Processing Personal Data (4) Flashcards
What does the ‘‘Integrity and Confidentiality’’ principle under GDPR imply?
personal data processed in a manner that ensures appropriate security
What are the 7 principles for processing personal data under GDPR?
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
What principle was violated in the Denmark DPA fine against Taxa related to their management of ride records?
Data Minimization
Taxi company maintained ride records, including phone numbers, after 2 year retention period
What are 3 criteria for territorial scope of the GDPR?
- activities of EU-established organizations (regardlesss of whether processing takes place in EU or not)
- organizations offer goods and services to or monitor the behavior of individuals in the EU
- in a place where member state law applies by virtue of international treaties (embassies)
What is the material scope of GDPR under Article 2?
- processing of personal data wholly or partly by automated means
- personal data which forms part of a filing system, even if not conducted by automated means
Which activities fall outside the material scope of GDPR?
- activities outside the scope of Union law
(national laws around public security, defense, national security) - official bodies carrying out crime prevention, investigation, detection or prosecution of criminal offenses
- purely personal or household activities
What was the decision in Bodil Lindquist vs Aklagarkammaran regarding material scope?
Lindquist maintained private home page of personal data of colleagues
CJEU ruled that private home page accessible to only those who have address is NOT qualified under the household activity exclusion and GDPR does apply
What are the 6 lawful grounds for processing personal data?
(obligations)
- Consent
- Performance of a contract
- Compliance with a legal obligation
(interests)
- Protection of vital interests of data subject or another person
- Public interest or exercise
- Legitimate interests
What are the 5 original conditions for consent under GDPR?
- demonstrable
- clearly distinguishable
- intelligible and easily acccessible form, using clear and plain language
- right to withdraw at any time
- not conditional for performance of contract
What are the 2 possible conditions to apply performance of a contract as a lawful basis?
- processing is necessary to perform the contract and data subject is party to the contract
or
- if data subject requests processing to enter into contract
What legal obligations apply for “Compliance with a legal obligation” as a lawful basis?
legal obligations required by EU and member state laws only
What are the conditions for ‘‘Protection of vital interests’’ as a lawful basis?
to ensure an individual’s survival or of another person
only in where processing cannot be manifestly based on another legal basis
some cases may serve both public interest and vital interest (epidemics,
Who defines what qualifies as ‘‘processing for public interest’’ as a lawful basis?
Union law or member state law
must be necessary for the task carried out in the public interest
What is the exception to processing for ‘‘legitimate interests’’ as a lawful basis?
if overridden by interests or fundamental rights and freedoms of the data subject
in particular where data subject is a child
What are the 4 updated requirements for consent in Recital 32?
(demonstrable, distinguishable, right to withdraw, not conditional)
- Clear affirmative act
- Freely given, specific, informed and unambiguous
- Consent given for each purpose
- For electronic means: clear, concise and not disruptive to use of the service
What are the conditions to process children’s data for information society services?
Article 8
consent must be given by parent or guardian if under 16
must make reasonable efforts to verify
What are the 10 justifications for processing special category data?
- Explicit consent
- Employment, social security or social protection law authorized by Union or Member State law, with safeguards
- Vital interests, incapable of giving consent
- Political, philosophical, religious purposes fpr legitimate activities
- Made public by the data subject
- Legal claims
- Substantial public interest
- Healthcare
- Public health
- Archives or research
How do you determine if GPDR applies - by the organization or by the processing activity?
Processing Activitiy
Some activities may fall under GDPR and others may not
What is the definition of “establishment” in the EU?
effective and real exercise of activity through stable arrangements
What did case Weltimmo v NAIH establish with regard to establishment?
Weltimmo, although incorporated in Slovakia, targeted Hungarian market, advertised Hungarian properties and written in Hungarian.
Weltimmo had representative in Hungary, used letter box in Hungary and had Hungarian bank account
Is GDPR restricted to individuals within the EU?
No, GDPR applies to:
- activities of an establishment in the EU, regardless of where processing takes place
- processing of personal data of data subjects who are in the Union
What are relevant factors in determining if goods or services are being offered to data subjects in the EU?
naming EU states in reference to goods/services
use of an EU language
marketing/advertising directed at EU audiences
paying search engine to facilitate access by individuals in EU
dedicated addresses or phone numbers for individuals in EU
top-level EU domain (.de or .eu)