The six principles of the GDPR
Data controller: purpose and means of processing data
Article 5 of the EU GDPR stipulates that the controller is accountable for the legality, fairness, and openness of information. Data controllers are also expected to ensure the accuracy of personal data, storage limits, and confidentiality. To avoid fines and penalties, data controllers should only choose data processors that comply with the GDPR.
In certain instances, a data controller may collaborate with a third party or another service to do data analysis, even if it can handle the data using its own methods. For instance, a payroll service provider is a third-party data controller since it determines how payrolls should be handled.
Data processor: maintain a record of activity
It is not always straightforward to determine what constitutes a data processor. Typical data processors include legal businesses, medical offices, and accounting firms. A processor must keep a record of all...