The data protection glossary.

The key terms of data protection law, explained by lawyers. Short enough to look up, precise enough to quote.

Book a consultation

62 terms, from A to Z.

9 terms

Census judgment (Volkszählungsurteil) The census judgment is the decision of the Federal Constitutional Court of 15 December 1983 which established the right to informational self-determination. BVerfG, judgment of 15 December 1983 Cloud computing Cloud computing is the provision of IT resources such as storage, computing power or software over the internet by an external provider. Art. 28 GDPR Collection of personal data Collection is the obtaining of personal data about a person and at the same time the first step of any processing. Art. 4(2) GDPR Compensation under the GDPR Under Art. 82 GDPR, any person who has suffered material or non-material damage as a result of an infringement of the GDPR has the right to receive compensation. Art. 82 GDPR Consent Consent is a freely given, specific, informed and unambiguous indication of a person's wishes by which they agree to the processing of their data. Art. 4(11) GDPR Consent management Consent management refers to obtaining, documenting and managing consent, typically through a consent management platform on websites and in apps. Section 25 TDDDG Controller The controller is the natural or legal person, public authority or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Art. 4(7) GDPR Cookies Cookies are small text files that a website stores on the user's terminal device in order to recognise the user or save settings. Section 25 TDDDG Customer data Customer data is all information about customers that a company processes in the course of the business relationship, and it is personal data insofar as it relates to natural persons. Art. 6(1)(b) GDPR

11 terms

Data access control Data access control ensures that authorised persons can only access the data they need for their tasks. Art. 32(1)(b) GDPR Data breach A data breach is a breach of the security of personal data, for example through loss, unauthorised access or accidental disclosure. Art. 4(12) GDPR Data breach notification The obligation to notify personal data breaches requires controllers to report a data breach to the supervisory authority within 72 hours of becoming aware of it. Art. 33 GDPR Data minimisation Data minimisation is the principle that only as much personal data may be processed as is necessary for the purpose in question. Art. 5(1)(c) GDPR Data processing agreement (DPA) The data processing agreement is the contract between a controller and its processor that is required under Art. 28 GDPR. Art. 28(3) GDPR Data protection Data protection is the protection of natural persons with regard to the processing of their personal data. Art. 8 EU Charter of Fundamental Rights Data protection impact assessment (DPIA) The data protection impact assessment is a structured risk analysis for processing operations that are likely to result in a high risk to data subjects. Art. 35 GDPR Data protection officer (DPO) The data protection officer monitors compliance with data protection rules within an organisation and is the point of contact for the supervisory authority and data subjects. Art. 37 GDPR Data security Data security refers to the protection of data against loss, manipulation and unauthorised access through technical and organisational measures. Art. 5(1)(f) GDPR Data subject The data subject is the identified or identifiable natural person to whom personal data relates. Art. 4(1) GDPR Deletion concept A deletion concept sets out in a binding manner which personal data is deleted when, how and by whom. Art. 5(1)(e) GDPR

11 terms

Personal data Personal data means any information relating to an identified or identifiable natural person. Art. 4(1) GDPR Physical access control Physical access control prevents unauthorised persons from physically entering premises and facilities in which personal data is processed. Art. 32 GDPR Privacy by default Privacy by default means choosing default settings so that, by default, only the personal data necessary for the specific purpose is processed. Art. 25(2) GDPR Privacy by design Privacy by design means building data protection into the technical and organisational design of systems, products and processes from the outset. Art. 25(1) GDPR Privacy notice The privacy notice is the information with which a controller informs data subjects about the processing of their personal data, typically on a website. Art. 12 GDPR Processing of personal data Processing is any operation performed on personal data, from collection through storage and use to erasure. Art. 4(2) GDPR Processing on behalf of a controller Processing on behalf of a controller takes place when a service provider processes personal data for another company and is bound by its instructions. Art. 4(8) GDPR Prohibition of tying (Koppelungsverbot) The prohibition of tying means that consent is generally not freely given if a contract is made conditional on consent that is not necessary for its performance. Art. 7(4) GDPR Prohibition subject to permission (Verbot mit Erlaubnisvorbehalt) The prohibition subject to permission describes the principle that processing personal data is prohibited unless it is permitted by a legal basis. Art. 6(1) GDPR Pseudonymisation Pseudonymisation is the processing of personal data in such a way that it can no longer be attributed to a specific person without additional information that is kept separately. Art. 4(5) GDPR Purpose limitation Purpose limitation is the principle that personal data may only be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes. Art. 5(1)(b) GDPR

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.