GDPR (General Data Protection Regulation) is privacy a security regulations put in effect by the European Union, but impacts all organizations if they collect data from people in the EU.
Terms that GDPR uses include:
- Personal data: Personal data is any information that relates to an individual who can be directly or indirectly identified. Names and email addresses are obviously personal data. Location information, ethnicity, gender, biometric data, religious beliefs, web cookies, and political opinions can also be personal data. Pseudonymous data can also fall under the definition if it’s relatively easy to ID someone from it.
- Data processing: Any action performed on data, whether automated or manual. The examples include collecting, recording, organizing, structuring, storing, using, and erasing.
- Data subject: The person whose data is processed. These are your customers or site visitors.
- Data controller: The person who decides why and how personal data will be processed. If you’re an owner or employee in your organization who handles data, this is you.
- Data processor: A third party that processes personal data on behalf of a data controller. The GDPR has special rules for these individuals and organizations. They could include cloud servers or email service providers.
Comments
0 comments
Please sign in to leave a comment.