Chapter 9: International Laws Flashcards
What is the definition of jurisdiction?
The jurisdiction is the land and people subject to a specific court or courts.
When took the General Data Protection Regulation (GDPR) legal effect?
In 2018.
What is the scope of GDPR?
The scope of GDPR is notable for its breadth. The GDPR aims to protect all personal data for everyone in the EU by regulating any entity that handles the data.
GDPR: what is the definition of Personal Data?
Personal Data includes any information that identifies an individual.
Examples include:
- names
- IP addresses
- geolocation information
- as well as any characteristics of a person that might be used individually or in combination to identify that person.
The GDPR refers to individuals protected by the law as natural persons or data subjects. Importantly, the GDPR does not restrict its scope to citizens of EU member states.
GDPR: What is the data controller?
Data Controller
A data controller is usually the entity that ultimately is in charge of the data.
The GDPR says that a controller “… determines the purposes and means of the processing of personal data…”
GDPR: What is the data processor?
Data Processor
A data processor is any other entity that handles personal data for the controller.
For example, a retailer may hire a digital marketing firm to help it increase online sales with better website analytics. In this case, the retailer would be the controller and the marketing firm would be the processor. Under GDPR, both controllers and processors have obligations and liabilities.
With this framework, the GDPR aims to protect data even as it changes hands.
Does the GDPR restrict its scope to only citizens of EU member states?
The GDPR refers to individuals protected by the law as natural persons or data subjects. Importantly, the GDPR does not restrict its scope to citizens of EU member states.
Does GDPR allow the transfer of data to non-eu countries?
GDPR prohibits the transfer of data to non-EU countries unless the recipient offers the same privacy protections as the EU.
GDPR: What are avenues to transfer data to non-EU countries?
GDPR offers a few avenues for approving data transfers outside the EU.
For example, EU authorities decide in advance that a non-EU country has adequate data privacy protections in place to allow data transfers to take place.
This is known as an adequacy decision. Mechanisms to facilitate data transfer between the United States and the EU are in flux, but they include the:
- EU-U.S. Privacy Shield program
- Binding Corporate Rules
- and Standard Contractual Clauses
GDPR: What do all data processors and data controllers need to provide?
- transparent notice to customers explaining what data is collected
- and how data is used
- and information about any third-parties with whom data may be shared.
GDPR: What are the requirements for consent according to GDPR?
Consent must be meaningful, and controllers must be able to show that they have obtained consent.
GDPR requires that written consent must be
- “clearly distinguishable from other matters,
- easy to understand
- accessible
This means that a consent clause may not be buried in some long and obtuse end user agreement.
Data subjects may also retract their consent whenever they like.
GDPR: Explain the right to erasure?
The right to be forgotten means, quite simply, that EU data subjects have the right to ask data controllers to erase all of their personal data.
A request for erasure may be made in a number of circumstances, including when a data subject withdraws consent. In such cases, controllers are required to erase the personal data in question “without undue delay.”
GDPR: What is the simplest mechanism to allow international data transfer to and from the EU?
Probably the smoothest and simplest mechanism to allow international data transfers to and from the EU is via an adequacy decision.
An adequacy decision occurs when the Eu reviews the privacy laws of another nation and decides those laws are adequate to protect EU data subject’s privacy at a level commensurate with the provisions of the GDPR.
The European Commission is empowered to make adequacy decisions under the GDPR. Once such a decision is made, international data transfers may occur to and from the EU and the other country without the need of any further legal approval,.
An adequacy decision allows the EU to treat a company from another country virtually just like a European Country. The EU has only made adequacy decisions in favor of a handful of nations so far, including:
GDPR: Can Data Subjects under GDPR pursue damages for any harm vaused by a violation of GDPR?
Yes.
Data subjects may also pursue damages for any harm caused by a violation of GDPR.
GDPR: Penalties and Fines: How high can the fines go?
Penalties for violating the GDPR can be very steep. Depending on which provision of GDPR is violated and whether the violation was intentional or negligent, administrative penalties for infringements may reach up to 20,000,000€ or 4% of a company’s annual revenue, whichever is greater.