5 BRIEF OVERVIEW ON GDPR COMPLIANCE
This section outlines the essential GDPR components to be considered for the TIPS4PED project. Reading
this section is highly recommended for all partners, as it highlights key concepts that can help avoid potential
data issues during project development.
This section is intended to ensure that all stakeholders understand the importance of GDPR compliance in
the context of the KPI evaluation and definition. Understanding the implications of GDPR is crucial for defining
and measuring the KPIs without inadvertently violating data protection laws. Ultimately, this GDPR section
clarifies the responsible handling of personal data within the KPIs, demonstrating TIPS4PED commitment to
transparency and accountability while aligning our objectives with legal requirements.
Below are the essential elements of the regulation.
a) The legal framework governing data protection in every EU member state: REGULATION (EU)
2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL is the General Data
Protection Regulation (GDPR).
b) In general, take care not to disclose any personal data, which is defined as any information that can
be used to identify or uniquely identify a natural person, such as their name, identification number,
location, online identifier, or any combination of characteristics unique to their physical, physiological,
genetic, mental, cultural, or social identity, including their IP address.
c) In this sense, under GDPR, TIPS4PED is obliged to ensure that personal data shall be:
• Processed lawfully, fairly and in a transparent manner in relation to the data subject
• Collected for specified, explicit and legitimate purposes and not further processed in a
manner that is incompatible with those purposes
• Adequate, relevant and limited to what is necessary to the purposes
• Accurate and, where necessary, kept up to date
• Kept for no longer than is necessary
• Processed in a manner that ensures appropriate security
d) Regarding personal data, TIPS4PED digital twinning works will be mainly focused on building data
and weather data, which allows a sufficient degree of anonymisation and aggregation of personal
data (if any) to avoid a potential identification of a natural person. This must be ensured for any data
collection and data processing task within TIPS4PED.
e) In case there is a need for processing any personal data within TIPS4PED, the consortium must
ensure:
• The consent has been provided