Articles Flashcards

1
Q

What is the main topic for GDPR Chapter 1 Articles 1- 4?

A

General Provisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the main topic for GDPR Chapter 2 Articles 5 - 11?

A

Principles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the main topic for GDPR Chapter 3 Articles 12 - 23?

A

Rights of the data subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the main topic for GDPR Chapter 4 Articles 24 - 43?

A

Controller and processor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the main topic for GDPR Chapter 5 Articles 44 - 50?

A

Transfers of personal data to third countries or international organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the main topic for GDPR Chapter 6 Articles 51 - 59?

A

Independent supervisory authorities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the main topic for GDPR Chapter 7 Articles 60 - 76?

A

Cooperation & consistency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the main topic for GDPR Chapter 8 Articles 77 - 84?

A

Remedies, liability and penalties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the main topic for GDPR Chapter 9 Articles 85 - 91?

A

Provisions relating to specific processing situations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the main topic for GDPR Chapter 10 Articles 92 - 93?

A

Delegated acts and implementing acts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the main topic for GDPR Chapter 11 Articles 94 - 99?

A

Final provisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
  • Sets out rules about how personal data is processed
  • Protects people’s rights and freedoms in relation to personal data
  • Ensures that personal data can move freely within the EU.
A

Article 1
Subject - matter & objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
  • Applies where data is processed automatically or is part of a filing system
  • Doesn’t apply to purely domestic or personal activity
  • Doesn’t apply to certain law enforcement activities.
    Article 3 - Territorial Scope
A

Article 2
Material Scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The GDPR:

  • Applies to any data processing that takes place in the EU (no matter where the person or organization doing the processing is based)
  • Applies to anyone:
    * Offering goods or services (paid or free) in the EU, or
    * Monitoring people’s behavior in the EU
A

Article 3
Territorial scope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
  • Personal data - information that can be used to identify an individual.
  • Processing - any action taken with personal data.
  • Controller - any body or organization that decides how or why personal data is processed.
  • Processor - any body or organization that processes personal data for a controller.
  • Consent - A statement or affirmative action that shows agreement to having personal data processed. Must be freely given, specific, informed and unambiguous
A

Article 4
Definitions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

All personal data processing must adhere to six principles, which are the responsibility of the data controller:

  • Lawfulness, fairness and transparency;
  • Limitation of processing to legitimate purposes;
  • Data minimization;
    Accuracy;
  • Limitation on time period of storage;
  • Integrity and confidentiality.
A

Article 5
Principles relating to processing of personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

All personal data processing must occur under one of six lawful bases:

  • Consent;
  • Contract;
  • Legal obligation;
  • Vital interests;
  • Public task;
  • Legitimate interests.
A

Article 6
Lawfulness of processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Consent must be:

  • Freely given;
  • Given via a clear, affirmative act (opt-in);
  • Easy to withdraw.
A

Article 7
Conditions for consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

If you need to process the personal data of a child under the age of 16 for “information society services” and you’re relying on consent as your lawful basis for doing this, you need the consent of their parent or carer.

You also need to take reasonable steps to make sure it was actually their parent or carer that consented.

Information society service (ISS) broadly means any online service - apps, websites, games, streaming services.

A

Article 8
Conditions applicable to child’s consent in relation to information society services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Special categories of personal data include information about a person’s:
Race; Political views; Religion or beliefs; Sex life; Genetic, biometric or health data; Union membership.

You may only process special category data under very specific circumstances, including:

  • You have a person’s consent in connection with a specific purpose;
  • The person’s life is at risk;
  • You’re a not-for-profit organization and can demonstrate that it’s in your legitimate interests.
A

Article 9
Processing of special categories of personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

You can only process data about people’s criminal convictions if:

  • You’re doing so under the control of an official authority
  • You’re authorized to do so under the GDPR-compliant law of an EU Member State.
A

Article 10
Processing of personal data relating to criminal convictions and offences

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q
A

Article 11
Processing which does not require identification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q
A

Article 12
Transparent information, communication and modalities for the exercise of the rights of the data subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q
A

Article 13
Information to be provided where personal data are collected from the data subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q
A

Article 14
Information to be provided where personal data have not been obtained from the data subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q
A

Article 15
Right of access by the data subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q
A

Article 16 Right to rectification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q
A

Article 17
Right to erasure (‘right to be forgotten’)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q
A

Article 18
Right to restriction of processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q
A

