Search results

From GDPRhub
  • Article 25 GDPR (category GDPR Articles) (section (1) Data protection by design)
    Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 577 (Oxford University Press 2020). Although Article 25(1) mentions that the measures
    43 KB (4,675 words) - 06:43, 16 June 2023
  • Article 28 GDPR (category GDPR Articles) (section (c) Measures required by Article 32 GDPR)
    mechanism referred to in Article 63 GDPR (Article 28(8) GDPR). The Commission has made use of its power under Article 28(7) GDPR and published standard contractual
    72 KB (9,140 words) - 13:12, 2 June 2023
  • HDPA (Greece) - 20/2023 (category Article 25(1) GDPR)
    registered letter in violation of article 15 (1) cond. 12 par. 2, 3 and 4 GDPR and c) 30,000 euros for violation of Article 25 (1) GDPR because it did not in practice
    6 KB (634 words) - 17:48, 17 July 2023
  • HDPA (Greece) - 25/2023 (category Article 25(1) GDPR)
    processing of personal data meets the legal requirements, in breach of Article 25(1) GDPR. Finally, the DPA stated that the response to the access request was
    6 KB (694 words) - 14:25, 20 January 2024
  • Vodafone S.p.A in violation of the following GDPR provisions: Article 5(1) and Article 5(2) and Article 25(1): for failing to implement control systems of
    7 KB (810 words) - 15:52, 6 December 2023
  • the GDPR. In light of this, the Court agreed with the DPA that the controller had violated Article 5(1)(a) GDPR, Article 12 GDPR, Article 13 GDPR, Article
    22 KB (3,193 words) - 10:34, 29 February 2024
  • on final judgments did not comply with Article 25(1) GDPR. Pursuant to Article 58(2)(b) and Article 58(2)(d) GDPR, the DPA reprimanded the controller for
    43 KB (6,671 words) - 08:49, 27 January 2022
  • on final judgments did not comply with Article 25(1) GDPR. Pursuant to Article 58(2)(b) and Article 58(2)(d) GDPR, the DPA reprimanded the controller for
    43 KB (6,677 words) - 08:47, 27 January 2022
  • APD/GBA (Belgium) - 53/2020 (category Article 25(1) GDPR)
    comply with section 5.1(b) of the MDR, and for failure to comply with section 5.1(a) of the MDR. and 5.1(b), 6.1, 25.1 and 25.2, 32.1 and 32.4 of the MDR
    35 KB (5,853 words) - 16:58, 12 December 2023
  • the controller had violated Article 5(1)(a) GDPR, Article 12 GDPR, Article 13 GDPR, Article 15 GDPR and Article 25(1) GDPR. As a result, the DPA issued
    52 KB (7,936 words) - 22:32, 2 March 2024
  • this from happening, in violation with Article 24(1), Article 24(2), and Article 25(1) GDPR. According to Article 24(4) of the Finish Data Protection Act
    42 KB (6,579 words) - 08:46, 27 January 2022
  • necessary. For the intentional infringement of Article 25(1) GDPR and Article 5(1)(a), (c), and (e) GDPR, the authority imposed a pecuniary penalty of €14
    7 KB (936 words) - 16:39, 12 December 2023
  • UODO (Poland) - ZSPR.421.2.2019 (category Article 25(1) GDPR)
    (f), Article 5(2), Article 6(1), Article 7(1), Article 24(1), Article 25(1), Article 32(1)(b), Article 32(1)(c) and Article 32(1)(b), Article 32(1)(c) and
    71 KB (11,304 words) - 10:01, 17 November 2023
  • BlnBDI (Berlin) - 711.412.1 (category Article 25(1) GDPR)
    coming into force of the GDPR, the DPA found that the company still did not comply. How do Article 5(1)(e) and Article 25(1) GDPR apply to archives? The
    8 KB (965 words) - 16:38, 12 December 2023
  • HDPA (Greece) - 64/2022 (category Article 25(1) GDPR)
    of natural persons who decisions, in accordance with the provisions of the GDPR. The DPA examined the rules for the removal of identification data displayed
    3 KB (199 words) - 20:46, 13 December 2022
  • HDPA (Greece) - 4/2022 (category Article 25(1) GDPR)
    HDPA held that COSMOTE violated Article 25(1) GDPR, because the processing for statistical purposes under Article 89(1) GDPR should have been done with anonymised
    11 KB (1,274 words) - 10:37, 23 February 2022
  • Commissioner (Cyprus) - 11.17.001.008.029 (category Article 25(1) GDPR)
    Commissioner held that CYTA violated articles 5 (1), 24 (1) and (2), 25 (1) and (2) and 32 of the GDPR and instructed CYTA to establish such security measures
    3 KB (193 words) - 16:52, 6 December 2023
  • HDPA (Greece) - 30/2023 (category Article 25(1) GDPR)
    violation of article 5 par. 1 item. e' of the GDPR, b) reprimanded the OASA for the violations of the provisions of article 25 par. 1 and article 35 par. 1 of the
    6 KB (623 words) - 09:08, 25 October 2023
  • HDPA (Greece) - 61/2022 (category Article 25(1) GDPR)
    information provided to data subjects was less than that required by the GDPR, and the information was not provided in an intelligible and easily accessible
    6 KB (663 words) - 15:31, 6 December 2023
  • HDPA (Greece) - 50/2021 (category Article 25(1) GDPR)
    information in accordance with Article 13 GDPR. In addition, the HDPA found that the Ministry violated the obligation of Article 35(9) GDPR in relation to the expression
    5 KB (548 words) - 09:23, 12 October 2022
  • €283,000). It held that the controller violated Articles 25(1), 32(1)(b), 32(1)(d) and 32(2) GDPR by not taking appropriate technical and organizational
    7 KB (855 words) - 15:30, 30 October 2023
  • AZOP (Croatia) - Decision 18-05-2023 (category Article 25(1) GDPR)
    was fined €380,000 for violating Articles 6(1), 13(1) and (2), and 25(1) and (2) and 32(1)(a) and (d) GDPR. A sports betting agency, acting as the controller
    9 KB (1,276 words) - 15:25, 30 October 2023
  • AZOP (Croatia) - Decision 28-08-2019 (category Article 25(1) GDPR)
    of Article 5, Article 6, and Article 25 GDPR. It ordered the controller to comply with the data subject's erasure request pursuant to Article 17(1)(d)
    16 KB (2,373 words) - 15:31, 30 October 2023
  • CNIL (France) - MED-2019-027 (category Article 25(1) GDPR)
    design and default. The CNIL ordered the Ministry to comply with Article 24 and 25 GDPR regarding the collection and further processing of personal data
    21 KB (3,274 words) - 17:08, 6 December 2023
  • Finnish DPA found a retail chain to have breached Article 5(1)(e) GDPR, Article 25(1) GDPR and Article 25(2) GDPR for its lengthy storage of purchase behaviour
    61 KB (9,477 words) - 13:38, 12 January 2024
  • even though Article 32 GDPR stipulates such a technical measure for certain emails. It is important to note that only Article 6(1)(a) GDPR allows for such
    30 KB (4,562 words) - 15:27, 6 December 2023
  • APD/GBA (Belgium) - 03/2021 (category Article 25(1) GDPR)
    fulfilled. The school breaches Article 6(1)(b) in combination with Article 6(4) and Article 6(1) Articles 24 and 25 GDPR Furthermore, as the school continued
    32 KB (4,880 words) - 16:50, 12 December 2023
  • UODO (Poland) - DKN.5130.2815.2020 (category Article 25(1) GDPR)
    and Article 58(2)(b) in connection with Article 5(1)(f), Article 24(1), Article 25(1), Article 32(1) and (2) of 2 of Regulation EU 2016/679 of the European
    37 KB (5,819 words) - 09:58, 17 November 2023
  • APD/GBA (Belgium) - 74/2020 (category Article 25(1) GDPR)
    the basis of Article 58, paragraph 2, point b) GDPR and Article 100, §1, 5 ° WOG to be reprimanded for the infringement of Article 25 (1) GDPR; b. on the
    82 KB (12,100 words) - 17:01, 12 December 2023
  • AEPD (Spain) - PS/00268/2022 (category Article 25(1) GDPR)
    According to Article 72.1 LOPDGDD, the violation of data processing principles under Article 5 GDPR was considered very serious. Considering Article 25(1) GDPR
    63 KB (9,551 words) - 12:33, 13 December 2023
  • Court of Appeal of Brussels - 2020/AR/1333 (category Article 25(1) GDPR)
    5- □ 1-i; -J L ..J Brussels-2020 Court of Appeal / AR / 1333 p. 3 breach of articles 5.1.a} and 5.1.b), 6.1, 25.1 and 25.2, 32.1 and 32.4 of the GDPR read
    51 KB (7,792 words) - 11:43, 24 January 2022
