General Data Protection Regulation (GDPR)

The GDPR is a data protection and privacy regulation by the EU, effective since May 25, 2018. It applies to EU member states and organizations processing EU citizens' personal data, even if located outside the EU. GDPR covers the following scope:
  1. Personal data: Identifiable information about an individual, such as names, email addresses, location data, ethnicity, gender, biometric data, religious beliefs, web cookies, and political opinions.
  2. Data processing: any action, whether automated or manual, performed on data. Examples include collecting, recording, organizing, structuring, storing, using, and erasing data.
  3. Data subject: A person whose data is being processed, such as customers or site visitors.
  4. Data controller: A person responsible for determining the purposes and methods of processing personal data. 
  5. Data processor: A third party (email server, cloud) that processes personal data  on behalf of a data controller. 

Key principles of the GDPR include:
  1. Lawfulness, fairness, and transparency: Personal data must be processed lawfully, with transparency about how it will be used, and in a way that respects individuals' rights.
  2. Purpose limitation: Personal data should only be collected and processed for specific, explicit, and legitimate purposes.
  3. Data minimization: Organizations should collect and process only the personal data that is necessary for the stated purposes.
  4. Accuracy: Personal data should be accurate, and reasonable steps should be taken to ensure it is kept up to date.
  5. Storage limitation: Personal data should be kept for no longer than necessary for the purposes it was collected, and organizations should have policies in place to determine retention periods.
  6. Integrity and confidentiality: Organizations are required to implement appropriate security measures to protect personal data from unauthorized access, loss, or disclosure.
  7. Accountability: Organizations must be able to demonstrate compliance with the GDPR and have processes and policies in place to protect individuals' rights.

Comments

Popular posts from this blog

QUALITY MANAGEMENT PRINCIPLES & PRACTICES

KPIs EXAMPLES

Firmware Development and Debugging