3. Key principles of GDPR
Lawfulness, Fairness, and Transparency
This principle requires that personal data be processed lawfully, fairly, and in a transparent manner in relation to the data subject. Data processing must be based on a clearly defined legal basis, such as the user’s consent, the existence of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest, or the legitimate interests of the data controller.
Purpose Limitation
Personal data must be collected for specified, explicit, and legitimate purposes and must not be further processed in a manner incompatible with those purposes. This means that an organisation must clearly define and communicate to users why their data are being collected and processed and must not use them for other purposes.
Example: If an organisation collects data to fill an order (e.g., name, address, telephone number), those data may not be used for sending marketing materials unless the user has explicitly consented to this.
Data Minimisation
This principle means that only personal data that are necessary to achieve the stated purposes should be collected. Organisations must not collect or process data that are irrelevant or unnecessary for fulfilling the purpose of processing.
Example: If an organisation needs to process an order, it should collect only the data relevant to fulfilling that order (e.g., name, address, contact information), and not additional data such as the user’s hobbies.
Accuracy
Personal data must be accurate and, where necessary, kept up-to-date. Organisations must take all reasonable steps to ensure that inaccurate personal data are rectified or erased without delay. This principle ensures that individuals are not adversely affected by incorrect information that could be used against them.
Example: If a user changes their address, the organisation should update the data to avoid sending packages to the old address.
Storage Limitation
Personal data may be stored only for as long as necessary for the purposes for which they were collected. Once the data are no longer needed, they must be erased or anonymised to prevent further processing. This principle ensures that data are not retained longer than necessary, thereby reducing the risk of misuse.
Example: If data are collected for the performance of a contract, they must be deleted after a reasonable period following the completion of the contract, unless the law requires longer retention (e.g., accounting records).
Integrity and Confidentiality
Personal data must be processed in a manner that ensures their security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical and organisational measures. This includes data encryption, authentication, access control, backups, and other security methods.
Example: Using encryption for the transmission of sensitive data (e.g., credit card information or personal identification numbers) ensures that the data will not be disclosed in the event of a cyberattack.
Accountability
Data controllers (organisations that process personal data) must be responsible for compliance with all of the above principles and must be able to demonstrate their compliance with the GDPR. This means that organisations must implement appropriate policies, procedures, and measures to ensure GDPR compliance and be prepared for supervision and audits conducted by the regulatory authority (AZOP in Croatia).
Example: An organisation must maintain records of all data processing activities, conduct regular security audits, and ensure that employees are trained in data protection.
Background Colour
Font Face
Font Size
Text Colour
Font Kerning
Image Visibility
Letter Spacing
Line Height
Link Highlight