Notes

← Back to home

A collection of fragments of understanding in the pursuit of deeper questions.

The General Data Protection Regulation - Rights and Obligations

(Risk base approach, depending on the entity processing data (Hospitals, social networks, small online shops, the control has to be different according to the quantity and risk assessed).

Processing of Personal Data

  • Data Subject - Rights

    • Right of Access
    • Right to be Informed
    • Right to Rectification
    • Right to Erasure
    • Right to Restrict the Processing
    • Right to Object
    • Right to Data Protability
    • Right to not be subject to automated decision-making
  • Data Controller/Processor - Obligations

    • Data Breach Notification
    • DPO
    • Record of Processing Activities
    • Data Breach Communication
    • DPIA
    • Prior Consultation

Right to Access

  • The data subject has the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and access to the personal data.
  • The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs.
  • Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form.
  • The right to obtain a copy of data shall not adversely affect the rights and freedoms of other parties.
  • The Information to be provided:
    • The purposes of the processing
    • The categories of personal data concerned
    • The recipient to whom the personal data have been or will be disclosed
    • Where possible, the envisaged period for which the personal will be stored, or, if not possible, the criteria used to determine that period
    • The existence of the right to request from the controller rectification or erasure or restriction of processing of personal data;
    • The right to lodge a complaint with a supervisory authority;
    • Where the personal data are not collected from the data subject, any available information as to their source;
    • The existence of automated decision-making, including profiling, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.

Right to Rectification (and Integration)

  • The data subject shall have the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her.
  • Taking into account the purposes of processing, the data subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

Right to Erasure The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay.

  • According to specific grounds (consent withdrawal, objection, unlawful processing)
  • Provided that it is not excluded in some cases (freedom of expression, legal obligation, public interest) (There might be circumstances where the erasure is not possible, because there are reasons like protection freedom of expression).

Right to Restriction of Processing (You're not interested in the erasure of information, but you are asking for a restriction of information) The data subject shall have the right to obtain from the controller restriction of processing where:

  • The accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data
  • The processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead
  • The controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims
  • The data subject has objected to processing pending the verification whether the legitimate grounds of the controller override those of the data subject.

But: with the exception of storage, personal data shall only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest.

Right to Object (Similar to the right to erasure, you object that there has never been the consent to process data). The data subject shall have the right to object, on ground relating to his or her particular situation, at any time to the processing of personal data concerning him or her where processing is necessary for:

  • The performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
  • The purposes of the legitimate interests pursued by the controller or by a third party.

The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.

Right to Object, the case of direct marketing Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.

  • The personal data shall no longer be processed for such purposes.

Right to Data Portability (Important) The data subject shall have the right to receive the personal data concerning him or her, in a structured, commonly used and machine-readable format and have the right to transmit those data from the controller to a new controller, without hindrance (Without suffering any negative effect/obstacle), where:

  • The processing is based on a contract or consent
  • The processing is automated The right to data portability shall not adversely affect the rights and freedoms of others.

Automated Individual Decision-Making, including Profiling The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

The right does not apply where the processing:

  • Is necessary for entering into, or performance of, a contract between the data subject and a data controller
  • Is authorized by Union or Member State Law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, or
  • Is based on the data subject's explicit consent.

Risk-Based Approach

  • The GDPR encourages controllers to engage in risk analysis and to adopt risk-measured responses. It imposes additional obligations for data processing activities that pose a high risk to individuals, while requiring controllers to account for risk in complying with many provisions of the GDPR.
  • Controllers that engage in low-risk processing activities, or that adequately address risk, may avoid specific requirements (e.g. to notify a data protection authority of a data breach, to appoint a representative in the EU). The GDPR also requires the supervisory authorities to consider the risk level of the activity when deciding whether to impose fines for a violation.

Data Protection by Design and by Default - Art. 25 GDPR Controllers must ensure that, both in the planning phase of processing activities and the implementation phase of any new product or service, data protection principles, and appropriate safeguards, are addressed and implemented.

  • For example, the controller must implement measures that provide for the security of any data processed, and give effect to the rights of data subjects.

Compliance with data protection law should not be an after-thought, but should be treated as a key issue in the planning and implementation of any new product or service that affects personal data.

Security of Processing Must be taken into account:

  • The State of Art
  • The Nature, Scope, Context and Purposes of Processing
  • The Costs of Implementation
  • The Risk of varying likelihood and severity for the rights and freedoms of natural persons

The controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia:

  • The pseudonymization and encryption of personal data
image3 image2
  • A process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing
  • The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
  • The ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.

In assessing the appropriate level of security, account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful:

Data Breach

  • Destruction
  • Loss
  • Alteration
  • Unauthorised disclosure of/access to Of personal data transmitted, stored or otherwise processed.

Data Breach Notification In the case of a personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it the controller shall notify the personal data breach to the competent supervisory authority. Unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken.

Data Breach Communication In the case of a personal data breach without undue delay and, where feasible**, not later than 72 hours** after becoming aware of it the controller shall notify the personal data breach to the competent supervisory authority and, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. The controller shall communicate the personal data breach to the data subject without undue delay.

Records of Processing Activities Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. Each processor and, where applicable, the processor's representative shall maintain a record of all categories of processing activities carried out on behalf of a controller.

