Information Provision Obligations (6) Flashcards

1
Q

What are the 3 transparency obligations under GDPR?

A
  1. provide information about processing - provision of information to data subjects
  2. communicate their rights - communication with data subjects in relation to their rights
  3. provide means to exercise rights - facilitation of the exercise of data subject rights
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the required characteristics of controller communication with data subjects?

A
  1. intelligible and easily accessible
  2. clear and plain language
  3. concise
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a privacy notice?

A

a statement made to a data subject that describes how the organization collects, uses, retains and discloses personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a layered privacy notice?

A

multiple layers of increasingly detailed notices

Article 29 endorses up to 3 layers - top (key elements + links), second and third (condensed then full or full notice then FAQs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is just-in-time notice?

A

bite sized delivered right before user accepts a service or product

(eg cookie web forms)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

When must controllers provide notice to data subjects?

A

Prior to collection or prior to further processing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What information must be provided to data subjects in direct collection?

A

1 identity of controller and DPO
2. purpose and legal basis of processing
3. recipients of personal data
4. intention to transfer to 3rd country or IO
5. legal basis for international transfers
6. legitimate interest of controller when legitimate interest is legal basis

  1. storage period
  2. data subject rights
  3. if there is a contractual requirement
  4. use of automated decision-making
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What information must be included in indirect collection notices (that is not included in direct collection)?

A

categories of personal data used
source of the data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the exceptions to notice for indirect collection?

A

data subject already has information
if impossible or requires disproportionate effort
if would render impossible or seriously impair purpose of processing
if national laws require secrecy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which principle was violated in Poland’s GDPR fine to Bisnode?

A

Notice (failure to provide notice)

DPA gave Bisnode 3 months to notify 6m people to meet Article 14 information notification requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Can a controller charge an administrative fee to data subjects if they request information providing in oral format?

A

No

(Article 14 says information must be provided in oral format if requested by data subject)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Is detail or conciseness more important in a privacy notice?

A

Conciseness is more important.

(intelligible and easily accessible, clear and plain language, concise)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What additional information must be provided to data subjects when controller necessity is used as legal basis?

A

controller’s legitimate interest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What information must be provided to data subjects when personal data is collected indirectly?

A

source of the data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What information must be provided to data subjects when information will be shared outside organization?

A

recipients of the data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What information must be provided to data subjects in all circumstances?

A

purpose of processing
data subjects rights
identity of controller

17
Q

What does the GDPR require the data subject to know in order to provide valid consent?

A

identity of the controller

purposes for which personal data are processed

18
Q

What information (7) must be provided to the data subject in all cases when data is collected directly from the data subject?

(article 13-1)

A
  1. identity and contact of controller
  2. DPO contact
  3. purpose and basis of processing
  4. legitimate interests (where applicable)
  5. recipients or categories of recipients
  6. intention to transfer
  7. if transfer based on adequacy or safeguards
19
Q

What additional information must be provided to the data subject to ensure fair and transparent processing?

A
  1. retention period
  2. data subject rights
  3. right to withdraw consent (if based on consent)
  4. right to complain to SA
  5. if data is required by contract or other obligation and consequences of refusal
  6. existence of automated decision-making
20
Q

Why are information provision requirements spread across two different articles (13-1 and 13-2)?

A

following structure of the directive

article 13-1: mandatory set of information
article 13-2: information to ensure fair processing

21
Q

What additional information must be provided to data subjects when personal data is not obtained directly from data subject?

A

categories of personal data

source of personal data

22
Q

What information must be provided to data subjects when transferring to a 3rd country or IO on basis of legitimate interest?

A

the transfer
compelling legitimate interest of controller

23
Q

What information must be provided to data subjects when transferring to a 3rd country or IO on basis of consent?

A

possible risks of the transfer due to lack of adequacy or other appropriate safeguard

24
Q

What information must be provided to data subjects when transferring under BCRs?

A

data protection principles contained in the BCRs
data subject rights and how to exercise,
including right to compensation for BCR breach

25
Q

When should information be provided to the data subject if the data is not obtained directly from the data subject?

A
  1. within reasonable period after obtaining the data but at the latest one month
  2. if for communication, at the latest at the time of the first communication
  3. at the latest when personal data are first disclosed
26
Q

How should information be provided to the data subject? (in what form)

A

concise, transparent, intelligible, and easily accessible, using clear and plain language

27
Q

In what format should information be provided to the data subject?

A

in writing or by other means, where appropriate by electronic means

28
Q

Why does the WP stress the word “provide” for information provision?

A

controllers must actively furnish information, shouldn’t have to search for fair processing information among other content

29
Q

What are possible approaches to providing fair processing information that comply with the requirement to be concise?

A
  1. layered notices
  2. just-in-time notices
  3. privacy dashboards
  4. alternative forms and channels
  5. adapt to requirements of diverse technologies
30
Q

What should be provided in the first layer of a layered privacy notice (WP29)?

A

purpose of processing
controller identity
rights granted by GDPR
processing that could surprise or have an impact on data subject

31
Q

What does a “just-in-time” privacy notice mean?

A

providing information about processing at specific points of collection

32
Q

What does the WP29 recommend regarding full privacy notices?

A

That in addition to using alternative formats (layered, just in time) a full unlayered version of the notice should be made available