Week 13 Flashcards
1
Q
Under the GDPR, lawfulness requires either:
A
- consent of the data subject;
- necessity to enter or perform a contract;
- a legal obligation;
- necessity to protect the vital interests of the data subject or another person;
- necessity for performing a task in the public interest;
- necessity for the legitimate interests of the controller or a third party, if they are not overridden by the interests and rights of the data subject.
2
Q
When must the purpose of processing data be provided
A
Before data processing is started
3
Q
Definition of the principle of purpose limitation
A
any processing of personal data must be done for a specific well-defined purpose. And, only for additional, specified, purposes compatible with the original one.
4
Q
Purpose of processing data must be:
A
Explicit, specified, and legitimate
5
Q
Who should the principle of data accuracy be implemented by
A
The controller in all processing obligations