Summary of Introduction to Cybercrime Law
Introduction to Cybercrime Law: Key Concepts & Frameworks
Introduction
The General Data Protection Regulation (GDPR) is the EU's comprehensive legal framework for protecting personal data. It sets rules for how organisations process personal data, defines rights of individuals (data subjects), and prescribes technical and organisational measures to reduce risks to those rights and freedoms. This material explains core GDPR concepts, territorial scope, key principles, security requirements, and the Data Protection Impact Assessment (DPIA). Practical examples and comparisons help you apply GDPR requirements in real-world situations.
Key concepts and definitions
Personal data: Any information relating to an identified or identifiable natural person. An identifiable person can be singled out directly or indirectly by identifiers such as name, ID number, location data, online identifier, or one or more factors specific to physical, genetic, mental, economic, cultural or social identity.
Processing: Any operation performed on personal data, whether or not by automated means, including collection, recording, organisation, storage, retrieval, use, disclosure, erasure or destruction.
Controller: The person or organisation that determines the purposes and means of processing personal data.
Processor: The person or organisation that processes personal data on behalf of the controller.
Data Protection Impact Assessment (DPIA): A process to identify and mitigate risks to the rights and freedoms of natural persons where processing is likely to result in high risk, especially when using new technologies.
Territorial scope: when GDPR applies
Who is covered
- Controllers or processors established in the EU — GDPR applies regardless of where processing occurs.
- Controllers or processors not established in the EU, but who:
- offer goods or services to data subjects in the EU (paid or unpaid), or
- monitor the behaviour of data subjects located in the EU.
Core principles of data processing (Article 5)
Organisations must follow these principles when processing personal data:
- Lawfulness, fairness and transparency
- Inform data subjects about processing and purposes.
- Disclose profiling and consequences.
- Be able to demonstrate a legal basis for processing.
- Keep records: what is processed, why, legal grounds, retention, and safeguards.
- Purpose limitation
- Collect data for specified, explicit and legitimate purposes; do not repurpose incompatibly.
- Data minimisation
- Collect only data adequate, relevant and limited to what is necessary.
- Accuracy
- Keep personal data up to date; erase or correct inaccurate data without delay.
- Storage limitation
- Keep data in an identifiable form no longer than necessary for the purpose.
- Integrity and confidentiality
- Process data securely with appropriate technical and organisational measures.
Security of personal data (Article 32)
Controllers and processors must implement appropriate technical and organisational measures, taking into account the state of the art, costs, nature, scope, context and purposes of processing, and the risk to individuals. Measures include:
- Pseudonymisation and encryption of personal data
- Ensuring ongoing confidentiality, integrity, availability and resilience of systems
- Ability to restore availability and access to data after an incident
- Regular testing, assessment and evaluation of security measures
Practical example: encrypting a database that contains customer identifiers reduces risk if a server is breached and supports pseudonymisation to limit identifiability.
Already have an account? Sign in
GDPR & EU Data Protection
Klíčová slova: Cybercrime types & offenses, Cybercrime legal & data protection, Cyber attacks & malware, Online safety & fraud prevention, ICT security & cyber defense, Cybercrime legislation & policy, Critical infrastructure & cyberattacks, Cybersecurity Law & Policy, Internet Regulation & Governance Law, Cybercrime context & policy, Criminal & Cybercrime Law, ISP Liability & Safe Harbor Law, Communications & Data Retention Law, Cybersecurity & Defenses: Policy & Legal, Cybersecurity & Defenses: Security Services, GDPR & EU Data Protection, Digital Footprints & IP Issues, Cybersecurity & Defenses: Privacy & Data Protection, Forensics & Incident Response, Online Privacy & Platform Practices, IoT Security & Embedded Systems, Social Engineering & Phishing — Social Engineering Techniques, Identity, Access & Authentication, Botnets and network threats, Malware law & cybercrime, Malware types and platforms, Spam & Unwanted Communications, Social Engineering & Phishing — Phishing Types, Social Engineering & Phishing — Email-based Attacks, Attacks, Exploits & Hacking — Hacking Techniques, IP & Copyright Law, Attacks, Exploits & Hacking — Denial of Service, Online Safety & Child Protection: Sexual Exploitation, Online Safety & Child Protection: Online Harassment
Klíčové pojmy: GDPR protects personal data and applies EU-wide and extraterritorially, Personal data = any information identifying an individual directly or indirectly, Processing covers any operation on personal data, automated or not, GDPR applies if controller/processor is in EU or targets/monitors EU data subjects, Follow Article 5 principles: lawfulness, purpose limitation, minimisation, accuracy, storage limitation, integrity/confidentiality, Article 32 requires risk-based technical and organisational security measures (encryption, availability, testing), Conduct DPIAs for high-risk processing (profiling, special categories, large-scale monitoring), Record processing activities and legal bases (RoPA) to demonstrate accountability, IP addresses and logs can be personal data when they allow identification, Controllers determine purposes/means; processors act on controller instructions, Start DPIAs early and embed privacy by design into projects, Minimise retention, restrict access, and document security controls