Supervision and Enforcement (11) Flashcards
What is the 6 functions of the Supervisory Authority?
- Enforce GDPR
- Promote awareness
- Conduct investigations
- Protect human rights
- Make annual reports
- Facilitate free flow of personal data within EU
What 3 types of powers do Supervisory Authorities have over controllers and processors?
- Investigative
- Corrective
- Authorization and advisory
What are corrective measures Supervisory Authorities can take?
issue warnings, reprimands
order notification to data subjects of breach
ban processing and suspend transfers
impose fines
Can member states grant SA additional powers?
Yes, through member state law
How do you identify the lead supervisory authority for cross-border processing?
Single establishment - SA of establishment
Multiple establishments - SA of place of central administration or where decisions about purpose and means take place
If processor and controller - SA of controller location
What is cross-border processing?
processing that takes place in the context of activities in which controller/processor are established in more than one member state,
or
activities substantially affect data subjects in more than one member state
What are the 6 types of procedures to support SA cooperation and GDPR application?
- Cooperation (lead SA cooperates with other SAs)
- Mutual assistance (SAs provide each other with information)
- Joint operations (SAs conduct joint investigations or enforcement)
- Consistency mechanism (cooperate with other SAs in implementing new measures that impact other member states)
- Dispute resolution (Board resolves disputes)
- Urgency procedure (derogation from consistency mechanism)
What is a consistency mechanism procedure (SAs)?
collaborative process between SAs, Commission and EDPB to adopt measures and ensuring consistent GDPR application
What is an urgency procedure for SAs?
for immediate adoption of provisional measures within a member state
Who makes up the European Data Protection Board?
representatives of each member state’s SA
(only 27 of the 30 may actively participate)
What is the European Data Protection Supervisor?
the data protection regulator for the EU as an entity
What are the functions of the EDPS?
(European Data Protection Supervisor)
Monitor and ensure personal data protection from EU institutions and bodies
Advise EU institutions
Monitor new technology
Intervene before CJEU to interpret data protection law
Cooperate with supervisory authorities
What kinds of infringements can receive fines up to 20m euros or 4% of total turnover?
infringements of principles, data subject rights, international data transfers, obligations of member state law, noncompliance with SA order
What is the fine for other infringements?
10m euros or 2% of total turnover
Why did the French data protection authority fine Google $57m?
lack of transparency, inadequate information and lack of valid consent for personalizing ads
google had not sufficiently established its Ireland establishment and was making decisions around processing within the US so France could be the competent SA