Skip to main content
European Commission logo
European Commission

Application of the GDPR

Information on what constitutes personal data and processing under the GDPR and which businesses and organisations the regulation applies to.

Definitions of “personal data” and “processing”

What is personal data and processing?

Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which collected together can lead to the identification of a particular person, also constitute personal data.

Personal data that has been de-identified, encrypted or pseudonymised but can be used to re-identify a person remains personal data and falls within the scope of the General Data Protection Regulation (GDPR).

Personal data that has been rendered anonymous in such a way that the individual is not or no longer identifiable is no longer considered personal data. For data to be truly anonymised, the anonymisation must be irreversible.

The GDPR protects personal data regardless of the technology used for processing that data – it is technology neutral and applies to both automated and manual processing, provided the data is organised in accordance with pre-defined criteria (for example alphabetical order). 

It also does not matter how the data is stored – in an IT system, through video surveillance, or on paper; in all cases, personal data is subject to the protection requirements set out in the GDPR.

Examples of personal data

  • a name and surname;
  • a home address;
  • an email address such as name [dot] surnameatcompany [dot] com (name[dot]surname[at]company[dot]com);
  • an identification card number;
  • location data (for example the location data function on a mobile phone)*;
  • an Internet Protocol (IP) address;
  • a cookie ID*;
  • the advertising identifier of your phone;
  • data held by a hospital or doctor, which could be a symbol that uniquely identifies a person.

*Note that in some cases, there is a specific sectoral legislation regulating for instance the use of location data or the use of cookies – the ePrivacy Directive (Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002(OJ L 201, 31.7.2002, p. 37)  and Regulation (EC) No 2006/2004) of the European Parliament and of the Council of 27 October 2004 (OJ L 364, 9.12.2004, p. 1)

Examples of data not considered personal data

  • a company registration number;
  • an email address such as infoatcompany [dot] com (info[at]company[dot]com);
  • anonymised data.

References

What constitutes data processing?

Processing covers a wide range of operations performed on personal data, including by manual or automated means. 

It includes the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of personal data.

The GDPR applies to the processing of personal data wholly or partly by automated means as well as to non-automated processing, if it is part of a structured filing system.

Examples of processing include:

  • staff management and payroll administration;
  • access to/consultation of a contacts database containing personal data;
  • sending promotional emails*;
  • shredding documents containing personal data;
  • posting/putting a photo of a person on a website;
  • storing IP addresses or MAC addresses;   
  • video recording (CCTV).

*Please remember that to send direct marketing emails, you also have to comply with the marketing rules set out in the ePrivacy Directive.

References

Roles of controller and processor 

What is a data controller or a data processor?

The data controller determines the purposes for which and the means by which personal data is processed. If a company/organisation decides ‘why’ and ‘how’ the personal data should be processed, it is the data controller. Employees processing personal data within an organisation do so to fulfil its tasks as data controller. 

The data controller is responsible for complying with the principles of data processing (Article 5 GDPR) and must be able to demonstrate its compliance with them.

A company/organisation is a joint controller when together with one or more organisations it jointly determines ‘why’ and ‘how’ personal data should be processed. Joint controllers must enter into an arrangement setting out their respective responsibilities for complying with the GDPR rules. The main aspects of the arrangement must be communicated to the individuals whose data is being processed.

The data processor processes personal data only on behalf of the controller. The data processor is usually a third party external to the company/organisation. However, in the case of groups of undertakings, one undertaking may act as processor for another undertaking.

The duties of the processor towards the controller must be specified in a contract or other legal act that is binding on the processor. For example, the contract must indicate what happens to the personal data once the contract is terminated. A typical activity of processors is offering IT solutions, including cloud storage. The data processor may only sub-contract a part of its task to another processor or appoint a joint processor when it has received a prior written authorisation from the data controller.

There are situations where a company/organisation can be a data controller, or a data processor, or both, in relation to different parts of the same processing operation.

Examples

Controller and processor

A brewery has many employees. It signs a contract with a payroll company to pay the wages. 

The brewery tells the payroll company when the wages should be paid, when an employee leaves or has a pay rise, and provides all other details for the salary slip and payment. 

The payroll company provides the IT system and stores the employees’ data. 

The brewery is the data controller and the payroll company is the data processor.

Joint controllers

A company offers baby-sitting services via an online platform. 

