defencia/knowledge/gdpr
Privacy · Principles · Data subject rights

GDPR

A compressed walkthrough of GDPR: the data controller's obligations, the seven data-protection principles, data subject rights, and how breaches are handled.

GovernanceISO 27701

Obligations of the data controller

The controller decides why and how personal data is processed and is responsible for compliance. GDPR has applied since 25 May 2018 and is built on seven core principles.

The 7 data protection principles

PrincipleMeaning
Transparency & lawfulnessProcessing must be lawful, fair and transparent to the data subject.
Purpose limitationCollect for specified, explicit, legitimate purposes only.
Data minimisationCollect only what is adequate, relevant and necessary.
AccuracyKeep data correct and up to date; erase or rectify errors.
Storage limitationKeep data no longer than necessary for the purpose.
Confidentiality & integrityProtect against unauthorised access, loss or damage (security).
AccountabilityBe able to demonstrate compliance with all of the above.

Data subject rights

Data breach through GDPR's eyes

A breach involving personal data must be handled under GDPR. Map your data (data mapping) so you know what you hold and where, and align handling with ISO 27701 (the privacy extension to ISO 27001).

On personal-data loss, involve the DPO and keep contact with the supervisory authority — in Denmark, Datatilsynet — within the notification deadline.