Seminar 13-15 - Rights of the data subjects Flashcards
Relevant provisions?
● Chapter III (art. 12-23)
Can MS restrict the rights of the data subjects?
Yes, MS may restrict the data subject’s rights (art. 12-22) in accordance with art. 23.
Name some rights of the data subject?
● Art. 12-14: Right of transparent communication and information
● Art. 15: Right of access
● Art. 16: Right to rectification
● Art. 17: Right to erasure
● Art. 18: Right to restriction of processing
● Art. 19: Obligation to notify data recipients of rectification, erasure of restriction on data subjects.
● Art. 20: Right to data portability
● Art. 21: Right to object
● Art. 22: Right not to be subject to automated decision making (ADM)
● Other
What is GDPR art. 12: The right to transparent communication and information (“the principle of transparency”)?
● Art. 12 establishes a broad comprehensive obligation for controllers in providing transparent information referred to in art. 13 and 14 and any communication under art. 15-22 and 34 (notification of data breach to data subject).
What is GDPR art. 13 and 14: The right to be informed ?
With the right of data subjects to be informed, where data are collected directly from them (art. 13) or where data are obtained from a third party (art. 14). Providing data subjects with this information puts them in a position to effectively exercise their rights and contributes to ensuring data quality.
Are there any Exemptions from the obligation to inform ?
Yes, there is a list of exemptions:
Any exemptions must be necessary in a democratic society and proportionate to the aim pursued.
Example:
● GDPR art. 13(4): does not apply if the data subject already has all of the relevant information - the information shall be that provided in art. 13(1).
What is GDPR art. 15 and Charter Art. 8(2): The right of access to an individual’s own data ?
Enhancing transparency and data control.
What is GDPR art. 17: Right to erasure (‘the right to be forgotten’)
Gives effect to data subjects’ requests to have data erased or deleted.
Name two cases that illustrates right to erasure?
See balancing in Google Spain (could be erased - DS had financial troubles), Manni (could not be erased - previous bankruptcy of his company - public interest)
What is the main challenge with “right to erasure”?
Freedom of expression.
What are the 5 exemptions to “right to erasure”?
■ (a) for exercising the right of freedom of expression and information
● See balancing in Google Spain (could be erased), Manni (could not be erased)
■ (b) for compliance with a legal obligation
■ (c) for reasons of public interest in the area of public health
■ (d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes
■ (e) for the establishment, exercise or defence of legal claims
What is GDPR art. 20: Right to data portability?
The right to data portability allows individuals to obtain and reuse their personal data for their own purposes across different services (move, copy or transfer personal data).
Are there any Sanctions? And where is that found in GDPR?
GDPR Art. 83 empowers MS’ supervisory authorities to impose administrative fines for infringements of the regulation.
What are the tiers for fines under GDPR?
○ Art. 5, 6, 9, 7, 12-22 or 44-49: Up to € 20,000,000 or, in the case of an undertaking, 4 % of its total worldwide annual turnover (whichever is higher)
○ When other breaches: Up to € 10,000,000 or, in the case of an undertaking, 2 % of its total worldwide annual turnover (whichever is higher)
What is the required time of providing data subject with information? And what are the two situations that can occur?
The GDPR distinguishes between two scenarios and two points in time at which the data controller must provide information to the data subject:
- Where the personal data is obtained directly from the data subject, the controller must notify the data subject about all of his or her related information and rights under the GDPR at the time the data are obtained.
- Where the personal data has not been obtained from the data subject directly, the controller is obliged to provide the information about the processing to the data subject “within a reasonable period after obtaining the personal data, but at the latest within one month”, or before data are disclosed to a third party.