Module #3: GDPR Flashcards
5 GDPR Provisions
1) International Data Transfers
2) Accountability
3) Individual Rights
4) Data Breach Notifications
5) Controller and Processor Obligations
Article 3 Section 1
1) Processing of personal data when a controller or processor is established in the EU (regardless of whether or not the actual processing takes place in the EU)
GDPR Fines
Up to 20,00,000 EUR or 4% of total annual revenue, whichever is higher.
GDPR Scope of Territorial (article 3)
1) When a controller or Processer is established in the EU
2) Of data subjects relating to offering goods or services or monitoring behavior
3) By a controller in a place where member state law applies
(1 of the following criteria must be met)
Material Scope of GDPR (article 2)
1) processing personal data wholly by automated means. any processing performed with or without human intervention. (doesn’t include automated decision making)
2) personal data that forms part of a filing system. processing is not conducted by automated means.
GDPR’s definition of processing (article 4 section 2)
- collection
- recording
- organization
- structuring
- storage
- adaptation or alteration
- retrieval
- consultation
- use
- disclosure by transmission
- dissemination or otherwise making available
- alignment or combination
- restriction, erasure, or destruction
What category is covered by
-withdraw consent
What consumers can do
What category is covered by
-Consult regulators before processing (sometimes)
What organizations must do
What category is covered by
Implement data protection by design and by default
What organizations must do
What category is covered by
take responsibility for vendor processing
What organizations must do
What category is covered by
request a copy of their personal data
What consumers can do
What category is covered by
follow rules for processing children’s data
What organizations must do
What category is covered by
request a copy of their personal data
What consumers can do
What category is covered by
enforce penalties up to 20 million euros or 4% total annual revenue
What regulators may do
What category is covered by
request a copy of their personal data
What consumers can do
What category is covered by
order erasure of personal data
What regulators may do
What category is covered by
ask for records of compliance
What regulators may do
What category is covered by
erasure compliance of data transfers
What organizations must do
What category is covered by
maintain appropriate data security
What organizations must do
What category is covered by
object to automated decision-making
What consumers can do
What category is covered by
provide notification of breaches (sometimes)
what organizations must do
What category is covered by
suspend international data flows
What regulators may do
What category is covered by
“freeze” processing of their personal data
What consumers can do
What category is covered by
impose temporary processing ban
What regulators may do
What category is covered by
Conduct DPIAs (sometimes)
what organizations must do
What category is covered by
keep records and demonstrate compliance
what organizations must do
What category is covered by
Appoint a DPO (sometimes)
what organizations must do
International data transfers
- What mechanisms before it can transfer data across borders
1) Adequacy decisions
2) Ad hoc contracts
3) standard contractual clauses (SCCs)
4) binding corporate rules (BCRs)
5) codes of contacts / self-certification mechanisms