CHAPTER IGENERAL PROVISIONS

Article 4Definitions

Official text

For the purposes of this Regulation:

(1)‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

(2)‘processing’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

(3)‘restriction of processing’ means the marking of stored personal data with the aim of limiting their processing in the future;

(4)‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;

(5)‘pseudonymisation’ means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;

(6)‘filing system’ means any structured set of personal data which are accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis;

(7)‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

(8)‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;

(9)‘recipient’ means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;

(10)‘third party’ means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;

(11)‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;

(12)‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;

(13)‘genetic data’ means personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question;

(14)‘biometric data’ means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data;

(15)‘data concerning health’ means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status;

(16)‘main establishment’ means:

(a)as regards a controller with establishments in more than one Member State, the place of its central administration in the Union, unless the decisions on the purposes and means of the processing of personal data are taken in another establishment of the controller in the Union and the latter establishment has the power to have such decisions implemented, in which case the establishment having taken such decisions is to be considered to be the main establishment;

(b)as regards a processor with establishments in more than one Member State, the place of its central administration in the Union, or, if the processor has no central administration in the Union, the establishment of the processor in the Union where the main processing activities in the context of the activities of an establishment of the processor take place to the extent that the processor is subject to specific obligations under this Regulation;

(17)‘representative’ means a natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27, represents the controller or processor with regard to their respective obligations under this Regulation;

(18)‘enterprise’ means a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity;

(19)‘group of undertakings’ means a controlling undertaking and its controlled undertakings;

(20)‘binding corporate rules’ means personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity;

(21)‘supervisory authority’ means an independent public authority which is established by a Member State pursuant to Article 51;

(22)‘supervisory authority concerned’ means a supervisory authority which is concerned by the processing of personal data because:

(a)the controller or processor is established on the territory of the Member State of that supervisory authority;

(b)data subjects residing in the Member State of that supervisory authority are substantially affected or likely to be substantially affected by the processing; or

(c)a complaint has been lodged with that supervisory authority;

(23)‘cross-border processing’ means either:

(a)processing of personal data which takes place in the context of the activities of establishments in more than one Member State of a controller or processor in the Union where the controller or processor is established in more than one Member State; or

(b)processing of personal data which takes place in the context of the activities of a single establishment of a controller or processor in the Union but which substantially affects or is likely to substantially affect data subjects in more than one Member State.

(24)‘relevant and reasoned objection’ means an objection to a draft decision as to whether there is an infringement of this Regulation, or whether envisaged action in relation to the controller or processor complies with this Regulation, which clearly demonstrates the significance of the risks posed by the draft decision as regards the fundamental rights and freedoms of data subjects and, where applicable, the free flow of personal data within the Union;

(25)‘information society service’ means a service as defined in point (b) of Article 1(1) of Directive (EU) 2015/1535 of the European Parliament and of the Council (¹);

(26)‘international organisation’ means an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries.

¹ Directive (EU) 2015/1535 of the European Parliament and of the Council of 9 September 2015 laying down a procedure for the provision of information in the field of technical regulations and of rules on Information Society services ( OJ L 241, 17.9.2015, p. 1).

Commentary

Article 4 is one of the most important provisions of the GDPR because it defines the legal concepts used throughout the Regulation. These definitions determine whether the GDPR applies to particular information, who bears responsibility for compliance, and how the rights and obligations under the Regulation should be interpreted. Every controller, processor, supervisory authority and court must first look to Article 4 before applying the substantive provisions of the GDPR.

The definitions contained in Article 4 are intentionally broad and technology-neutral. Rather than being confined to traditional databases or identifiable information such as names and addresses, they are designed to accommodate evolving technologies including cloud computing, artificial intelligence, online tracking, biometric identification and digital platforms.

Article 4 must be interpreted together with Recitals 26, 28, 30, 31, 32, 33, 35, 39, 78, 79 and 85, as well as relevant guidance issued by the European Data Protection Board (EDPB), particularly Guidelines 07/2020 on the concepts of Controller and Processor and Guidelines 05/2020 on Consent under Regulation 2016/679.

