GDPR Articles Flashcards
Article 1
Subject-matter and objectives
Article 2
Material Scope
Article 3
Territorial Scope
Article 4
Definitions
Article 5
Principles relating to processing of personal data
Article 6
Lawfulness of processing
Article 7
Conditions for consent
Article 8
Conditions applicable to child’s consent in relation to information society services
Article 9
Processing of special categories of personal data
Article 10
Processing of personal data related to criminal convictions
Article 11
Processing which does not require identification
Article 12
Transparent information, communication and modalities for the exercise of rights of the data subject
Article 13
Information to be provided where personal data are collected from the data subject
Article 14
Information to be provided where personal data have not been obtained by the data subject
Article 15
Right of access by the data subject
Article 16
Right to rectification
Article 17
Right of erasure (right to be forgotten)
Article 18
Right to restriction of processing
Article 19
Notification Obligation regarding rectification or erasure of personal data or restriction of processing
Article 20
Right to data portability
Article 21
Right to object
Article 22
Automated individual decision-making, including profiling
Article 23
Restrictions
Article 24
Responsibility of the controller
Article 25
Data protection by design and default
Article 26
Joint controllers
Article 27
Representatives of controllers or processors not established in the Union
Article 28
Processor
Article 29
Processing under the authority of the controller or processor
Article 30
Records of processing activities
Article 31
Cooperation with the supervisory authority
Article 32
Security of processing
Article 33
Notification of personal data breach to the supervisory authority
Article 34
Communication of a personal data breach to the data subject
Article 35
Data protection impact assessment
Article 36
Prior Consultation
Article 37
Designation of the data protection officer
Article 38
Position of the data protection officer
Article 39
Tasks of the data protection officer
Article 40
Codes of conduct
Article 41
Monitoring approved codes of conduct
Article 42
Certification
Article 43
Certification bodies
Article 44
General principles for transfer
Article 45
Transfers on the basis of an adequacy decision
Article 46
Transfers subject to appropriate safeguards
Article 47
Binding corporate rules
Article 48
Transfers of disclosures not authorized by Union law
Article 49
Derogations for specific situations
Article 50
International cooperation for the protection of personal data
Article 51
Supervisory authority
Article 52
Tasks
Article 58
Powers
Article 59
Activity reports
Article 53
General conditions for the members of the supervisory authority
Article 54
Rules on the establishment of the supervisory authority
Article 55
Competence
Article 56
Competence of the lead supervisory authority
Article 57
Tasks
Article 60
Cooperation between the lead supervisory authority and the other supervisory authorities concerned
Article 61
Mutual Assistance
Article 62
Joint operations of supervisory authorities
Article 63
Consistency mechanism
Article 64
Opinion of the Board
Article 65
Disputed resolution by the Board of
Article 66
Urgency procedure
Article 67
Exchange of information
Article 68
European Data Protection Board
Article 69
Independence
Article 70
Tasks of the Board
Article 71
Reports
Article 72
Procedure
Article 73
Chair
Article 74
Tasks of the chair
Article 75
Secretariat
Article 76
Confidentiality
Article 77
Right to lodge a complaint with the supervisory authority
Article 78
Right to an effective judicial remedy against a supervisory authority
Article 79
Right to an effective judicial remedy against a controller or processor
Article 80
Representation of data subjects
Article 81
Suspension of procedings
Article 82
Right to compensation and liability
Article 83
General conditions for imposing administrative fines
Article 84
Penalties
Article 85
Processing and freedom of expression and information
Article 86
Processing and public access to official documents
Article 87
Processing of the national identification number
Article 88
Processing in the context of employment
Article 89
Safeguards and derogations relating to the processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes
Article 90
Obligations of secrecy
Article 91
Existing data protection rules of churches and religious associations
Article 92
Exercise of the delegation
Article 93
Committee procedure
Article 94
Repeal of Directive 95/46/EC
Article 95
Relationship with Directive 2002/58/EC - ePrivacy Directive
Article 96
Relationship with previously concluded Agreements
Article 97
Commission reports
Article 98
Review of other Union legal acts on data protection
Article 99
Entry into force and application
Recital 26
How to determine if a natural person is identifiable - there must be a reasonable likelihood
Recital 30
Information that constitutes an online identifier such as IP address, cookie, or radio frequency identification (RFID) may be used to create a person’s profile and identify them, demonstrating the breadth of content considered personal data
Recital 15
Clarifies that GDPR is intended to be technologically neutral
Recital 27
GDPR does not apply to the personal data of deceased persons which may be protected through the SCCs although member states may provide for rules in this area
Recital 22
The term establishment is not defined in GDPR but it implies that the effective and real exercise of activity through a stable arrangement - even a minimal one - in the context of which that processing is carried out
Recital 60
Data subject should be provided any information to ensure fair and transparent processing, taking into account the specific circumstances and context in which personal data are processed
Recital 67
The types of methods that can be used to restrict processing include temporarily moving the selected data to another processing system, making the selected personal data unavailable to users or temporarily removing published data from a website