Lawful Processing Flashcards
What legal basis is determined in GDPR art. 6(1)(a)?
GDPR art. 6(1)(a): the data subject has given consent to the processing of his or her personal data for one or more specific purposes
GDPR art. 4(11): ‘consent’ of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes (…) to the processing of personal data
GDPR art. 7: further conditions for consent (documentation, withdraw, etc.)
What legal basis is determined in GDPR art. 6(1)(b)?
GDPR art. 6(1)(b): Necessity for the performance of a contract
What legal basis is determined in GDPR art. 6(1)(c)?
GDPR art. 6(1)(c): Legal obligations of the data controller
I.e. Business must proces data about their custommers for tax purposes
What legal basis is determined in GDPR art. 6(1)(d)?
GDPR art. 6(1)(d): Vital interests of the data subjects or those of another natural person
What is the legal basis in GDPR art. 6(1)(e)?
GDPR art. (6)(1)(e): Public interest and excercise of official authority
What legal basis is determined in GDPR art. 6(1)(f)?
GDPR art. 6(1)(f): Legitimate interests, except where such interests are overriden by the interests of the data subject
What is sensitive personal data?
GDPR art. 9(1): • racial or ethnic origin, • political opinions, • religious or philosophical beliefs, or • trade union membership, and • genetic data, • biometric data for the purpose of uniquely identifying a natural person, • data concerning health or • data concerning a natural person's sex life or sexual orientation
AND processing of these are prohibited in principle
What legal grounds are there for processing sensitive data?
- GDPR art. 9(2)(a): explicit consent
- GDPR art. 9(2)(b): employment law and social Security and social law
- GDPR art. 9(2)(c): vital interests of persons incaple of giving consent
- GDPR art. 9(2)(d): charities and non-profit
- GDPR art. 9(2)(e): Data made public by the subject
- GDPR art. 9(2)(f): Legal claims
- GDPR art. 9(2)(g): Public interests on the basis of Union or member state law
- GDPR art. 9(2)(h-j): medicine purposes + Public health + research purposes