests accuracy (pending verification), when processing is unlawful but the data subject opposes erasure, when the controller no longer needs the data but the data subject needs them for legal claims, or when the data subject has objected pending verification of whether legitimate grounds override. During restriction, data may only be stored, not actively processed.

Source: Art. 18 GDPR · Regulation (EU) 2016/679 Related service →

Right to data portability

The right of the data subject to receive personal data they have provided to a controller in a structured, commonly used and machine-readable format (such as JSON or CSV), and to transmit those data to another controller without hindrance. Applies only when processing is based on consent or a contract and carried out by automated means. The controller must, where technically feasible, transmit data directly from one controller to another upon the data subject's request.

Source: Art. 20 GDPR · Regulation (EU) 2016/679 Related service →

Right to object

The right of the data subject to object at any time, on grounds relating to their particular situation, to processing based on legitimate interests or the performance of a public interest task. The controller must cease processing unless it demonstrates compelling legitimate grounds that override the data subject's interests, or for legal claims. Where personal data are processed for direct marketing (including profiling), the data subject may object at any time and without any justification, with absolute effect.

Source: Art. 21 GDPR · Regulation (EU) 2016/679 Related service →

Data Protection Impact Assessment (DPIA)

A mandatory prospective analysis that must be carried out before processing likely to result in a high risk to the rights and freedoms of natural persons. Required when: new technologies are used with large-scale data processing, systematic monitoring of publicly accessible areas is performed, special categories are processed at large scale, or in other cases identified by supervisory authorities. If the DPIA reveals a high residual risk that cannot be mitigated, the supervisory authority must be consulted before processing begins.

Source: Art. 35 GDPR · EDPB Guidelines 04/2022 · Regulation (EU) 2016/679 Related service →

Data Protection Officer (DPO)

Mandatory role for: (a) public authorities and bodies; (b) controllers or processors carrying out large-scale processing of special categories of data; (c) controllers carrying out large-scale systematic monitoring of individuals. Functions: informing and advising on GDPR obligations, monitoring compliance, overseeing DPIAs, and acting as the contact point with the supervisory authority and data subjects. May be an employee or an external service provider (DPO as a service). Must be registered with the national supervisory authority.

Source: Arts. 37-39 GDPR · Regulation (EU) 2016/679 Related service →

Personal data breach

A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Must be notified to the supervisory authority within 72 hours of the controller becoming aware of it, unless unlikely to result in a risk to individuals' rights and freedoms. If the breach is likely to result in a high risk, affected data subjects must also be informed without undue delay. Controllers must document all breaches, regardless of whether notification is required.

Source: Arts. 33-34 GDPR · Regulation (EU) 2016/679 Related service →

Pseudonymisation

The processing of personal data in such a manner that they can no longer be attributed to a specific data subject without the use of additional information, provided that additional information is kept separately and is subject to technical and organisational measures ensuring non-attribution to an identified person. Pseudonymised data remain personal data subject to the GDPR (unlike anonymised data). It is a recommended security measure that reduces processing risk and may reduce obligations under certain GDPR provisions.

Source: Arts. 4(5), 25, 32 GDPR · Regulation (EU) 2016/679 Related service →

Anonymisation

A process by which personal data are irreversibly transformed so that the data subject cannot be identified directly or indirectly, even by the controller or by third parties with access to additional information. Truly anonymised data fall outside the scope of the GDPR. The assessment of anonymisation must account for all means reasonably likely to be used for re-identification. Unlike pseudonymisation, anonymisation is irreversible. Techniques include aggregation, noise addition, k-anonymity and differential privacy.

Source: Recital 26 GDPR · WP29 Opinion 05/2014 on anonymisation techniques · Regulation (EU) 2016/679 Related service →

Records of processing activities (RoPA)

A mandatory written record that controllers and processors with 250 or more employees must maintain, or those carrying out processing that is likely to result in a risk to data subjects' rights, is not occasional, or includes special categories. The controller's RoPA must contain: identity of the controller, purposes of processing, categories of data subjects and personal data, recipients, international transfers, retention periods, and a general description of security measures. The RoPA is the foundation for demonstrating accountability.

