Article 4 GDPR: Key Legal Definitions
Article 4 GDPR defines the foundational concepts of European data protection law: personal data (Art. 4.1), processing (Art. 4.2), the controller determining purposes and means (Art. 4.7), and the processor acting on instructions (Art. 4.8).
Personal Data and Processing (Art. 4.1 & 4.2)
Article 4(1) defines personal data as ‘any information relating to an identified or identifiable natural person’. Identification may occur directly by name or indirectly via an online identifier (dynamic IP address, cookie identifier — CJEU Case C-582/14 Breyer).
Article 4(2) confers an exceptionally broad scope upon processing, covering any operation or set of operations performed on personal data (collection, recording, storage, alteration, retrieval, consultation, dissemination, erasure or destruction).
Controller vs Processor (Art. 4.7 & 4.8)
The legal qualification of actors is functional and follows EDPB Guidelines 07/2020:
- Data controller (Art. 4.7): The natural or legal person which, alone or jointly with others, determines the purposes (‘why’) and essential means (‘how’) of the processing;
- Data processor (Art. 4.8): The entity which processes personal data on behalf of the controller and strictly in accordance with documented instructions;
- Recipient (Art. 4.9) and Third party (Art. 4.10): Natural or legal persons to whom personal data are disclosed.
Verified Official Sources
General Data Protection Regulation — EU Reference Legal Framework
Consult official source →Adresse IP dynamique qualifiée de donnée personnelle dès lors que des moyens légaux raisonnablement susceptibles d'identifier la personne existent
Consult official source →Responsable du traitement (RT), sous-traitant (ST), responsabilité conjointe (Art. 26, 28)
Consult official source →See Also in the Legal Framework
Article 5 GDPR: Cardinal Processing Principles & Accountability
Legal analysis of the cardinal principles in Article 5 GDPR: lawfulness, fairness, transparency, purpose limitation, dat...
Article 28 GDPR: Data Processing Agreement & Mandatory Clauses
Comprehensive guide to Article 28 GDPR: mandatory clauses of the Data Processing Agreement (DPA), controller and process...