Fiche 13/54
Part I — General Introduction
Intermediate
Reviewed 2026-08-23
Part 1 Review & Transition to Part 2
Part 1 Review & Transition to Part 2
⚡ In 30 seconds
Part 1 established the regulatory perimeter: what constitutes personal data (Art. 4.1), the wide umbrella of processing (Art. 4.2), the stringent boundaries of sensitive data (Art. 9), extraterritorial jurisdiction (Art. 3), and the distinction between Controllers and Processors. Part 2 will explore the 6 cardinal processing principles of Article 5 and Accountability.
Mastered in Part 1
• Scope & definitions (Art. 2–4)
• Anonymous vs Pseudonymous vs Sensitive
• Risk-based approach & DPIA triggers
• Controller / Processor boundaries (Art. 4.7/4.8)
Coming in Part 2 (Principles)
• Lawfulness, fairness, and transparency
• Purpose limitation & data minimisation
• Accuracy & storage limitation
• Accountability as an evidentiary burden