  • controller had violated Article 5(1)(f) GDPR, Article 17(1) GDPR, Article 25(1) GDPR, Article 32(1) GDPR and Article 32(2) GDPR. As a result, the DPA issued
    56 KB (8,980 words) - 08:47, 4 March 2024
  • APD/GBA (Belgium) - 136/2023 (category Article 25(1) GDPR)
    violating Article 5(1)(f) GDPR, Article 5(1)(a) GDPR, Article 5(2) GDPR, Article 12 GDPR, Article 13 GDPR, Article 14 GDPR, Article 24(1) GDPR, and Article
    58 KB (9,184 words) - 16:49, 12 December 2023
  • UODO (Poland) - DKN.5101.25.2020 (category Article 25(1) GDPR)
    with Art. 5 sec. 1 lit. f, art. 24 sec. 1, art. 25 sec. 1, art. 32 sec. 1 lit. d, art. 32 sec. 2, art. 33 paragraph. 1 and art. 34 sec. 1 of the Regulation
    63 KB (10,088 words) - 09:52, 17 November 2023
  • NAIH (Hungary) - NAIH-2020/2204/8 (category Article 25(1) GDPR)
    (2) § 23, § 25, 25 / G. § (3), (4) and (6), 25 / H. § (2) paragraph 25 / M. § (2), 25 / N. §, 51 / A. § (1), Articles 52-54. §- in Section 55 (1) - (2), Sections
    60 KB (9,820 words) - 10:08, 17 November 2023
  • NAIH (Hungary) - NAIH/2020/66/21 (category Article 25(1) GDPR)
    regard to Client 1 that data management - infringed Article 25 (1) to (2) of the General Data Protection Regulation, - infringed Article 32 (1) (b) of the General
    67 KB (10,492 words) - 10:11, 17 November 2023
  • UODO (Poland) - DKN.5130.1354.2020 (category Article 25(1) GDPR)
    expressed in Article 5 (1 ) (a)) f, and reflected in the obligations set out in Article 24 (1), Article 25 (1), Article 32 (1 ) (b ) and (d) and Article 32 (2)
    74 KB (11,513 words) - 09:58, 17 November 2023
  • UODO (Poland) - DKN.5130.2024.2020 (category Article 25(1) GDPR)
    sec. 1 lit. a) and art. 58 sec. 2 lit. i) in connection with Art. 5 sec. 1 lit. f), art. 24 sec. 1, art. 25 sec. 1, art. 28 sec. 1 and 3 and article. 32
    75 KB (12,104 words) - 09:58, 17 November 2023
  • APD/GBA (Belgium) - 55/2021 (category Article 25(1) GDPR)
    data on the basis of Article 6.1.e GDPR ? - Did the administration sharing confidential data with a third party violates article 25 GDPR ? - Should the administration
    81 KB (13,211 words) - 16:59, 12 December 2023
  • processing carried out is in violation of Article 5(1)(f) GDPR, Article 25(1) GDPR, Article 32 GDPR and Article 35 GDPR. Especially, the controller cannot exclude
    119 KB (19,123 words) - 11:29, 16 August 2022
  • APD/GBA (Belgium) - 82/2020 (category Article 25(1) GDPR)
    artikel 100, §1, 2° WOG de buitenvervolgingstelling bevelen, of de klacht seponeren overeenkomstig artikel 95, §1, 1° of artikel 100, §1, 1° WOG (naargelang
    124 KB (18,772 words) - 17:01, 12 December 2023
  • UODO (Poland) - ZSOŚS.421.25.2019 (category Article 25(1) GDPR)
    5 sec. 1 lit. f, art. 5 sec. 2, art. 25 sec. 1, art. 32 sec. 1 lit. b, art. 32 sec. 1 lit. d, art. 32 sec. 2, art. 38 sec. 1, art. 39 sec. 1 lit. b and
    156 KB (25,012 words) - 10:01, 17 November 2023
  • EDPB - Binding Decision 2/2022 - 'Instagram' (category Article 25(1) GDPR)
    the performance of a contract (Article 6(1)(b) GDPR) and for legitimate interest (Article 6(1)(f) GDPR). Article 6(1)(b) GDPR In its original draft decision
    276 KB (38,206 words) - 09:46, 20 January 2023
  • DPC (Ireland) - IN-19-7-2 (category Article 25(1) GDPR)
    violated Article 25(1) GDPR by failing to take measures designed to implement the accuracy principle in the database, and Articles 5(2) and 24(1) GDPR by failing
    5 KB (620 words) - 13:13, 19 May 2021
  • HDPA (Greece) - 20/2022 (category Article 12(3) GDPR)
    violation of article 17 in combination with article 21 par. 3 and article 12 paragraph 3 of the GDPR and article 25 paragraph 1 of the GDPR. For its judgment
    16 KB (2,374 words) - 11:46, 18 August 2022
  • This amounted to a violation of Article 25(1) GDPR, Article 32(1)(b) GDPR, Article 32(1)(d) GDPR, Article 32(2) GDPR. Consequently, the DPA fined the
    5 KB (558 words) - 08:06, 26 September 2022
  • ANSPDCP (Romania) - Raiffeisen Bank SA (category Article 25(1) GDPR)
    violating Article 32(4) jo Article 32(1) and (2) GDPR (security of processing). In addition, a fine of €5,000 for violating Article 25(1) GDPR (data protection
    14 KB (1,905 words) - 15:22, 29 November 2022
  • ANSPDCP (Romania) - Fine against Bitfactor SRL (category Article 25(1) GDPR)
    laid down in Article 5(1)(f) GDPR. In this context, the DPA referred to Article 25(1) GDPR (data protection by design) and Recital 78 GDPR. As a result
    6 KB (708 words) - 08:12, 6 October 2022
  • APD/GBA (Belgium) - 29/2023 (category Article 25(1) GDPR)
    risk analysis. Therefore, the DPC found a violation of Article 25(1), 25(2), 5(1)(b) and 5(1)(f) GDPR, ordered Meta to comply with the provisions and imposed
    5 KB (536 words) - 14:11, 21 March 2023
  • HDPA (Greece) - 41/2022 (category Article 25(1) GDPR)
    thereby violating Article 13(2) GDPR. The investigated controllers did not comply with the storage limitation principle under Article 5(1) GDPR because the data
    14 KB (2,046 words) - 19:00, 21 September 2022
  • data free of charge in light of the principle of privacy by design (Article 25(1) GDPR). According to this principle, data protection issues should be taken
    14 KB (2,085 words) - 10:24, 4 November 2021
  • HDPA (Greece) - 13/2024 (category Article 25(1) GDPR)
    processing under Article 9 GDPR. Second, the HDPA also found a violation of the principle of lawfulness under Article 5(1a) of the GDPR. It found that the
    12 KB (1,511 words) - 16:01, 10 April 2024
  • Datatilsynet (Denmark) - 2021-441-10244 (category Article 25(1) GDPR)
    accordance with Article 32 (1) of the Data Protection Regulation. 1. 3.2. Article 25 of the Data Protection Regulation It follows from Article 25 (1) of the Data
    19 KB (2,832 words) - 14:47, 27 July 2022
  • data constituted a breach of Articles 5(1)(f) and 32 GDPR. Additionally, the controller violated Article 25(1) GDPR because it failed to implement a secure
    24 KB (3,588 words) - 13:43, 2 November 2022
  • HDPA (Greece) - 13/2021 (category Article 25(1) GDPR)
    that in accordance with Article 1 7 in in conjunction with Article 21 (3) and Article 12 (3) of the GIPA and Article 25 par. 1 of the GCP meet the conditions
    22 KB (3,167 words) - 07:59, 14 October 2021
  • APDCAT (Catalonia) - PS 28/2021 (category Article 25(1) GDPR)
    city council had violated Article 13 GDPR and Article 25(1) GDPR. However, since the deficiencies regarding Article 13 GDPR were corrected before the end
    42 KB (6,526 words) - 14:26, 24 November 2022
  • APD/GBA (Belgium) - 165/2023 (category Article 25(1) GDPR)
    violation of: 1. Article 5.1.f) and 5.2 of the GDPR, Article 24.1 of the GDPR, Article 25.1 of the GDPR and Articles 32.1 and 32.2 GDPR; 2. Articles 35.1, 35.2
    67 KB (9,908 words) - 11:09, 10 January 2024
  • APD/GBA (Belgium) - 60/2023 (category Article 25(1) GDPR)
    information obligations under Article 5(1)(a), Article 6(1), Article 12, Article 13, Article 24(1), Article 25(1) and Article 25(2). Share your comments here
    39 KB (5,541 words) - 08:17, 6 June 2023
  • controllers have violated Article 5(1)(a), Article 6(1), Article 13, paragraphs 1 and 2, Article 25, Article 32, paragraphs 1 and 2, and Articles 44 and
    44 KB (6,748 words) - 16:10, 21 March 2023
  • APD/GBA (Belgium) - 162/2022 (category Article 25(1) GDPR)
    (2) GDPR; b. a breach of Article 12(1) and (6) GDPR, Article 13(1) and (2) GDPR and Article 14(1) and (2) GDPR, Article 5(2) GDPR, Article 24(1) GDPR and
    71 KB (10,426 words) - 08:21, 23 November 2022
  • UODO (Poland) - DKN.5131.8.2022 (category Article 25(1) GDPR)
    the laptop theft, in breach of Article 32(1) GDPR. Moreover, the DPA found a violation of Articles 24(1) and 25(1) GDPR because the controller failed to
    48 KB (7,609 words) - 12:24, 23 November 2022
  • Datatilsynet (Norway) - 18/04147 (category Article 25(1) GDPR)
