GDPR

The General Data Protection Regulation (GDPR) is the European Union's primary data protection law. It establishes rules for the collection, use, storage, and other processing of personal data and protects the privacy rights of individuals in the European Union (EU) and the European Economic Area (EEA). GDPR came into effect on May 25, 2018.
The General Data Protection Regulation (GDPR) is a legal framework that protects the personal data and privacy of individuals residing in the European Union (EU) and the European Economic Area (EEA).
GDPR applies to any organization, regardless of its location, that processes the personal data of individuals in the EEA. Consequently, GDPR may also apply to organizations based outside the EU and EEA, including those in the United States, where they collect, store, use, disclose, transfer, or otherwise process the personal data of individuals in the EU and/or EEA.
Personal DataAs defined in GDPR Article 4, personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Sensitive Personal DataPersonal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade- union membership; data concerning health or sex life and sexual orientation; genetic data or biometric data.
European Union (EU)The European Union is a political and economic union of 27 member states that are located primarily in Europe.
European Economic Area (EEA)The European Economic Area (EEA), which was established via the EEA Agreement in 1992, is an international agreement which enables the extension of the European Union (EU)'s single market to non-EU member parties.
Data SubjectsUnder GDPR, a data subject is any person (residing in the European Union, irrespective of nationality) whose personal data is being collected, held or processed.
Data ProcessingAny operation or set of operations performed upon personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
ControllerThe data controller is a person or company that determines the purposes for which and the means by which personal data is processed.
ProcessorThe data processor is a person or company which processes personal data only on behalf of the controller. The data processor is usually a third party external to the company.

 

The General Data Protection Regulation (GDPR) is a comprehensive data protection law consisting of 11 chapters and 99 articles. It establishes requirements for organizations that collect, use, store, or otherwise process the personal data of individuals in the European Union (EU) and European Economic Area (EEA).

To comply with GDPR, organizations are expected to:

  • Identify and document a valid legal basis for collecting and processing personal data.
  • Limit the collection and use of personal data to what is necessary for a specific and legitimate purpose.
  • Implement appropriate technical and organizational safeguards to protect personal data.
  • Assess privacy risks associated with data processing activities and take steps to mitigate those risks.
  • Maintain procedures for detecting, reporting, and responding to personal data breaches, including notifying the appropriate supervisory authority when required.

The George Washington University is committed to complying with GDPR requirements through its Privacy of Personal Information Policy, Statement of Privacy Practices , and website cookie consent mechanisms.

GDPR grants individuals in the European Union (EU) and European Economic Area (EEA) a number of rights regarding how their personal data is collected, used, shared, and otherwise processed by organizations. These rights are intended to provide individuals with greater transparency and control over their personal information.

Under GDPR, individuals have the right to:

  • Request access to the personal data an organization holds about them.
  • Receive information about why and how their personal data is being processed, including the categories of personal data involved.
  • Request correction of inaccurate or incomplete personal data.
  • Be informed of the period for which their personal data will be retained, or the criteria used to determine that period.
  • Request the deletion of their personal data in certain circumstances (commonly referred to as the "right to erasure" or "right to be forgotten").
  • Object to or restrict certain types of processing, where permitted by GDPR.
  • Receive their personal data in a structured, commonly used format and, where applicable, request that it be transferred to another organization (the right to data portability).

These rights are subject to certain conditions, limitations, and exceptions under GDPR and other applicable laws.

Exercise your privacy rights

GDPR training is available to staff and faculty in Talent@GW

Online Training

Training links below:

GDPR guidance for Researchers:

For additional information or training, %20privacyatgwu [dot] edu (contact the GW Privacy Office).

Resources