Module 4 Flashcards
Processing personal data
Processing
Any operation performed upon personal data
GDPR principles
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimalisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
Denmark DPA recommends GDPR fine for
taxi company (2019)
Danish DPA issues its first GDPR fine for late deletion of customer telephone numbers
Dutch DPA hits tennis association with 525K
euro GDPR fine (2020)
The Dutch Data Protection Authority (Dutch DPA) recently imposed a fine of EUR 525,000 on the Royal Dutch Tennis Association (KNLTB) for sharing the personal data of its members with two of its sponsors in June 2018 on the basis of its own commercial interests.
Territorial scope of the GDPR: Three criteria
- Where the data is processed in the context of the activities of an
establishment of a controller or processor in the EU - Intentional processing of personal data of data subjects in the
EU relating to offering goods or services or intentional monitoring
behaviour in the EU - Processing of personal data by a controller not established in
the EU but in a place where member state law applies by virtue
of public international law
Material scope
Processing
of personal data wholly or
partly by automated means’
or
‘processing other than by
automated means of personal
data which form part of a
filing system’ (Article 2)
Lawfull grounds for controllers
- Consent
- Contractual necessity
- Legal obligation
- Vital interests
- Public interest
- Legitimate interests
Processing personal data - consent
- Clear affirmative act
- Freely given
- Specific and informed
- Unambiguous indication of wishes
- Written, electronic, oral or any other means
- Conditions
Consent for children’s data
Article 8
- Information society services
- Authorisation of parent or guardian of children below 16 years old
- Reasonable efforts to verify
Legitimate interests
- Processing is necessary
- Interests are balanced against
the data subject’s - Criteria is more restrictive
Belangenafweging - driestappentoets
- Heeft de organisatie een gerechtvaardigd belang?
- Is het verwerken van persoonsgegevens noodzakelijk
om het doel te bereiken?
- Proportionaliteit
- Subsidiariteit - Belang van de organisatie vs. het belang van de
betrokkene
Processing special categories of personal data
Prohibition to proces, except if:
- Explicit consent
- In the context of employment
- Vital interest of individual
- Political, philosophical and religious purposes
- Sensitive data manifestly made public
- Establishment, exercise or defence of legal claims
- Substantial public interest
- Medicine and social healthcare
- Public health
- Public archives, scientific or historical research or statistical
What is data processing?
Any action performed upon data
What are the criteria used to
determine the territorial scope
of the GDPR? Select all that
apply
A. Where the data is processed in the
context of the activities of an
establishment of a controller or
processor in the EU
B. Intentional processing of personal data
of data subjects in the EU relating to
offering goods or services or intentional
monitoring of their behaviour in the EU
C. Processing of personal data by a
controller not established in the EU but
in a place where member state law
applies
Which exception to the
prohibition on processing
special categories of personal
data must be explicit?
Consent