    violating Article 5(1) GDPR, Article 17(1)(a), Article 17(1)(d) and Article 25(1), cf. Article 5(1)(c), Article 5(1)(d), Article 5(1)(e) and Article 5(1)(f)
    47 KB (7,575 words) - 11:35, 18 November 2023
  • UODO (Poland) - DKN.5130.2559.2020 (category Article 25(1) GDPR)
    provisions of Article 5(1)(f) GDPR, Article 5(2) GDPR, Article 24(1) GDPR, Article 25(1) GDPR, Article 32(1) GDPR and Article 32(2) GDPR by: (a) failing
    62 KB (9,906 words) - 09:02, 11 October 2022
  • UODO (Poland) - DKN.5131.31.2022 (category Article 25(1) GDPR)
    controller €5,400 for infringements of Articles 5(1)(f) and 5(2) GDPR as well as Article 25(1) and Article 32(1) GDPR. First, the controller did not ensure adequate
    71 KB (11,306 words) - 10:51, 22 January 2024
  • The DPA found violations of Articles 5(1)(a)(c)(f), 9, 25(1)(2) and issued a fine of 25,000 euros under Article 83. An advertising billboard depicted a
    60 KB (9,523 words) - 08:00, 23 August 2023
  • APD/GBA (Belgium) - 24/2021 (category Article 7(1) GDPR)
    fairness and transparency (Article 5.1 a) GDPR), purpose limitation (Article 5.1 b) GDPR) and minimum data processing (Article 5.1 c) GDPR); 4) the legal basis
    110 KB (18,238 words) - 16:56, 12 December 2023
  • OLG München - 18 U 2822/19 Pre (category Article 25(1) GDPR)
    violated section 13(6) of the German Telemedia Act (TMG) or Article 4(7) GDPR and Artcicle 25(1) GDPR? The Higher Regional Court Munich dismissed the appeal
    59 KB (9,846 words) - 14:03, 20 September 2021
  • UODO (Poland) - DKN.5131.12.2020 (category Article 25(1) GDPR)
    comply with the principles under Article 5 GDPR, including the principle of integrity and confidentiality (Article 5(1)(f) GDPR). According to this principle
    74 KB (11,896 words) - 15:14, 7 March 2023
  • APD/GBA (Belgium) - 15/2023 (category Article 25(1) GDPR)
    regard resources. II.1. Article 5 (1) (a) and (2) of the GDPR and Article 6 (1) of the GDPR II.1.1. Article 5 (1) a) and Article 6 (1) GDPR with regard to legality
    105 KB (15,883 words) - 15:05, 8 March 2023
  • UODO (Poland) - DKN.5131.22.2021 (category Article 25(1) GDPR)
    that the controller breached Article 5(1)(f), Article 24(1), Article 25(1), Article 32(1)(b) and (d), and Article 32(2) GDPR due to a lack of a reliably
    68 KB (10,909 words) - 14:47, 25 October 2021
  • APD/GBA (Belgium) - 188/2022 (category Article 25(1) GDPR)
    of Article 5 of the GDPR, Article 24(1) of the GDPR and Article 25(1) paragraph 2 of the GDPR; and 2. a breach of Article 12 paragraph 1 and paragraph 4
    95 KB (14,325 words) - 14:27, 25 January 2023
  • UODO - DKN.5112.1.2020 (category Article 25(1) GDPR)
    controller under Article 24(1) GDPR, Article 25 (1) GDPR, Article 32(1)(b) GDPR and Article 32(1)(d) GDPR and Article 32 GDPR#2"Article 32(2) GDPR. Share blogs
    89 KB (14,285 words) - 12:21, 10 September 2021
  • UODO (Poland) - DKN.5112.1.2020 (category Article 25(1) GDPR)
    of the case (Article 107 § 3 of the Code of Administrative Procedure in connection with Article 77 § 1, Article 80, Article 8 § 1 and Article 11 of the Code
    110 KB (17,607 words) - 15:35, 3 January 2023
  • personal data during the promotional phone call. Article 5(1)(a), Article 6(1)(a) and Article 7 GDPR, for having carried out promotional telephone calls
    87 KB (13,867 words) - 13:11, 28 September 2023
  • WSA Warsaw (Poland) - II SA/Wa 2559/19 (category Article 25(1) GDPR)
    5 sec. 1 lit. f of Regulation 2016/679 (and reflected in the form of obligations set out in Article 24 (1), Article 25 (1) and Article 32 (1) (b) and
    90 KB (14,642 words) - 11:12, 18 November 2020
  • Article 5 GDPR (category GDPR Articles) (section (1) Principles)
    consent under Article 6(4) GDPR and further processing for a compatible purpose under Article 6(4) GDPR. See the commentary on Article 6(4) GDPR for details
    51 KB (6,355 words) - 08:25, 18 April 2024
  • UODO (Poland) - DKN.5130.2215.2020 (category Article 25(1) GDPR)
    sec. 1 lit. f), art. 24 sec. 1, art. 25 sec. 1, art. 28 sec. 1 and sec. 3, art. 32 sec. 1 and 2 and article. 34 sec. 1, as well as art. 83 sec. 1-3 and
    110 KB (17,650 words) - 12:27, 29 April 2022
  • (2016/679) Article 12(1), 2, 3, 4 and 6, Article 5(1)(c), Article 15, Article 17, Article 25, Article 58(2)(b) and (d), Article 83 paragraphs 1, 2, 3, 4
    139 KB (22,397 words) - 21:48, 13 July 2022
  • APD/GBA (Belgium) - 57/2023 (category Article 5(1) GDPR)
    violation of: 1. Article 5 (1) (a) and (2) and Article 6 (1) GDPR; 2. Article 5, Article 24 (1) and 25 (1) and (2) GDPR; 3. Article 12 paragraph 1, paragraph
    99 KB (15,129 words) - 09:21, 31 May 2023
  • violated Articles 5(2), 24 and 25(1) GDPR. At last, the DPA established a violation of Article 5(2), Article 24 and Article 13 GDPR, for failing to provide evidence
    131 KB (21,176 words) - 12:52, 20 December 2022
  • APD/GBA (Belgium) - 37/2021 (category Article 5(1)(b) GDPR)
    condition of necessity is maintained under Article 6.1 b) to f) of the GDPR. The article 6.1 of the GDPR replaces Article 7 of the Directive, without the relevant
    45 KB (6,780 words) - 16:57, 12 December 2023
  • flows by the SA pursuant to Article 58(2) GDPR or failure to provide access in violation of Article 58(1) GDPR. Article 83(6) GDPR is a superfluous provision
    55 KB (7,622 words) - 14:04, 7 November 2023
  • accuracy of Article 5(1)(d) GDPR and data protection by design of Article 25(1) GDPR. In addition, the DPA held that the controller violated Articles 5(1)(a) and
    149 KB (24,224 words) - 12:20, 2 January 2023
  • No Article 5 (1) (a) and (b), Article 6 (1), Article 6 (4) Article 12 (1), Article 13, Article 21 (1) and (2), Article 24 (1), Article 25 Article 1 (1)
    147 KB (23,028 words) - 13:36, 28 February 2023
  • justify it, in breach of Articles 5(1)(a) and 6 GDPR. Finally, the Italian DPA found a violation of Article 25(1) and (2) GDPR because the controller had not
    152 KB (24,743 words) - 14:39, 21 March 2023
  • infringement of Article 33(1) GDPR, a fine of €145,600 for infringement of Article 34(1) GDPR, and a fine of €316,800 for infringement of Article 5(1)(f) GDPR. In
    153 KB (24,570 words) - 15:11, 26 March 2024
  • Article 4 GDPR (category GDPR Articles) (section (1) Personal data)
    Articles 4(11), 6(1)(a), 7 and 8 GDPR. For the definition of 'consent', see the more commentary under Article 6(1)(a) GDPR and Article 7 GDPR. For the definition
    125 KB (16,328 words) - 16:01, 8 March 2024
  • security of the data, in violation of Article 32(1) and (2) GDPR and warned the controller for a violation of Article 25(1) GDPR. The DPA fined the controller
    6 KB (788 words) - 08:33, 31 May 2023
  • Article 32 GDPR (category GDPR Articles) (section (1) Measures appropriate to the risk)
    non-material damage. Article 32(1) GDPR reflects the principle of integrity and confidentiality enshrined in Article 5(1)(f) GDPR. The controller and the
    41 KB (5,197 words) - 12:17, 17 April 2024
  • DSB (Austria) - D130.1170 (category Article 7(3) GDPR)
    violation of Article 7(3) GDPR and it also failed to comply with the requirements set out in Article 5(1)(a) GDPR and Article 25(1) GDPR. Accordingly,
    5 KB (661 words) - 08:56, 27 September 2023
  • DPC (Ireland) - IN-21-9-1 (category Article 5(1)(a) GDPR)
    minimisation (Article 5(1)(c) GDPR), integrity and confidentiality (Article 5(1)(f) GDPR) and privacy by design and by default (Article 25 GDPR). These principles
    7 KB (858 words) - 12:25, 20 September 2023
  • CJEU - C807/21 - Deutsche Wohnen (category Article 83(4) GDPR)
    fined DW €14,385,000 for intentional infringement of Article 5(1)(a), (c) and (e) and of Article 25(1) GDPR. The DPA found that DW intentionally failed to take
    10 KB (1,543 words) - 13:53, 8 December 2023
  • Article 2 GDPR (category GDPR Articles) (section (1) Material scope)
