Module 4 Flashcards

Processing personal data

1
Q

Processing

A

Any operation performed upon personal data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

GDPR principles

A
  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimalisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Denmark DPA recommends GDPR fine for
taxi company (2019)

A

Danish DPA issues its first GDPR fine for late deletion of customer telephone numbers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Dutch DPA hits tennis association with 525K
euro GDPR fine (2020)

A

The Dutch Data Protection Authority (Dutch DPA) recently imposed a fine of EUR 525,000 on the Royal Dutch Tennis Association (KNLTB) for sharing the personal data of its members with two of its sponsors in June 2018 on the basis of its own commercial interests.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Territorial scope of the GDPR: Three criteria

A
  1. Where the data is processed in the context of the activities of an
    establishment of a controller or processor in the EU
  2. Intentional processing of personal data of data subjects in the
    EU relating to offering goods or services or intentional monitoring
    behaviour in the EU
  3. Processing of personal data by a controller not established in
    the EU but in a place where member state law applies by virtue
    of public international law
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Material scope

A

Processing
of personal data wholly or
partly by automated means’

or

‘processing other than by
automated means of personal
data which form part of a
filing system’ (Article 2)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Lawfull grounds for controllers

A
  • Consent
  • Contractual necessity
  • Legal obligation
  • Vital interests
  • Public interest
  • Legitimate interests
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Processing personal data - consent

A
  • Clear affirmative act
  • Freely given
  • Specific and informed
  • Unambiguous indication of wishes
  • Written, electronic, oral or any other means
  • Conditions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Consent for children’s data

A

Article 8
- Information society services
- Authorisation of parent or guardian of children below 16 years old
- Reasonable efforts to verify

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Legitimate interests

A
  • Processing is necessary
  • Interests are balanced against
    the data subject’s
  • Criteria is more restrictive
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Belangenafweging - driestappentoets

A
  1. Heeft de organisatie een gerechtvaardigd belang?
  2. Is het verwerken van persoonsgegevens noodzakelijk
    om het doel te bereiken?
    - Proportionaliteit
    - Subsidiariteit
  3. Belang van de organisatie vs. het belang van de
    betrokkene
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Processing special categories of personal data

Prohibition to proces, except if:

A
  • Explicit consent
  • In the context of employment
  • Vital interest of individual
  • Political, philosophical and religious purposes
  • Sensitive data manifestly made public
  • Establishment, exercise or defence of legal claims
  • Substantial public interest
  • Medicine and social healthcare
  • Public health
  • Public archives, scientific or historical research or statistical
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is data processing?

A

Any action performed upon data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the criteria used to
determine the territorial scope
of the GDPR? Select all that
apply

A

A. Where the data is processed in the
context of the activities of an
establishment of a controller or
processor in the EU

B. Intentional processing of personal data
of data subjects in the EU relating to
offering goods or services or intentional
monitoring of their behaviour in the EU

C. Processing of personal data by a
controller not established in the EU but
in a place where member state law
applies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which exception to the
prohibition on processing
special categories of personal
data must be explicit?

A

Consent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q
A