Definitions
Article 2
For the purposes of this Decision, the definitions contained in Regulation (EU) No 1024/2013 and Regulation (EU) No 468/2014 (ECB/2014/17) shall apply, unless otherwise provided for, together with the following definitions: (1) ‘processing’ means processing as defined in Article 3, point (3), of Regulation (EU) 2018/1725 or Article 4, point (2), of Regulation (EU) 2016/679; (2) ‘personal data’ means personal data as defined in Article 3, point (1), of Regulation (EU) 2018/1725 or Article 4, point (1), of Regulation (EU) 2016/679; (3) ‘national competent authority’ (NCA) means a national competent authority as defined in Article 2, point (9), of Regulation (EU) No 468/2014 (ECB/2014/17); (4) ‘supervisory task’ means a task conferred on the ECB under Article 4(1) and (2) and carried out within the framework of Article 6 of Regulation (EU) No 1024/2013; (5) ‘controller’ means a controller as defined in Article 3, point (8), of Regulation (EU) 2018/1725 or Article 4, point (7), of Regulation (EU) 2016/679; (6) ‘joint controller’ means a joint controller within the meaning of Article 28(1) of Regulation (EU) 2018/1725 or Article 26(1) of Regulation (EU) 2016/679; (7) ‘processor’ means a processor as defined in Article 3, point (12), of Regulation (EU) 2018/1725 or Article 4, point (8), of Regulation (EU) 2016/679; (8) ‘Union institutions and bodies’ means Union institutions and bodies as defined in Article 3, point (10), of Regulation (EU) 2018/1725; (9) ‘data protection notice’ means a document whereby data subjects are provided with information in accordance with Articles 15 or 16 of Regulation (EU) 2018/1725 or Articles 13 or 14 of Regulation (EU) 2016/679; (10) ‘data subject request’ means a request addressed by a data subject to one or more of the joint controllers whereby the data subject exercises any of their rights under Chapter III of Regulation (EU) 2018/1725 or Chapter III of Regulation (EU) 2016/679; (11) ‘personal data breach’ means a personal data breach as defined in Article 3, point (16), of Regulation (EU) 2018/1725 or Article 4, point (12), of Regulation (EU) 2016/679; (12) ‘supervisory authority’ means a national supervisory authority as defined in Article 3, point (22), of Regulation (EU) 2018/1725, a supervisory authority as defined in Article 4, point (21), of Regulation (EU) 2016/679, or the European Data Protection Supervisor; (13) ‘home Member State’ means the Member State in which a credit institution has been granted authorisation; (14) ‘host Member State’ means the Member State in which a credit institution has a branch or in which it provides services.