Supervision, Enforcement and Surveillance Activities Flashcards

1
Q

Define this Concept: Surveillance

A

Observation of individuals or groups, covert or carried out openly, conducted in real time or by access to store materials.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False. Surveillance includes accessing observation data in stored materials (video).

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are examples of electronic surveillance.

A

Social network, data mining, aerial surveillance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the GDPR general rule regarding the use of surveillance.

A

Article 23 of the GDPR requires (i) necessity, and (ii) respect the essence of fundamental rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What article of the GDPR governs surveillance?

A

Article 23

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or False. Necessity is required for the use of surveillance strategies under the GDPR.

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

True or False. Private entities may conduct surveillance?

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

True or False. Public entities can conduct surveillance?

A

True. Only in interest of national security or law enforcement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What purpose is required for public entities to conduct surveillance?

A

National security interest or law enforcement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What purpose is required for private entities to conduct surveillance?

A

Legitimate interests

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False: Private entities may conduct surveillance under the GDPR for any purpose.

A

False. Must be legitimate interest.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the 3 categories of power for supervisory authorities?

A

(1) Investigate
(2) Corrective
(3) Authorization and Advisory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How is the lead supervisory authority determined for single establishment?

A

Place of establishment in EU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How is the lead supervisory authority determined for multiple establishments?

A

Supervisory authority is place of central administration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Name some supervisory authority mechanisms.

A
  1. Cooperation
  2. Mutual Assistance
  3. Joint Operations
  4. Consistency Mechanisms
  5. Dispute Resolution
  6. Urgency Procedures
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Define “cooperation” with respect to supervisory authority.

A

Cooperation between the lead supervisory authority and other concerned authorities.

17
Q

Define mutual assistance.

A

Provision of relevant information between supervisory authorities, facilities the provision of relevant information between SAs

18
Q

Define joint operations

A

investigations of controllers or processors in several member states or of data subjects in more than 1 member state.

19
Q

Define consistency mechanism.

A

Specific collaboration between the Commission, EDPB and supervisory authorities to ensure consistent GDPR application.

20
Q

What is the EDPB?

A

European Data Protection Board

21
Q

True or False. Article 29 WP was replaced by EDPB?

22
Q

How many active members are participating in the EDPB?

A

27 active participants

23
Q

What is EDPB role in review of WP 29 opinions?

A

Decides what WP opinions must be updated.

24
Q

How many tiers are in the fining regime?

25
What are the two tiers for fines?
(A) $10 Million o4 2% of annual turnover (B) $20 Million or 4% of annual turnover
26
What standard applies to determining which penalties apply?
Totality of the circumstances.
27
What are some examples of factors reviewed when examining the totality of the circumstances?
(i) Number of data subjects involved (ii) purpose of processing (iii) Damage suffered by data subjects (iv) Duration of the infringement