Article 19
Notification obligation regarding rectification or erasure of personal data or restriction of processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q
A

Article 20
Right to data portability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Article 21

A

Right to object

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Article 22

A

Automated individual decision-making, including profiling

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Article 23

A

Restrictions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Article 24

A

Responsibility of the controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Article 25

A

Data protection by design and by default

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Article 26

A

Joint controllers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Article 27

A

Representatives of controllers or processors not established in the Union

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Article 28

A

Processor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

Article 29

A

Processing under the authority of the controller or processor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Article 30

A

Records of processing activities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

Article 31

A

Cooperation with the supervisory authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

Article 32

A

Security of processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

Article 33

A

Notification of a personal data breach to the supervisory authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

Article 34

A

Communication of a personal data breach to the data subject

46
Q

Article 35

A

Data protection mpact assessment

47
Q

Article 36

A

Prior consultation

48
Q

Article 37

A

Designation of the data protection officer

49
Q

Article 38

A

Position of the data protection officer

50
Q

Article 39

A

Tasks of the data protection officer

51
Q

Article 40

A

Codes of conduct

52
Q

Article 41

A

Monitoring of approved codes of conduct

53
Q

Article 42

A

Certification

54
Q

Article 44

A

General principle for transfers

54
Q

Article 43

A

Certification bodies

55
Q

Article 45

A

Transfers on the basis of an adequacy decision

56
Q

Article 46

A

Transfers subject to appropriate safeguards

57
Q

Article 47

A

Binding corporate rules

58
Q

Article 48

A

Transfers or disclosures not authorized by Union law

59
Q

Article 49

A

Derogations for specific situations

60
Q

Article 50

A

International cooperation for the protection of personal data

61
Q

Article 51

A

Supervisory authority

62
Q

Article 52

A

Independence

63
Q

Article 53

A

General conditions for the members of the supervisory authority

64
Q

Article 54

A

Rules on the establishment of the supervisory authority

65
Q

Article 56

A

Competence of the lead supervisory authority

66
Q

Article 55

A

Competence

67
Q

Article 57

A

Tasks

68
Q

Article 58

A

Powers

69
Q

Article 59

A

Activity reports

70
Q

Article 60

A

Cooperation between the lead supervisory authority and the other supervisory authorities concerned

71
Q

Article 61

A

Mutual assistance

72
Q

Article 62

A

Joint operations of supervisory authorities

73
Q

Article 63

A

Consistency mechanism

74
Q

Article 64

A

Opinion of the Board

75
Q

Article 65

A

Dispute resolution by the Board

76
Q

Article 66

A

Urgency procedure

77
Q

Article 67

A

Exchange of information

78
Q

Article 68

A

European Data Protection Board

79
Q

Article 69

A

Independence

80
Q

Article 70

A

Tasks of the Board

81
Q

Article 71

A

Reports

82
Q

Article 72

A

Procedure

83
Q

Article 73

A

Chair

84
Q

Article 74

A

Tasks of the Chair

85
Q

Article 75

A

Secretariat

86
Q

Article 78

A

Right to an effective judicial remedy against a supervisory authority

87
Q

Article 76

A

Confidentiality

88
Q

Article 77

A

Right to lodge a complaint with a supervisory authority

89
Q

Article 79

A

Right to an effective judicial remedy against a controller or processor

90
Q

Article 80

A

Representation of data subjects

91
Q

Article 81

A

Suspension of proceedings

92
Q

Article 82

A

Right to compensation and liability

93
Q

Article 83

A

General conditions for imposing administrative fines

94
Q

Article 84

A

Penalties

95
Q

Article 85

A

Processing and freedom of expression and information

96
Q

Article 86

A

Processing and public access to official documents

97
Q

Article 87

A

Processing of the national identification number

98
Q

Article 88

A

Processing in the context of employment

99
Q

Article 89

A

Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes

100
Q

Article 90

A

Obligations of secrecy

101
Q

Article 91

A

Existing data protection rules of churches and religious associations

102
Q

Article 92

A

Exercise of the delegation

103
Q

Article 93

A

Committee procedure

104
Q

Article 94

A

Repeal of Directive 95/46/EC

105
Q

Article 95

A

Relationship with Directive 2002/58/EC

106
Q

Article 96

A

Relationship with previously concluded Agreements

107
Q

Article 97

A

Commission reports

108
Q

Article 98

A

Review of other Union legal acts on data protection

109
Q

Article 99

A

Entry into force and application