Accountability (10) Flashcards
What does accountability mean?
The ability to demonstrate that a data protection program has been implemented and run in compliance with the law.
What is the responsibility of the controller?
Article 24: Responsibiity of the Controller
implement appropriate technical and organizational measures to ensure and be able to demonstrate that processing is in accordance with GDPR
What instruments are used to practice accountability?
Data protection by design/default
DPIAs
ROPAs
DPO
What in general is requireed by Article 25: data protection by design and data protection by default?
- implement technical and organizational measures and integrate necessary safeguards
- minimum and limited personal data use and maximum security settings are the default
When should the SA be consulted for a DPIA?
prior to processing commencing processing
(if DPIA indicates high risk)
What are best practices for designing a data protection policy?
GDPR does not specify required contents.
- Language - that speaks to recipients
- Contents - what to do, what not to do and consequences, principles
- Goals - how metrics will demonstrate results, ensure tasks are achievable, realistic, relevant, timely
When is an organization required to maintain records of processing activities?
if the organization has 250 employees or more –> always
if the organization has less than 250 employees, when processing:
- likely to result in risks to rights and freedoms of data subjects
- not occasional
- special category data or criminal convictions
What 7 pieces of information must be in controller records?
Article 30
1) name and contact of controller and DPO
2) purposes
3) categories of data subjects and personal data
4) technical and organizational security measures
5) recipients
6) international data transfers and safeguards
7) time limits for erasure
What 4 pieces of information must processor records contain?
Article 30
1) name and contact info of processor and controller
2) categories of processing
3) international data transfers and safeguards
4) technical and organizational security measures
What are 4 elements required in controller records that are NOT required in processor records?
1) purpose of processing
2) categories of data subjects and personal data
3) recipients
4) time limits for erasure
decisions that a controller makes: determines means and purpose
Can a DPO be external to the organization?
Yes
can be internal staff or externally contracted
When is a DPO legally required?
When the core activities of the controller include:
- regular and systematic monitoring on a large scale
- processing sensitive data on a large scale
- processing by public bodies, other than courts acting in judicial capacity
What are the major tasks and responsibilities of the DPO?
monitor compliance with GDPR, and other data protection laws
inform and advise controllers, processors and employees
manage risk
cooperate with SA
communicate with data subjects and SA
exercise professional secrecy
Is the DPO responsible or legally liable for compliance?
No
What are controller and processor obligations to the DPO?
- communicate
- provide access to personal data and processing
- provide resources
- enable DPO to perform independently
- report to highest level of management
Who is responsible for data protection by design and default?
controllers or processors?
controllers
Who is responsible for DPIAs?
controllers or processors?
controllers
(processors have duty to assist)