Personal Data Essentials
Recognise personal data before you handle it.
What Is Personal Data Essentials?
Most privacy incidents start with someone who did not recognise the file in front of them as personal data. You work through a real recruiting export: a candidate longlist carrying an application IP address and device identifier nobody asked for, and free-text recruiter notes holding health data and trade union membership. You will apply the Article 4(1) definition, separate the Article 9 special categories from data that merely feels sensitive, decide whether each recipient is a processor or a separate controller, and route the decision to the Data Protection Officer.
What You'll Learn in Personal Data Essentials
- Apply the Article 4(1) definition of personal data, including the indirect identification test and pseudonymised records
- Recognise online identifiers such as IP addresses, device IDs, cookie identifiers and location data as personal data
- Distinguish the closed Article 9 list of special categories from commercially sensitive data that falls outside it
- Spot special-category data that arrives inferred from free-text notes, attachments and photographs
- Assign the controller, processor and third-party roles under Article 4(7) to (10) and explain what changes when data leaves the organisation
- Route a request that carries a privacy question to the Data Protection Officer instead of deciding it at your desk
Personal Data Essentials — Training Steps
-
Access on Hold
Marktvel runs a marketplace with millions of listings, which means almost every internal tool touches someone's personal data. Your request for access to the customer records system came back with a condition attached: the privacy foundation module has to be completed first. It is not a formality. Most privacy incidents at companies like this one start with somebody who genuinely did not know that what they were handling counted as personal data.
-
A Note From the DPO
Ines Haller, the Data Protection Officer at Marktvel, has sent the enrolment mail with the portal link.
-
Opening the Portal
The module sits on the internal privacy portal.
-
Signing In
The portal uses your regular Marktvel work account.
-
What the Law Calls Personal Data
Section one opens with the definition from Article 4(1), and then with the part that catches people out: the list of things that are personal data even though they carry nobody's name. The test is not whether you can look at a value and see a person. The test is whether the person can be singled out from it, by anyone, using means reasonably likely to be available.
-
The Analytics Export
A colleague on the growth team wants to share a raw traffic export with an outside consultant. He tells you it is fine to send without any approval because the file contains no names, no email addresses and no account numbers, only IP addresses, device identifiers and timestamps.
-
The Categories That Need More Care
Section two covers Article 9. A short list of categories is treated as inherently riskier, because getting it wrong exposes people to discrimination rather than inconvenience. Processing this data is prohibited by default. It becomes lawful only when one of the narrow exceptions in Article 9(2) applies, which is a much higher bar than the ordinary legal bases.
-
Who Is Responsible for What
Section three is the one that decides what you are allowed to do when another company is involved. The GDPR splits the roles by who decides, not by who holds the data. Marktvel is the controller for its customer and candidate data. Everyone else is either processing on Marktvel instructions, or acting for their own purposes, and the difference changes what has to be in place before data moves.
-
A Request From the Vendor
The module closes section three with a scenario drawn from a real support ticket. Hirelane, the applicant tracking system Marktvel uses, has written to several customers proposing to use the candidate records already in its platform to train and improve its own matching algorithm, at no extra cost.
-
The Module Meets Real Work
The module is done. Within the hour the theory turns into an actual request. Tomas Brandl in Talent Acquisition is running the backend engineer hire and wants to move the longlist along. He has attached the export and asked you to pass it to two places.
Security Framework Coverage
CIS Controls
- CIS 3 Data Protection
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
- PR.DS Data Security
GDPR
- Art. 4 Definitions
- Art. 9 Processing of special categories of personal data