Exemptions from the obligation to keep record of processing activities The obligation does not apply to an enterprise or an organization employing fewer than 250 persons, unless:

  • The processing it carries out is likely to result in a risk to the rights and freedoms of data subjects
  • The processing is not occasional
  • The processing includes special categories of data or personal data relating to criminal convictions and offences.

DPIA (Data Protection Impact Assessment) A DPIA is a process designed to:

  • Describe the processing
  • Assess the necessity and proportionality of a processing
  • Help manage the risks to the right and freedoms of natural persons resulting from the processing of personal data (by assessing them and determining the measures to address them).

DPIAs are important tools for accountability, as they help controllers to comply with GDPR requirments and to demonstrate that appropriate measures have been taken to ensure compliance (a process for building and demonstrating compliance).

(You conduct an assessment to define which is the risk, if you realize that the specific data processing has high risk, you have to ask to the supervisory authority consultation on the process of data processing).

Supervisory authorities shall establish and make public a list of the kind of processing operations which are subject to the requirement for a DPIA and of the kind of processing operations for which no DPIA is required.

Where a DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk, the controller shall consult the supervisory authority prior to processing. If the supervisory authority finds that the intended processing would infringe the GDPR, in particular where the controller has insufficiently identified or mitigated the risk, it shall, within up to eight weeks of receipt of the request for consultation (extended by six weeks, taking into account the complexity of the intended processing), provide written advice to the controller and, where applicable, to the processor. Those periods may be suspended until the supervisory authority has obtained information it has requested for the purposes of the consultation. Member State may in any case require controllers to consult with, and obtain prior authorisation from, the supervisory authority in relation to processing by a controller for the performance of a task carried out by the controller in the public interest, including processing in relation to social protection and public health.

image5

Designation of the DPO (Data Protection Officer) The controller and the processor shall designate a data protection officer in any case where:

  • The processing is carried out by a public authority or body, except for courts acting in their judicial capacity.
  • The core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale.
  • The core activities of the controller or the processor consist of processing on a large scale of special categories of data and personal data relating to criminal convictions and offences. In cases other than those where the designation is mandatory, the controller or processor or associations and bodies representing categories of controllers and processors may or, when required by EU or national law, shall designate a DPO. The DPO may act for such associations and other bodies representing controllers or processors.

Who is the DPO? The DPO shall be designated on the basis of professional qualities and, in particular, expert knowledge of data protection law and practices and the ability to fulfil the tasks provided by Article 39 GDPR. The DPO may be a staff member of the controller or processor, or fulfill the tasks on the basis of a service contract. The controller or the processor shall publish the contact details of the data protection officer and communicate them to the supervisory authority. (Contact point between data controllers/processors and supervisory authorities)

Position of the DPO

  • The controller and the processor shall ensure that the DPO is involved, properly and in a timely manner, in all issues which relate to the protection of personal data.
  • The controller and processor shall support the DPO in performing the relevant tasks by providing resources necessary to carry out the same and access to personal data and processing operations, and to maintain his or her expert knowledge.
  • The controller and processor shall ensure that the DPO does not receive any instructions regarding the exercise of those tasks. The DPO shall not be dismissed or penalised by the controller or the processor for performing his tasks. The DPO shall directly report to the highest management level of the controller or the processor.
  • Data subjects may contact the DPO with regard to all issues related to processing of their personal data and to the exercise of their rights under the GDPR.
  • The DPO shall be bound by secrecy or confidentiality concerning the performance of his or her tasks.
  • The DPO may fulfil other tasks and duties. The controller or processor shall ensure that any such tasks and duties do not result in a conflict of interests.

Transfer of Personal Data to Third Countries (Nothing changed from the Directive 95/46 to the GDPR)

  • Adequacy Decision
  • Appropriate Safeguards
    • Standard Contractual Clauses, the Commission has the power to decide that certain standard contractual clauses offer sufficient safeguards as required by the GDPR
    • Binding Corporate Rules, rules adopted by the competent supervisory authority as internal rules for data transfers within multinational companies. Binding corporate rules are like a code of conduct. They allow multinational companies to transfer personal data internationally within the same corporate group to countries that do not provide an adequate level of protection.
  • Derogations for Specific Situations, in the absence of an adequacy decision, or of appropriate safeguards, a transfer or a set of transfer of personal data to a third country or an international organization shall take place only on the specific conditions provided by Article 49 (e.g. Explicit consent of the Data Subject).

Penalties "In order to strengthen the enforcement of the rules of this Regulation, penalties including administrative fines should be imposed for any infringement of this Regulation, in addition to, or instead of appropriate measures imposed by the supervisory authority pursuant to this Regulation. In a case of a minor infringement or if the fine likely to be imposed would constitute a disproportionate burden to a natural person, a reprimand may be issued instead of a fine". "Member States should be able to lay down the rules on criminal penalties for infringements of this Regulation, including for infringements of national rules adopted pursuant to and within the limits of this Regulation. Those criminal penalties may also allow for the deprivation of the profits obtained through infringements of this Regulation. However, the imposition of criminal penalties for infringements of such national rules and of administrative penalties should not lead to a breach of the principle of ne bis in idem, as interpreted by the Court of Justice".

Three possible "layers"

  • Criminal Penalties
  • Administrative fines
  • Appropriate measures, reprimand

There exist two types of administrative fines:

  • Administrative fines up to 10.000.000 EUR, or in the case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher.
  • Administrative fines up to 20.000.000 EUR, or in the case of an undertaking, up to 4% of the total worldwide annual turnover of the preceding financial year, whichever is higher.