What does the ‘‘Integrity and Confidentiality’’ principle under GDPR imply?
personal data processed in a manner that ensures appropriate security
What are the 7 principles for processing personal data under GDPR?
What principle was violated in the Denmark DPA fine against Taxa related to their management of ride records?
Data Minimization
Taxi company maintained ride records, including phone numbers, after 2 year retention period
What are 3 criteria for territorial scope of the GDPR?
What is the material scope of GDPR under Article 2?
Which activities fall outside the material scope of GDPR?
What was the decision in Bodil Lindquist vs Aklagarkammaran regarding material scope?
Lindquist maintained private home page of personal data of colleagues
CJEU ruled that private home page accessible to only those who have address is NOT qualified under the household activity exclusion and GDPR does apply
What are the 6 lawful grounds for processing personal data?
(obligations)
(interests)
What are the 5 original conditions for consent under GDPR?
What are the 2 possible conditions to apply performance of a contract as a lawful basis?
or
What legal obligations apply for “Compliance with a legal obligation” as a lawful basis?
legal obligations required by EU and member state laws only
What are the conditions for ‘‘Protection of vital interests’’ as a lawful basis?
to ensure an individual’s survival or of another person
only in where processing cannot be manifestly based on another legal basis
some cases may serve both public interest and vital interest (epidemics,
Who defines what qualifies as ‘‘processing for public interest’’ as a lawful basis?
Union law or member state law
must be necessary for the task carried out in the public interest
What is the exception to processing for ‘‘legitimate interests’’ as a lawful basis?
if overridden by interests or fundamental rights and freedoms of the data subject
in particular where data subject is a child
What are the 4 updated requirements for consent in Recital 32?
(demonstrable, distinguishable, right to withdraw, not conditional)
What are the conditions to process children’s data for information society services?
Article 8
consent must be given by parent or guardian if under 16
must make reasonable efforts to verify
What are the 10 justifications for processing special category data?
How do you determine if GPDR applies - by the organization or by the processing activity?
Processing Activitiy
Some activities may fall under GDPR and others may not
What is the definition of “establishment” in the EU?
effective and real exercise of activity through stable arrangements
What did case Weltimmo v NAIH establish with regard to establishment?
Weltimmo, although incorporated in Slovakia, targeted Hungarian market, advertised Hungarian properties and written in Hungarian.
Weltimmo had representative in Hungary, used letter box in Hungary and had Hungarian bank account
Is GDPR restricted to individuals within the EU?
No, GDPR applies to:
What are relevant factors in determining if goods or services are being offered to data subjects in the EU?
naming EU states in reference to goods/services
use of an EU language
marketing/advertising directed at EU audiences
paying search engine to facilitate access by individuals in EU
dedicated addresses or phone numbers for individuals in EU
top-level EU domain (.de or .eu)
What is “monitoring” according to Recital 24?
tracking individuals online to create profiles, including where used to make decisions concerning them or for analyzing or predicting their preferences, behaviors and attitudes
What are examples of monitoring?
behavioral advertising
online tracking (cookies)
personalized health analytics
CCTV
market surveys