Skip to content

An independent study reference written by Dr Phuc V. Nguyen. It is not official subject material — for assessment requirements always follow your subject outline and vUWS.

GDPR and what it requires

The General Data Protection Regulation, Regulation (EU) 2016/679, governs the processing of personal data and has applied since May 2018. Three features matter to an analyst. It is purpose-bound: you need one of six lawful bases before you process anything, and you may not quietly repurpose data you already hold. It is extraterritorial: Article 3 reaches an organisation anywhere in the world that offers goods or services to people in the EU or monitors their behaviour there. And it gives individuals enforceable rights over their own records, including access, correction, erasure, portability and, under Article 22, a limit on decisions taken solely by automation.

Why it matters

Treat the regulation as a set of promises attached to every row of personal data. The promise says: you told me why you wanted this, so that is the only thing you may use it for; you told me how long you would keep it, so delete it then; and if I ask what you hold about me and why, you have to tell me. Most failures under this regulation are broken promises about purpose, not spectacular leaks.

Before you read on — recall

A Sydney retailer ships only within Australia but its website accepts visitors from anywhere and runs a tracking pixel that profiles them, including a steady trickle of visitors in Ireland. Which statement is most accurate?

Formulas

Administrative fine ceiling, Article 83(5)
Cap=max(EUR 20,000,000,  0.04×worldwide annual turnover)\text{Cap} = \max\bigl(\text{EUR } 20{,}000{,}000,\; 0.04 \times \text{worldwide annual turnover}\bigr)
For the most serious infringements the ceiling is whichever of the two is HIGHER, so turnover binds for any large group and the flat figure binds for a small one. A lower tier applies to procedural breaches, capped at the higher of EUR 10 million or two per cent of turnover. This is a maximum, not a tariff; the actual amount is set against the criteria in Article 83(2), including the nature of the breach and what the organisation did about it.

Worked examples

Scenario

An Australian ed-tech company with no European office sells a study app. It lists the app in German, prices it in euro and advertises it to students in Germany, where about 3,000 of its users live. The app also tracks how each user studies in order to record which topics they struggle with. The team assumes Australian law is the only law in play.

Solution

Article 3(2) says otherwise, though not because 3,000 German users sit in the database. The trigger is that the company offers the service to people located in the EU and monitors their behaviour there, and either limb on its own is enough whatever the location of the company, its staff or its servers. The consequences are concrete: a valid lawful basis under Article 6, and an Article 9 check alongside it, because a record of which topics a learner struggles with can shade into health data about a learning disability, and special-category data needs its own separate condition. Then a retention period with a real deletion job behind it, a route for a German user to obtain a copy or request erasure, a record of processing activities, and a 72-hour clock for notifying a supervisory authority.

Scenario

A bank collected transaction data to run customer accounts. A new team now wants to feed the same data into a model that prices insurance.

Solution

The original lawful basis was performance of a contract, and insurance pricing is a different purpose. Under the compatibility test the bank has to weigh the link between the old purpose and the new one, the context in which the data was collected, how sensitive the data is, the likely consequences for customers, and what safeguards apply. If the new purpose is not compatible, the bank cannot ride on the old basis and has to identify one in Article 6 that genuinely covers insurance pricing. Consent is one candidate rather than the default remedy, and it is often the hardest to obtain validly, because it has to be freely given and specific. This is the point where most analytics projects actually meet the regulation, not at the moment of collection.

Common mistakes

  • The GDPR only applies to European companies. Article 3 extends it to any organisation that offers goods or services to people in the EU or monitors their behaviour there, whatever its own location, which catches a great many Australian websites and apps.
  • Consent is how you make processing lawful. Consent is one of six bases in Article 6 and often the weakest, because it must be freely given, specific, informed, unambiguous and as easy to withdraw as to give. Contract, legal obligation and legitimate interests carry most routine processing.
  • Once the data is anonymised the obligations fall away, so pseudonymised records are outside scope. Pseudonymised data, where a key still links records back to people, remains personal data. Only genuinely anonymous data, which cannot be re-identified by any means reasonably likely to be used, falls outside.
  • Article 22 bans automated decisions. It restricts decisions based solely on automated processing that produce legal or similarly significant effects, and it allows them where a contract, a law or explicit consent applies, provided safeguards exist including human intervention and a right to contest the outcome.

Revision bullets

  • Regulation (EU) 2016/679, applying since May 2018
  • Article 6: six lawful bases, consent among them; Article 9 covers special-category data
  • Article 5: purpose limitation, data minimisation, storage limitation, accountability
  • Article 3: reaches non-EU organisations serving or monitoring people in the EU
  • Rights: access, rectification, erasure, portability, plus Article 22 on automation
  • Article 33: 72 hours to notify the supervisory authority once aware of a breach

Quick check

A Sydney retailer ships only within Australia but its website accepts visitors from anywhere and runs a tracking pixel that profiles them, including a steady trickle of visitors in Ireland. Which statement is most accurate?

A marketing team wants to reuse three years of customer service transcripts, originally collected to resolve complaints, as training data for a churn model. What does the regulation put to them first?

Connected topics

More in Ethics and Governance

Sources

  1. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data. Official Journal of the European Union, L 119, 4 May 2016.
    Primary text. Articles 3, 5, 6, 15-22, 25, 33 and 83 carry everything referenced here.
  2. Office of the Australian Information Commissioner. Australian Privacy Principles, Schedule 1, Privacy Act 1988 (Cth), as amended.
    The domestic comparison. Thirteen principles covering collection, use and disclosure, access and correction, plus the Notifiable Data Breaches scheme.
How to cite this page
Dr. Phil's Quant Lab. (2026). GDPR and what it requires. Derivatives Atlas. https://phucnguyenvan.com/concept/ba-gdpr
Next concept
PAPA: privacy, accuracy, property, accessibility
Built by Dr. Phuc V. Nguyen ·Follow on LinkedInWork with PhilEmail