Data Protection Concepts Flashcards
Is online identifiers, such as IP addresses and cookies, personal data?
Yes. GDPR expressly states that online identifiers are personal data in the definition of personal data in art. 4 (1).
What does the concept of personal data include?
All information concerning an identifiable individual. The concept is widely interpreted and is not limited to information about the individual’a privat and family life.
What are the four building blocks that compromise the meaning of personal data?
Within Opinion 4/2007, WP29 sets these four building blocks: 1) Any information, 2) Relating to, 3) An identified of identifiable. 4) Natural person.
Does information have to be true to be personal data?
No, information does not have to be true to be considered personal data.
Can a subjective statement, such as “the employee is a good worker and merits promotion” be considered personal data?
Yes, both objective and subjective statements may be considered personal daa.
Is information in any form included in the concept of personal data?
No. The Regulation expressly applies to information processed by automated means and manual means when this is part of a filing system.
Which elements does the WP29 in Opinion 4/2007 consider in regards to when information is relating to an individual?
One or more of the three elements must apply for the information to be relating to an individual: the content element, the purpose element or the result element.
When is the individual identifiable?
When it is possible to identify the person either directly or indirectly. The person does not have to be identified yet.
What is the threshold for the possibility of identification?
There must be a reasonable likelihood. The factors to consider is, cost of and the amount of time required for identification and the available technology at the time of the processing and technological developments. See Recital 26.
What is the definition of ‘natural person’?
The Regulation does not define the concept of natural person, but leaves it up to member states. However, Recital 27 states that personal data of deceased persons is not included.
Why does the Regulation identify certain types of personal data as special categories/sensitive personal data?
The nature of the information needs special protection as the processing of the information could create significant risks to individuals’ fundamental rights and freedoms.
What is defined as being sensitive personal data?
- Racial or ethnic origins
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- Biometric dta
- Health data
- Sexlife or sexual orientation data
When will a photograph be sensitive personal data?
Photographs aren’t always sensitive personal data, as they are only covered by the definition of biometric data, when processed by specific technical means allowing the identification or authentication of a natural person (recital 51)
The regulation doesn’t address where a photography shows racial origin, religious beliefs or certain physical disabilities (health data) .
What is the definition of a data controller?
- The natural or legal person, public authority, agency or any other body
- Which alone or jointly
- Determines the purpose and means of the processing of personal data.
What is the definition of a data processor?
- A person, other than an employee of the controller
- Who process on behalf of a controller.