    elements in Article 2(1) are fulfilled, the GDPR applies unless the processing falls under one of the exemptions named in Article 2(2)(a) to (d) GDPR. The first
    34 KB (4,652 words) - 12:07, 12 November 2023
  • AEPD (Spain) - PS/00120/2021 (category Article 25(1) GDPR) (section On Article 25 GDPR)
    of the GDPR, Article 6 of the GDPR, Article 9 of the GDPR, Article 12 of the GDPR, Article 35 of the RGPD, Article 13 of the RGPD, Article 25 of the RGPD
    337 KB (50,591 words) - 15:29, 5 August 2021
  • APD/GBA (Belgium) - 75/2023 (category Article 6(1)(f) GDPR)
    paying profiles. II.4. Article 12(1),(2) and (3), Article 17, Article 19, Article 24(1) and Article 25(1) AVG 63. Article 12 (1) GDPR stipulates that the
    77 KB (11,604 words) - 08:55, 29 June 2023
  • categories of data established in Article 9(2)(a) GDPR, Article 9(2)(c) GDPR, Article 9(2)(g) GDPR and Article 9(2)(i) GDPR directly correlate with a specific
    44 KB (5,905 words) - 14:00, 24 October 2023
  • (e.g. Article 25 (1) and (2), Article 28(1), Article 32(1) GDPR, Article 89(1) GDPR). These measures can also be regarded as measures under Article 24(1)
    30 KB (3,458 words) - 10:31, 25 April 2024
  • exercise on their behalf all rights foreseen under Articles 77 and 78 GDPR and Article 20 of L. 4624/2019. The mandate shall be given with a specific written
    23 KB (2,039 words) - 08:15, 25 April 2024
  • Article 49 GDPR (category GDPR Articles) (section (1) Derogations for Specific Situations)
    According to the final paragraph in Article 49(1) GDPR, when none of the derogations described above (Article 49(1)(a-g) GDPR) is applicable, transfers to third
    29 KB (3,500 words) - 08:54, 27 March 2023
  • provided for in Article 6(1)(a) GDPR or, as the case may be, Article 9(2)(a) GDPR, and consent is withdrawn according to Article 7(3) GDPR, data must be
    61 KB (8,488 words) - 15:47, 18 March 2024
  • reliance on Article 6(1)(f) GDPR or at least exercise the right to object under Article 21 GDPR. If the legal basis is Article 6(1)(f) GDPR (i.e. 'legitimate
    71 KB (9,532 words) - 13:30, 6 March 2024
  • Datatilsynet (Denmark) - Unknown (category Article 32(1) GDPR)
    was clear to the DPA that the principle of privacy by design under Article 25(1) GDPR had not been considered. Better testing of the platform before launching
    19 KB (2,823 words) - 13:59, 24 January 2024
  • Article 94 GDPR (category Article 94 GDPR)
    place from 25 May 2018 is no longer regulated by Directive 95/46/EC, but by the GDPR. This provision is to be differentiated from Article 99(1) GDPR, which
    13 KB (530 words) - 09:40, 3 October 2023
  • Article 91 GDPR (category Article 91 GDPR) (section (1) Conditions for the Derogation to Apply)
    Regulation (GDPR), Article 91 GDPR, p. 1263 (Oxford University Press 2020). Tosoni, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article
    25 KB (2,482 words) - 10:04, 19 March 2024
  • Article 97 GDPR (category Article 97 GDPR)
    recitals for Article 97 GDPR. Article 97 GDPR imposes a "comprehensive reporting obligation" upon the Commission. The first paragraph of Article 97 GDPR sets out
    16 KB (778 words) - 08:24, 19 October 2023
  • between Article 21(3) GDPR and Article 17 GDPR on the right to erasure must be considered. The tight relationship between Article 21(3) and Article 17(1)(c)
    49 KB (5,993 words) - 06:22, 16 June 2023
  • Article 35 GDPR (category GDPR Articles) (section (1) Mandatory DPIA)
    must also be involved in the drafting of the DPIA under Article 35(2) GDPR and Article 39(1)(c) GDPR, and their advice should be recorded by the controller
    52 KB (7,297 words) - 08:05, 18 July 2023
  • Article 99 GDPR (category Article 99 GDPR)
    European Union. 2. It shall apply from 25 May 2018. There is no relevant recital for Article 99 GDPR. Article 99 GDPR sets out the dates of the Regulation's
    12 KB (295 words) - 08:25, 19 October 2023
  • establishes an EU-wide penalty regime for violations under Article 83 GDPR, Article 84(1) GDPR dispenses with complete harmonisation. It does, however, provide
    19 KB (1,477 words) - 14:12, 7 November 2023
  • any appropriate assessment by the Authority. Violation of Article 5(2) GDPR and Article 25(1) GDPR, for not having taken effective action against undue promotional
    380 KB (62,114 words) - 15:20, 26 January 2022
  • Article 72 GDPR (category Article 72 GDPR) (section (1) Principle of simple majority)
    within the meaning of Article 72(1) GDPR. The GDPR does not contain detailed content requirements for the RoP. Article 74(2) GDPR only stipulates that the
    22 KB (2,266 words) - 08:26, 17 October 2023
  • Article 45 GDPR (category GDPR Articles) (section (1) Adequacy Decision)
    with the support of the EDPB in accordance with Article 70(1)(b) GDPR. According to Article 45(5) GDPR, the continued monitoring referred to in paragraph
    43 KB (5,641 words) - 14:58, 28 April 2022
  • APD/GBA (Belgium) - 165/2022 (category Article 5(1)(a) GDPR)
    (2) GDPR, Article 14 (1) and (1) 2 GDPR, Article 5 (2) GDPR, Article 24 (1) GDPR and Article 25 (1) GDPR. II. Motivation II.1. Interest of the complainant
    28 KB (4,010 words) - 13:40, 14 December 2022
  • proceedings under Article 79(1) GDPR where no subjective rights under the GDPR are concerned. For example, a data subject cannot use Article 79(1) GDPR to bring
    31 KB (3,550 words) - 11:11, 29 November 2023
  • APD/GBA (Belgium) - 07/2024 (category Article 5(1)(c) GDPR)
    those involved (Article 12.1, Article 13.1 and 13.2, Article 14.1 and 14.2, Article 5.2, Article 24.1, and Article 25.1 GDPR) 57 II.4.1. Position of the
    350 KB (51,369 words) - 09:25, 31 January 2024
  • Article 26 GDPR (category GDPR Articles) (section (1) Joint controllership)
    mentioned in Article 26(1), but also encompasses other obligations of controllers under the GDPR. EDPB: This extends to various obligations under the GDPR, including
    37 KB (3,915 words) - 12:49, 24 May 2023
  • access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), notification obligation
    44 KB (4,896 words) - 06:25, 16 June 2023
  • Article 41 GDPR (category GDPR Articles) (section (1) The monitoring body)
    clear from the wording of Article 41(1) GDPR. Article 41(1) GDPR does not define accreditation. Nonetheless, Article 41(2) GDPR provides a criterion against
    30 KB (2,720 words) - 14:02, 28 July 2023
  • Article 8 GDPR (category GDPR Articles) (section (1) Material scope)
    the information society service(s)." According to Article 4(25) GDPR, which in turn refers to Article 1(1) of Directive (EU) 2015/1535, an "information society
    19 KB (1,335 words) - 13:56, 24 October 2023
  • Article 88 GDPR (category Article 88 GDPR) (section (1) May, by law or by collective agreements)
    opening clause under Article 88(1) GDPR, any rules introduced must meet the criteria imposed by Article 88(2) GDPR. Lastly, Article 88(3) GDPR imposes an obligation
    32 KB (3,228 words) - 13:32, 30 November 2023
  • Article 3 GDPR (category GDPR Articles) (section (1) Establishment in the Union)
    the territorial scope of the GDPR (Article 3)’, 12 November 2019 (Version 2.1), p. 16 (available here) referring to Article 1(1)(b) Directive (EU) 2015/1535
    37 KB (4,635 words) - 13:29, 24 October 2023
  • Article 77 GDPR (category GDPR Articles) (section (1) Right to a formal complaint)
    compliance with the GDPR under Article 58(2)(d) GDPR or even ban it under Article 58(2)(f) GDPR. Therefore, complaints under Article 77 GDPR should extend to
    33 KB (3,641 words) - 09:51, 19 March 2024
  • further details see Article 14(1)(d) GDPR. Similar to the ex-ante information in Article 13(1)(e) and 14(1)(e) GDPR, Article 15(1)(c) GDPR requires the controller
    73 KB (9,896 words) - 15:46, 18 March 2024
