Learning path
GDPR — Data protection
The six blocks of the General Data Protection Regulation, from basic principles to security breach management.
Your progress
It is saved only in this browser on this device: no account needed and nothing leaves your machine. Clear the site data or open it on another device and you start from scratch.
- 1 Principles and lawful bases How to identify the legal basis for each personal data processing activity. Block 1
- 2 Record of processing activities How to keep the record of processing activities required by the GDPR up to date. Block 2
- 3 Data subject rights How to manage requests for access, rectification, erasure, and other data subject rights. Block 3
- 4 Security measures How to apply technical and organizational measures proportional to the processing risk. Block 4
- 5 Data protection impact assessment (DPIA) How to determine when a DPIA is mandatory and how to document it. Block 5
- 6 Security breaches and data processors How to respond to a security breach and control data processors. Block 6
Every GDPR block explained
The GDPR applies to any organization that processes personal data of European citizens, regardless of its size or sector.
This path explains each block with examples of how to document the record of processing activities, data subject rights, and responding to a security breach.
Sources
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- Regulation (EU) 2016/679, General Data Protection Regulation EUR-Lex · Applicable since 25 May 2018
- Organic Law 3/2018 on Data Protection and guarantee of digital rights BOE-A-2018-16673 · 6 December 2018
- Spanish Data Protection Agency AEPD · Supervisory authority