Key Terms

Key terms you need know covered in the EU GDPR.

  • Information commissioner's office

    The ICO’s role is to uphold information rights in the public interest.  Further information and guidance is available on the ICO’s website at:

  • Personal data

    Data that relates to a living individual who can be identified from the data.

  • Sensitive personal data

    Includes personal data relating to racial or ethnic origin, political opinions, religious belief, physical or mental health.

  • Data subjects

    People about whom personal data is held.

  • Data controller and processor

    The data controller determines the purposes and means of processing personal data. A data processor is responsible for processing personal data on behalf of a controller.

    The University is a data controller.

  • The 6 principles of the GDPR

    Article 5 of the GDPR requires that personal data shall be:

    1. processed lawfully, fairly and in a transparent manner in relation to individuals;
    2. collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes;
    3. adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
    4. accurate, kept up to date and erased or rectified
    5. kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed;
    6. processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures
  • 8 rights of data subjects

    GDPR provides the following rights for individuals in respect of their personal data:

    1. The right to be informed
    2. The right of access
    3. The right to rectification
    4. The right to erasure
    5. The right to restrict processing
    6. The right to data portability
    7. The right to object
    8. Rights in relation to automated decision making and profiling.