Information Provision Obligations (6) Flashcards
What are the 3 transparency obligations under GDPR?
- provide information about processing - provision of information to data subjects
- communicate their rights - communication with data subjects in relation to their rights
- provide means to exercise rights - facilitation of the exercise of data subject rights
What are the required characteristics of controller communication with data subjects?
- intelligible and easily accessible
- clear and plain language
- concise
What is a privacy notice?
a statement made to a data subject that describes how the organization collects, uses, retains and discloses personal data
What is a layered privacy notice?
multiple layers of increasingly detailed notices
Article 29 endorses up to 3 layers - top (key elements + links), second and third (condensed then full or full notice then FAQs)
What is just-in-time notice?
bite sized delivered right before user accepts a service or product
(eg cookie web forms)
When must controllers provide notice to data subjects?
Prior to collection or prior to further processing
What information must be provided to data subjects in direct collection?
1 identity of controller and DPO
2. purpose and legal basis of processing
3. recipients of personal data
4. intention to transfer to 3rd country or IO
5. legal basis for international transfers
6. legitimate interest of controller when legitimate interest is legal basis
- storage period
- data subject rights
- if there is a contractual requirement
- use of automated decision-making
What information must be included in indirect collection notices (that is not included in direct collection)?
categories of personal data used
source of the data
What are the exceptions to notice for indirect collection?
data subject already has information
if impossible or requires disproportionate effort
if would render impossible or seriously impair purpose of processing
if national laws require secrecy
Which principle was violated in Poland’s GDPR fine to Bisnode?
Notice (failure to provide notice)
DPA gave Bisnode 3 months to notify 6m people to meet Article 14 information notification requirements
Can a controller charge an administrative fee to data subjects if they request information providing in oral format?
No
(Article 14 says information must be provided in oral format if requested by data subject)
Is detail or conciseness more important in a privacy notice?
Conciseness is more important.
(intelligible and easily accessible, clear and plain language, concise)
What additional information must be provided to data subjects when controller necessity is used as legal basis?
controller’s legitimate interest
What information must be provided to data subjects when personal data is collected indirectly?
source of the data
What information must be provided to data subjects when information will be shared outside organization?
recipients of the data