GDPR & privacy
The GDPR (General Data Protection Regulation, EU 2016/679) governs the processing of personal data in the EU. For security it matters twice: it imposes security measures on the data and requires breach notification. In Spain it’s complemented by the LOPDGDD and supervised by the AEPD.
Key concepts
Section titled “Key concepts”Personal data any info about an identified or identifiable personSpecial categories health, origin, religion, biometrics... (reinforced protection)Controller decides the WHY and the HOW of the processingProcessor processes data ON BEHALF of the controller (art. 28 contract)Data subject the person whose data is processed (rights holder)Principles (art. 5)
Section titled “Principles (art. 5)”- lawfulness, fairness, and transparency; purpose limitation- data minimization; accuracy; storage limitation- integrity and CONFIDENTIALITY (security); accountability (proactive responsibility)Legal bases and rights
Section titled “Legal bases and rights”Bases consent, contract, legal obligation, vital interest, public interest, legitimate interest (art. 6)Rights access, rectification, erasure ("to be forgotten"), objection, restriction, portability, no automated decisions (arts. 15-22)Security and privacy by design
Section titled “Security and privacy by design”- art. 25: data protection BY DESIGN and BY DEFAULT- art. 32: technical and organizational measures (encryption, pseudonymization, resilience, testing)- DPIA (art. 35): impact assessment for high-risk processing- record of processing activities (art. 30); DPO if applicable (art. 37)Breach notification (key for IR)
Section titled “Breach notification (key for IR)”- to the authority (AEPD) within 72h of becoming aware, if there's risk (art. 33)- to the data subjects without delay if the risk is HIGH (art. 34)- document EVERY breach (even if not notified) -> link with dfir-incidentesPenalties and the Spanish framework
Section titled “Penalties and the Spanish framework”- fines up to EUR 20M or 4% of global annual turnover (whichever is higher)- Spain: LOPDGDD (LO 3/2018) complements the GDPR; AEPD is the supervisory authority- international transfers: mechanisms (standard clauses, adequacy decisions)Blue Team / GRC
Section titled “Blue Team / GRC”- Treat data security (art. 32) as part of the ISMS: encryption, pseudonymization, testing.
- Privacy by design (art. 25) in threat modeling (Threat modeling/Threat modeling in design, LINDDUN).
- A 72h breach notification process integrated into the IR plan (Incident response).
- Record of processing, DPIA for high risk, and processor contracts (art. 28) with providers.
Real cases and fines
Section titled “Real cases and fines”- Multi-million fines from the AEPD and other authorities for breaches and unlawful processing.
- Breaches where the 72h notification and documentation shaped the regulatory response.
- International-transfer cases (Schrems II) that forced rethinking data flows.
Testing checklist
Section titled “Testing checklist”- Record of processing activities (art. 30)
- Legal basis identified per processing (art. 6)
- Art. 32 security measures (encryption, pseudonymization, testing)
- Privacy by design/default (art. 25) in the SDLC
- DPIA for high-risk processing (art. 35)
- 72h breach notification process (art. 33) in the IR
- Processor contracts (art. 28) and DPO if applicable
- Data subject rights management