The principle requiring personal data to be processed securely and protected against unauthorised access, loss, or damage using appropriate technical and organisational measures (Articles 5(1)(f), 32).
Small files or scripts placed on a visitor’s device to remember activity or preferences; where they involve personal data, GDPR consent rules apply alongside the ePrivacy Directive (Articles 4(11), 7).
A documented three-part test — purpose, necessity, and balancing — an organisation must complete to rely on legitimate interest as its lawful basis (Article 6(1)(f)).
A core legal test requiring that data processing goes no further than what is genuinely needed to achieve its purpose (Articles 5–6).
An assessment carried out before transferring personal data to a third country under SCCs, checking whether the destination’s laws actually protect the data in practice — a post-Schrems II requirement (Articles 44–46).
A legal or policy requirement that certain personal data be stored and processed within a specific country or region, rather than transferred abroad (Articles 44–49).