Personal Data Essentials

Personal Data Essentials

Recognise personal data before you handle it.

What Is Personal Data Essentials?

Most privacy incidents start with someone who did not recognise the file in front of them as personal data. You work through a real recruiting export: a candidate longlist carrying an application IP address and device identifier nobody asked for, and free-text recruiter notes holding health data and trade union membership. You will apply the Article 4(1) definition, separate the Article 9 special categories from data that merely feels sensitive, decide whether each recipient is a processor or a separate controller, and route the decision to the Data Protection Officer.

What You'll Learn in Personal Data Essentials

Personal Data Essentials — Training Steps

  1. Access on Hold

    Marktvel runs a marketplace with millions of listings, which means almost every internal tool touches someone's personal data. Your request for access to the customer records system came back with a condition attached: the privacy foundation module has to be completed first. It is not a formality. Most privacy incidents at companies like this one start with somebody who genuinely did not know that what they were handling counted as personal data.

  2. A Note From the DPO

    Ines Haller, the Data Protection Officer at Marktvel, has sent the enrolment mail with the portal link.

  3. Opening the Portal

    The module sits on the internal privacy portal.

  4. Signing In

    The portal uses your regular Marktvel work account.

  5. What the Law Calls Personal Data

    Section one opens with the definition from Article 4(1), and then with the part that catches people out: the list of things that are personal data even though they carry nobody's name. The test is not whether you can look at a value and see a person. The test is whether the person can be singled out from it, by anyone, using means reasonably likely to be available.

  6. The Analytics Export

    A colleague on the growth team wants to share a raw traffic export with an outside consultant. He tells you it is fine to send without any approval because the file contains no names, no email addresses and no account numbers, only IP addresses, device identifiers and timestamps.

  7. The Categories That Need More Care

    Section two covers Article 9. A short list of categories is treated as inherently riskier, because getting it wrong exposes people to discrimination rather than inconvenience. Processing this data is prohibited by default. It becomes lawful only when one of the narrow exceptions in Article 9(2) applies, which is a much higher bar than the ordinary legal bases.

  8. Who Is Responsible for What

    Section three is the one that decides what you are allowed to do when another company is involved. The GDPR splits the roles by who decides, not by who holds the data. Marktvel is the controller for its customer and candidate data. Everyone else is either processing on Marktvel instructions, or acting for their own purposes, and the difference changes what has to be in place before data moves.

  9. A Request From the Vendor

    The module closes section three with a scenario drawn from a real support ticket. Hirelane, the applicant tracking system Marktvel uses, has written to several customers proposing to use the candidate records already in its platform to train and improve its own matching algorithm, at no extra cost.

  10. The Module Meets Real Work

    The module is done. Within the hour the theory turns into an actual request. Tomas Brandl in Talent Acquisition is running the backend engineer hire and wants to move the longlist along. He has attached the export and asked you to pass it to two places.

Security Framework Coverage

CIS Controls

  • CIS 3 Data Protection

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • PR.DS Data Security

GDPR

  • Art. 4 Definitions
  • Art. 9 Processing of special categories of personal data