Article 4(1): Personal Data

Article 4(1) defines personal data as any information relating to an identified or identifiable natural person ("data subject"). This is one of the broadest definitions under the GDPR and serves as the threshold for the application of the Regulation. Unless information qualifies as personal data, the GDPR does not apply.

Meaning and Scope

The definition contains three essential elements:

  • there must be information;
  • the information must relate to a natural person; and
  • the person must be identified or identifiable.

The expression "any information" is deliberately broad. It covers objective facts, subjective opinions, evaluations, assessments and records, irrespective of their accuracy or format. Personal data may exist in electronic records, paper documents, audio recordings, video footage, photographs or any other medium capable of recording information.

Personal data may include:

  • a person's name;
  • an identification number;
  • an email address;
  • location data;
  • an IP address;
  • an online identifier;
  • financial records;
  • employment records;
  • medical records; or
  • CCTV footage.
  • "Relating To" a Natural Person

Information relates to a person where it concerns, describes, evaluates or influences that individual.

Accordingly, personal data is not limited to information that directly identifies someone. Performance reviews, disciplinary findings, examination scripts, customer ratings, interview notes and internal assessments may all constitute personal data because they concern an identifiable individual.

The CJEU adopted this broad interpretation in Nowak (Case C-434/16), where examination scripts and examiner comments were held to be personal data since they related to the candidate and could affect his rights.

An individual may be identified:

  • directly through a unique identifier; or
  • indirectly by combining different pieces of information.

Identification may therefore occur through:

  • a customer number;
  • an employee code;
  • device identifiers;
  • location history;
  • browser identifiers;
  • biometric characteristics; or
  • a combination of several identifiers.

Recital 26 clarifies that identifiability must be assessed by considering all means reasonably likely to be used to identify the individual, taking into account technology, costs, time and available resources.

Accordingly, organisations should assess whether re-identification is reasonably possible rather than whether they presently know the individual's identity.

The CJEU reaffirmed this principle in Breyer (Case C-582/14) by recognising that dynamic IP addresses may constitute personal data where legal means exist through which identification is reasonably possible.

Practical Issues

In practice, organisations frequently underestimate the breadth of this definition.

Personal data commonly includes:

  • business email addresses identifying employees;
  • employee photographs;
  • customer account numbers;
  • mobile device identifiers;
  • vehicle registration numbers;
  • recorded customer service calls; and
  • metadata generated during online interactions.

The definition applies only to living natural persons. Information relating exclusively to legal entities generally falls outside the GDPR unless it simultaneously identifies one or more individuals.

Illustration

A retailer replaces customer names with customer identification numbers before analysing purchasing behaviour. Because the retailer retains a separate database linking those numbers to individual customers, the information remains personal data and continues to be subject to the GDPR.

Article 4(2): Processing

Article 4(2) defines processing as any operation or set of operations performed on personal data, whether or not by automated means.

Meaning and Scope

The definition is intentionally comprehensive and covers every stage of the personal data lifecycle.

Processing includes:

  • collection;
  • recording;
  • organisation;
  • structuring;
  • storage;
  • adaptation;
  • alteration;
  • retrieval;
  • consultation;
  • use;
  • disclosure;
  • dissemination;
  • restriction;
  • erasure; or
  • destruction.

The list is illustrative rather than exhaustive. Consequently, almost every interaction with personal data constitutes processing.

Processing begins when personal data is first collected and continues until it is permanently erased or irreversibly anonymised.

Automated and Manual Processing

Processing may occur through:

  • automated software;
  • cloud platforms;
  • AI systems;
  • mobile applications;
  • paper records forming part of a filing system; or
  • hybrid processing involving both electronic and manual records.

The definition therefore complements Article 2, which extends the GDPR to automated processing and structured manual filing systems.

Practical Issues

Many organisations mistakenly believe that processing requires sophisticated technology or advanced analytics.

However, processing also occurs where an employee:

  • opens a personnel file;
  • searches a customer database;
  • views CCTV footage;
  • scans an identity document;
  • forwards an email containing personal data; or
  • deletes a customer record.

