Chapter 2F: Data Subject Rights Flashcards

1
Q

What must data controllers implement to verify the identity of data subjects making data subject rights requests under the GDPR?

A

Verification requirements that are reasonable and proportionate, while being limited to the minimum necessary to verify data subject identity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False: Only a data subject may exercise his or her right to access under Article 15 of the GDPR.

A

False. An authorized representative may also make a request for access (e.g., an attorney)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Other than requesting that inaccurate data be corrected, what other right do data subjects possess under Article 16 of the GDPR?

A

The right to request that incomplete information be made complete.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

True or False: The right to request information under Article 15 of the GDPR is limited to what information is processed and the reasons for processing.

A

False. There are at least eight required disclosures that must be made under Article 15, including the source of the information and the period of retention, among other disclosures.

  • the purposes of the processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  • the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
  • the right to lodge a complaint with a supervisory authority;
  • where the personal data are not collected from the data subject, any available information as to their source;
  • the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

In what two situations is a request to restrict processing under Article 18 only temporary?

A

(1) When the accuracy of the data is also contested; and
(2) When the data subject has objected to the processing under Article 21.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

If personal data is no longer necessary for the purposes for which it was collected, may a data subject request that it be erased?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What period of time does the GDPR provide for data controllers to respond to data subject requests?

A

A response must be provided “without undue delay” and no later than one month after the request is received, with some limited exceptions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

When providing a second copy of personal information processed by an organization under Article 15 of the GDPR, what may a data controller do that it generally is not permitted to do in responding to other data subject requests?

A

Charge a cost-based fee for providing a copy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

True or False: The right to erasure is always available to data subjects under the GDPR.

A

False. The right to erasure applies only in limited situations.

controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:

the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;

the data subject withdraws consent on which the processing is based according to point (a) ofArticle 6(1), or point (a) ofArticle 9(2), and where there is no other legal ground for the processing;

the data subject objects to the processing pursuant toArticle 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant toArticle 21(2);

the personal data have been unlawfully processed;

the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;

the personal data have been collected in relation to the offer of information society services referred to inArticle 8(1).?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

May a data controller charge a data subject for responding to a data subject request under the GDPR?

A

Yes, but only if the request is unfounded, excessive, or repetitive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What three requirements are necessary for the right to data portability to apply under the GDPR?

A

(1) The data was provided directly by the data subject;
(2) The data is processed based upon the data subject’s consent and for no other reason; and
(3) The processing is carried out by automated means.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What obligation does Article 12 of the GDPR impose on data controllers?

A

The obligation to facilitate the exercise of data subject rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What two data subject rights might serve as a basis to request delisting from a search engine?

A

The right to object to data processing and the right to erasure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

True or False: A key part of responding to a DSAR is determining “why” the data subject is making his or her access request.

A

False. A controller should not consider “why” the request is made, only “what” the data subject is requesting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What two requirements are necessary for the right not to be subject to automated processing to apply under the GDPR?

A

(1) The decision-making is based solely on automated processing; and
(2) The processing “produces legal effects concerning him or her or similarly significantly affects him or her.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Does the right to request delisting from a search engine apply to search results, the underlying web pages contained in search results, or both?

A

Only the search engine results.

17
Q

True or False: When a data subject requests that data be corrected, the determination of whether the data is inaccurate is subjective in nature.

A

True. There is no definition of what constitutes “inaccurate” information under the GDPR.

18
Q

True or False: The right to object to data processing is the same as the right to withdraw consent to processing.

A

False. The right to object to data processing is provided to data subjects when processing is NOT based on the consent of the individual.

19
Q

According to the EDPB, what are the three components of the Right to Access?

A

(1) confirmation as to whether data about the person is processed or not;
(2) access to this personal data; and
(3) access to information about the processing.

20
Q

True or False: Information provided in response to a request to access personal data under the GDPR must be provided in a commonly used electronic form.

A

Yes, if it is requested that way by the data subject.

21
Q

If it is not clear whether personal data is accurate, what is a best practice in responding to a data subject request to correct that data?

A

The data should be corrected as requested.

22
Q

What data subject right under the GDPR was not provided for under its precursor, the Data Protection Directive?

A

The right to data portability.

23
Q

Are data controllers obligated to notify data processors that have personal data in their possession of a request of erasure under Article 17 of the GDPR?

A

Yes

24
Q

What right under the GDPR is often a prelude to further legal action by a data subject?

A

The right to access information under Article 15.

25
Q

What are the three situations in which controllers may utilize automated decision-making that has a legal effect on data subjects?

A

When doing so is:
(1) necessary to enter a contract;
(2) otherwise required by law; or
(3) done with explicit consent of the data subject.

26
Q

A controller must stop processing in all instances when a data subject objects to data processing for conducted for what purpose?

A

Marketing

27
Q

True or False: Controllers engaged in profiling data subjects under Article 22 must set up systems that permit the intervention of a human.

A

True

28
Q

What are the circumstances in which a member state of the European Union may restrict data subject rights under the GDPR by passing legislation?

A

Where doing so is necessary to safeguard the security of the nation or its public, to facilitate law enforcement, to facilitate public government functions, to protect judicial independence, to regulate certain professions, to protect the rights of other data subjects, or to permit the enforcement of civil claims.

29
Q

True or False: In exercising the right to data portability under the GDPR, a data subject may request that information be provided directly to himself or herself, or to another data controller.

A

True

30
Q

Art. 15

A

Right to Access by a DS

31
Q

Art. 16

A

Right to rectification (Correction)
(and make complete)

32
Q

Art. 17

A

Right to Erasure (Right to be forgotten)

33
Q

Art. 18

A

Right to restriction of processing

34
Q

Art. 19

A

Notification obligation regarding
rectification
errasure
restriction

to recipients of data

35
Q

Art. 20

A

Right to data portability

36
Q

Art. 21

A

Right to Object