Source: Art. 30 GDPR · Regulation (EU) 2016/679 Related service →

Privacy by Design

A principle requiring data protection to be integrated from the outset into the design of any system, process, product or service that will process personal data—not added as an afterthought. Requires appropriate technical and organisational measures (data minimisation, encryption, access controls, etc.) from the design phase. Applies to all stages: database design, API development, AI system architecture, SaaS platform configuration. Non-compliance may be sanctioned by supervisory authorities.

Source: Art. 25 GDPR · EDPB Guidelines 4/2019 · Regulation (EU) 2016/679 Related service →

Privacy by Default

A principle complementary to Privacy by Design requiring that, by default and without any action by the individual, only personal data necessary for each specific processing purpose are processed. The default configuration of systems and applications must offer the highest possible level of privacy: minimum data collected, shortest retention period, minimum accessibility. Users should not have to act to protect their privacy—the protective settings must be the default state.

Source: Art. 25 GDPR · Regulation (EU) 2016/679 Related service →

Profiling

Any form of automated processing of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. The GDPR establishes specific safeguards when profiling produces legal or similarly significant effects on data subjects (Art. 22). Highly relevant for AI-based credit scoring, recruitment systems and recommendation engines.

Source: Art. 4(4) GDPR · Art. 22 GDPR · EDPB Guidelines 05/2022 · Regulation (EU) 2016/679 Related service →

Automated individual decision-making

The right of data subjects not to be subject to a decision based solely on automated processing (without meaningful human involvement), including profiling, which produces legal effects or similarly significantly affects them (credit denial, hiring decisions, insurance pricing). Exceptions are permitted when necessary for a contract, authorised by law, or based on explicit consent—in each case with appropriate safeguards including the right to obtain human review, to express a point of view and to contest the decision.

Source: Art. 22 GDPR · EDPB Guidelines 05/2022 · Regulation (EU) 2016/679 Related service →

International data transfers

Any communication, copy or transfer of personal data to a country outside the European Economic Area (EEA) or to an international organisation. Lawful only if: (a) the destination country benefits from a European Commission adequacy decision (e.g. Japan, Switzerland, Israel, the EU-US Data Privacy Framework); (b) appropriate safeguards are in place (standard contractual clauses, binding corporate rules, approved codes of conduct); or (c) an exception under Art. 49 GDPR applies (explicit consent, contract performance, vital interests, etc.).

Source: Arts. 44-49 GDPR · European Commission adequacy decisions · Regulation (EU) 2016/679 Related service →

Standard Contractual Clauses (SCCs)

A standardised set of contractual clauses approved by the European Commission that provide adequate safeguards for transfers of personal data to countries without an adequacy decision. The current SCCs (Implementing Decision (EU) 2021/914) include four modules covering controller-to-controller and controller-to-processor relationships. Must be supplemented by a Transfer Impact Assessment (TIA) when the destination country has surveillance legislation that may allow government access to the transferred data.

Source: Art. 46(2)(c) GDPR · Implementing Decision (EU) 2021/914 · Regulation (EU) 2016/679 Related service →

Supervisory authority

An independent public authority established in each Member State responsible for monitoring and enforcing the application of the GDPR to protect the fundamental rights and freedoms of natural persons with regard to personal data processing. In Spain: the Agencia Española de Protección de Datos (AEPD). For cross-border processing (data subjects in multiple Member States), the one-stop-shop mechanism applies: the lead supervisory authority (of the controller's main establishment) coordinates the procedure with other concerned authorities.

Source: Arts. 51-59 GDPR · Regulation (EU) 2016/679 Related service →

GDPR fines and penalties

The GDPR establishes two tiers of administrative fines: (1) up to €10 million, or 2% of total worldwide annual turnover of the preceding financial year (whichever is higher), for infringements of general obligations of controllers/processors, certification bodies and monitoring bodies; (2) up to €20 million, or 4% of total worldwide annual turnover (whichever is higher), for infringements of basic principles, data subjects' rights and international transfers. Supervisory authorities may also impose temporary or permanent bans on processing.

