The processing of personal data in Europe is governed by the General Data Protection Regulation (GDPR¹). The GDPR applies to any private or public organisation that collects and/or processes data, regardless of its sector or size. It applies to all organisations established within the European Union, as well as to any organisation based outside the EU whose activities directly target EU residents.
Cultural venues are therefore fully subject to this regulation.
What is personal data?
According to the CNIL (France's data protection authority), personal data is defined as "any information relating to an identified or identifiable natural person."
There are two types of identification:
- Direct identification (name, surname, etc.)
- Indirect identification (ID number, code, etc.)
What is personal data processing?
Any operation or set of operations performed on personal data is considered personal data processing. The CNIL gives the following examples of data processing activities:
- Maintaining a customer database
- Collecting contact details from prospects via a questionnaire
- Updating a supplier file
1 Règlement (UE) 2016/679 du Parlement européen et du Conseil du 27 avril 2016, relatif à la protection des personnes physiques à l'égard du traitement des données à caractère personnel et à la libre circulation de ces données, et abrogeant la directive 95/46/CE (règlement général sur la protection des données).