At the same time that company has a contract with another company allowing it to offer value-added services. Those services include the possibility for parents not only to choose the babysitter but also to rent games and DVDs that the babysitter can bring. 

Both companies are involved in the technical set-up of the same online platform. In that case, the two companies have decided to use the platform for both purposes (babysitting services and DVD/games rental) and will very often share clients’ names. 

Therefore, the two companies are joint controllers because not only do they agree to offer the possibility of ‘combined services’ but they also design and use a common platform.

References

 

Can someone else process data on behalf of a company or organisation?

Someone else (a natural or legal person or any other body) may process personal data on behalf of a company/organisation (the ‘controller’) provided that there is a contract or other legal act allowing it. 

It is important that the processor appointed by the controller provides sufficient guarantees to implement appropriate technical and organisational measures to ensure that the processing will meet the standards of the GDPR and to guarantee the protection of the rights of the individuals.

The appointed processor cannot subsequently appoint another processor without a prior, specific or general written authorisation of the data controller. The contract or legal act between the controller and the processor should make explicit for instance the following elements:

  • the processing can take place only on documented instructions from the controller;
  • the processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  • the processor must implement appropriate security measures, including those defined by the controller;
  • the processor must assist in ensuring compliance with the GDPR.

Examples

A construction company is using a sub-contractor for specific construction work and provides it with the contact details of the clients where the construction work needs to be done. The sub-contractor further uses the data to send marketing material to those clients. The sub-contractor in that case does not qualify merely as a ‘processor’ under the GDPR as the sub-contractor is not only processing personal data on behalf of the construction company, but also processing this data for its own purposes. The sub-contractor is therefore also acting as a ‘data controller’.

A retail company decides to store a back-up version of its client database on a cloud server. To that end it enters into a contract with a cloud provider known for its high data protection standards, including a certified system of encryption of data. The cloud provider is the retail company’s processor, as by storing the clients’ personal data in its servers it will be processing personal data on behalf of the retail company.

References

Businesses and organisations subject to data protection rules

Who does the data protection law apply to?

The GDPR applies to:

  1. a company or entity which processes personal data as part of the activities of one of its branches established in the EU, regardless of where the data is processed; or
  2. a company established outside the EU and is offering goods/services (paid or for free) or is monitoring the behaviour of individuals in the EU.

If your company is a small and medium-sized enterprise (SME) that processes personal data as described above you have to comply with the GDPR. 

However, if processing personal data is not a core part of your business and your activity does not create risks for individuals, then some obligations of the GDPR will not apply to you (for example the appointment of a Data Protection Officer (DPO)). 

Note that ‘core activities’ should include activities where the processing of data forms is an inextricable part of the controller’s or processor’s activities.

Examples

When the regulation applies

Your company is a small, tertiary education company operating online with an establishment based outside the EU. It targets mainly Spanish and Portuguese language universities in the EU. 

It offers free advice on a number of university courses and students require a username and a password to access your online material. Your company provides the said username and password once the students fill out an enrolment form.

When the regulation does not apply

Your company is service provider based outside the EU. It provides services to customers outside the EU. Its clients can use its services when they travel to other countries, including within the EU. 

Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR. 

What does the General Data Protection Regulation (GDPR) govern?

The GDPR regulates the processing by an individual, a company or an organisation of personal data relating to individuals in the EU.

It doesn’t apply to the processing of personal data of deceased persons or of legal persons.

The rules don’t apply to data processed by an individual for purely personal reasons or for activities carried out in one's home, provided there is no connection to a professional or commercial activity. 

When an individual uses personal data outside the personal sphere, for socio-cultural or financial activities, for example, then the data protection law has to be respected.

Examples

When the regulation applies

A company with an establishment in the EU provides travel services to customers based in the Baltic countries and in that context processes personal data of natural persons.

When the regulation doesn’t apply

An individual uses their own private address book to invite friends via email to a party that they are organising (household exception).

References

Specific rules for SMEs 

Do the data protection rules apply to SMEs?

The application of the GDPR does not depend on the size of your company/organisation but on the nature of your activities. Activities that present high risks for the individuals’ rights and freedoms, whether they are carried out by an SME or by a large corporation, trigger the application of more stringent rules. However, some of the obligations of the GDPR do not apply to all SMEs. 

