Ch. 6 GDPR Principles Flashcards
Lawfulness
personal data must only be processed when data controllers have a legal ground for processing the data
Fairness
DS must be aware their data will be processed, how this is done, with what purposes, allowing them to make informed decisions. Also requires an assessment on how the processing will affect the data subject.
Transparency + exceptions
Processing must be open and clear towards DS, in a timely manner.
Exceptions:
- When providing the information will involve a disproportionate effort or can be considered impossible
- To protect the data subject’s legitimate interest, in which case, the disclosure is expressly governed by the applicable law
- To preserve the confidentiality of the information, also regulated by the laws to which the data controller is subject
Purpose limitation
Data controllers must only collect and process personal data to accomplish specified, explicit and legitimate purposes and not process personal data beyond such purposes unless the further processing is considered compatible with the purposes for which the personal data was originally collected
Compatibility test:
Factors to take into account, and if the are met no additional legal basis is required for further processing:
- Any link between those purposes and the purposes of the intended further processing
- The context in which the personal data has been collected, in particular the reasonable expectations of data subjects based on their relationship with the controller as to their further use
- The nature of the personal data
- The consequences of the intended further processing for data subjects
- The existence of appropriate safeguards in both the original and intended further processing operations’
Data minimization
data controllers must only collect and process personal data that is relevant, necessary and adequate to accomplish the purposes for which it is processed
Data accuracy
Controllers must take reasonable measures to ensure the data is accurate and, where necessary, kept up to date.