What are the principles listed in GDPR Article 5?
What mnemonic device helps to remember the GDPR processing principles?
Llamas parade drowsily as Smurfs implode accidentally.
When is processing of personal data lawful under GDPR?
Only when a legal basis exists and processing is fair and transparent.
What are the 6 legal bases for processing personal data under GDPR?
Mnemonic: Crazed clowns vandalize long purple limos.
What does fairness in data processing require?
What is ‘justified detriment’ in data processing?
Processing with negative effects that remains fair.
Examples: investigations or tax assessments
What is required of controllers under the principle of transparency?
When must fair processing information be provided if data is collected directly from the data subject?
At the point or time of collection.
How should fair information processing notices be designed?
When is notification not required for directly collected data?
When the data subject is already aware of the collection.
What are exceptions to notification for data collected from other sources?
What is the principle of purpose limitation under GDPR?
Personal data must be collected for specified, explicit, and legitimate purposes.
What is secondary/further processing?
Use of personal data beyond the original purpose.
When is further processing permitted under GDPR?
Only when compatible with the original purpose.
What factors determine the lawfulness of secondary processing?
What is the principle of data minimization?
Controllers must collect and process only data that is relevant, necessary, and adequate to accomplish a stated purpose.
What are the 2 key implementation concepts for data minimization?
What does necessity mean in data minimization?
Data must be strictly required to achieve a specific, legitimate purpose.
What does proportionality mean in data minimization?
Interference with privacy must not exceed what is necessary to achieve the purpose.
What factors are considered under proportionality?
What is the principle of accuracy under the GDPR?
Controllers must ensure personal data is correct, complete, and current.
What are ‘reasonable measures’ in the context of accuracy?
Implementing data quality processes throughout the data life cycle.
What should controllers do during data collection to ensure accuracy?
What should controllers do to maintain accuracy?