Week 5: IP and the information society Flashcards
Right to Privacy
United States
* Amendment IV US Constitution; Search and Seizure
* Not an absolute right; can be interfered with IF there is a probable cause
Europe
* Article 8 ECHR
* Not absolute
* Unlawful interference (Negative and Positive Obligation)
Right to Data Protection
(seen as a separate right)
“Fair and legitimate collection, storage, use and processing of personal data (by the State or private actors)”
Right to Privacy
basically closing the doors to protect the sphere of individuals
Personal Data
GDPR
any information relating to an identified or identifiable natural person
(Art 4(1) GDPR)
Sensitive Data
GDPR
Data revealing eg. race/ethnicity, gender/orientation, health etc. (Art 9(1) GDPR)
Processing is prohibited, unless (Art 9(2) GDPR)
Data processing Principles (Art 5 GDPR)
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
Lawful grounds for data processing
(Art 6 GDPR)
* Consent
* Necessary for the performance of a contract
* Legal obligation
* Vital interest
* Public interest
* Legitimate interest
Consent ; is
- A clear , affirmative action
- Freely given
- Specific, informed , ambiguous → no reasonable doubt, there cannot be any assumption or doubt regarding the consent of data.
- Documented
- Easily withdrawn
Material Scope of GDPR
Article 2 GDPR
- Activities that fall outside the scope of the EU
- Activities in the area of Common Foreign and Security Policy
- Law enforcement activities
- Purely personal and household activities (but is suuuuper strict)
Territorial Scope of the GDPR
Art 3 GDPR
- Everytime a controller or processor is established in the EU
- If controller or processor is not established in the EU but:
- Offers goods or services to data subjects in the EU, or
- Monitors behaviors of data subjects in the EU
Key roles
Art 4 GDPR
Data Subject
any natural person to whom the personal data belong
Data controller
alone or jointly with others, determines the purposes and means of the processing of personal data
Data Processor
process personal data on behalf of the controller
Supervisory Authority independent public authority established by each MS
Rights of the data subject
Art 12-22 GDPR
Obligations of controllers and processors
Article 24-26
Obligations in case of data breaches
Art 32-35 GDPR
- Notify the Supervisory authority without undue delay
- Latest within 72 hours after having become aware of breach
- Inform individuals affected if data breach is high risk!
Data Protection Officer
Art 37-39 GDPR