  • Article 75 GDPR (category Article 75 GDPR) (section (1) The Secretariat)
    Protection Regulation (GDPR), Article 75 GDPR, p. 1105 (Oxford University Press 2020). Dix, in Kühling, Buchner, DS-GVO BDSG, Article 75 GDPR, margin number 6
    20 KB (1,347 words) - 14:21, 17 October 2023
  • Article 39 GDPR (category GDPR Articles) (section (1) DPO's Tasks)
    from any of the GDPR’s protections. → You can find all related decisions in Category:Article 39 GDPR Just as Article 38 GDPR, Article 39 GDPR also shows similarities
    23 KB (2,165 words) - 15:10, 27 July 2023
  • of such processing (see Article 5(1)(b) GDPR), the requirement to have a legitimate basis laid down by law (see Article 6(1) GDPR), the right to access and
    48 KB (5,978 words) - 15:57, 1 February 2024
  • this purpose (Article 52(4)(5)(6) GDPR). Elements of SAs' complete independence are also addressed in Article 53 GDPR and Article 54 GDPR. The CJEU in the
    47 KB (5,594 words) - 22:45, 1 April 2024
  • Article 14 GDPR (category Article 14 GDPR) (section Relationship with Article 13 GDPR)
    additional benefit of Article 14(1)(d) GDPR may be questionable, if one agrees that Article 14(1)(c) (see commentary on Article 13(1)(c) GDPR) already requires
    47 KB (5,644 words) - 17:49, 5 March 2024
  • Article 12 GDPR (category GDPR Articles) (section (1) Clear and transparent communication)
    under Article 13 should not be too long. Article 12 GDPR may be limited by Union or national Law in accordance with Article 23 GDPR. Article 12(1) GDPR
    76 KB (11,304 words) - 08:37, 4 March 2024
  • Article 64 GDPR (category Article 64 GDPR) (section (1) A mandatory opinion of the EDPB)
    64(2) GDPR). The remaining paragraphs of Article 64(3)-(8) GDPR lay down substantive rules and a detailed procedure for the EDPB’s opinions. Article 64(1) GDPR
    23 KB (2,079 words) - 16:07, 2 November 2023
  • controller is subject, under Article 6(1)(c) GDPR. In line with the general objectives of the GDPR, as outlined in Article 1 GDPR Article 16 TFEU, SAs are also
    27 KB (2,604 words) - 14:24, 16 January 2024
  • accordance with Article 58(1) GDPR. Article 90 GDPR was drafted with a view to regulate potential conflicts between the application of the GDPR on the one hand
    18 KB (1,599 words) - 12:26, 29 April 2022
  • possible "legitimate interest" under Article 6(1)(f) GDPR. Equally to Article 6(1)(c) GDPR, Article 6(2) and (3) GDPR require that Union or Member State
    108 KB (17,005 words) - 15:39, 18 March 2024
  • KG Berlin - 3 Ws 250/21 - 161 AR 64/21 (category Article 83 GDPR)
    DPA fined Deutsche Wohnen SE € 14,500,000 for violating Article 5(1)(e) and Article 25(1) GDPR as the company's archive system was structurally unable
    38 KB (5,956 words) - 11:41, 21 January 2022
  • difference between Article 42(1) GDPR and Article 42(2) GDPR is that in the former, the applicant for certification is subject to the GDPR, while in latter
    27 KB (2,452 words) - 14:26, 28 July 2023
  • Article 58 GDPR (category GDPR Articles) (section (1) Investigative powers)
    access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction (Article 18 GDPR), notification (Article 19 GDPR) or data
    46 KB (5,825 words) - 11:12, 7 November 2023
  • relevance of Article 29 GDPR were rooted in the fact that Article 28(3)(b) GDPR already seems to cover much of the scope of Article 29 GDPR. More specifically
    13 KB (674 words) - 13:15, 2 June 2023
  • the establishment of SAs are set out in Article 51(1) and 52 GDPR, Article 54(1)(a) GDPR repeats that these should be legislated for through a Member State's
    34 KB (3,649 words) - 13:19, 30 October 2023
  • Article 40 GDPR (category GDPR Articles) (section (1) Drawing up codes of conduct)
    up. Indeed, the wording of Article 40(1) establishes that they “shall encourage” this (emphasis added). Article 40(1) GDPR clarifies that codes of conduct
    44 KB (5,008 words) - 14:50, 28 July 2023
  • Article 56 GDPR (category GDPR Articles) (section Without prejudice to Article 55 GDPR)
    processing), Article 57 GDPR (tasks of SAs), Article 58 GDPR (powers of SAs), as well as Article 65 GDPR (dispute resolution by the board), Article 63 GDPR (consistency
    55 KB (7,446 words) - 22:28, 1 April 2024
  • Article 96 GDPR (category Article 96 GDPR)
    protected by Article 96 GDPR if it is found to be incompatible with other GDPR provisions. → You can find all related decisions in Category:Article 96 GDPR It follows
    13 KB (450 words) - 08:22, 19 October 2023
  • Article 74 GDPR (category Article 74 GDPR) (section (1) Tasks of the Chair)
    decisions in Category:Article 74 GDPR For more on this point, see Article 72 GDPR. Dix in Kühling, Buchner, DS-GVO BDSG, Article 74 GDPR, margin number 7 (C
    15 KB (808 words) - 09:44, 17 October 2023
  • Article 87 GDPR (category Article 87 GDPR)
    process them. This was already the case under Article 8(7) of the DPD, the precursor of Article 87 GDPR. In many Member States, the processing of NIN and
    15 KB (660 words) - 09:37, 1 December 2023
  • Article 76 GDPR (category Article 76 GDPR) (section (1) Confidentiality, Where Necessary)
    in the EDPB's Rules of Procedure (“RoP”). Article 33(1) RoP stipulates that in “accordance with Art 76 (1) GDPR”, discussions of the Board and of expert
    15 KB (787 words) - 08:17, 19 October 2023
  • will not have to submit another request for erasure under Article 17(1)(b) GDPR. Article 7(4) GDPR provides some useful guidance on the factors to be taken
    31 KB (3,489 words) - 16:00, 8 March 2024
  • one of the 'other administrative or non-judicial' remedies, which Article 78(2) GDPR refers to. If the DPA decides to uphold their decision, they will
    10 KB (1,078 words) - 06:40, 26 March 2023
  • Article 59 GDPR (category GDPR Articles)
    accordance with Article 58(2) [GDPR]”. These is a reference to the information that SAs must keep in internal records according to Article 57(1)(u) GDPR. The report
    15 KB (718 words) - 15:31, 19 October 2023
  • accountability (Article 5 (2) and 24 (1), (2) GDPR), privacy by design (Article 25 (1) GDPR) and as controller towards its data processors (Article 28 GDPR). Consequently
    144 KB (23,155 words) - 15:46, 6 December 2023
  • Article 10 GDPR (category GDPR Articles)
    from Article 6(1) GDPR and comply with the principles enshrined in Article 5 GDPR. Additionally, the processing will still be subject to other GDPR provisions
    17 KB (1,768 words) - 15:41, 18 March 2024
  • Article 67 GDPR (category Article 67 GDPR)
    Category:Article 67 GDPR See EDPB, State of Play - IMI for GDPR purposes, 27 June 2018 (available here). See EDPB, 2019 Annual Report, Section 4.3.1 (available
    15 KB (810 words) - 16:13, 2 November 2023
  • Article 20 GDPR (category GDPR Articles) (section (1) Right to data portability)
    consent pursuant to point (a) of Article 6(1) or point (a) of Article 9(2) or on a contract pursuant to point (b) of Article 6(1); and (b) the processing is
    40 KB (5,349 words) - 07:05, 1 June 2023
  • Article 44 GDPR (category GDPR Articles)
    important to note that Article 13(1)(f) GDPR, Article 14(1)(f) GDPR, Article 15(1)(c) GDPR and Article 15(2) GDPR, make specific reference to transfers of personal
    21 KB (1,831 words) - 08:51, 27 March 2023
  • Article 19 GDPR (category GDPR Articles)
    of Article 15(1)(c) GDPR, which permits in certain cases that the information provided is limited to "categories of recipient[s]": Article 15 GDPR is a
    19 KB (1,436 words) - 12:35, 12 May 2023
  • Article 48 GDPR (category GDPR Articles)
    subject to the GDPR or, in cases where they are not established in the EU, act within the material and territorial scope of the GDPR. Article 48 GDPR refers to
    14 KB (716 words) - 15:19, 28 April 2022
  • Article 63 GDPR (category Article 63 GDPR)
