Foundations of Data Protection According to GDPR
摘要
The most important, though not the only, legal instrument for data protection in Europe is the GDPR. This chapter provides an introduction to GDPR and its provisions, focusing on the content relevant to software development and IT as a foundation for their implementation. After an overview of the basic terminology used in the GDPR, the principles of data protection as formulated in the GDPR such as lawfulness, data minimisation and storage limitation are introduced. Another central component of the GDPR are the rights of data subjects defined therein, such as the right to information. The basic concepts of identifiability, pseudonymisation and anonymisation are then considered. The chapter concludes with an introduction to some of the other provisions of the GDPR that are relevant for software development and IT, such as the data protection impact assessment.