GDPR Flashcards
Covered entities?
- Processing of personal data when a controller or processor is established in the EU, regardless of whether or
not the actual processing takes place in the EU - Processing of personal data of EU subjects relating to offering goods or services or monitoring behaviour,
regardless of whether or not the controller or processor is established in the EU - Processing of personal data by a controller not established in the EU but in a place where member state law
applies
Rights to individuals?
Access Erasure Rectification Restriction of processing Data Portability Object to processing No profiling
Who is covered by this law?
EU Data Subjects. Doesn’t matter if the data is processed in the EU or not
Provisions of the EU’s General Data Protection Regulation (GDPR) include
Accountability obligations Rules for international data transfers Requirements for processors (contractors who act on behalf of data controllers) Designation of data protection officers Notification of security breaches
Fines
Sanctions of up to €20 million or four percent of total annual, worldwide revenues.
Exclusions
- Activities outside the scope of EU law (e.g., national security activities)
- Law enforcement and public security
- Purely personal or household activities
US Safe Harbor
Overturned in 2015 due to US government surveillance
A multinational company can transfer data between countries after certification of their practices by an EU privacy supervisory agency
Binding Corporate Rules (BCR)
A company adopts EU-approved contractual provisions requiring compliance with EU law and submission to the supervision of an EU privacy supervisory agency
Standard Contractual Clauses (SCC)
Other approved transfer mechanisms
Codes of conduct and certification mechanisms
Ad hoc contractual clauses authorized by supervisory authorities (i.e., non-standardized contractual clauses)
EDPB
European Data Protection Board
Privacy by design accountability
Controllers
Privacy by default accountability
Controllers
DPIAs accountability
Controllers (Where required) and processors (to assist)
Data Protection Officers accountability
Controllers and Processors where required