Datafication 2 Flashcards
Art. 1 Subject Matter & Objective
Protecting np…
(1) …regarding processing of pd
(2) … fundamental rights
(3) Free movement of data in EU
Art. 2 (1) Material Scope: When applies GDPR?
(1) processing of pd
- wholly or partly by automated means &
- forms part or intends filing system (= any structured set of pd accessible according to specific criteria)
Art. 2 (2) Material Scope: When applies GDPR? – exceptions
- activity outside scope of Union law
- Member States carrying out common foreign & security policy (security law) activity
- natural person in purely personal / household activity (-> refers to activity of dc & processor, not ds)
- competent authorities: criminal offences / penalties
Art. 3 Territorial scope: Where applies GDPR?
processing of personal data:
(1) activities of establishment of dc / processor in EU (processing doesn’t have to be in EU)
(2) ds in EU (controller not) if
- offering goods or services to ds in EU (e.g. US company sells something in EU) (independent of payment)
- monitoring of behavior that takes place in EU (e.g. facebook)
Art. 4(1) Personal data
- any information
- relating to natural person
- who can be identified or identifiable
Art. 4(1) Personal data - any information
any sort of statement about person in any format, e.g. photo, acoustic
Art. 4(1) Personal data - any information - relating to natural person
- data subject <-> legal persons e.g. corporations,
- about person = refer to identity, characteristics or behavior of individual, or if such information us used to determine or influence how person is treated or evaluated <-> no necessary that data “focuses” on person to relate to person
Art. 4(1) Personal data - any information relating to natural person - who is identified or identifiable
distinguished or possible to form other group members by identifier
- directly from data info (e.g. name) or
- indirectly from combination of info (5-6 points of data to identify a person, e.g. social security number)
- Means of identifying depend on context (e.g., name, location data, online identifier)
Data Subject
an identified or identifiable natural person to whom the information relates (e.g. never company)
Art 4(2) Processing
- Any operation performed on pd whether or not by automated means
- all processing steps: generation, use, transfer, transformation, storage (= copy of used data), archival (= not used), destruction
Art. 4(5) Pseudonymization
- processing so that that pd not attributable to 1 specific ds without use of additional info (but with identifiable)
- under GDPR
Anonymous data
- data where person not identifiable by data controller or any other person
- considering likely or reasonably means (e.g. time & costs)
- not under GDPR
Art. 4(22) Supervisory Authority
independent public authority which is established by a Member State
- sufficient financial, human resources & infrastructure to cooperate & align with other SA
- main tasks: monitor, enforce & drive awareness on GDPR compliance
Art. 4(7) Data Controller
natural or legal person that determines purpose & means of processing (exercises decision making power)
Art. 4(7) Data Processor
natural or legal person which processes personal data on behalf of data controller