Since the concept of processing is interpreted broadly, controllers should generally assume that any interaction with personal data constitutes processing unless specifically excluded by the GDPR.

Illustration

An HR manager accesses an employee's personnel file solely to verify the employee's date of joining before responding to an internal enquiry. Although no information is modified or disclosed, merely consulting the file constitutes processing under Article 4(2).

Article 4(3): Restriction of Processing

Restriction of processing means marking stored personal data with the aim of limiting its future processing.

Meaning and Scope

Restriction differs from deletion.

Where processing is restricted:

  • the personal data continues to be stored;
  • ordinary processing activities are suspended;
  • access is limited to specific authorised purposes; and
  • the information is preserved until the relevant issue is resolved.

Restriction commonly arises where:

  • the accuracy of personal data is contested;
  • the lawfulness of processing is disputed;
  • the controller no longer requires the information but the data subject requires it for legal claims; or
  • an objection to processing under Article 21 is pending.

Restriction therefore acts as an important safeguard that balances the interests of the controller and the data subject while preserving evidence where necessary.

Article 4(4): Profiling

Profiling means any form of automated processing of personal data used to evaluate certain personal aspects relating to a natural person.

Meaning and Scope

Profiling involves analysing personal data to assess or predict matters concerning an individual. Not every profiling activity produces legal effects. However, where profiling forms the basis of decisions producing legal or similarly significant effects, Article 22 imposes additional safeguards, including the right not to be subject to certain solely automated decisions.

Controllers should carefully assess whether profiling activities trigger additional transparency obligations, data protection impact assessments or Article 22 safeguards.

Illustration

An online marketplace analyses a customer's browsing history, purchase records and search behaviour to predict future purchasing preferences and display personalised advertisements. This constitutes profiling because automated processing is used to evaluate the customer's behaviour and preferences.

Article 4(5): Pseudonymisation

Article 4(5) defines pseudonymisation as the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and protected by appropriate technical and organisational measures.

Meaning and Scope

Pseudonymisation is one of the GDPR's recognised privacy-enhancing techniques. Instead of removing personal data altogether, it replaces direct identifiers with codes, reference numbers or other pseudonyms, thereby reducing the likelihood of identifying an individual.

For pseudonymisation to satisfy Article 4(5):

the identifying information must be separated from the remaining dataset; the additional information must be stored independently; access to the identifying information must be restricted; and appropriate technical and organisational safeguards must prevent unauthorised re-identification.

Recital 28 encourages the use of pseudonymisation as an important security measure capable of reducing risks to data subjects while enabling controllers to continue legitimate processing activities.

Pseudonymisation should not be confused with anonymisation. Properly anonymised data falls outside the GDPR because individuals can no longer be identified. Pseudonymised data, however, remains personal data since re-identification is still possible through the additional information.

Practical Issues

Pseudonymisation is widely used in:

clinical research; banking and financial services; employee identification systems; analytics platforms; artificial intelligence training datasets; and software development and testing environments.

Controllers should not assume that pseudonymisation eliminates GDPR obligations. The Regulation continues to apply because the possibility of re-identification remains.

Illustration

A hospital replaces patient names with randomly generated patient codes before sharing medical records with a research institution. Since the hospital retains a separate key linking each code to the patient's identity, the dataset remains pseudonymised personal data and continues to be governed by the GDPR.

Article 4(6): Filing System

Article 4(6) defines a filing system as any structured set of personal data that is accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.

Meaning and Scope

The definition ensures that the GDPR applies not only to electronic databases but also to organised paper records.

A filing system exists where personal data is arranged according to identifiable criteria that permit efficient retrieval.

The structure need not be sophisticated. Even a manually maintained filing cabinet may constitute a filing system where documents are systematically organised.

This definition should be read together with Article 2, which extends the GDPR to non-automated processing where personal data forms part of, or is intended to form part of, a filing system.

Article 4(7): Controller

Article 4(7) defines a controller as the natural or legal person, public authority, agency or other body which determines the purposes and means of processing personal data.

Meaning and Scope

The concept of controller is functional rather than contractual. Whether an organisation is a controller depends upon its actual decision-making role, not the title used in agreements.

