
Data protection explained - European Commission
Read about key concepts such as personal data, data processing, who the GDPR applies to, the principles of the GDPR, the rights of individuals, and more.
What is a data controller or a data processor? - European Commission
Joint controllers must enter into an arrangement setting out their respective responsibilities for complying with the GDPR rules. The main aspects of the arrangement must be communicated to the individuals …
Legal framework of EU data protection - European Commission
Dec 11, 2018 · The General Data Protection Regulation (GDPR) Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free …
Data protection - European Commission
Jun 16, 2025 · In today's digital age, where information is constantly shared, collected and processed, there is a need for clear and strong data protection rules. Data protection is a fundamental right …
What is a data breach and what do we have to do in case of a data ...
A data breach occurs when the data for which your company/organisation is responsible suffers a security incident resulting in a breach of confidentiality, availability or integrity. If that occurs, and it is …
What personal data is considered sensitive? - European Commission
The following personal data is considered ‘sensitive’ and is subject to specific processing conditions: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs; …
What does data protection ‘by design’ and ‘by default’ mean?
Companies/organisations are encouraged to implement technical and organisational measures, at the earliest stages of the design of the processing operations, in such a way that safeguards privacy and …
Data protection adequacy for non-EU countries
Jan 26, 2026 · Discover the procedure that allows the European Commission to determine whether a country outside the EU offers an adequate level of data protection.
When is consent valid? - European Commission
When consent is required to process personal data, for that consent to be valid the following conditions must be met: it must be freely given; it must be informed; it must be given for a specific purpose; all …
Sensitive data - European Commission
Information on data considered sensitive under EU data protection law and the safeguards it is subject to when being processed.