General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR): the EU law on personal data - legal basis, minimisation, breach duties for identity and trust services.
The General Data Protection Regulation (Regulation (EU) 2016/679; in Dutch: AVG) is the EU regulation on the protection of personal data. It has applied since 25 May 2018 across the European Union - the European Economic Area followed through incorporation into the EEA Agreement on 20 July 2018 - and it also applies to controllers and processors outside the Union that offer goods or services to, or monitor the behaviour of, people in the Union. It requires a legal basis for every processing, gives data subjects rights (access, rectification, erasure, objection, restriction of processing, and data portability), and demands privacy by design, security of processing, and notification of personal data breaches that are likely to result in a risk to the rights and freedoms of data subjects to the supervisory authority within 72 hours of becoming aware, where feasible. High-risk processing, such as large-scale biometric identity verification, also triggers a data protection impact assessment (DPIA) under Article 35, and some organisations must appoint a data protection officer (DPO). The regulation distinguishes controllers from processors, requires a processor agreement under Article 28 when a processor is engaged, and imposes additional safeguards under Chapter V for transfers of personal data outside the EEA. In the Netherlands it is supervised by the Autoriteit Persoonsgegevens and complemented by the Uitvoeringswet AVG (UAVG), which fills in national derogations and additional conditions, for example for processing special category data. The Autoriteit Persoonsgegevens can impose fines of up to EUR 20 million or 4 percent of global annual turnover for the most serious infringements, and up to EUR 10 million or 2 percent for others, whichever is higher in each tier.
For identity and trust services the GDPR is ever-present: identity verification processes passport data and, when used for unique identification, biometric data, which is special category data under the GDPR; certificates contain personal data; and wallet ecosystems such as the EUDI Wallet are built around data minimisation - which is exactly what selective disclosure of attestations delivers. eIDAS 2 adds wallet-specific privacy safeguards, such as requiring wallet providers to keep personal data relating to the provision of the wallet logically separate from any other data they hold, and prohibiting wallet providers from profiling usage data, though the technical detail is still being filled in through implementing acts.