Data protection concepts Flashcards
4 building blocks of the term “Personal data” are:
- Any information
- Relating to
- An identified or identifiable
- Natural person
What are the aspects of term “information”?
- Nature (objective/subjective)
- Content (any sort of information)
- Format (any form)
What are the elements of term “relating to”?
- Content (information is about person)
- Purpose (to evaluate/consider/analyze)
- result (impact on rights/interests)
Sensitive personal data is data about:
- racial or ethnic
- political
- religious/philosophical
- trade union membership
- genetic data
- biometric for purpose uniq identifying
- regarding health
- sex life/orientation
What are the 5 building blocks of concept Controller
- Natural or legal person, public authority, agency or other body
- Determines
- Alone or jointly with others
- The purpose and means
- of the processing of PD
Example when Controller has no contact with PD but still remains controller
Ordering Marketing research with specific parameters.
Converging decision as per Guidelines is
Decision of joint controllers, which complement each other, necessary for processing and have tangible impact on determination of purpose and means
Case example of joint controllership
Fashion ID + Facebook like button
What are the 2 building blocks of concept Data processor
- Separate legal entity from Controller
- Processes PD on behalf of Controller
Example when entity can be processor and controller simultaneously
Pay role provider processes PD to administer benefits, but it also can use same data of key management for procurement purposes
Which GDPR article sets the requirement for processing agreement?
28
requirements as per art 28 for processing agreement:
- processing only on instructions
- persons processing data are bound with confidentiality
- Take all security measures as per art. 32
- Assist Controller to execute data subject rights
- Assist Controller to comply with security, DPIA, breach notif.
Art.32-36 - At Controller`s choice delete o return PD
- Help Controller to demonstrate compliance w Art 28 (audit, insp)
What are the building blocks of concept Processing?
- Any operation or sets of operations
- performed on PD or sets of PD
such as:
- Collection
- recording
- organization
- structuring
- storage
- adaptation
- retrieval
- consultation
- use
- disclosure
- alignment
- erasure
- destruction
As per territorial scope, GDPR applies to:
- EU-established organizations (in context of their activity)
-organization offer to sell products - services / or monitor individuals in EU
name guidelines detailing territorial scope
EDPB Guidelines 3/2018