top of page
cyber-security-network-padlock-icon-internet-technology-networking-businessman-protecting-

GDPR in plain language

The information contained in this site is provided for informational purposes only, and should not be used as legal advice on any subject matter. You should not act or refrain from acting on the basis of any content included on this site without seeking legal or other professional advice 

The journey begins

How it all began

Article 1 - First things first

Who is the star of our show?.

Article 2 - Material Scope

What is the subject of this story?

Article 3 - Territorial scope

If only Europe counts, why should we care about it???

Article 4 - Definitions

Let's call them by name

Article 5 - Principles

We are people of Principles. Let's see what they are

Article 6 - Lawfulness

The first principle is all about transparency

Article 7 - Conditions for consent

Are you totally sure that you agree?

Article 8 - Child's consent

A child is just a child

Article 9 - Special categories

Not every private information is equal

Article 10 - Criminal convictions

Criminals are not doomed forever

Article 11 - No ID required

How can we take care of an individual's rights if we don't have details that identify him?

Article 12 - Transparent information

Now you see me, now you don't

Article 13 - Data collected from the data subject

Tell us what you really really want

Article 14 - Information not obtained directly

What are you doing with MY data?

Article 15 - Right of access

If you want it, come and get it!

Article 16 - Right to rectification

You are what you are.

Article 17 - Right to be forgotten

Now you see it, now you don't

Article 18 - Right to restriction of processing

Wait a minute, Mr. controller!

Article 19 - Notification regarding rectification or erasure

Follow the trail of our information.

Article 20 - Right to data portability

Get your data back

Article 21 - Right to object

Objection! Don't process my data

Article 22 - Automated decision

Don't let the machine make the decision about us!

Article 23 - Restrictions

Sometimes privacy is not the only consideration

Article 24 - Responsibility of the controller

You got our data. Protect it!

Article 25 - Data protection by design and by default

First things first

Article 26 - Joint controllers

One and one and one is three.

Article 27 - Representatives of controllers or processors

And who shall I say is calling?

Article 28 - Processor

Make sue your processors is comitted.

Article 29 - Processing data

Do what you have to do. Not more and not less

Article 30 - Records of processing activities

It's the ROPA time. This is the place to start the GDPR journey.

Article 31 - Cooperation with the supervisory authority

Please cooperate with the authorities

Article 32 - Security of processing

Security is not the core of this story, but it definitely matters!

Article 33 - Notification of a personal data breach

Notify the authorities when personal data leaks

Article 34 - Communication of a breach to the data subject

Let us know that our data leaked

Article 35 - Data protection impact assessment

Assess the risk before implementing a new product or service

Article 36 - Prior consultation

If your abilities to protect the private data are limited - consult the authorities

Article 37 -Designation of adata protection officer

When should you nominate an officer? (Hint - always)

Article 38 - Position of the Data Protection Officer

The DPO is your privacy coordinator both internally and externally.

Article 39 - Tasks of the Data Protection Officer

Being a DPO is a complicated assignment. He should be able to wear many hats.

Article 40 - Codes of conduct

Codes of Conduct assist members of that Code with data protection compliance and accountability in specific sectors.

Article 41 - Monitoring of approved codes of conduct

How can one demonstrate that the code of conduct meets the requirements?

Article 42 - Certification

Will we ever have a formal way to get GDPR certification? Great expectations

Article 43 - Certification bodies

Who will be able to certify us (when and if certification will exist)?

Article 44 - Transfers of personal data to third countries

When the data leaves Europe

Article 45 - Transfers on the basis of an adequacy decision

The wonderful life of the adequate countries

Article 46 - Transfers subject to appropriate safeguards

It's not so easy to move data. The story of Schrems.

Article 47 - Binding corporate rules

All together now - Establish rules that hold for all the enterprise

Article 48 - Transfers or disclosures not authorized by Union law

The right to refuse even to the big guys

Article 49 - Derogations for specific situations

Few exceptions

Article 50 - International cooperation

Imagine all the people
Livin' life in peace

Article 51 - Supervisory authority

Some intro to the EU and its governing bodies

bottom of page