Skip to content

GDPR & privacy

The GDPR (General Data Protection Regulation, EU 2016/679) governs the processing of personal data in the EU. For security it matters twice: it imposes security measures on the data and requires breach notification. In Spain it’s complemented by the LOPDGDD and supervised by the AEPD.

Personal data any info about an identified or identifiable person
Special categories health, origin, religion, biometrics... (reinforced protection)
Controller decides the WHY and the HOW of the processing
Processor processes data ON BEHALF of the controller (art. 28 contract)
Data subject the person whose data is processed (rights holder)
- lawfulness, fairness, and transparency; purpose limitation
- data minimization; accuracy; storage limitation
- integrity and CONFIDENTIALITY (security); accountability (proactive responsibility)
Bases consent, contract, legal obligation, vital interest, public interest,
legitimate interest (art. 6)
Rights access, rectification, erasure ("to be forgotten"), objection, restriction,
portability, no automated decisions (arts. 15-22)
- art. 25: data protection BY DESIGN and BY DEFAULT
- art. 32: technical and organizational measures (encryption, pseudonymization, resilience, testing)
- DPIA (art. 35): impact assessment for high-risk processing
- record of processing activities (art. 30); DPO if applicable (art. 37)
- to the authority (AEPD) within 72h of becoming aware, if there's risk (art. 33)
- to the data subjects without delay if the risk is HIGH (art. 34)
- document EVERY breach (even if not notified) -> link with dfir-incidentes
- fines up to EUR 20M or 4% of global annual turnover (whichever is higher)
- Spain: LOPDGDD (LO 3/2018) complements the GDPR; AEPD is the supervisory authority
- international transfers: mechanisms (standard clauses, adequacy decisions)
  • Treat data security (art. 32) as part of the ISMS: encryption, pseudonymization, testing.
  • Privacy by design (art. 25) in threat modeling (Threat modeling/Threat modeling in design, LINDDUN).
  • A 72h breach notification process integrated into the IR plan (Incident response).
  • Record of processing, DPIA for high risk, and processor contracts (art. 28) with providers.
  • Multi-million fines from the AEPD and other authorities for breaches and unlawful processing.
  • Breaches where the 72h notification and documentation shaped the regulatory response.
  • International-transfer cases (Schrems II) that forced rethinking data flows.
  • Record of processing activities (art. 30)
  • Legal basis identified per processing (art. 6)
  • Art. 32 security measures (encryption, pseudonymization, testing)
  • Privacy by design/default (art. 25) in the SDLC
  • DPIA for high-risk processing (art. 35)
  • 72h breach notification process (art. 33) in the IR
  • Processor contracts (art. 28) and DPO if applicable
  • Data subject rights management