Supervision, Enforcement and Surveillance Activities Flashcards
Define this Concept: Surveillance
Observation of individuals or groups, covert or carried out openly, conducted in real time or by access to store materials.
True or False. Surveillance includes accessing observation data in stored materials (video).
True.
What are examples of electronic surveillance.
Social network, data mining, aerial surveillance.
What is the GDPR general rule regarding the use of surveillance.
Article 23 of the GDPR requires (i) necessity, and (ii) respect the essence of fundamental rights.
What article of the GDPR governs surveillance?
Article 23
True or False. Necessity is required for the use of surveillance strategies under the GDPR.
True.
True or False. Private entities may conduct surveillance?
True.
True or False. Public entities can conduct surveillance?
True. Only in interest of national security or law enforcement.
What purpose is required for public entities to conduct surveillance?
National security interest or law enforcement
What purpose is required for private entities to conduct surveillance?
Legitimate interests
True or False: Private entities may conduct surveillance under the GDPR for any purpose.
False. Must be legitimate interest.
What are the 3 categories of power for supervisory authorities?
(1) Investigate
(2) Corrective
(3) Authorization and Advisory
How is the lead supervisory authority determined for single establishment?
Place of establishment in EU
How is the lead supervisory authority determined for multiple establishments?
Supervisory authority is place of central administration.
Name some supervisory authority mechanisms.
- Cooperation
- Mutual Assistance
- Joint Operations
- Consistency Mechanisms
- Dispute Resolution
- Urgency Procedures
Define “cooperation” with respect to supervisory authority.
Cooperation between the lead supervisory authority and other concerned authorities.
Define mutual assistance.
Provision of relevant information between supervisory authorities, facilities the provision of relevant information between SAs
Define joint operations
investigations of controllers or processors in several member states or of data subjects in more than 1 member state.
Define consistency mechanism.
Specific collaboration between the Commission, EDPB and supervisory authorities to ensure consistent GDPR application.
What is the EDPB?
European Data Protection Board
True or False. Article 29 WP was replaced by EDPB?
True.
How many active members are participating in the EDPB?
27 active participants
What is EDPB role in review of WP 29 opinions?
Decides what WP opinions must be updated.
How many tiers are in the fining regime?
Two
What are the two tiers for fines?
(A) $10 Million o4 2% of annual turnover
(B) $20 Million or 4% of annual turnover
What standard applies to determining which penalties apply?
Totality of the circumstances.
What are some examples of factors reviewed when examining the totality of the circumstances?
(i) Number of data subjects involved
(ii) purpose of processing
(iii) Damage suffered by data subjects
(iv) Duration of the infringement