Basic principles of personal data and the EU General Data Protection Regulation (GDPR).
Data processing (DP) generally refers to the organized handling of data volumes with the aim of obtaining information about these data volumes or modifying them. The term was used even before the introduction of computer systems.
Data protection is standardized within the EU. The basis is the General Data Protection Regulation (GDPR), EU Regulation 2016/679, which the individual EU member states also reflect in their national regulations.
The EU regulation is available in at least 24 languages as a PDF or HTML version. >>> General Data Protection Regulation (GDPR)
General data processing is now a daily part of the use of computers, software, and media, and can be carried out via a variety of technical channels and components. This aspect will not be discussed in this section. Rather, the focus will be on the protection regulations governing the processing itself, especially personal data.
Fundamentals of personal data
The daily handling of data volumes, their collection, and storage is not subject to individual discretion. While data processing in private life and for personal purposes on a home PC or smartphone is not subject to any supervision, there are clear rules and conditions for data exchange in business life. These are subject to the General Data Protection Regulation. According to Article 4, Number 2 of the General Data Protection Regulation (GDPR), the term "processing" is defined as:
"‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;"
Source: Art. 4 (2) GDPR
Personal data is particularly protected. The General Data Protection Regulation sets out mandatory rules for the collection and processing of such data. Processing must, in particular, comply with the following principles (Art. 5 Nr. 1 GDPR):
- It must be subject to lawfulness, fairness and transparency
- Data may only be collected for specified, explicit and legitimate purposes and may not be further processed for purposes other than those for which it was collected.
- It is subject to data minimization. Therefore, it is appropriate to the purpose and limited to what is necessary for the purposes of processing.
- It must ensure accuracy and be up to date.
- The form of data storage should only allow the identification of data subjects for as long as is necessary for the purposes for which they are processed.
- As well as ensuring integrity and confidentiality. Their storage must be protected against loss, unauthorized or unlawful processing, as well as accidental damage or destruction.
For larger amounts of data, it is advisable to seek advice from an external data protection officer/consultant, as violations of regulations are subject to sanctions.
Data processing within the framework of order management
If data is processed on behalf of a business partner, the controller and the contractor must agree to this in a separate data processing agreement (data processing agreement with a customer service office or call center). The content of this agreement must also comply with the additional requirements of the General Data Protection Regulation. The aim is to guarantee that:
"... appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.."
Source: Art. 28 (1) DSGVO
Data exchange within corporate groups also requires a legal basis. Subordinate companies are subject to similar regulations as external companies.
Rights of the data subjects
Affected individuals are granted extensive rights in accordance with the regulation EU 2016/679. Including the right to access, rectification, erasure (the "right to be forgotten"), restriction of processing, data portability, and objection. These rights strengthen control over one's own personal data.
The Regulation requires every Member State to establish independent data protection supervisory authorities. Violations may be penalized with fines of up to €20 million or 4% of a company's total worldwide annual turnover.
Application of the GDPR on the Internet
The GDPR sets out the guidelines applicable when personal data is processed. It addresses the question of whether specific data may be processed at all, such as:
- The consumer's name and email address
- The consumer's IP addresses
- The consumer's location data
- Customer data in the provider's system
- Data used for sending newsletters Tracking and analysis involving personal data
The GDPR establishes general legal bases for data processing, information obligations, data protection impact assessments, and data processing on behalf of a controller, as well as provisions regarding fines. It also encompasses fundamental rights for data subjects, such as the right to access, delete, or amend personal data.
Legal Notice and Privacy Policy (GDPR)
A legal notice is mandatory for business purposes, as well as for affiliate (advertising partner) activities. Both the legal notice and the privacy policy must be accessible, visible, and understandable from every page of the website. While the legal notice identifies the party responsible for the online presence, the privacy policy names the person responsible for data protection.
The privacy policy must contain information regarding
- Type of data collected: An explanation of which data are collected (e.g., name, IP addresses, cookies, etc.)
- Purpose of data processing: Disclosure of the reason why the data are being collected in the first place
- Applicable legal bases: Consent, explanation of legitimate interests
- Disclosure of data transfer to third parties (e.g., hosting services or tracking services)
- Associated user rights (e.g., access to collected data, requests for deletion, and the right to object)
- Contact details of the data protection officer as a permanent point of contact
The privacy policy must be kept up to date and adapted to current requirements - both legal and technical. Technical modifications to the website must be reflected in the privacy policy if they affect data protection provisions.
Consent box (cookie banner) and consent to data collection
Cookies that are not technically necessary (so-called optional cookies) may only be set after explicit consent has been obtained. These cookies may relate to tracking (systematic monitoring of user activity), marketing or sales purposes (displaying advertisements, usage-based pre-selections), or analysis purposes. To comply with the GDPR, a cookie banner must:
- Provide transparent information
- Obtain active consent (opt-in)
- Offer a simple way to withdraw consent (opt-out), particularly regarding the transfer of data to third parties
- Tracking tools may only be used if legally compliant consent has been obtained. In this process, user IP addresses must be anonymized.
Integrating third-party resources places additional requirements on the privacy policy
To ensure data protection compliance, the privacy policy must disclose instances where external content is technically integrated. This applies particularly to embedded YouTube videos, digital maps (e.g., Google Maps), feeds from online platforms, social media plugins (such as Facebook or Instagram), and external fonts (e.g., dynamically loaded Google Fonts). In these cases, personal data - such as the user's IP address - is often transmitted to third parties as soon as the page loads.
While linking to a third-party site via a standard text link is not particularly significant in this context (provided no tracking or cookie placement is involved), the integration of external graphic banners is a matter of importance. This is because third-party content is being displayed directly on your own website. Consequently, such integration must be mentioned in the privacy policy, and the third-party provider must be identified. Furthermore, the policy must explain what data is transmitted to these third parties.
---
Source:
General Data Protection Regulation (GDPR) EU Regulation 2016/679