For instance, companies and organisations with fewer than 250 employees do not need to keep records of their processing activities unless processing of personal data is a regular activity, poses a threat to individuals’ rights and freedoms, or concerns sensitive data or criminal records. 

Similarly, SMEs data controllers and processors, including SMEs, will only have to appoint a Data Protection Officer if processing is their main business and it poses specific threats to the individuals’ rights and freedoms (such as monitoring of individuals or processing of sensitive data or criminal records), in particular if it is done on a large scale. 

References

Are the obligations the same regardless of the amount of data a company/organisation handles?

The GDPR is based on the risk-based approach. This means that companies/organisations processing personal data must implement protective measures corresponding to the risks created by their data processing activities

The likelihood and severity of the risk to the rights of an individual should be determined on the basis of the nature, scope, context and purposes of the processing.

For example, it is more likely for a company/organisation processing a lot of data than for a company/organisation processing a small amount of data to be obliged to hire a Data Protection Officer (in that case this links to the notion of processing of personal data on a ‘large scale’).

At the same time, the nature of the personal data and the impact of the envisaged processing also play a role. Processing of a small amount of data, but which is of a sensitive nature, for example health data, would require implementing more stringent measures to comply with the GDPR.

In all cases, the principles of data processing must be respected and individuals allowed to exercise their rights.

Reference

Public authorities and data protection

What are the main aspects of the GDPR that public authorities should be aware of?

Public authorities are subject to the rules of the GDPR when processing personal data relating to an individual.  

In most cases public authorities process personal data as it is necessary to comply with a legal obligation they are subject to, or as it is necessary to perform their task or tasks carried out in a public interest or in the exercise of official authority vested in them. Such legal obligation, task or official authority must be based either on EU or Member State law.  

When processing personal data, a public authority must respect the principles of data processing under the GDPR, such as: 

  • fair and lawful processing; 
  • purpose limitation; 
  • data minimisation;  
  • storage limitation; and 
  • integrity and confidentiality. 

Prior to processing personal data, individuals must be informed about the processing, such as its purposes, the types of data collected, the recipients, and their data protection rights. 

A public authority is required to appoint a Data Protection Officer (DPO); howevera single data protection officer may be designated for several public bodies or this work can be outsourced to an external DPO.  

A public authority must also ensure that appropriate technical and organisational measures have been implemented to secure personal data. If parts of the processing are outsourced to an external organisation (the ‘processor’), there must be a contract or another legal act guaranteeing that the processor provides sufficient guarantees to implement appropriate technical and organisational measures that meet the standards of the GDPR. 

In cases where personal data held is disclosed accidentally or unlawfully to unauthorised recipients or is temporarily unavailable or altered, the breach must be notified to the Data Protection Authority (DPA) without undue delay and at the latest within 72 hours after having become aware of the breach. The public authority may also need to inform individuals about the breach. 

More information about the public authorities’ obligations as data controllers under the GDPR can be found in the section Obligations.

References

What if a public authority fails to comply with data protection rules?

The data protection authorities (DPAs) have different tools at their disposal in cases of non-compliance. 

In the case of a likely infringement, a warning may be issued. In the case of an infringement, the possibilities include a reprimand or a temporary or definitive ban on the processing

In some countries, public authorities may also be subject to administrative fines. A public authority should check the data protection law of its Member State. 

Individuals can claim compensation where a public body is in breach of the GDPR and they have suffered material damages as a consequence of that breach (for example, financial loss), or non-material damages (for example, reputational loss or psychological distress). 

The GDPR ensures that they will be provided with compensation, regardless of the number of organisations involved in the processing of their data. Compensation can be claimed directly from the public body or before the competent national courts of the Member State concerned.  

More information about the consequences of non-compliance can be found in the section Enforcement and sanctions.

References

Data about legal persons

Do the data protection rules apply to data about a company/organisation?

The GDPR rules only apply to personal data about individuals; they do not govern data about companies or any other legal entities. 

However, information in relation to companies may constitute personal data where it allows the identification of a natural person. 

The rules also apply to all personal data relating to natural persons in the course of a professional activity, such as the employees of a company/organisation, business email addresses like ‘forename [dot] surnameatcompany [dot] eu (forename[dot]surname[at]company[dot]eu)’ or employees’ business telephone numbers.

References