Source: Art. 83 GDPR · Regulation (EU) 2016/679 Related service →

Data processing principles

Art. 5 GDPR establishes the principles that must govern all personal data processing: (1) lawfulness, fairness and transparency; (2) purpose limitation (data may not be processed for purposes incompatible with those for which they were collected); (3) data minimisation (only data necessary for the purpose); (4) accuracy; (5) storage limitation (no longer than necessary); (6) integrity and confidentiality (appropriate security). The controller is responsible for, and must be able to demonstrate, compliance with all these principles (accountability principle).

Source: Art. 5 GDPR · Regulation (EU) 2016/679 Related service →

Binding Corporate Rules (BCRs)

Personal data protection policies adopted by a multinational group of companies or a group of undertakings engaged in a joint economic activity, which allow intra-group international transfers of personal data to countries without an adequacy decision, subject to approval by the competent lead supervisory authority after consultation with other authorities. BCRs must include enforceable rights for data subjects against any member of the group and must be binding on all group members.

Source: Art. 47 GDPR · EDPB Guidelines 04/2021 · Regulation (EU) 2016/679 Related service →

Accountability

Principle by which the controller is responsible for demonstrating compliance with the GDPR. It is not enough to comply: the controller must be able to prove it through documentation (records of processing activities, DPIAs, legal basis analyses, processor contracts, consent records). Accountability is the basis of reactive supervision by authorities: the AEPD does not audit continuously, but requires the controller to prove compliance during an inspection or complaint.

Source: Art. 5(2) GDPR · Regulation (EU) 2016/679 Related service →

Sub-processor

Natural or legal person who processes personal data on behalf of the processor, with the controller's authorisation. The processor may only engage a sub-processor with the controller's prior specific or general authorisation. In case of general authorisation, the processor must inform the controller of any changes. The sub-processor is subject to the same obligations as the processor through a contract or other legal act (Art. 28(4)). The sub-processor chain is critical in cloud and SaaS environments.

Source: Art. 28(2)-(4) GDPR · Regulation (EU) 2016/679 Related service →

Transfer Impact Assessment (TIA)

Analysis that the controller or processor must conduct before making an international data transfer based on Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs), to assess whether the destination country offers an essentially equivalent level of protection to the EU. The TIA must consider the third country's legislation (especially government surveillance/access laws), the practices of its authorities, and the supplementary measures that can be adopted (encryption, pseudonymisation, reinforced contracts). The EDPB issued specific recommendations in 2020.

Source: EDPB Recommendations 01/2020 on supplementary measures · Regulation (EU) 2016/679 Related service →

Adequacy decision

Commission decision determining that a third country, a territory, one or more specified sectors within a third country, or an international organisation, offers an essentially equivalent level of personal data protection to the EU. With an adequacy decision, international transfers may take place without specific additional authorisation. Countries with a valid adequacy decision include Japan, Switzerland, Israel, the United Kingdom, South Korea, and the EU-US Data Privacy Framework (2023). The Commission may suspend or revoke the decision if the level of protection is no longer equivalent.

Source: Art. 45 GDPR · Regulation (EU) 2016/679 Related service →

EU-US Data Privacy Framework

Bilateral agreement in force since 10 July 2023 that allows US companies to self-certify with the US Department of Commerce to receive personal data from the EU with adequate safeguards. It replaces the Privacy Shield (invalidated by the CJEU in 2020, Schrems II case) and the Safe Harbor (invalidated in 2015, Schrems I case). Certified companies must comply with data protection principles, submit to supervision by the EU Data Protection Ombudsman and allow complaints from European data subjects. The framework's validity is pending judicial confirmation before the CJEU.

Source: Implementing Decision (EU) 2023/1795 · Regulation (EU) 2016/679 Related service →

Code of conduct

Set of rules of conduct or best practices drawn up by an association or representative body of categories of controllers or processors, contributing to the proper application of the GDPR. It must be approved by the competent supervisory authority and, for international transfers, by the EDPB. Codes of conduct can serve as an international transfer mechanism (Art. 46(2)(e)) and as a transparency element for data subjects. Adherence is voluntary but, once adopted, binding.

