Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Article 4 (Definitions)
Resources
🇫🇷 FR 🇬🇧 EN 🇳🇱 NL
EU Legal Reference⚖️ GDPR Regulatory Text⚖️ Binding Legal Force

Article 4 GDPR: Key Legal Definitions

Official EU Regulation (EU) 2016/679 legal analysis · Controlled official sources

⚡ In 30 seconds:

Article 4 GDPR defines the foundational concepts of European data protection law: personal data (Art. 4.1), processing (Art. 4.2), the controller determining purposes and means (Art. 4.7), and the processor acting on instructions (Art. 4.8).

Personal Data and Processing (Art. 4.1 & 4.2)

Article 4(1) defines personal data as ‘any information relating to an identified or identifiable natural person’. Identification may occur directly by name or indirectly via an online identifier (dynamic IP address, cookie identifier — CJEU Case C-582/14 Breyer).

Article 4(2) confers an exceptionally broad scope upon processing, covering any operation or set of operations performed on personal data (collection, recording, storage, alteration, retrieval, consultation, dissemination, erasure or destruction).

Controller vs Processor (Art. 4.7 & 4.8)

The legal qualification of actors is functional and follows EDPB Guidelines 07/2020:

  • Data controller (Art. 4.7): The natural or legal person which, alone or jointly with others, determines the purposes (‘why’) and essential means (‘how’) of the processing;
  • Data processor (Art. 4.8): The entity which processes personal data on behalf of the controller and strictly in accordance with documented instructions;
  • Recipient (Art. 4.9) and Third party (Art. 4.10): Natural or legal persons to whom personal data are disclosed.

Verified Official Sources

⚖️ Binding Source
Regulation (EU) 2016/679 (GDPR) · CELEX: 32016R0679 · 2016-04-27

General Data Protection Regulation — EU Reference Legal Framework

Consult official source →
⚖️ Binding Source
Breyer (19 oct. 2016) · ECLI: ECLI:EU:C:2016:779

Adresse IP dynamique qualifiée de donnée personnelle dès lors que des moyens légaux raisonnablement susceptibles d'identifier la personne existent

Consult official source →
🇪🇺 Adopted EDPB Guidelines
Guidelines 07/2020 on the concepts of controller and processor in the GDPR

Responsable du traitement (RT), sous-traitant (ST), responsabilité conjointe (Art. 26, 28)

Consult official source →

See Also in the Legal Framework

Article 5 GDPR Official Text

Article 5 GDPR: Cardinal Processing Principles & Accountability

Legal analysis of the cardinal principles in Article 5 GDPR: lawfulness, fairness, transparency, purpose limitation, dat...

View document
Article 28 GDPR Official Text

Article 28 GDPR: Data Processing Agreement & Mandatory Clauses

Comprehensive guide to Article 28 GDPR: mandatory clauses of the Data Processing Agreement (DPA), controller and process...

View document
← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-08-23 Last modified: 2026-08-23

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice