Article 4 GDPR lists 26 definitions. A working practitioner reaches for maybe eight of them every week. Memorising these eight, in their operational meaning, saves you from the most common misreadings.
Personal data (Art 4(1))
Any information relating to an identified or identifiable natural person. Two elements: (a) it must be information about a natural person (not a legal person, not a machine), and (b) that person must be identified or identifiable. Identifiability is a wide test: identifiable directly (name, government ID) or indirectly (device fingerprint, cookie, browsing pattern, IP address, wallet address). CJEU IAB Europe (C-604/22) [L4-C1] confirmed that pseudonymous identifiers are personal data where re-identification is reasonably likely.
Processing (Art 4(2))
Any operation performed on personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure, or destruction. The word "processing" catches almost everything you can do to data. Storing a customer email in your CRM is processing. Reading it a year later is processing. Deleting it is processing.
Controller (Art 4(7))
The natural or legal person which, alone or jointly with others, determines the purposes and means of the processing. Determination is factual, not contractual. Whoever decides why the processing is happening and, at the essential level, how, is the controller. EDPB Guidelines 07/2020 is the operational reading.
Processor (Art 4(8))
A natural or legal person which processes personal data on behalf of the controller. A processor does not determine purposes; it acts on the controller\'s documented instructions. Most Indian IT services engagements make the Indian IT firm a processor of the EU client controller.
Pseudonymisation (Art 4(5))
The processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures. Pseudonymised data remains personal data (Recital 26); it is not anonymous. Practical use: pseudonymisation is a security measure and a transfer-risk mitigation, not an escape from GDPR.
Third country (implied through Chapter V)
A country outside the EEA (EU plus Iceland, Norway, Liechtenstein). India is a third country under GDPR. Transfers from EU to India require compliance with Chapter V (adequacy, or Article 46 mechanism, or Article 49 derogation).
Cross-border transfer (Chapter V)
The Regulation does not define "transfer" explicitly, but EDPB Guidelines 05/2021 on the interplay between the territorial scope and international transfers offer the three-cumulative-criterion test: (i) the exporter is a controller or processor subject to GDPR for the given processing; (ii) the exporter transmits or otherwise makes the personal data available to the importer; (iii) the importer is in a third country or is an international organisation. All three must be present for a Chapter V transfer analysis to apply. Note: an Indian entity accessing EU personal data from India (rather than the data being moved to India) can still trigger a Chapter V analysis if the exporter is EU-based and the importer (you) is in a third country.
Data subject (Art 4(1))
The identified or identifiable natural person to whom the personal data relates. In DPDP the equivalent term is Data Principal (Section 2). The rights held by a data subject under GDPR Chapter III largely map to the rights held by a Data Principal under DPDP Section 11-14, with the DPDP Section 13 nomination right having no direct GDPR counterpart.
Recipient (Art 4(9))
A natural or legal person to whom the personal data are disclosed, whether a third party or not. Includes processors, joint controllers, and any other party you disclose to. The Article 30 ROPA obligation requires you to list categories of recipients per processing activity.
Why definitions matter
Almost every misreading of GDPR by a first-time practitioner starts with a definition confusion. Treating pseudonymous data as anonymous. Treating a controller-processor as a joint controller. Missing that Article 3(2) makes "third country" the wrong lens (because a non-EU processor is directly caught, not just receiving a transfer). Memorise Article 4 the way a securities lawyer memorises the SEBI Act definitions.