Laws · GDPR ·art-4-par-2 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
How it connects
Cited by
- Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020
- Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them
- Guidelines 3/2019 on processing of personal data through video devices
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
All 90
- Guidelines 07/2022 on certification as a tool for transfers
- HvJ EU 9 januari 2025, C‑394/23 (Mousse).
- One-Stop-Shop case digest on right of access
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- Österreichische Datenschutzbehörde v CRIF
- OLG Köln - 15 W 55/26
- Can the GPC standard eliminate consent banners in the EU?
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
- UODO (Poland) - DKN.5131.27.2023
- Perlindungan Hukum Data Pribadi di Era Globalisasi Digital: Studi Perbandingan General Data Protection Regulation Uni Eropa dengan Undang-Undang Perlindungan Data Pribadi Indonesia
- CJEU - C-526/24 - Brillen Rottler
- EDPS: European Parliament is sole controller for COVID testing website and failed
- Court rejects DFW request for Ziggo customer IP addresses due to insufficient transparency
- GC T-318/24: EPSO access logs and Article 17 access requests under Regulation 2018/1725
- Norwegian Supreme Court: Legelisten.no has Art. 6(1)(f) legal basis for doctor reviews
- Guidelines 01/2023 on Article 37 Law Enforcement Directive
- Opinion 04/2024 on the notion of main establishment of a controller in the Union under Art. 4.16(a) GDPR
- EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space
- EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)
- EDPB-EDPS Joint Opinion 04/2021 on the Proposal for a Regulation of the European Parliament and of the Council on a framework for the issuance, verification and acceptance of interoperable certificates on vaccination, testing and recovery
- EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)
- Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications
- EDPB-EDPS Joint Opinion 1/2019 on the processing of patients’ data and the role of the European Commission within the eHealth Digital Service Infrastructure (eHDSI)
- X v Russmedia Digital SRL and Inform Media Press SRL
- European Data Protection Supervisor v Single Resolution Board
- Philippe Latombe v European Commission
- Nemzeti Adatvédelmi és Információszabadság Hatóság v UC
- Agentsia po vpisvaniyata v OL
- Meta Platforms Ireland Limited v Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V
- La Quadrature du Net and Others v Premier ministre and Ministère de la Culture
- Endemol Shine Finland Oy
- IAB Europe v Gegevensbeschermingsautoriteit
- Nacionalinis visuomenės sveikatos centras prie Sveikatos apsaugos ministerijos v Valstybinė duomenų apsaugos inspekcija
- Gesamtverband Autoteile-Handel e.V. v Scania CV AB
- RK v Ministerstvo zdravotnictví
- Proceedings brought by J.M
- European Commission v Republic of Poland
- UZ v Bundesrepublik Deutschland
- Norra Stockholm Bygg AB v Per Nycander AB
- HYA and Othersprokuratura
- VS v Inspektor v Inspektorata kam Visshia sadeben savet
- Proximus NV v Gegevensbeschermingsautoriteit
- Digi Távközlési és Szolgáltató Kft. v Nemzeti Adatvédelmi és Információszabadság Hatóság
- Komisia za zashtita na lichnite danni and Tsentralna izbiratelna komisia v Koalitsia „Demokratichna Bulgaria - Obedinenie“
- OT v Vyriausioji tarnybinės etikos komisija
- Ligue des droits humains ASBL v Conseil des ministres
- Robert Roos and Others v European Parliament
- X and Z v Autoriteit Persoonsgegevens
- SIA 'SS' v Valsts ieņēmumu dienests
- Mircom International Content Management & Consulting (M.I.C.M.) Limited v Telenet BVBA
- Deutsche Post AG v Hauptzollamt Köln
- Maria Psara and Others v European Parliament
- European Commission v Patrick Breyer
- The Bavarian Lager Co. Ltd v Commission of the European Communities
- Subsequent Use of GDPR Data for a Law Enforcement Purpose:
- Data Protection Regulation and International Arbitration: Can There Be Harmonious Coexistence (with the GDPR Requirements Concerning Cross-Border Data Transfer)?
- DSB (Austria) - 2026-0.043.390
- NAIH (Hungary) - NAIH-11443-3/2026
- Cour Administrative - 49701C
- DSB (Austria) - 2025-0.950.759
- OLG München - 36 U 1054/25 e
- Garante per la protezione dei dati personali (Italy) - 462/2026
- UODO (Poland) - DKN.5131.5.2025
- Austrian FAC rules on publishing full court judgment naming witness on social media
- NAIH (Hungary) - NAIH-450-7-2026
- NAIH (Hungary) - NAIH-4462-5-2026
- US Zagreb - Us I-4772/2023-10
- VG Berlin - 42 K 73/25
- Austrian DSB: Employee who shared customer's phone number acted as GDPR controller
- AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor
- DSB: Retailer must grant full access and delete data after third-party fraud order
- DSB (Austria) - DSB-D124.2437/25
- AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded
- AEPD: Continuous workplace audio recording violates GDPR data minimisation principle
- BVwG - W137 2334047-1
- VG Munich: university may be GDPR controller for professors' editorial work emails
- AEPD (Spain) - ps-00256-2025
- BVwG - W292 2292202-1
- BVwG - W292 2298015-1
- AEPD: CaixaBank requested excessive inheritance documentation from heirs
- BVwG - W298 2314952-1
- European Commission v Hungary
- HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- AEPD (Spain) - ps-00287-2025