Common GDPR Terms Defined
Learn about key EU-GDPR concepts such as Privacy by Default, Portability, Icons, and Pseudonymization
Written By Micah
This guide defines specific terms and concepts found in the EU-GDPR.
Data Portability - Data portability is a fundamental GDPR data subject right and simply means that a data subject may receive and reuse information about them that they provided to a controller. For example, if Jane has provided her personal data to a social media company, then decides to shut down her account and move to a different social media company, the first social media company can't lock her in - they must provide the data she has provided and do so in an easily readable format. The key is that the data must have been provided by consent or via contract to the controller to be processed in an automated manner.
Data Pseudonymization - This refers to a method that switches a data set with an alias or pseudonym. For GDPR, this means taking PII and replacing it with data that cannot be used to identify an individual without additional information. Pseudonymization is not a GDPR requirement but is one of many methods that can be used to protect PII. It is used in the GDPR world to remove direct identifiers to mitigate the risk of misuse of PII. Pseudomyzed data is STILL considered PII because when used with other data, it can point back to an individual. Examples include a customer ID Number used during processing but converted back to the customer's name when they view their data.
Data Privacy by Design (aka PbD) - This concept refers to protecting personal data through technological means throughout the entire engineering process. For GDPR, this means building privacy checks and balances (or safeguards) when updating or creating new business processes. Many organizations will include a PbD check or stage in their change management processes. Encryption and pseudonymization are examples of privacy by design.
Data Privacy by Default - This concept refers to ensuring the highest level of privacy protections, such as collecting only what is necessary for the specified purpose, pre-configuring privacy settings for users, and limiting access to PII when it is first provided. Any privacy by design methods identified by the organization should be enabled, by default.
EU GDPR Representative - The EU GDPR requires that a representative be identified to act as the contact point between the organization and GDPR supervisory authorities. This individual or representative is not a Data Protection Officer (or DPO). The representative needs to be located in one of the EU Member states (this is where the processing of personal data takes place), so many organizations turn to service providers. If you don't have an office in the EU, you will need to find an EU Based Representative. Refer to Article 27(2) for exceptions to this requirement.
Data Processing by Design and Default (DPbDaD) - Certification. The EU-GDPR mentions that there can be a certification for DPbDaD. To date, this certification has not been created. This regulation is not mapped to a control within Strike Graph, because no certification exists yet.
GDPR Code of Conduct - The GDPR mentions that organizations may adhere to a GDPR Code of Conduct. The codes of conduct can be established by trade organizations, private entities, or governing bodies. For a fee, organizations can indicate they comply with a GDPR Code of Conduct and post a seal or badge on their websites. The GDPR Code of Conduct is generally self-assessed.
Icons - If an organization uses icons to describe privacy concepts, they must be clear and understandable (and machine-readable). A great example of a clear icon is the shield - it has come to signify that something is protected or secure. There are no standardized icons for privacy, but a quick internet search for “data privacy Icons” will bring up examples.
Security of Processing - GDPR requires that organizations employ and document security measures to protect the processing of personal data. Based on a privacy risk assessment, appropriate measures should be adopted, such as encryption, pseudonymization, data restoration, and testing of security measures.
Questions?
Reach out through our chat feature for real-time Customer Success support 8 am - 5 pm PT Monday through Friday.