Week 12 Flashcards

1
Q

What are the distinct rights related to privacy and data protection?

A

Right to respect for private life and right to personal data protection

These rights are closely related but not the same.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When did privacy rights emerge in international human rights law?

A

With the Universal Declaration of Human Rights (UDHR) in 1948.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What document affirmed privacy rights in Europe?

A

The European Convention on Human Rights (ECHR) in 1950.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Article 8 of the ECHR about?

A

Right to respect for private and family life, home, and correspondence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What impact did technological advancements have on privacy rights?

A

Improved quality of life, efficiency, and productivity, but introduced new risks to private life.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is ‘informational privacy’?

A

The concept developed to address the collection and use of personal information, emphasizing individuals’ control over their data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What decade saw the emergence of data protection laws in Europe?

A

1970s.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What article acknowledges data protection as a fundamental right in EU Law?

A

Article 16 of the Treaty on the Functioning of the EU.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the key differences between the right to privacy and the right to data protection?

A
  • Right to privacy: Protects private and family life, home, and communications from interference
  • Right to data protection: Specifically addresses the protection of personal data.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What was the main issue with the Data Protection Directive of 1995?

A

Inconsistent implementation across member states.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What regulation replaced the Data Protection Directive of 1995?

A

The General Data Protection Regulation (GDPR).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

When did the GDPR become applicable?

A

May 2018.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the main goals of the GDPR?

A
  • Stronger data protection rules
  • Enhanced individual rights
  • Stricter obligations for organizations.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does Article 4 of the GDPR define as ‘personal data’?

A

Any information relating to an identified or identifiable natural person.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does ‘processing’ refer to in the context of the GDPR?

A

Any operation performed on personal data, including collection, storage, and erasure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the role of a ‘controller’ under the GDPR?

A

Determines the purposes and means of processing personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

True or False: Data protection under EU law is limited to automated data processing.

A

False.

18
Q

What is required for valid consent under the GDPR?

A
  • Freely given
  • Specific
  • Informed
  • Unambiguous indication of wishes.
19
Q

What is the territorial scope of the GDPR?

A

Applies to processing of personal data in the context of activities of an establishment in the EU, regardless of where processing takes place.

20
Q

Define ‘processor’ in the context of the GDPR.

A

A natural or legal person processing personal data on behalf of the controller.

21
Q

What must a written contract between a controller and processor include?

A
  • Subject matter
  • Nature
  • Purpose
  • Duration of processing
  • Type of personal data.
22
Q

What does GDPR Article 3 specify about non-EU controllers?

A

Applies if they offer goods or services to data subjects in the Union or monitor their behavior within the Union.

23
Q

What does ‘establishment’ refer to in the context of GDPR?

A

A company based in Europe that has European customers, such as a subsidiary or office.

24
Q

Fill in the blank: The GDPR applies to the processing of personal data in the context of the activities of an establishment of a ______.

A

controller or processor in the Union.

25
Q

What does Article 3 of the GDPR state about its territorial scope?

A

It applies to the processing of personal data in the context of the activities of a controller or processor in the Union, regardless of whether the processing takes place in the Union or not.

26
Q

What is required for a company outside of Europe to comply with the GDPR?

A

If the company offers goods or services to European customers or monitors their behavior within the Union, compliance is necessary.

27
Q

True or False: A company must have a physical presence in Europe to be subject to the GDPR.

A

False

28
Q

Fill in the blank: The GDPR applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to the offering of goods or services or the _______.

A

monitoring of their behaviour

29
Q

What does ‘monitoring behavior’ include according to Recital 24 of the GDPR?

A

Tracking natural persons on the internet and processing techniques such as profiling.

30
Q

List some examples of activities that might constitute the ‘monitoring’ of people’s behavior.

A
  • Behavioral ads
  • Geo-localization activities
  • Online tracking via cookies
  • Personalized diet and health analytics
  • CCTV
  • Market surveys
  • Monitoring health
31
Q

True or False: The GDPR’s monitoring provision requires intention to monitor behavior.

A

False

32
Q

What is the significance of public international law regarding the GDPR?

A

It applies to a controller not established in the Union, such as in a Member State’s diplomatic mission.

33
Q

According to Article 2 of the GDPR, what does the Regulation not apply to?

A
  • Activities outside the scope of Union law
  • Member States’ activities under Chapter 2 of Title V of the TEU
  • Purely personal or household activities
  • Criminal law enforcement activities
34
Q

What are the principles relating to the processing of personal data as stated in Article 5 of the GDPR?

A
  • Lawfulness, fairness, and transparency
  • Purpose limitation
  • Data minimization
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability
35
Q

What does ‘lawfulness, fairness, and transparency’ mean in the context of GDPR?

A

It refers to the requirement that personal data must be processed in a way that is lawful, fair, and transparent to the data subject.

36
Q

Fill in the blank: Personal data must be _______ for specified, explicit and legitimate purposes.

A

collected

37
Q

What is meant by ‘data minimization’ under the GDPR?

A

Personal data must be adequate, relevant, and limited to what is necessary for the purposes for which they are processed.

38
Q

What does the GDPR require regarding the accuracy of personal data?

A

Personal data must be accurate and kept up to date; inaccurate data must be erased or rectified without delay.

39
Q

What is the requirement for storage limitation under the GDPR?

A

Personal data should be kept in a form that permits identification of data subjects for no longer than necessary for the purposes of processing.

40
Q

What does ‘integrity and confidentiality’ entail according to the GDPR?

A

Personal data must be processed securely to protect against unauthorized processing and accidental loss.

41
Q

What is the accountability principle in the GDPR?

A

The controller must be responsible for and be able to demonstrate compliance with the processing principles.