A controller determines:

  • why personal data is processed; and
  • how the essential aspects of processing will be carried out.

The controller therefore exercises overall decision-making authority regarding the processing operation.

Controllers may include:

  • private companies;
  • government departments;
  • educational institutions;
  • hospitals;
  • charitable organisations; or
  • individual professionals.

The concept of controller should be interpreted together with EDPB Guidelines 07/2020 on the concepts of Controller and Processor, which emphasise that factual influence and decision-making are more important than contractual terminology.

Joint Controllers

Two or more organisations may qualify as joint controllers where they jointly determine the purposes and essential means of processing.

Joint controllership does not require equal participation. It is sufficient that each party meaningfully influences the decisions governing the processing operation.

The CJEU has repeatedly interpreted joint controllership broadly in decisions such as Wirtschaftsakademie Schleswig-Holstein (C-210/16), Fashion ID (C-40/17) and Jehovan Todistajat (C-25/17).

Controllers bear primary responsibility for GDPR compliance, including:

  • identifying the lawful basis for processing;
  • providing privacy notices;
  • responding to data subject requests;
  • implementing appropriate security measures;
  • ensuring processor compliance; and
  • demonstrating accountability under Article 5(2).

Organisations should therefore assess their actual role in determining the purposes and means of processing rather than relying solely upon contractual descriptions.

Illustration

A retail company appoints a cloud service provider to host its customer database. The retailer determines why customer information is collected, which information is collected and how long it will be retained. The retailer is therefore the controller, while the cloud provider acts as the processor.

Article 4(8): Processor

A processor is a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller.

Meaning and Scope

Unlike controllers, processors do not determine the purposes of processing. They process personal data only in accordance with the documented instructions of the controller.

Typical processors include:

  • cloud hosting providers;
  • payroll service providers;
  • managed IT vendors;
  • customer support providers;
  • document storage companies; or
  • Software-as-a-Service (SaaS) providers.

Although processors act on behalf of controllers, they are subject to several direct obligations under the GDPR, particularly those relating to:

  • security;
  • confidentiality;
  • record keeping;
  • sub-processing; and
  • cooperation with supervisory authorities.

Where a processor exceeds the controller's instructions and independently determines the purposes or essential means of processing, it may itself become a controller in respect of that processing.

Article 4(9): Recipient

A recipient is any natural or legal person, public authority, agency or other body to whom personal data is disclosed, whether or not that person is a third party.

Meaning and Scope

The definition is intentionally broad.

Recipients may include:

  • processors;
  • joint controllers;
  • affiliated companies;
  • external consultants;
  • auditors;
  • government departments; or
  • regulatory authorities.

However, public authorities receiving personal data in the course of a particular investigation under Union or Member State law are not regarded as recipients for the purposes of this definition. Their subsequent processing remains governed by the applicable data protection rules.

Article 4(10): Third Party

A third party means any person other than:

  • the data subject;
  • the controller;
  • the processor; or
  • persons acting under the direct authority of the controller or processor.

The distinction is important because several GDPR provisions regulate disclosures to third parties, including transparency obligations, international transfers and lawful processing requirements.

Article 4(11): Consent

Article 4(11) defines consent as any freely given, specific, informed and unambiguous indication of the data subject's wishes by which the individual signifies agreement through a statement or clear affirmative action.

Meaning and Essential Elements

For consent to be valid, it must be:

  • freely given;
  • specific;
  • informed;
  • unambiguous; and
  • communicated through a clear affirmative action.

Silence, inactivity or pre-ticked boxes do not constitute valid consent.

This definition must be read together with Article 7, Recitals 32, 42 and 43, and EDPB Guidelines 05/2020 on Consent under Regulation 2016/679.

The GDPR sets a deliberately high standard because consent must represent a genuine exercise of individual choice rather than mere acquiescence.

Article 4(12): Personal Data Breach

A personal data breach means a breach of security leading to:

  • accidental or unlawful destruction;
  • loss;
  • alteration;
  • unauthorised disclosure; or
  • unauthorised access,

to personal data transmitted, stored or otherwise processed.

