← back to the act's dossier

GDPR — Article 4

The article's text

Article 4 Definitions For the purposes of this Regulation: (1) ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; (2) ‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; (3) ‘restriction of processing’ means the marking of stored personal data with the aim of limiting their processing in the future; (4) ‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evalu
full text
ate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements; (5) ‘pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person; (6) ‘filing system’ means any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis; (7) ‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law; (8) ‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller; (9) ‘recipient’ means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing; (10) ‘third party’ means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data; (11) ‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her; (12) ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed; (13) ‘genetic data’ means personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question; (14) ‘biometric data’ means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data; (15) ‘data concerning health’ means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status; (16) ‘main establishment’ means: (a) as regards a controller with establishments in more than one Member State, the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union and the latter establishment has the power to have such decisions implemented, in which case the establishment having taken such decisions is to be considered to be the main establishment; (b) as regards a processor with establishments in more than one Member State, the place of its central administration in the Union, or, if the processor has no central administration in the Union, the establishment of the processor in the Union where the main processing activities in the context of the activities of an establishment of the processor take place to the extent that the processor is subject to specific obligations under this Regulation; (17) ‘representative’ means a natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27, represents the controller or processor with regard to their respective obligations under this Regulation; (18) ‘enterprise’ means a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity; (19) ‘group of undertakings’ means a controlling undertaking and its controlled undertakings; (20) ‘binding corporate rules’ means personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity; (21) ‘supervisory authority’ means an independent public authority which is established by a Member State pursuant to Article 51; (22) ‘supervisory authority concerned’ means a supervisory authority which is concerned by the processing of personal data because: (a) the controller or processor is established on the territory of the Member State of that supervisory authority; (b) data subjects residing in the Member State of that supervisory authority are substantially affected or likely to be substantially affected by the processing; or (c) a complaint has been lodged with that supervisory authority; (23) ‘cross-border processing’ means either: (a) processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State; or (b) processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State. Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State. (24) ‘relevant and reasoned objection’ means an objection to a draft decision as to whether there is an infringement of this Regulation, or whether envisaged action in relation to the controller or processor complies with this Regulation, which clearly demonstrates the significance of the risks posed by the draft decision as regards the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the Union; (25) ‘information society service’ means a service as defined in point (b) of Article 1(1) of Directive (EU) 2015/1535 of the European Parliament and of the Council ; (26) ‘international organisation’ means an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries. law, or any other body which is set up by, or on the basis of, an agreement between two or more countries. CHAPTER II Principles

Who wrote about this article in the consultations

Filers who named this exact article number in their own text. It is their sentence, not our reading — and not a causal claim.

