EU Data Protection

3 min read

We’ve put together this glossary to help explain some of the terms used in data protection and in the GDPR. If there’s a term you think we should add let us know.

Agencia de Proteccción de Datos = the Spanish data protection regulator, often known as the AEPD.

Anonymisation = the method of processing personal data in order to irreversibly prevent identification.  Organisations try and anonymise data to make it more secure and to help them comply with their data protection responsibilities.  It is a complicated topic however – for example in 2014 the Article 28 Working Party issued a detailed Opinion (approx. 37 pages long) on anonymisation.

Article 29 Working Party (sometimes known as WP29) = was set up under the 1995 European Directive as an advisory body. It comprises representatives of the supervisory authorities for each EU member state, representatives of the EU institutions and a representative of the European Commission. It issues Opinions on matters of common interest involving data protection across the EU but those opinions are advisory and need not be followed by any local Data Protection Regulator.

Article 31 Committee = The Article 31 Committee was established by the 1995 EU Data Protection Directive.  It is made up of representatives of each of the Member States who cooperate in taking decisions whenever Member States approval is required under the Directive.  The Article 31 Committee have been active in the process for adoption of the adequacy decision for Privacy Shield.

Autoriteit Persoonsgegevens = the Dutch Data Protection Regulator.  The Autoriteit Persoonsgegevens (AP) replaced the former Dutch Data Protection Regulator, The College Bescherming Persoonsgegevens (CBP), in January 2016.

Binding Corporate Rules = a binding global code of practice based on EU privacy standards, reinforced by an organisation’s internal compliance system, and which national regulators approve in accordance with their own legislation. More information at An international summer: are binding corporate rules the way forward?  BCRs receive statutory footing for the first time in GDPR.  BCRs are defined by Article 4(20) as “personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings or a group of enterprises engaged in joint economic activity”.  The system of BCRs under GDPR is set out in article 47 of GDPR.

Biometric Data = Biometric Data has its own definition within GDPR which is “personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data.”.

Commission Nationale de I’Informatique et des Libertés = the French data protection regulator, often referred to as CNIL.

Data = information which: (i) is processed electronically, including computer, CCTV, card access data; (ii) is not processed electronically but forms part of a relevant filing system, structured to allow easy access to information; or (iii) is part of an accessible record, relating, broadly, to health, education or other public service.

Data Controller = any person, partnership or company who determines how and for what purposes personal data is processed. A third party may carry out processing on the controller’s behalf, although the data controller remains responsible for the processing.

Data Processor = a person who processes personal data for a data controller, other than the controller’s employee. Outsourced IT and HR service providers may be processors.

Data Protection Impact Assessment = DPIA.  The successor to the PIA.  See Privacy Impact Assessment below.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at corderycompliance.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.