GDPR explained EASILY | Study Law Made Easy

Опубликовано: 11 Апрель 2026
на канале: Studiare Diritto Facile
144,261
like

Learn more about the method at https://www.studiarediritto.it/lp-stu...
Visit the website https://www.studiarediritto.it/

The GDPR, which stands for GENERAL DATA PROTECTION REGULATION, is the European Union Regulation No. 679/2016, which came into force on May 25, 2018.

In this video, I will attempt to summarize the content of this regulation in 6 key points.

Important premise: the GDPR is a European regulation. This means it is immediately applicable throughout the EU.

Let's look at the key elements of this regulation together:

POINT 1: When is processing lawful?
A. Processing is lawful when I process the data because the data subject has given consent to process it for one or more specific purposes;

B. Processing is lawful when I process the data because the processing is necessary for the performance of a contract to which the data subject is party;
C. Processing is lawful when I process the data because the processing is necessary for compliance with a legal obligation to which the data controller is subject;
D. Processing is lawful when I process the data because it is necessary to protect the vital interests of the data subject;
E. Processing is lawful when I process the data because the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
F. Finally, processing is lawful when I process the data because: the processing is necessary for the pursuit of the legitimate interests of the data controller or a third party – obviously, here the law requires a balance between the legitimate interests of the data controller and those of the data subject to ensure that their fundamental rights and freedoms are not infringed.

POINT 2: The main roles involved in data processing
1. Data subject
2. Data controller
3. Data processor
4. Joint data controller
5. Data processor
6. Data protection officer (also known as DPO)

POINT 3: The privacy notice
The privacy notice is a communication addressed to the data subject that aims to inform the data subject about the purposes and methods of the data controller's processing.
If the data controller provides the privacy notice, it can demonstrate that it has ensured transparency and fairness in processing from the very beginning of each individual processing activity.
The privacy notice also serves the purpose of allowing the data subject to provide valid consent, if such consent is required as the legal basis for processing. In this case, the privacy notice is not only required based on the principle of transparency and fairness, but is also a condition of the legitimacy of the processing.
The privacy notice must have a minimum content, which can be found in Articles 13 and 14 of the GDPR: for example, it must indicate the categories of data processed and the purposes of the processing; the legal basis for the processing; the mandatory or optional nature of providing data and the consequences of refusal, and so on.
The information must be concise, clear, easily accessible, and understandable for the data subject and should use images and icons whenever possible. It can also be provided verbally, but it is clearly preferable to provide it in a form that demonstrates its existence.

POINT 4: Rights of data subjects
The GDPR provides us with the rights of data subjects in relation to their data.

1. The right of access
2. The right to rectification
3. The right to erasure or the right to be forgotten
4. The right to restriction of processing
5. The right to data portability

POINT 5: The principle of accountability
This English term means "accountability." In other words, the perspective is completely different from the old Privacy Code: it is the data controller who must independently decide the methods, guarantees, and limits of personal data processing in compliance with regulatory provisions and in light of some specific criteria indicated in the regulation.

POINT 6: Noteworthy innovations
An important innovation stems precisely from this risk-based approach: there is no longer a list of minimum security measures that the data controller must adopt to be considered compliant (as was the case in the old Privacy Code). The GDPR merely provides an open list but states that the data controller must adopt appropriate measures to "ensure a level of security appropriate to the risk."

Another important innovation, starting May 25, 2018, is that all data controllers must notify the supervisory authority of personal data breaches of which they become aware, within 72 hours and in any case "without undue delay," only if they believe the breach is likely to result in risks to the rights and freedoms of data subjects.

Who makes this assessment? Always the data controller.

If you enjoyed the video, please give it a thumbs up and follow my channel.