Principles Flashcards
What does the principle of lawfulness, fairness and transparency means?
GDPR art. 5(1)(a): personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject
i. e.:
1) legal basis for processing and consistent with all apllicable laws
2) processed with the subject’s knowledge and not obtained by deception
3) the subject must be informed of the processing
What does the purpose limitation means?
GDPR art. 5(1)(b): personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes
GDPR art. 6(4): The elements of the incompatible assement
What does the data minimisation principle means?
GDPR art. 5(1)(c): personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed
What does the principle of accuracy means?
GDPR art. 5(1)(d): personal data shall be accurate and, where necessary, kept up to date
What does the storage limitation principle means?
GDPR art. 5(1)(e): personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed;
What does the principle of integrity and confiendiality means?
GDPR art. 5(1)(f): personal data shall be processed in a manner that ensures appropriate security of the personal data
What does the principle of accountability means?
GDPR art. 5(2): The controller shall be responsible for, and be able to demonstrate compliance with, art. 5, paragraph 1
GDPR art. 24: the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in accordance with this Regulation
GDPR art. 30: record of processing activities
What provisions are relevant for personal data breaches?
GDPR art. 4(12): personal data breach’ means a breach of security leading to the accidental or unlawful destruction of, unauthorised disclosure of, or access to, personal data
GDPR art. 33(1): The controller shall within 72 hours notify the supervisory authority
GDPR art. 34(1): Notifying of data subjects when High risk to the subject’s rights and freedoms