✳ EU · GDPR

GDPR: personal data rules security people meet (not a HIPAA twin)

An educational overview of the EU General Data Protection Regulation: personal data of natural persons, controller and processor roles, and security of processing. Not a coverage determination.

EU · GDPRJurisdiction explainerLast reviewed

What category this is

The GDPR is Regulation (EU) 2016/679, the General Data Protection Regulation. It protects natural persons with regard to the processing of personal data and the free movement of such data. It entered into force on 24 May 2016 and applies since 25 May 2018. The European Commission says it has been incorporated into the EEA Agreement, so it applies throughout the European Economic Area.

The official text is on EUR-Lex, Official Journal L 119, 4 May 2016. This page names that instrument. It does not walk the recitals, and it does not decide a real processing activity.

What it is about

The regulation is a set of rules for processing personal data of natural persons: rights of those persons, obligations of the organizations that decide or carry out the processing, and supervisory authorities that oversee application. Personal data is the category. It is not "any file on a server," and it is not a product you buy.

Read this as the category of regime. The articles stay on EUR-Lex. Atlas does not paste them into the privacy-versus-security lesson, and it does not turn them into a worksheet.

Controller and processor, at literacy depth

A controller determines the purposes and means of the processing. A processor processes personal data on behalf of the controller. Those are role words, not department names. A contract title that says "processor" is a clue to read, not a finding this page will make.

Security people meet the split when they ask who owes which security duties, who chooses the vendor, and who notifies whom. Both roles can have security work. Deciding which role a real team holds belongs to counsel or the data protection officer, using the actual purposes and the agreement.

Security of processing is the security hook

Article 32 is the security-of-processing hook. Controllers and processors implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The themes EUR-Lex puts around that duty are the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risk to the rights and freedoms of natural persons.

Measures may include pseudonymisation and encryption, the ongoing confidentiality, integrity, availability, and resilience of processing systems and services, the ability to restore availability and access after an incident, and a process for regularly testing those measures. That is a risk-appropriate security duty. It is not a gadget checklist, and encryption alone does not finish it. Open Article 32 on EUR-Lex for the text. Do not treat this paragraph as a substitute.

Use the privacy lesson for the boundary, not for the articles

The GDPR is a privacy and data-protection regime with a security-of-processing duty inside it. Monitoring, retention, and access controls can serve security and still create a privacy tension: a log that proves an export may also copy more personal data than the purpose needs.

That boundary habit lives in the privacy-versus-security lesson. Follow it when the question is whether a control is a security job, a privacy job, or both. Do not look there for Regulation (EU) 2016/679, and do not paste articles into it from here.

What this regulation is not

It is not the U.S. HIPAA Security Rule. That rule is a different legal family, with a covered-entity and business-associate model, and it is about electronic protected health information. Naming both on a slide does not make them twins. The HIPAA explainer stays the place for that U.S. rule.

It is not a statement that any encryption finishes the security duty. It is also not a substitute for product security engineering, or for the shared-responsibility habit of configuring a cloud service the customer still controls. An authorization, a framework row, or a vendor badge does not close those jobs.

Name the role on one synthetic flow

Harbor Mail, a fictional product, processes employee records on behalf of Riverstone HR. Riverstone HR decides why the records exist and how they are used, so this pattern reads as controller. Harbor Mail processes those records on behalf of that controller, so this pattern reads as processor. Literacy only: it is not a finding about a real contract, and it is not a finding that either party has met Article 32.

At work, privately note whether your team looks more like the controller or the processor for one product data flow, then ask the privacy owner. Do not paste personal data into Atlas. Where the organization is headquartered does not, by itself, answer whether the regulation applies. That territorial question is fact-specific. Escalate it. This page does not quiz you into an answer.

Claims to retire

GDPR is the European HIPAA.

The GDPR is an EU data-protection regulation for personal data of natural persons. It is not the HIPAA Security Rule. Different legal family, different covered-entity model, different information type.

We encrypted the database, so GDPR security is done.

Encryption can be one measure under Article 32. The duty is a level of security appropriate to the risk, which can also include confidentiality, integrity, availability, resilience, restore ability, and regular testing. One control setting is not the article.

Processor means we have no security duties.

A processor processes personal data on behalf of the controller. Article 32 names controllers and processors for the security-of-processing duty. The role split changes who decides purposes. It does not erase security work.

If our headquarters is outside the EU, GDPR can never apply.

Where the headquarters sits is not a complete answer. Territorial scope is fact-specific. Ask counsel or the data protection officer. This page does not offer a quiz that decides it.

A vendor badge that says the product meets the GDPR is the same as a supervisory authority determination.

A supervisory authority determination is a decision by that authority. A homepage badge is marketing. Atlas does not issue a seal, and completing this lesson is not that determination.

Sort two regimes

Teaching sort only. It does not decide that a real organization is in scope, and it does not assign controller or processor roles.

Two categories security people mix up. Not a compliance determination.
RegimeCategoryWhat this page is teaching
GDPR, Regulation (EU) 2016/679Privacy and data-protection regime with a security-of-processing dutyRules for processing personal data of natural persons. Article 32 is the security hook inside that regime, not a gadget list.
HIPAA Security RuleU.S. healthcare Security Rule for ePHIA different legal family, a covered-entity model, and electronic protected health information. Not a twin of the GDPR.

CHECK THE CATEGORY

Harbor Mail processes employee records on behalf of Riverstone HR. Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.