Individual Topics
Individual topics of the GDPR, organized by regulatory area.
Individual topics of the GDPR, organized by regulatory area.
Available sections
- 1.3.1 Scope of the GDPR: the material and territorial scope of the GDPR under Articles 2 and 3 GDPR: the forms of processing covered, exclusions from the material scope, the establishment criterion and the targeting criterion.
- 1.3.2 Legal Bases for Processing: the structure and system of Article 6 GDPR: the general prohibition subject to permission, the exhaustive catalog of grounds for lawful processing, the necessity requirement, and the relationship with the opening clauses and with the purpose limitation principle.
- 1.3.3 Principles Relating to Processing: the principles relating to the processing of personal data under Article 5 GDPR. Classification, legal nature, relationship with Article 6 GDPR, addressees, exceptions under Articles 23 and 85 GDPR, and liability to administrative fines.
- 1.3.5 Transparency Obligations (Privacy Notice): the information and transparency obligations under Articles 12 to 14 GDPR: when a privacy notice is required, the mandatory information where data are collected from the data subject and from third parties, exceptions, as well as drafting and practice.
- 1.3.6 Controllers and Processors: the data protection roles under the GDPR and how they are distinguished: controller (Article 4(7), Article 24), persons acting under the authority of the controller (Article 29), joint controllers (Article 26), and processor (Article 28 GDPR), including the data processing agreement.
- 1.3.7 Records of Processing Activities: the obligation to maintain records of processing activities under Article 30 GDPR: mandatory content for controllers and processors, form, the obligation to make the records available, the SME exemption under paragraph 5, and reform proposal COM(2025) 501.
- 1.3.8 Data Protection Officer: designation, position, tasks, and liability of the data protection officer under Articles 37 to 39 GDPR and § 38 of the German Federal Data Protection Act (BDSG); qualification, the internal and the external data protection officer, and drafting guidance for the contract with an external data protection officer.
- 1.3.10 Data Protection Impact Assessment: when it is required (threshold analysis), the six-step procedure with risk assessment and report, and the internal organization of those involved under Articles 35 and 36 GDPR.
- 1.3.12 Special Categories of Personal Data (Article 9 GDPR): the processing of special categories of personal data under Article 9 GDPR: the general prohibition of processing, the grounds for lawful processing, the relationship with Article 6 GDPR, and opening clauses for Member State law.
- 1.3.13 Transfers to Third Countries (Data Export): the transfer of personal data to unsafe third countries under Chapter V of the GDPR (Articles 44 to 49 GDPR): assessment framework, derogations under Article 49, standard contractual clauses with a Transfer Impact Assessment, the Data Privacy Framework, and Binding Corporate Rules.
- 1.3.14 Automated Individual Decision-Making (Article 22 GDPR): the general prohibition of decisions based solely on automated processing under Article 22 GDPR: the statutory criteria, profiling and scoring, the exceptions under paragraph 2, the safeguards under paragraph 3, sensitive data under paragraph 4, information and access rights, and the relationship with the AI Act.
- 1.3.15 Personal Data Breach (Data Breach): handling a personal data breach under Articles 4(12), 33, and 34 GDPR: the concept, the internal process from detection through to documentation, the three-stage risk assessment, notification to the supervisory authority and communication to the data subjects, as well as further notification obligations outside the GDPR.
Further individual topics will be added over time.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Data Concerning Health (Article 4(15) GDPR)
Data concerning health is personal data about a person's physical or mental health from which information about their state of health can be derived. As a special category, it is subject to a general prohibition of processing.
Scope of Application of the GDPR (Articles 2 and 3 GDPR)
Overview of the material and the territorial scope of the GDPR: when European data protection law applies at all, and which processing operations and which situations it covers.