Introduction
Getting started
()
1. Origins and Historical Context of Data Protection Law
What is privacy, and why does it matter?
()
Human rights, consumer protection, and state-centric approaches
()
2. European Union (EU) Institutions
Council of Europe
()
European Union
()
3. EU Legislative Framework
A timeline for data privacy laws
()
Extent of the GDPR: Territorial and material scope
()
4. Data Protection Concepts and Scope
Types of personal data, anonymization, and pseudonymization
()
Regulators, controllers, processors, and data subjects
()
5. Data Processing Principles
The principles themselves
()
Purpose limitation and use limitation
()
Accuracy and retention
()
6. Lawful Processing Criteria
The balance of power and its basis
()
The legal basis and the problem with consent
()
Legal basis for special category data
()
7. Transparency and Data Subjects' Rights
Privacy notices
()
Subject access requests
()
Erasure, rectification, and objection
()
Automated decision-making, portability, and complaints
()
8. Obligations of Controllers and Processors
Accountability and documentation
()
Data privacy impact assessments (DPIAs) and data protection
()
Data protection officers (DPOs) and other requirements
()
9. Security and Data Breaches
Appropriate organizational and technical measures
()
Security breaches and breach notification
()
Managing data processors and third-party vendors
()
10. International Data Transfer
What locations are safe, and why does this matter?
()
Justifying international transfers
()
Transferring data between the EEA and the United States
()
11. Powers of the Regulator
Roles of regulators
()
Enforcement powers
()
12. Application of the Law
Employment
()
Surveillance activities
()
Direct marketing
()