GDPR Flashcards

1
Q

FIRST LEGAL ARTICLE PUBLISHED ON THE RIGHT TO PRIVACY

A

SAMUEL WARREN AND LUIS BRANDEIS ; HARVARD LAW REVIEW 1890

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

1ST LAW ON DATA PROTECTION PASSED

A

FEDERAL STATE OF HESSEN, GERMANY 1970

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

ADEQUACY PRINCIPLE

A

FUNDAMENTAL PRINCIPLE; GUIDES THE EXPORT OF PERSONAL DATA OF EU CITIZENS OUTSIDE OF THE UNION ( TO COUNTRIES WITH ADEQUATE REGULATIONS REGARDING DATA PROCESSING)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

EU LEGAL PACKAGE

A

GDPR, CONVENTION 108, DIRECTIVE 680/2016, DIRECTIVE 95/46, FUTURE E-PRIVACY REGULATION

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

DIRECTIVES

A

DIRECTIVE 95/46; REPEALED BY GDPR BUT STILL RELEVANT FOR SOME TRANSITIONAL ISSUES
DIRECTIVE 680/2016; KNOWN AS THE LAW ENFORCEMENT DIRECTIVE (AGAINST TERRORISM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

GDPR MAINLY:

A

-OVERRIDES EU DATA PROTECTION DIRECTIVE OF 1995
-COVERS ONLY PERSONAL DATA PROCESSING OF ORGANIZATIONS
-ENSHRINES 6 PRINCIPLES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

CONFLICT BETWEEN RIGHT TO PROTECTION OF PERSONAL DATA AND RIGHT TO FREEDOM OF EXPRESSION

A

AD HOC BASIS, THE PRELEVANCE OF ONE OVER ANOTHER IS JUDGED BY THE FACTS OF EACH INDIVIDUAL CASE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

WHAT TYPE OF LAW IS GDPR

A

RISK-BASED, EVEN IF THERE IS A MINIMUM RISK REGARDING DATA-PROCESSING THEN GDPR IS CONSIDERED

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

BALANCING OF RIGHTS

A

AS ESTABLISHED BY RECITAL 4, THE PROTECTION OF PERSONAL DATA IS NOT AN ABSOLUTE RIGHT, IT MUST BE CONSIDERED IN RELATION TO ITS FUNCTION IN SOCIETY AND BE BALANCED AGAINST FUNDAMENTAL RIGHTS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

THE PRINCIPLE OF PROPORTIONALITY

A

MUST BE CONSIDERED IN THE CASE OF CONFLICT BETWEEN PERSONAL DATA PROTECTION RIGHTS AND FUNDAMENTAL RIGHTS, BALANCE OF INTEREST BETWEEN DATA CONTROLLER AND SUBJECT. RELATES TO THE IDEA THAT PROCESSING OF DATA MUST BE PROPORTIONATE TO ITS INTENDED USE.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

TERRITORIAL SCOPE OF GDPR

A

Article 3 specifies that the GDPR applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the European Union (EU), regardless of where the processing takes place.
IN ACCORDANCE TO ARTICLE 3, PROCESSING OF DATA SUBJECTS WITHIN THE EU BY A CONTROLLER/ PROCESSOR NOT ESTABLISHED IN THE EU.
- THE SELLING OF GOODS AND SERVICES TO EU RESIDENTS (IRRESPECTIVE TO WETHER PAYMENT IS REQUIRED)
-THE MONITORING OF BEHAVIOUR WITHIN EU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

ARTICLE 5

A

ALL BASIC PRINCIPLES OF GDPR SHOULD APPLY IN A ACUMMULATIVE WAY

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

CONTROLLER

A

NATURAL OR LEGAL PERSON, AGENCY OR BODY WHO ALONE OR JOINTLY DETERMINES THE PURPOSES AND MEANS OF PROCESSING DATA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

RECITALS

A

EXPLAIN THE REASONING BEHIND THE PROVISIONS AND PROVIDE COMPLIMENTARY INFORMATION ON GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ARTICLE 29 WORKING PARTY

A

PROVIDES EU WITH INDEPENDENT ADVICE ON DATA PROTECTION MATTERS AND HELPS THE DEVELOPMENTS HARMONIZED POLICIES.
(MADE UP OF NATIONAL REPRESENTATIVES)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

PRIMARY V SECONDARY LAW

A

PRIMARY LAWS ARE LAWS CREATED BY TREATIES AND CHARTERS
SECONDARY LAWS ARE REGULATIONS MADE MY MINISTERS AND DIRECTIVES

17
Q

CONVENTION 108

A

IS THE OLDEST CONVENTION WHICH PROTECTS PERSONAL DATA PROTECTION

18
Q

EU CHARTER OF FUNDAMENTAL RIGHTS; ARTICLE 8

A

EVERYONE HAS THE RIGHT TO PROTECTION OF DATA CONCERNING HIM OR HER. THERE MUST BE A SPECIFIED REASON AND A BASIS OF CONSENT.

19
Q

INTERNAL MARKET

A

THE SINGLE MARKET CREATED BY THE EU AMONG ITS MEMBER STATES TO EASE MOVEMENTS OF GOODS AND SERVICES

20
Q

PERSONAL DATA

A

PERSONAL DATA WHICH RELATES TO AN IDENTIFIED OR IDENTIFIABLE PERSON

21
Q

PROCESSING

A

ACTIONS DONE WITH PERSONAL DATA; AUTOMATED OR NOT. COULD BE COLLECTING, RECORDING, ORGANIZING, ADAPTING AND EVEN DELETING.

22
Q

RESTRICTION OF PROCESSING

A

MARKING DATA TO LIMIT ITS PROCESSING IN THE FUTURE.

23
Q

PROFILING

A

AUTOMATED PROCESSING OF DATA TO ANALYZE OR PREDICT ASPECTS OF A NATURAL PERSON IN THE FUTURE (HEALTH, LOCATION MOVEMENT) USUALLY THROUGH AI

24
Q

ICO

A

SUPERVISORY SUBJECT FOR DATA PROTECTION IN THE EU

25
Q

THE BRUSSELS EFFECT

A

HOW EU REGULATIONS AND STANDARDS HAVE IMPACT GLOBALLY, EU IS A REGULATORY SUPERPOWER SINCE COMPANIES MUST COMPLY.

26
Q

MATERIAL SCOPE OF GDPR

A

ARTICLE 2 OF GDPR, THE PROCESSING OF PERSONAL DATA WHOLLY OR PARTLY BY AUTOMATED MEANS, AS WELL AS THE PROCESSING OF DATA MANUALLY FOR FILING SYSTEMS FOR COMPANIES AND INDUSTRIES

27
Q

GOOGLE SPAIN AND FACEBOOK CASES

A

ESTABLISHED THAT EU LAW APPLIES EVEN IN CORPORATIONS WHICH ARE OVERSEAS. INTRODUCED THE RIGHT TO BE FORGOTTEN, AND DELETE INFORMATION FROM SEARCH ENGINES

28
Q

EXTRATERITORIALITY OF GDPR

A

CONSIDERED TO BE LEGAL IMPERIALISM BC THEY ARE IMPOSED THE USE OF THEM TO ALL COMPANIES WHO WORK WITHIN THE EU AND THEREFORE ARE ABIDED TO APPLY THESE RULES. CAN BURDEN THOSE WHO HAVE TO COMPLY WITH VARIOUS JURISDICTIONS