Source: Art. 40 GDPR · Regulation (EU) 2016/679 Related service →

Certification mechanism

Voluntary procedure by which an accredited certification body assesses and certifies that a personal data processing operation complies with the GDPR. Certification may be issued by the supervisory authority or by an accredited certification body, with a maximum validity of 3 years, renewable. Certifications can serve as an international transfer mechanism (Art. 46(2)(f)) and as a transparency element. In Spain, the AEPD has accredited schemes such as the ENS privacy seal.

Source: Art. 42 GDPR · Regulation (EU) 2016/679 Related service →

Genetic data

Personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or health of that person and which are obtained, in particular, through an analysis of a biological sample. They are special categories of data (Art. 9) and require a specific legal basis (explicit consent, medical diagnosis, scientific research with safeguards). DNA analysis for paternity, disease predisposition or genealogy constitutes processing of genetic data.

Source: Art. 4(13) GDPR · Regulation (EU) 2016/679 Related service →

Biometric data

Personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm their unique identification, such as facial images or dactyloscopic data. They are special categories when used for the purpose of uniquely identifying a natural person (Art. 9(1)). The use of facial recognition, fingerprints, iris scans or voice for authentication or identification constitutes processing of biometric data. The AI Act additionally regulates biometric systems (Annex III, point 1).

Source: Art. 4(14) GDPR · Art. 9 GDPR · Regulation (EU) 2016/679 Related service →

Health data

Personal data relating to the physical or mental health of a natural person, including the provision of health care services, that reveal information about their health status. They are special categories (Art. 9(1)). They include data from medical records, test results, diagnoses, treatments, data from medical devices and health app data. Processing requires explicit consent or one of the exceptions of Art. 9(2)(h) (health care) or (i) (public health). The Spanish LOPDGDD additionally regulates them in its arts. 7-11.

Source: Art. 4(15) GDPR · Art. 9 GDPR · Regulation (EU) 2016/679 Related service →

Lead supervisory authority (one-stop-shop)

GDPR mechanism by which, when a controller or processor has establishments in several Member States, a single supervisory authority acts as the main interlocutor. The lead authority is that of the place of the controller's main establishment (where decisions on purposes and means of processing are taken). Other concerned authorities must cooperate and may raise motivated objections. If no agreement is reached, the EDPB resolves through a binding decision. It does not apply if the controller has no establishment in the EU (then the competent authority is that of the place of the affected data subjects).

Source: Arts. 56-57 GDPR · Regulation (EU) 2016/679 Related service →

Cooperation between supervisory authorities

Obligation of supervisory authorities to cooperate with each other and with the European Commission in the application of the GDPR. It includes information exchange, mutual assistance in investigations, and enforcement of measures. Authorities must provide each other with information and, upon request, assistance in cross-border investigations. Cooperation is channelled through the EDPB (European Data Protection Board) and the IMI information system platform. The AEPD routinely cooperates with authorities of other Member States in cross-border cases.

Source: Arts. 60-62 GDPR · Regulation (EU) 2016/679 Related service →

Complaint to a supervisory authority

Right of the data subject to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement, if they consider that the processing of their personal data infringes the GDPR. The authority must inform the complainant of the progress and outcome of the complaint, indicating judicial remedies. Filing the complaint is free of charge. The AEPD allows filing complaints online through its electronic headquarters.

Source: Art. 77 GDPR · Regulation (EU) 2016/679 Related service →

Right to an effective judicial remedy

Right of the data subject to an effective judicial remedy against decisions of a supervisory authority concerning them, and against a controller or processor that has carried out unlawful processing. The data subject may bring proceedings before the courts of the Member State where they have their residence or where the controller has its establishment. In Spain, the administrative litigation jurisdiction hears appeals against AEPD decisions, and the civil jurisdiction hears actions against controllers or processors. The limitation period is 6 months (administrative) or 1 year (civil).

Source: Art. 78-79 GDPR · Regulation (EU) 2016/679 Related service →

Does your company need to comply with the GDPR?

We help you identify the correct legal bases for processing, draft privacy notices, data processing agreements and DPIAs, and design a data protection policy tailored to your business and AI projects.

Request advice
Contact us