GDPR
| Personal Data | As defined in GDPR Article 4, personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. |
| Sensitive Personal Data | Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade- union membership; data concerning health or sex life and sexual orientation; genetic data or biometric data. |
| European Union (EU) | The European Union is a political and economic union of 27 member states that are located primarily in Europe. |
| European Economic Area (EEA) | The European Economic Area (EEA), which was established via the EEA Agreement in 1992, is an international agreement which enables the extension of the European Union (EU)'s single market to non-EU member parties. |
| Data Subjects | Under GDPR, a data subject is any person (residing in the European Union, irrespective of nationality) whose personal data is being collected, held or processed. |
| Data Processing | Any operation or set of operations performed upon personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. |
| Controller | The data controller is a person or company that determines the purposes for which and the means by which personal data is processed. |
| Processor | The data processor is a person or company which processes personal data only on behalf of the controller. The data processor is usually a third party external to the company. |
The General Data Protection Regulation (GDPR) is a comprehensive data protection law consisting of 11 chapters and 99 articles. It establishes requirements for organizations that collect, use, store, or otherwise process the personal data of individuals in the European Union (EU) and European Economic Area (EEA).
To comply with GDPR, organizations are expected to:
- Identify and document a valid legal basis for collecting and processing personal data.
- Limit the collection and use of personal data to what is necessary for a specific and legitimate purpose.
- Implement appropriate technical and organizational safeguards to protect personal data.
- Assess privacy risks associated with data processing activities and take steps to mitigate those risks.
- Maintain procedures for detecting, reporting, and responding to personal data breaches, including notifying the appropriate supervisory authority when required.
The George Washington University is committed to complying with GDPR requirements through its Privacy of Personal Information Policy, Statement of Privacy Practices , and website cookie consent mechanisms.
GDPR grants individuals in the European Union (EU) and European Economic Area (EEA) a number of rights regarding how their personal data is collected, used, shared, and otherwise processed by organizations. These rights are intended to provide individuals with greater transparency and control over their personal information.
Under GDPR, individuals have the right to:
- Request access to the personal data an organization holds about them.
- Receive information about why and how their personal data is being processed, including the categories of personal data involved.
- Request correction of inaccurate or incomplete personal data.
- Be informed of the period for which their personal data will be retained, or the criteria used to determine that period.
- Request the deletion of their personal data in certain circumstances (commonly referred to as the "right to erasure" or "right to be forgotten").
- Object to or restrict certain types of processing, where permitted by GDPR.
- Receive their personal data in a structured, commonly used format and, where applicable, request that it be transferred to another organization (the right to data portability).
These rights are subject to certain conditions, limitations, and exceptions under GDPR and other applicable laws.
GDPR training is available to staff and faculty in Talent@GW
Online Training
Training links below:
GDPR guidance for Researchers:
For additional information or training, %20privacy
gwu [dot] edu (contact the GW Privacy Office).