Supervision, Enforcement and Surveillance Activities Flashcards

1
Q

Define this Concept: Surveillance

A

Observation of individuals or groups, covert or carried out openly, conducted in real time or by access to store materials.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False. Surveillance includes accessing observation data in stored materials (video).

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are examples of electronic surveillance.

A

Social network, data mining, aerial surveillance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the GDPR general rule regarding the use of surveillance.

A

Article 23 of the GDPR requires (i) necessity, and (ii) respect the essence of fundamental rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What article of the GDPR governs surveillance?

A

Article 23

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or False. Necessity is required for the use of surveillance strategies under the GDPR.

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

True or False. Private entities may conduct surveillance?

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

True or False. Public entities can conduct surveillance?

A

True. Only in interest of national security or law enforcement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What purpose is required for public entities to conduct surveillance?

A

National security interest or law enforcement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What purpose is required for private entities to conduct surveillance?

A

Legitimate interests

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

True or False: Private entities may conduct surveillance under the GDPR for any purpose.

A

False. Must be legitimate interest.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the 3 categories of power for supervisory authorities?

A

(1) Investigate
(2) Corrective
(3) Authorization and Advisory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How is the lead supervisory authority determined for single establishment?

A

Place of establishment in EU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How is the lead supervisory authority determined for multiple establishments?

A

Supervisory authority is place of central administration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Name some supervisory authority mechanisms.

A
  1. Cooperation
  2. Mutual Assistance
  3. Joint Operations
  4. Consistency Mechanisms
  5. Dispute Resolution
  6. Urgency Procedures
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Define “cooperation” with respect to supervisory authority.

A

Cooperation between the lead supervisory authority and other concerned authorities.

17
Q

Define mutual assistance.

A

Provision of relevant information between supervisory authorities, facilities the provision of relevant information between SAs

18
Q

Define joint operations

A

investigations of controllers or processors in several member states or of data subjects in more than 1 member state.

19
Q

Define consistency mechanism.

A

Specific collaboration between the Commission, EDPB and supervisory authorities to ensure consistent GDPR application.

20
Q

What is the EDPB?

A

European Data Protection Board

21
Q

True or False. Article 29 WP was replaced by EDPB?

A

True.

22
Q

How many active members are participating in the EDPB?

A

27 active participants

23
Q

What is EDPB role in review of WP 29 opinions?

A

Decides what WP opinions must be updated.

24
Q

How many tiers are in the fining regime?

A

Two

25
Q

What are the two tiers for fines?

A

(A) $10 Million o4 2% of annual turnover
(B) $20 Million or 4% of annual turnover

26
Q

What standard applies to determining which penalties apply?

A

Totality of the circumstances.

27
Q

What are some examples of factors reviewed when examining the totality of the circumstances?

A

(i) Number of data subjects involved
(ii) purpose of processing
(iii) Damage suffered by data subjects
(iv) Duration of the infringement