GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.
Deep expertise in the General Data Protection Regulation (GDPR) - the European Union's comprehensive data protection law.
Expertise Areas
GDPR Overview
Regulation (EU) 2016/679: General Data Protection Regulation
Effective Date: May 25, 2018
Scope: Protection of natural persons with regard to processing of personal data and free movement of such data
Articles: 99 (11 chapters)
Recitals: 173 (interpretive guidance)
Territorial Scope (Article 3):
Establishment: Controller/processor established in EU (regardless of where processing occurs)
Targeting: Offering goods/services to EU data subjects (even if free)
Monitoring: Monitoring behavior of EU data subjects
Applies: Even if organization not in EU
Material Scope:
Automated processing of personal data
Non-automated processing in filing systems
Exemptions: National security, law enforcement (LED applies), purely personal/household
Key Definitions (Article 4)
Personal Data:
Any information relating to identified/identifiable natural person
Direct identifiers: Name, ID number, email
Indirect identifiers: Location data, IP address, cookie ID, device ID
Combination of factors: Age + ZIP code + occupation
Special Categories of Personal Data (Article 9 - "Sensitive Data"):
Racial or ethnic origin
Political opinions
Religious or philosophical beliefs
Trade union membership
Genetic data
Biometric data (for uniquely identifying a person)
Two or more controllers jointly determine purposes and means
Must arrange responsibilities via agreement
Each liable for entire processing
Data Subject:
Identified or identifiable natural person
Individual whose data is processed
Rights holder under GDPR
Supervisory Authority:
Independent public authority (Data Protection Authority/DPA)
Each EU Member State has one or more
Enforces GDPR in jurisdiction
Lead Supervisory Authority (Article 56):
For cross-border processing
Main establishment's DPA
One-stop-shop mechanism
7 Principles of Data Processing (Article 5)
1. Lawfulness, Fairness, and Transparency
Lawfulness: Must have lawful basis (Article 6)
Fairness: No deceptive, misleading, or detrimental processing
Transparency: Clear, plain language communication to data subjects
Implementation:
Privacy notices at collection
Layered notices (short + full)
Just-in-time notices
Clear language (no legalese)
Accessible information
2. Purpose Limitation
Requirements:
Specified purposes (documented, clear)
Explicit purposes (communicated to data subjects)
Legitimate purposes (lawful, ethical)
No processing for incompatible purposes
Compatible Processing:
Same or closely related purpose
Consider: Link between purposes, context, nature of data, consequences, safeguards
Exceptions:
Archiving in public interest
Scientific/historical research
Statistical purposes
3. Data Minimization
"Adequate, relevant, and limited to what is necessary"
Implementation:
Collect only what you need
Justify each data element
Regular review and purge
Limit access (need-to-know)
Pseudonymization/anonymization where possible
Common Violations:
"Nice to have" data collection
Speculative future use
Excessive profiling data
4. Accuracy
Requirements:
Personal data must be accurate
Kept up to date where necessary
Inaccurate data erased or rectified
Implementation:
Verification at collection
Regular reviews and updates
Easy rectification process
Notify recipients of changes
Quality control procedures
5. Storage Limitation
"Kept no longer than necessary for the purposes"
Implementation:
Retention schedules (per purpose)
Regular deletion reviews
Automated deletion where possible
Document retention rationale
Legal hold procedures
Exceptions (can retain longer):
Archiving in public interest
Scientific/historical research
Statistical purposes
With appropriate safeguards
6. Integrity and Confidentiality (Security)
"Appropriate security... including protection against unauthorized/unlawful processing and accidental loss, destruction or damage"
Implementation: See Article 32 (Security of Processing)
7. Accountability
"Controller shall be responsible for and able to demonstrate compliance"
Demonstration Requirements:
Documentation (policies, procedures, records)
Data Protection Impact Assessments (DPIAs)
Privacy by Design and Default
Data Processing Agreements (DPAs)
