Data Protection Concepts
Territorial and Material Scope of the General Data Protection Regulation
Data Processing Principles
Lawful Processing Criteria
Information Provision Obligations
- Transparency principle 
- Privacy notices 
- Layered notices 
Data Subjects’ Rights
- Access 
- Rectification 
- Erasure and the right to be forgotten (RTBF) 
- Restriction and objection 
- Consent, including right of withdrawal 
- Automated decision making, including profiling 
- Data portability 
- Restrictions 
Security of Personal Data
Accountability Requirements
- Responsibility of controllers and processors 
- Data protection by design and by default 
- Documentation and cooperation with regulators 
- Data protection impact assessment (DPIA) 
- Mandatory data protection officers 
- Auditing of privacy programs 
International Data Transfers
- Rationale for prohibition 
- Adequate jurisdictions 
- Safe Harbor and Privacy Shield 
- Standard Contractual Clauses 
- Binding Corporate Rules (BCRs) 
- Codes of Conduct and Certifications 
- Derogations a. Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 
- Transfer impact assessments (TIAs) 
Supervision and enforcement
- Supervisory authorities and their powers 
- The European Data Protection Board 
- Role of the European Data Protection Supervisor (EDPS) 
Consequences for GDPR violations