The definition extends beyond cyberattacks. Human error, accidental disclosure, lost devices and unauthorised internal access may all constitute personal data breaches.

This definition forms the basis for the notification obligations under Articles 33 and 34.

Article 4(13): Genetic Data

Genetic data refers to personal data relating to the inherited or acquired genetic characteristics of an individual that provide unique information about that person's physiology or health.

Because genetic data may reveal highly sensitive information about an individual's health, ancestry and biological characteristics, it is classified as a special category of personal data under Article 9.

Article 4(14): Biometric Data

Biometric data means personal data resulting from specific technical processing relating to an individual's physical, physiological or behavioural characteristics that enables or confirms unique identification.

Examples

include:

  • facial recognition templates;
  • fingerprint scans;
  • iris scans;
  • voice recognition templates; or
  • palm vein recognition data. Not every photograph constitutes biometric data. A photograph becomes biometric data only where it undergoes specific technical processing for identification purposes.

Article 4(15): Data Concerning Health

This definition covers personal data relating to the physical or mental health of an individual, including the provision of healthcare services, that reveals information about that person's health status.

Health data extends beyond medical records and may include:

  • medical diagnoses;
  • prescriptions;
  • laboratory reports;
  • disability information;
  • treatment history;
  • health insurance claims; or
  • clinical examination records.

Health data enjoys enhanced protection under Article 9 because of its particularly sensitive nature.

Article 4(16): Main Establishment

Article 4(16) defines main establishment for both controllers and processors operating in more than one Member State. The concept is fundamental to the GDPR's One-Stop-Shop (OSS) mechanism because it determines the Lead Supervisory Authority (LSA) under Article 56.

Meaning and Scope

The GDPR distinguishes between controllers and processors.

For a controller, the main establishment is generally the place of its central administration in the Union. However, if another establishment takes the decisions regarding the purposes and means of processing and has the authority to implement those decisions, that establishment becomes the main establishment.

For a processor, the main establishment is ordinarily its central administration within the Union. If no such central administration exists, it is the establishment where the principal processing activities are carried out in the context of the processor's obligations under the GDPR.

The assessment is based on actual decision-making authority, not merely where the organisation is incorporated or where its registered office is located.

The concept of main establishment should be read together with Recitals 36 and 124, as well as EDPB Guidelines 08/2022 on identifying a controller or processor's lead supervisory authority.

Practical Issues

Multinational organisations frequently assume that their European headquarters automatically constitutes the main establishment. This is incorrect.

The relevant establishment must have genuine authority to:

  • determine the purposes of processing;
  • determine the essential means of processing;
  • implement those decisions; and
  • assume responsibility for compliance.

If strategic decisions are actually made elsewhere, another establishment may qualify as the main establishment.

Article 4(17): Representative

A representative is a natural or legal person established in the Union who is designated in writing by a controller or processor under Article 27 to represent them regarding their GDPR obligations.

Meaning and Scope

The representative primarily applies to controllers or processors not established in the European Union but whose processing activities fall within the territorial scope of Article 3(2).

The representative serves as a point of contact for:

  • supervisory authorities;
  • data subjects; and
  • regulatory communications.

Appointment of a representative does not transfer GDPR liability from the controller or processor. Responsibility for compliance remains with the organisation undertaking the processing.

Article 4(18): Enterprise

An enterprise means a natural or legal person engaged in an economic activity, irrespective of its legal form.

Meaning and Scope

The concept is intentionally broad.

An enterprise may include:

  • companies;
  • partnerships;
  • sole proprietorships;
  • cooperatives;
  • associations; or
  • other organisations carrying on economic activities.

The definition is particularly relevant for provisions relating to administrative fines, Binding Corporate Rules and group-wide compliance obligations.

Article 4(19): Group of Undertakings

A group of undertakings consists of a controlling undertaking together with its controlled undertakings.

Meaning and Scope

This definition recognises that many organisations process personal data through complex corporate structures.

The concept is especially relevant when implementing:

-Binding Corporate Rules; -internal data-sharing arrangements; -group-wide privacy policies; and -common security frameworks.