    to in Article 46(2)(d) GDPR, contractual clauses referred to in Article 46(3)(a) GDPR, or binding corporate rules within the meaning of Article 47 GDPR
    15 KB (851 words) - 06:55, 29 April 2022
  • Article 93 GDPR (category Article 93 GDPR) (section (1) Implementing acts)
    unlike delegated acts made under Article 92 GDPR. Article 93(2) GDPR explicitly provides for the application of Article 5 of Regulation (EU) No 182/2011
    17 KB (1,096 words) - 08:19, 19 October 2023
  • Article 69 GDPR (category Article 69 GDPR) (section (1) The Board shall act independently)
    proposed amendments to the GDPR (pursuant to Article 70(1)(b) GDPR). Although not explicitly mentioned in Article 69(2) GDPR, the requirement that the Board
    18 KB (1,327 words) - 12:36, 14 December 2023
  • Article 71 GDPR (category Article 71 GDPR) (section (1) Obligation to prepare an annual report)
    practices published under Article 70(3) GDPR. Though Article 70(3) GDPR already obliges the EDPB to make these public, Article 71(2) GDPR ensures that the public
    15 KB (1,196 words) - 08:15, 19 October 2023
  • Article 16 GDPR (category GDPR Articles)
    However, Article 5(1)(d) GDPR gives the controller some leeway to continue processing inaccurate data - see more details under Article 5(1)(d) GDPR. Article
    23 KB (2,489 words) - 23:24, 6 March 2024
  • Article 43 GDPR (category GDPR Articles) (section (1-5) The certification body)
    Recital 167 GDPR and Article 291 TFEU, the aim of implementing acts is to “ensure uniform conditions for implementing” the GDPR. In its GDPR Certification
    22 KB (1,634 words) - 14:40, 28 July 2023
  • organisation-fined-for-gdpr-rule-breach-1.4255692?mode=amp https://www.irishlegal.com/article/tusla-fined-40-000-in-second-gdpr-breach https://www.dataprotection
    8 KB (1,034 words) - 14:13, 20 August 2021
  • Article 31 GDPR (category GDPR Articles) (section Supporting provision to Article 58 GDPR)
    falls outside the scope of Article 57 GDPR should be deemed inadmissible for the purposes of Article 31 GDPR. Article 31 GDPR can be read as a supporting
    22 KB (2,042 words) - 14:29, 20 November 2023
  • Article 66 GDPR (category Article 66 GDPR) (section (1) Adoption of provisional measures)
    binding decision under Article 66 GDPR, at the request of the Hamburg SA which adopted provisional measures under Article 66(1) GDPR, based on its consideration
    20 KB (1,590 words) - 16:11, 2 November 2023
  • Article 50 GDPR (category GDPR Articles)
    exchange of knowledge between them. This way, Article 50 GDPR expands the exhortation under Article 57(1)(g) GDPR that calls for cooperation between EU DPAs
    17 KB (1,142 words) - 15:41, 28 April 2022
  • Article 98 GDPR (category Article 98 GDPR)
    accordance with Article 98'. → You can find all related decisions in Category:Article 98 GDPR The CJEU has yet to rule on Article 98 GDPR. Nonetheless, the
    15 KB (943 words) - 09:58, 8 November 2023
  • Article 95 GDPR (category Article 95 GDPR)
    situation, Article 95 GDPR will not be relevant, and the GDPR applies as normal. Notably, Recital 173 GDPR, which relates to Article 95 GDPR, omits reference
    20 KB (1,539 words) - 08:21, 19 October 2023
  • Article 73 GDPR (category Article 73 GDPR) (section (1) Chair, deputy chairs and their election)
    simple majority principle under Article 72(1) GDPR would have applied regardless of Article 73(1) GDPR. In addition, the GDPR explicitly legislates for a simple
    19 KB (1,530 words) - 14:23, 12 October 2023
  • Article 82 GDPR (category GDPR Articles) (section (1) Right to receive compensation)
    specific rules. Article 82 GDPR introduces a right to compensation for damage caused as a result of an infringement of the GDPR. Article 82(1) contains the
    33 KB (4,215 words) - 09:57, 19 March 2024
  • Article 68 GDPR (category Article 68 GDPR) (section (1) Legal personality)
    decisions pursuant to Article 65 GDPR (Article 70(1)(t) GDPR). Article 68 GDPR is the first of nine Articles (Articles 68-76 GDPR) governing the EDPB set
    20 KB (1,632 words) - 10:01, 11 October 2023
  • category of data. Part 1 deals with processing within the scope of the GDPR. Part 2 deals with processing outside of the scope of the GDPR. Part 3 deals with
    18 KB (2,488 words) - 15:22, 14 December 2021
  • first glance, Article 92 GDPR's wording seems to be in conflict with Article 290(1) TFEU, but in actuality it is not. Article 92(2) GDPR must be read in
    19 KB (1,525 words) - 08:18, 19 October 2023
  • subjects - which would be counterproductive. Article 11 GDPR is meant to address this matter. Under Article 11(1) GDPR, when a processing operation does not or
    20 KB (1,854 words) - 16:32, 8 March 2024
  • Regulation (GDPR): A Commentary, Article 38 GDPR, p. 707 (Oxford University Press 2020). Bergt, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number
    29 KB (2,951 words) - 14:19, 25 July 2023
  • resolution mechanism under Article 65 GDPR in connection with Article 63 GDPR is triggered (Article 60 (4) GDPR). Article 60(2) GDPR clarifies that also in
    35 KB (4,017 words) - 16:04, 18 March 2024
  • Article 27 GDPR (category GDPR Articles) (section (1) Conditions for applicability)
    with the GDPR (Article 31 GDPR). Direct liability of the representative is limited to the obligations set out in Article 30 and Article 58(1)(a) GDPR. Article
    25 KB (2,418 words) - 14:11, 24 May 2023
  • request (Article 61(5) GDPR), the requesting SA may adopt a provisional measure on the territory of its Member State under Article 55(1) GDPR. If the SA
    24 KB (2,181 words) - 11:46, 15 January 2024
  • Article 62 GDPR (category Article 62 GDPR) (section (1) The power to conduct joint operations)
    framework of voluntary cooperation provided for in Article 62(1) GDPR is partly supplemented by Article 62(2) GDPR, which contains several cases in which joint
    22 KB (1,915 words) - 13:46, 15 January 2024
  • constituting a breach of Article 12(2) GDPR and Article 12(3) GDPR, as well as Article 15 GDPR, Article 17 GDPR and Article 21(2) GDPR. Thus, the calls carried
    63 KB (9,986 words) - 12:04, 11 October 2023
  • requirements of data minimization (Article 5(1)(c) GDPR) and storage limitation (Article 5(1)(e) GDPR). Under Article 30(1)(f) GDPR, where possible, the controller
    31 KB (3,327 words) - 15:31, 5 June 2023
  • leeway exists only in cases of Article 64(2) GDPR but not the context of Article 70(2) GDPR. According to Article 70(3) GDPR, the EDPB is obligated to “forward
    27 KB (3,038 words) - 12:19, 11 October 2023
  • the competent supervisory authority of such a breach. Article 34(1) GDPR differs from Article 33 GDPR. Instead of having to notify the supervisor authority
    37 KB (3,962 words) - 15:20, 16 June 2023
  • Article 46 GDPR (category GDPR Articles) (section (1) Scope)
    access (Article 15 GDPR), rectification (Article 16 GDPR), deletion (Article 17 GDPR), restriction of processing (Article 18 GDPR), objection (Article 21 GDPR)
    34 KB (3,646 words) - 08:53, 27 March 2023
  • Article 86 GDPR (category Article 86 GDPR) (section The GDPR remains applicable)
    Press 2020). Spiecker et al., GDPR Article-by-Article Commentary (2023), p 1090. Spiecker et al., GDPR Article-by-Article Commentary (2023), p 1090. CJEU
    22 KB (2,177 words) - 10:01, 19 March 2024
  • Article 80 GDPR (category GDPR Articles) (section Requirements under Article 80(1) GDPR)
    complaint under Article 77(1) GDPR on behalf of the data subject and to represent the them before all supervisory authorities (“SA”) (Article 4(21) GDPR). Secondly
    26 KB (2,575 words) - 15:50, 9 November 2023
  • Article 47 GDPR (category GDPR Articles) (section (1) Binding Corporate Rules)
    other DPAs concerned. The BCR Lead the submits, following Article 64(1) GDPR and Article 64(4) GDPR, a draft decision to the EDPB. The EDPB, in turn, issues
    29 KB (2,823 words) - 15:15, 28 April 2022
