Chapter 3
Digging In to Data: What’s Personal, What’s Sensitive, and How It’s Processed
IN THIS CHAPTER
Seeing what's personal data — and what isn't
Recognizing and dealing with special-category data
Understanding the lawful grounds of processing
Discovering the consequences of processing without a lawful ground
It's a simple fact that pretty much every organization (no matter what the size) is collecting and using individuals’ personal data and of course processing that data to gain benefit from it (such as emailing potential customers or storing personal data of employees).
The GDPR regulates how organizations process personal data. How processing of data is defined is exceptionally broad and I cover this in-depth later on in this chapter.
Before I do that, however, I want to describe what is meant by personal data, a term that also has a far-reaching definition in the GDPR. Personal data is defined in the GDPR as “any information relating to a natural person who is identified or identifiable, directly or indirectly, with particular reference to an identifier, such as name, ID ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access