Although entities belong to the same corporate group, each entity remains responsible for complying with its own GDPR obligations unless specific provisions provide otherwise.

Article 4(20): Binding Corporate Rules

Binding Corporate Rules (BCRs) are internal data protection policies adopted by multinational groups to facilitate transfers of personal data to group entities located outside the European Economic Area.

Meaning and Scope

BCRs establish legally enforceable obligations applicable throughout the corporate group.

They enable organisations to transfer personal data internationally while maintaining an adequate level of protection.

BCRs generally address:

  • governance structures;
  • accountability;
  • security measures;
  • complaint handling;
  • audit mechanisms;
  • employee training; and
  • enforceable rights for data subjects.

BCRs require approval by the competent supervisory authority under Articles 46 and 47 before they may be relied upon for international data transfers.

Article 4(21): Supervisory Authority

A supervisory authority is the independent public authority established by each Member State pursuant to Article 51.

Meaning and Scope

Supervisory authorities are responsible for monitoring and enforcing the application of the GDPR.

Their principal functions include:

  • investigating complaints;
  • conducting audits;
  • issuing guidance;
  • approving Binding Corporate Rules;
  • imposing corrective measures; and
  • levying administrative fines where appropriate.

Independence is a fundamental characteristic of supervisory authorities and is essential for ensuring impartial enforcement of data protection law.

Article 4(22): Supervisory Authority Concerned

A supervisory authority concerned is a supervisory authority having a legitimate interest in a particular processing activity.

It becomes concerned where:

  • the controller or processor is established within its Member State;
  • data subjects residing in that Member State are substantially affected or are likely to be substantially affected; or
  • a complaint has been lodged before that authority.

Meaning and Scope

This definition supports the GDPR's cooperation and consistency mechanism.

Although only one authority may act as the Lead Supervisory Authority, other supervisory authorities whose residents are affected continue to participate in regulatory decision-making under Chapter VII.

Article 4(23): Cross-Border Processing

Cross-border processing refers to processing activities affecting more than one Member State.

The GDPR recognises two situations:

  • processing carried out through establishments located in multiple Member States; or
  • processing undertaken by a single establishment that substantially affects data subjects in more than one Member State.

This definition forms the basis of the One-Stop-Shop mechanism under Article 56 and the cooperation procedures contained in Chapter VII of the GDPR.

Practical Issues

Cross-border processing is not determined solely by the location of servers or databases.

Instead, organisations should examine:

  • where processing activities occur;
  • where establishments are located;
  • where affected data subjects reside; and
  • whether the processing substantially affects individuals in multiple Member States.

Article 4(24): Relevant and Reasoned Objection

A relevant and reasoned objection is an objection raised by a supervisory authority during the GDPR cooperation mechanism.

Meaning and Scope

The objection must clearly explain:

  • why the draft decision may infringe the GDPR;
  • the risks posed to the rights and freedoms of data subjects; and
  • where applicable, the potential impact on the free movement of personal data.

General disagreement or unsupported criticism is insufficient.

This definition promotes effective cooperation while preventing unnecessary regulatory disputes.

Article 4(25): Information Society Service

An information society service has the meaning assigned under Directive (EU) 2015/1535.

Meaning and Scope

Broadly, it refers to services that are:

  • normally provided for remuneration;
  • supplied at a distance;
  • delivered by electronic means; and
  • provided at the individual request of the recipient.

Examples

include:

  • online marketplaces;
  • social media platforms;
  • streaming services;
  • cloud computing services;
  • search engines; and
  • e-commerce platforms. The definition assumes particular importance under Article 8 concerning children's consent in relation to online services.

Article 4(26): International Organisation

An international organisation means an organisation governed by public international law or another body established by agreement between two or more countries.

Examples

include: -the United Nations; -the World Bank; -the International Monetary Fund; -the World Health Organization; or -other treaty-based international bodies. The definition is primarily relevant to Chapter V, which governs transfers of personal data to third countries and international organisations. Transfers to international organisations remain subject to the GDPR's transfer mechanisms unless an applicable exemption or adequacy decision exists.