  • deadline of Article 36(1) GDPR, and it is still disputed whether the outcome of the procedure rather resembles that of Article 58(3)(a) GDPR or Article 58(3)(b)
    31 KB (3,646 words) - 08:51, 21 July 2023
  • the basis of (i) its legitimate interest (Article 6(1)(f) GDPR) or (ii) the public interest (Article 6(1)(e) GDPR). Hence, data subjects may find themselves
    32 KB (3,730 words) - 08:43, 7 March 2024
  • into force of the GDPR. Spiecker et al., GDPR Article-by-Article Commentary (2023), p 1073. Spiecker et al., GDPR Article-by-Article Commentary (2023)
    33 KB (3,748 words) - 14:25, 7 November 2023
  • Article 81 GDPR (category GDPR Articles) (section Scope of Article 81 GDPR)
    explicit wording of Article 81 GDPR does not limit its application to proceedings instigated either under Article 78 GDPR or Article 79 GDPR. Secondly, the
    27 KB (2,619 words) - 14:52, 16 November 2023
  • the SAs' tasks, please refer to Article 57 GDPR and for their powers please refer to Article 58 GDPR. See Recital 122 GDPR. In this respect, reference should
    29 KB (2,894 words) - 23:06, 1 April 2024
  • which would be competent under Article 55(1) GDPR, as provided in Article 56 GDPR in connection with Article 60 GDPR. For more information see commentary
    35 KB (3,971 words) - 21:34, 1 April 2024
  • categories of data listed under Article 9(1) GDPR. There have been conflicting arguments as to whether Article 22(1) GDPR lays down a right or a general
    31 KB (4,768 words) - 06:24, 16 June 2023
  • or infringes the GDPR or any other applicable laws, including national ones. See commentary under Article 77 GDPR. Article 78(1) GDPR establishes both
    30 KB (3,874 words) - 10:46, 7 December 2023
  • Article 1 GDPR (category GDPR Articles) (section (1) Subject-matter)
    the application of the GDPR. You can find further details about the territorial scope in Article 3 GDPR. According to Article 1(2), the Regulation generally
    28 KB (3,831 words) - 16:21, 14 March 2024
  • agreement on joint responsibility as required under Article 26(1) of the GDPR. Article 33(1) GDPR outlines that controllers (as defined above) have an
    54 KB (6,536 words) - 08:22, 16 June 2023
  • Hence, Article 89(2) and (3) GDPR also allow for specific derogation to the GDPR for these purposes, as further detailed below. Article 89(1) GDPR provides
    29 KB (3,695 words) - 13:44, 21 March 2024
  • Article 65 GDPR (category GDPR Articles) (section (1) Dispute resolution mechanism)
    lead SA (“LSA”) (Article 65(1)(b) GDPR), and where a SA is not following an opinion of the EDPB (Article 6(1)(c) GDPR). Article 65(1)(a) GDPR addresses the
    33 KB (4,185 words) - 16:09, 2 November 2023
  • surveillance cameras, it was therefore in breach of Article 37(1)(b) GDPR by not having a DPO. Article 37(1) GDPR specifies three conditions in which the designation
    43 KB (4,904 words) - 12:59, 21 July 2023
  • the parties. Section 100 of the Slovak Data Protection Act implements Article 77 GDPR. The complaint shall include (Section 100 (3)): The name, surname, correspondence
    9 KB (1,006 words) - 07:13, 7 July 2021
  • 1983 - 1 BvR 209/83, 1 BvR 269/83, 1 BvR 362/83, 1 BvR 420/83, 1 BvR 440/83, 1 BvR 484/83 (in DE) (Abstract in EN) - ECLI:DE:BVerfG:1983:rs19831215.1bvr020983
    18 KB (1,831 words) - 13:49, 3 November 2022
  • APD/GBA (Belgium) - 149/2022 (category Article 5(1)(b) GDPR)
    Violations of Article 5(1)(a) GDPR and Article 6(1) GDPR The DPA held that the controller did not violate Article 5(1)(a) GDPR and Article 6(1) GDPR. The DPA
    89 KB (13,017 words) - 15:07, 2 November 2022
  • commentary to Article 60 GDPR, Article 61 GDPR, Article 62 GDPR, Article 63 GDPR, Article 64 GDPR, Article 65 GDPR, Article 66 GDPR and Article 56 GDPR. The SA
    60 KB (7,796 words) - 20:12, 1 April 2024
  • OLG Hamm - 7 U 19/23 (category Article 82 GDPR)
    Art. 82 Para. 1, Para. 2, Art. 5 Para. 1 lit. a Var. 1, Article 6 paragraph 1 subparagraph. 1 lit. 1, Article 6 paragraph 1 subparagraph. 1 lit. a, Art.
    130 KB (21,874 words) - 09:43, 15 February 2024
  • CJEU - C-311/18 - Schrems II (category Article 2(2) GDPR)
    under Article 57(1)(f) of the GDPR, each supervisory authority is required on its territory to handle complaints which, in accordance with Article 77(1)
    12 KB (1,780 words) - 17:22, 10 March 2022
  • elements. Infringement of Article 6 and 9 GDPR qualifies for the maximum amount for administrative fines as set out in Article 83(5) GDPR: 20,000,000 € or 4%
    18 KB (2,375 words) - 16:17, 6 December 2023
  • protection authorities (Art. 78.1 GDPR), as well as by the possibility to bring actions directly in court (Art. 79 GDPR). Against the decisions that put
    15 KB (1,875 words) - 16:18, 13 July 2022
  • IMY (Sweden) - DI-2020-11397 (category Article 44 GDPR)
    subjects guaranteed by Article 44 GDPR and consequently breached Article 44 GDPR. The DPA issued a fine of 300,000 SEK (approx. €25,000). The controller
    121 KB (13,722 words) - 15:16, 5 July 2023
  • than those expressly indicated in Article 22(1), with the exception of personal data referred to in Article 10 GDPR. This means that data concerning criminal
    9 KB (1,215 words) - 16:58, 18 May 2021
  • obligation of the controller (Article 6 (1) (c)) or to perform a public interest task or exercise public authority paragraph (e)). Article 6 (3) of the Data Protection
    41 KB (6,555 words) - 08:37, 4 March 2024
  • CNIL (France) - SAN-2020-012 (category Article 26(1) GDPR)
    in the same article 83. 111. Article 83 of the GDPR, as referred to in Article 20, paragraph III, of the Data Protection Act, provides: 1. Each supervisory
    93 KB (14,936 words) - 17:09, 6 December 2023
  • practice. Recital 1: The protection of natural persons in relation to the processing of personal data is a fundamental right. Article 8(1) of the Charter
    182 KB (24,065 words) - 13:40, 9 July 2021
  • OLG Schleswig - 17 U 15/21 (category Article 6(1)(e) GDPR) (section Article 6(1)(e) GDPR)
    processing by the defendant can only be Article 6 (1) sentence 1 lit e) DSGVO (see b) or Article 6 (1) sentence 1 lit f) DSGVO (see c), the requirements
    51 KB (8,215 words) - 09:55, 13 May 2022
  • Moreover, the information provided as per Article 13 GDPR were not compliant with the requirements of Article 12 GDPR in light of the fact that TikTok services
    17 KB (2,519 words) - 15:55, 6 December 2023
  • of articles 38.1, 38.3, 39.1 a) and 39.1 b) of the GDPR; - to issue an injunction against Company A to comply with Article 38.1 of the GDPR, within four
    66 KB (9,458 words) - 19:42, 4 September 2021
  • Regulation Article 5 paragraph 1 subparagraph a Article 7 Article 9 Data Protection Act Section 6 subsection 1 paragraph 1 Insurance Contract Act Section 1 and
    49 KB (7,496 words) - 14:44, 24 January 2024
  • Helsingin hallinto-oikeus (Finland) - 116/2024 (category Article 5(1)(a) GDPR)
    life insurance company had breached Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, Article 9 GDPR and Article 25(2) GDPR as its as its practice was to process
    41 KB (6,133 words) - 10:29, 25 March 2024
  • violated Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, Article 9 GDPR and Article 25(2) GDPR. As a result, and in accordance with Article 58(2)(d) GDPR, the
    60 KB (9,117 words) - 14:46, 24 January 2024
  • violated Article 5(1)(e) GDPR and Article 25(2) GDPR. As a result, the DPA issued a reprimand to the controller in accordance with Article 58(2)(b) GDPR. Pursuant
    77 KB (12,352 words) - 07:20, 23 April 2024
  • AEPD (Spain) - PS/00240/2019 (category Article 5(1)(b) GDPR)
    given that Article 6(1), Article 5(1)(a), Article 5(1)(d), Article 5(1)(c), and Article 14 GDPR were infringed in connection to Article 5(1)(b), the AEPD
    602 KB (102,229 words) - 14:21, 13 December 2023
