What rights are granted to data subjects under Access?
What are the 3 considerations of fulfilling a data subject right to access in terms of cost, format and content?
What are the two types of data subject rights to rectification?
What are the three questions to ask when fulfilling a request to access or rectification?
What is the right to portability?
the right to receive personal data or have it transferred to another controller
applies where consent or performance of a contract is used as lawful grounds for processing
What are the limitations on responsibility of the controller following a portability request? (they do not….)
Assume responsibility for processing activities of recipient
Do not have to erase
What is interoperability?
formats that enable data portability
*does not imply controllers must maintain technically compatible systems
What are the cumulative conditions to exercise data portability?
(article 29 working party)
Is the right to erasure an absolute right?
No
What is the difference between erasure and right to be forgotten?
Right to be forgotten is the right to ensure the information is erased by third parties, including links, copies and replications
What are the obligations of the controller under the Right to be Forgotten?
The controller must inform other controllers that the data subject has requested erasure. Burden on controller to remove the data
What are the grounds to exercise a right to erasure (right to be forgotten)?
What are the exceptions to right to erasure / be forgotten?
freedom of expression
compliance with a legal obligation
public interest in the area of public health
archiving purposes
establishment, exercise or defense of legal claims.
What are 4 circumstances in which a data subject exercise their right to restriction of processing (article 18)?
1) when processing is unlawful but data subject prefers restriction to erasure
2) when accuracy is contested and controller needs time to verify
3) when controller no longer needs data but data subject needs it for legal claim
4) when data subject objects to processing pending controller’s verification
Under what conditions can data be further processed once exercised the right to restriction of processing?
New consent
Exercise or defend legal claims
Protect rights of another person
Important public interest reasons
What is the definition of the right to restriction of processing?
Personal data is stored without further processing
How can a controller fulfil a right to restriction of processing request?
When can you exercise the right to object to processing?
What are data subject rights related to automated decision-making under Article 22?
Data subject has the right not to be subject to a decision based solely on automated processing, including profiling, if decisions have legal and significant effects
When can a data subject NOT exercise right to not be subject to automated decision making?
1) when processing is necessary to enter or perform contract
2) when authorized under union or member state law and safeguards in place
3) when data subject has given explicit consent
When is automated decision-making permitted on special category data?
explicit consent
substantial public interest based
suitable measures in place
What are the good practice recommendations for automated decision-making under Article 29?
provide meaningful information about logic involved
WP29 guidelines on consent
implement mechanism to check profiles and correct
make clear to data subject their right to object
appropriate safeguards
What is profiling ?
automated processing of personal data for the purpose of evaluating, analyzing and predicting personal aspects relating to a natural person
What are examples of profiling/targeting?
adware (software on user computer)
cookies (piece of text web server can store on hard drive)
beacon (passes information from user computer to website)
digital fingerprint (end user device identification)