17
business association
10
company
7
NGO
4
other
2
EU citizen
WhoCountryWhat they wrote
Verband Insolvenzverwalter und Sachwalter Deutschlands e.V.DEnot aim to identify the individual, these data, contrary to their general state, are not considered personal data in the sense of Art. 4 No. 1 GDPR. Robert Hänel – Verband Insolvenzverwalter und Sachwalter Deutschlands e.V.
Bitkom e.V.DEs, privileges for processing pseudonymized data, and the exclusion of the process of rendering data anonymous as processing under Art. 4 Subsection 2 GDPR are considered essential solutions. Additional challenges persist in the coexistence of outdated sector-s
Selbstregulierung Informationswirtschaft e.V. (SRIW)DE...................................................................................................................... 34 15.1.1. Article 4 of the Data Act ........................................................................................................
Datenanfragen.de e. V.DEof tracking. In particular, this concerns the concepts of identification and identifiability in the definition of personal data (Art. 4(1) GDPR) and whether they apply to uni- que identifiers that in and of themselves do reveal a person’s legal identity. Trac
Gesellschaft für Datenschutz und Datensicherheit (GDD) e.V.DEelektronischer Form – wie in Art. 28. Abs. 9 DS-GVO – innerhalb der Begriffsbestimmun- gen in Art. 4 DS-GVO gelingen. 3. Datenschutzbeauftragte Nach Art. 37 Abs. 1 lit. a) DS-GVO muss jede öffentliche Stelle unabhängig von der personel- len Größe der Einrichtu
AMICE - Association of Mutual Insurers and Insurance Cooperatives in EuropeBEby a statement or by a clear affirmative action, his or her agreement to the processing of personal data relating to him or her” (Article 4(11) GDPR); − “[...] consent should not be considered freely given if the data subject does not have a genuine or free ch
FEBISDEpplies - professional in their business capacity – some exemptions to GDPR as this would not be qualified as personal data under art 4. b. Have the guidance and tools provided by data protection authorities and the EDPB in recent years assisted SMEs in their
Confederation of Swedish EnterpriseSErning or analysis could just as effectively be carried out with anonymous data. However, the broad definition of personal data in Article 4(1) of the GDPR makes it difficult to know with certainty whether the processing in a specific case falls outside the sco
Unipol GruppoITby a statement or by a clear affirmative action, his or her agreement to the processing of personal data relating to him or her” (Article 4 (11) GDPR); − “[...] consent should not be considered freely given if the data subject does not have a genuine or free c
BDI e.V. (Federation of German Industries)DEe it’s unclear, which additional national data protection law could possibly apply additionally to the GDPR. A similar rule as in Art 4 EC-Data Protection-Directive 95/46/EC should be provided. For the effective functioning of the Internal Market and to avoid
Intrum ABSEillustrated below. Controller vs. Processor roles The roles of Controllers and Processors are precisely defined in the GDPR, with Article 4 providing explicit definitions that do not allow for national variations. Those definitions are then clarified with mult
German Insurance AssociationDEconcludes that the personal data are changed by the process of rendering data anonymous and that this is processing according to Article 4 Subsection 2 GDPR and therefore needs a legal basis according to the GDPR. → Since this has never been stated in the GDP
Chalmers University of TechnologySEwalls may breach freely given consent requirements Cookie paywalls may raise doubts about whether consent is freely given, as per Article 4(11) and 7(3) of the GDPR. A freely given consent implies the consent request to be non-detrimental. Detrimental consent
United InternetDEview: Anonymization: Although not directly included in the GDPR, anonymization is derived from the definition of personal data in Art. 4 Nos. 1 and 5 of the GDPR and Recital 26.
EOS Holding GmbHDEnership and not on the actual decision-making regarding the purposes and means of data processing. It should be clearly stated in article 4 of the GDPR that the designation of the role of a Data Controller hinges upon the determinations regarding the purposes
Oplysningsforbundet May DayDKi forhold til nationale domstole, så fremgår det ifølge EU- Domstolen af loyalitetsforpligtelsen efter TEU art. 4, stk. 3, samt EU-Domstolens praksis, at nationale domstole har pligt til at rette sig efter EU-Domstolens fortolkninger32. Vedr. forholdet mellem
Institut der Wirtschaftsprüfer in Deutschland e.V. (IDW)DEgesetz). In der Praxis wurde der Begriff der Verletzung des Schutzes personenbezogener Daten unsachgemäß über die Definition nach Art. 4 Nr. 12 DSGVO hinaus erweitert. Z.B. wurde die mangelnde Verfügbarkeit von Daten als Verletzung qualifiziert, obwohl es sich
VNO-NCW / MKB NederlandNL● Brazil ● Indonesia ● Thailand ● Vietnam Questionnaire EC: GDPR and innovation / new technologies 7 This follows from the GDPR (article 4.10 and Chapter 5) a. What is the overall impact of the GDPR on the approach to innovation and to new technologies? With
Berufsverband der Datenschutzbeauftragten Deutschlands (BvD) e.V.DEgriffs mit dem der Produkthaftungsrichtlinie gewahrt werden sollte. Dies könnte durch Aufnahme einer entsprechenden Definition in Art. 4 DSGVO gewährleistet werden (so bereits der Erfahrungsbericht der unabhängigen Datenschutzaufsichtsbehörden des Bundes und d
Hessischer LandtagDEberücksichtigen. Eine Ausnahme des parlamentarischen Bereichs aus der DSGVO ist vor dem Hintergrund des Art. 4 Abs. 2 EUV, der die nationale Identität, die in ihren grundlegenden politischen und verfassungsgemäßen Strukturen zum Ausdruck kommt, schützt, zu beg
AUSTRIAN FEDERAL ECONOMIC CHAMBERATta protection officer is unclear. It has apparently not yet been clarified whether this person acts as an Controller according to Article 4 lit 7 GDPR or whether the role is outside the usual classification as controller or processor. b. Are there enough skill
Finnish EnergyFIce is not directly offered to the employees. General provisions and principles (Chapters I & II) Several definitions according to Article 4 of the GDPR are considered unclear and difficult to interpret in practical application situations.
Délégué à la Protection des Données (ancien et formateur)FRl’évaluation du règlement général sur la protection des données (RGPD) Auteur : Bruno RASLE (France) Paris, le 27 janvier 2024 1) Article 4 RGPD : y ajouter la définition de l’anonymisation L’article 4 du RGPD contient les définitions des « données à caractère
DATEV eGDEarticular. Clarifying Definitions and Terminology Further clarification is needed regarding the definition of personal data under Art. 4 GDPR. It needs to be specified under which conditions datasets containing personal data are considered as anonymous.
Media Scope Group OÜEEs and terminology One of the main areas of concern is the need for further clarification on the definition of personal data under Article 4 of the GDPR. Specifically, it should be specified under which conditions datasets containing personal data are considere
Teodor TotevBG, finden die Vorschriften über die mittelbare Vertretung Anwendung (Abschnitt 3). Ref. Ares(2024)329931 - 16/01/2024 Here is GDPR Art 4 (8) – definition of processor in different languages.
Anonos Inc.USin a manner that satisfies the new heightened statutory requirements under the GDPR. 2 The term “pseudonymisation” is defined in Article 4(5) of the GDPR as follows: “pseudonymisation means the processing of personal data in such a manner that the personal da
DIGITALEUROPEBEons to make a complaint, so as to reach amicable resolutions at an early stage. This should therefore be listed in the proposal’s Art. 4 and its Annex. Amicable case resolution We welcome the inclusion of a framework for amicable settlements in the proposal, g
Deutsche Industrie- und Handelskammer (DIHK) / German Chamber of Commerce and IndustryDEgenommen werden, dass nur solchen Orga­ nisationen der verfahrenstechnisch gleiche Status wie Betroffenen gegeben wird, die gemäß Art. 4 Richtlinie (EU) 2020/1828 des Europäischen Parlaments und des Rates vom 25. Novem­ ber 2020 als sogenannte qualifizierte Ei
Hans-Hermann SchildDEZE Da die Entscheidung des EuGH in den Verfahren C- 26/22 und C-64/22 zu den Pflichten der Aufsichtsbehörde noch aussteht, sollte Art. 4 VO-E im Lichte des dann vorliegenden Urteils noch einmal gründlich überarbeitet bzw. gestrichen werden.

Source: public consultation submissions and position papers. n = 48 mentions; counted as a literal reference to the article number.

Ask about this article →