  • AEPD (Spain) - EXP202206735 (category Article 6 GDPR)
    according to article 4.1 of the GDPR, is data personnel and their protection, therefore, is the subject of said Regulation. In article 4.2 of the GDPR defines
    75 KB (12,421 words) - 13:23, 13 December 2023
  • BVwG - W258 2217446-1 (category Article 4(1) GDPR)
    personal data under Article 9(1) GDPR. Their processing would require the data subjects' explicit consent under Article 9(2)(a) GDPR and § 151(4) GewO,
    79 KB (12,652 words) - 09:41, 10 September 2021
  • Rb. Rotterdam - C/10/576074/HA RK 19-694 (category Article 15(3) GDPR)
    referred to as [applicant] and the State. 1 The procedure 1.1. An application dated 30 January 2019 with productions 1 to 7 was received at the Registry of
    15 KB (2,504 words) - 16:27, 10 March 2022
  • Articles 5(1)(a), 12(1) and 13(1)(c) GDPR within three months, to refer not only to information provided on data processed pursuant to Article 6(1)(b) GDPR, but
    53 KB (8,413 words) - 14:10, 30 January 2023
  • fairness of processing (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), and data protection by default (Article 25(2) GDPR). The DPA suggested
    73 KB (11,237 words) - 05:34, 21 July 2022
  • artistic or literary purposes, only Article 24, Article 26, Article 28, Article 29, Article 32, and Article 40- Article 43 applies, following § 3. Special
    8 KB (1,064 words) - 12:53, 23 June 2023
  • HDPA (Greece) - 26/2023 (category Article 15 GDPR)
    provide for the possibility of bringing such actions of Article 25 of the Code of Civil Procedure1. 1 See, by way of example, the Authority's Decision No 73/2018
    14 KB (2,181 words) - 11:27, 13 September 2023
  • enshrined in Article 5(1)(d). Finally, the DPA also considered that the lack of any mechanism to check the age of the users entailed a violation of Article 8 GDPR
    14 KB (2,049 words) - 07:46, 1 August 2023
  • IMY (Sweden) - DI-2020-11370 (category Article 44 GDPR)
    be established on Article 45. Article 46.1 provides, among other things, that in the absence of a decision in accordance with Article 45.3 a personal data
    131 KB (14,752 words) - 08:36, 5 July 2023
  • meaning that no violation of Article 5(1)(e) GDPR could be established. Integrity and confidentiality - Article 5(1)(f) GDPR As explained above, the DPA
    429 KB (58,279 words) - 09:12, 2 November 2022
  • VK Baden-Württemberg - 1 VK 23/22 (category Article 44 GDPR)
    within the meaning of Article 4 no. 2 of the GDPR and the term "transfer" within the meaning of Article 44 et seq. of the GDPR. GDPR had to be differentiated
    62 KB (10,113 words) - 12:48, 17 August 2022
  • BVwG - W211 2210458-1/10 (category Article 2(1) GDPR)
    according to To 1): € 1.200,00 To 2): € 300,00 To 3): € 300,00 . . . In total: € 1.800 To 1): 3 days To 2): 1 day To 3): 1 day ... In total: 5 days Ad 1): Art.
    92 KB (15,435 words) - 16:00, 22 March 2022
  • LG Köln - 33 O 376/22 (category Article 6(1)(b) GDPR)
    application 1.b., from §§ 1, 3 para. 1 no. 1, 4 UKlag in conjunction with §§ 307 para. 1, para. 2 no.1 in conjunction with Art. 5 para. 1 lit. a), Art
    66 KB (9,990 words) - 12:30, 29 January 2024
  • VGH Baden-Württemberg - 1 S 397/19 (category Article 5(1)(d) GDPR)
    analogous to Article 18 (1)(a) GDPR the Court held that § 12 of the German Registration Law explicitly exludes the application of Article 18 (1)(a) GDPR. According
    112 KB (19,310 words) - 08:08, 23 June 2022
  • context Article 29 of the Data Protection Act 2019 establishes exceptions in Article 9(1) GDPR, Article 15 GDPR, Article 16 GDPR, Article 18(1)(a) GDPR, Article
    10 KB (1,037 words) - 14:52, 10 July 2020
  • minor, following Article 5(5) UAVG. In all other situations, the age of consent is 16 years, following Article 5(1) UAVG. Pursuant to Article 43 of the Dutch
    7 KB (764 words) - 07:50, 6 May 2024
  • CJEU - C-77/21 - Digi (category Article 5(1)(b) GDPR)
    regarding Articles 5(1)(b) GDPR and 5(1)(e) GDPR and held that national courts had to determine, using the factors of Article 6(4) GDPR, whether further processing
    49 KB (7,800 words) - 09:22, 5 January 2024
  • in particular of children was in breach of Article 5, Article 6, Article 8, Article 9, and Article 25 GDPR. Consequently, the DPA urgently imposed upon
    36 KB (5,598 words) - 10:15, 8 February 2023
  • Personvernnemnda (Norway) - 2021-03 (category Article 5(1)(a) GDPR)
    Ordinance Article 6 No. 1 letter f, for failure to assess protests, cf. Article 21, and for lack of information, cf. Article 13. 2. Pursuant to Article 58 (2)
    25 KB (4,046 words) - 18:37, 5 March 2022
  • Court of Appeal of Brussels - 2022/AR/549 (category Article 17(3)(e) GDPR)
    lawfulness, the Litigation Chamber concludes that Article 5.1.a. of the GDPR in conjunction with Article 6 of the GDPR have not been complied with with regard to
    37 KB (5,765 words) - 09:53, 14 December 2023
  • APD/GBA (Belgium) - 81/2020 (category Article 5(1)(c) GDPR)
    subjects required by Article 12.2. of the GDPR. 8.1.3. As for the breach of the principle of minimization (article 5.1 c) of the GDPR) 8.1.3.1. In view of the
    127 KB (21,484 words) - 17:01, 12 December 2023
  • LG Köln - 28 O 138/22 (category Article 82 GDPR)
    Sections 1004 analogously, Section 823 (1) and (2) BGB in conjunction with Article 6 (1) GDPR and Article 17 GDPR. Claims under data protection law could
    39 KB (6,362 words) - 14:01, 22 June 2023
  • AEPD (Spain) - EXP202201721 (category Article 6(1) GDPR)
    the violation of the GDPR: violation of article 6.1, violation typified in its article 83.5.a). IV Secondly, article 32 of the GDPR “Security of processing”
    79 KB (12,408 words) - 13:24, 13 December 2023
  • Court of Appeal of Brussels - 2019/AR/1600 (category Article 5(1)(c) GDPR)
    connection with the violation of article/and 5.1. c); 6.1.; 13.1. (c);13.1(e) and13.2(a)AVG: r PAGE 01-00001582885-0002-0033-01- □1-� r L _JCourt of Appeal Brussels
    60 KB (9,144 words) - 16:17, 22 March 2022
  • AEPD (Spain) - E/03276/2021 (category Article 6(1)(a) GDPR)
    the presumed responsible for the administrative offense. Article 64 of Law 39/2015, of October 1, on Administrative Procedure Common of Public Administrations
    10 KB (1,288 words) - 13:39, 13 December 2023
  • GDPR, Article 9 GDPR, Article 10 GDPR, Article 30 GDPR and Article 34 GDPR, as well as the provision of the PDPA governing processing of personal data
    10 KB (1,440 words) - 08:54, 17 January 2020
  • AEPD (Spain) - EXP202100764 (category Article 5(1)(f) GDPR)
    party, respectively. III Article 5.1.f) of the GDPR Article 5.1.f) “Principles relating to processing” of the GDPR establishes: "1. The personal data will
    34 KB (5,184 words) - 13:22, 13 December 2023
  • CNIL (France) - SAN-2020-009 (category Article 5(1)(a) GDPR)
    with the principle of fair and transparent processing contained in Article 5(1)(a) GDPR? Is the information relating to personal data processing operations
    48 KB (7,404 words) - 17:09, 6 December 2023
  • violating Article 5(1)(c) and Article 5(1)(e) GDPR. The DPA of Berlin fined Deutsche Wohnen SE for violating Article 5(1)(c) and Article 5(1)(e) GDPR, because
    36 KB (5,810 words) - 13:09, 21 January 2022
  • Datatilsynet (Denmark) - 2018-32-0357 (category Article 5(1)(a) GDPR) (section 1. Decision)
    The heading of Article 6(1) and the wording “has given” in Article 6(1)(a) support this interpretation. It follows logically from Article 6 and Recital
    65 KB (9,767 words) - 16:22, 6 December 2023
  • HDPA (Greece) - 28/2023 (category Article 58(2) GDPR)
    council in Greece to cease their processing activities, under Article 58(2) GDPR and Article 15(8) of Law 4624/2019, because of an unresolved data breach
    9 KB (1,211 words) - 20:32, 8 January 2024
View (previous 250 | ) (20 | 50 | 100 | 250 | 500)