# Concepts and Definitions

The central legal definitions of Article 4 GDPR in detail: personal data, processing, pseudonymization, controller, processor, and further defined terms, with interpretation and delimitation.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/begriffe-und-definitionen
> Sprache: en



Article 4 GDPR sets out up front the central concepts that the entire Regulation works with. Anyone applying a provision of the GDPR must first determine whether its statutory criteria are met, and those criteria are for the most part defined here. The following pages explain the individual legal definitions: their wording, their interpretation by the courts, and the distinctions that matter in practice.

## 1 The Data Concepts [#1-the-data-concepts]

What is subject to data protection law in the first place, and in what form data are processed.

* [1.2.1 Personal Data](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.1-personenbezogene-daten): the threshold that triggers all of data protection law: a natural and living person, identifiability, data relating to objects, synthetic data, and the distinction from anonymous data.
* [1.2.2 Processing](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.2-verarbeitung): the broad catch-all concept for any handling of data, from collection to destruction.
* [1.2.3 Restriction of Processing](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.3-einschraenkung-der-verarbeitung): the marking of stored data to limit its future processing (formerly "blocking").
* [1.2.5 Pseudonymization](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.5-pseudonymisierung): separating data from identity; the distinction from anonymization and encryption.
* [1.2.6 Filing System](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.6-dateisystem): a structured set that also covers manual files.
* [1.2.13 Genetic Data](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.13-genetische-daten): data resulting from the analysis of a biological sample.
* [1.2.14 Biometric Data](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.14-biometrische-daten): data obtained through technical processing for unique identification.
* [1.2.15 Data Concerning Health](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.15-gesundheitsdaten): data on a person's physical or mental state of health.

## 2 The Actors [#2-the-actors]

Who takes on which role within the data protection framework.

* [1.2.7 Controller](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.7-verantwortlicher): whoever determines the purposes and means; the primary addressee of the GDPR's obligations.
* [1.2.8 Processor](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.8-auftragsverarbeiter): processing on behalf of a controller, with its own obligations and liability.
* [1.2.9 Recipient](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.9-empfaenger): any body to which data are disclosed.
* [1.2.10 Third Party](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.10-dritter): a body outside the controller's organization; there is no group privilege.

## 3 Operations, Rights, and Risks [#3-operations-rights-and-risks]

Concepts relating to special processing operations and the self-determination of the data subject.

* [1.2.4 Profiling](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.4-profiling): the automated evaluation of personal aspects.
* [1.2.11 Consent](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.11-einwilligung): a freely given, informed indication of wishes serving as a legal basis.
* [1.2.12 Personal Data Breach](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.12-verletzung-des-schutzes-personenbezogener-daten): a breach of security that triggers the notification obligations.


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.