Records of Processing Activities
Training and awareness programs
Regular audits and reviews
Incident response and breach records
6 Lawful Bases for Processing (Article 6)
Must identify ONE for each processing purpose
1. Consent (Article 6(1)(a))
Requirements:
Freely given: No coercion, imbalance of power consideration
Specific: Separate consent for separate purposes
Informed: Identity, purposes, data types, rights, withdrawal
Unambiguous: Clear affirmative action (no pre-ticked boxes, silence, inactivity)
Additional for Consent:
Easy to withdraw (as easy as to give)
Withdrawal does not affect lawfulness of prior processing
Burden of proof on controller
Record of consent (who, when, what, how)
When Problematic:
Employment context (power imbalance)
Public authorities (no free choice)
Service bundling (cannot refuse)
Children's Consent (Article 8):
Under 16: Parental consent required (Member States can lower to 13)
Controller must make reasonable efforts to verify
2. Contract (Article 6(1)(b))
Two scenarios:
Processing necessary to perform a contract with data subject
Processing necessary to enter into contract (pre-contractual steps)
"Necessary":
Objectively essential to contract
Not just "helpful" or "customary"
Direct relationship to contract performance
Examples:
Shipping address for product delivery
Credit card for payment processing
Account credentials for service access
Not Sufficient:
Marketing to customers (use consent or legitimate interests)
Analytics not integral to service (use legitimate interests)
3. Legal Obligation (Article 6(1)(c))
Requirements:
Processing required by EU law or Member State law
Obligation on the controller
Must identify specific legal provision
Examples:
Tax records (legal retention requirements)
Employment records (labor law)
AML/KYC checks (financial regulations)
Health and safety reporting
Not Sufficient:
Contractual obligations (use contract basis)
Best practices or industry standards
Non-EU legal obligations
4. Vital Interests (Article 6(1)(d))
"Necessary to protect the vital interests of the data subject or another"
Scope:
Life or death situations
Serious health threats
Last resort when other bases not available
Examples:
Emergency medical treatment (unconscious patient)
Humanitarian crises
Pandemic response (in some cases)
Rarely Appropriate: Most organizations won't use this basis
5. Public Task (Article 6(1)(e))
"Necessary for task carried out in the public interest or in exercise of official authority"
Scope:
Public authorities
Private entities exercising official authority
Task must have basis in EU/Member State law
Examples:
Government agencies
Regulators
Educational institutions (public tasks)
Not Available: Commercial organizations (use legitimate interests)
6. Legitimate Interests (Article 6(1)(f))
"Necessary for purposes of legitimate interests pursued by controller or third party, except where overridden by interests, rights and freedoms of data subject"
Three-Part Test:
Purpose Test: Is interest legitimate?
Necessity Test: Is processing necessary?
Balancing Test: Do data subject's interests override?
Legitimate Interest Assessment (LIA) Required:
Identify legitimate interest
Necessity assessment (no less intrusive means)
Balancing test (impact on data subjects)
Document LIA
Examples of Legitimate Interests:
Fraud prevention
Network and information security
Direct marketing (subject to right to object)
Intra-group transfers
Employee monitoring (limited)
Analytics for service improvement
Cannot Use:
Public authorities (for official tasks)
When data subject's interests clearly override
Right to Object (Article 21):
Data subjects can object to legitimate interests processing
Controller must demonstrate compelling legitimate grounds to continue
Special Category Data (Article 9)
General Prohibition: Processing of special categories prohibited
Exceptions (Must meet Article 6 basis PLUS Article 9 exception):
Explicit consent (9(2)(a))
Employment, social security, social protection law (9(2)(b))
Vital interests (cannot obtain consent) (9(2)(c))
Not-for-profit body (political, philosophical, religious, trade union) (9(2)(d))
Made public by data subject (9(2)(e))
Legal claims (9(2)(f))
Substantial public interest (with basis in law) (9(2)(g))
Health/social care (professional secrecy) (9(2)(h))