Search results

From GDPRhub
  • Article 77 GDPR (category GDPR Articles) (section (2) Duty to inform the data subject)
    compliance with the GDPR under Article 58(2)(d) GDPR or even ban it under Article 58(2)(f) GDPR. Therefore, complaints under Article 77 GDPR should extend to
    33 KB (3,641 words) - 09:51, 19 March 2024
  • with Article 58(2)(d) GDPR, the DPA ordered the controller to bring its processing operations into compliance with the provisions of Article 9 GDPR. The
    49 KB (7,496 words) - 14:44, 24 January 2024
  • HDPA (Greece) - 27/2020 (category Article 58(2)(d) GDPR)
    recommendations that are included in the confidential report according to Article 58(2)(d) GDPR and inform the HDPA accordingly. Share your comments here! Share
    3 KB (224 words) - 15:35, 6 December 2023
  • BVwG - W258 2217446-1 (category Article 58(2)(d) GDPR)
    affinity" on the power of redress under Article 58(2)(d) of the DPA. In fact, it should have relied on Article 58(2)(f) of the DSGVO. In principle, this must
    79 KB (12,652 words) - 09:41, 10 September 2021
  • Moreover, the information provided as per Article 13 GDPR were not compliant with the requirements of Article 12 GDPR in light of the fact that TikTok services
    17 KB (2,519 words) - 15:55, 6 December 2023
  • HDPA (Greece) - 20/2020 (category Article 58(2)(d) GDPR)
    Articles 5, 6 par. 1 point (e) and 9 par. 2 (g) GDPR 2016/679 and c) calls, pursuant to article 58 par.2 verse. d GDPR 2016/679, 401 General Military Hospital
    29 KB (4,578 words) - 15:35, 6 December 2023
  • AEPD (Spain) - EXP202102430 (category Article 58(2)(d) GDPR)
    out and the resolutions issued under this article. (…)” SAW In accordance with the provisions of article 58.2 d) of the RGPD, each authority of control may
    33 KB (4,835 words) - 13:26, 13 December 2023
  • controller in accordance with Article 58 (2) (b) of the General Data Protection Regulation and an order in accordance with Article 58 (2) (d) of the General Data
    42 KB (6,579 words) - 08:46, 27 January 2022
  • on final judgments did not comply with Article 25(1) GDPR. Pursuant to Article 58(2)(b) and Article 58(2)(d) GDPR, the DPA reprimanded the controller for
    43 KB (6,671 words) - 08:49, 27 January 2022
  • on final judgments did not comply with Article 25(1) GDPR. Pursuant to Article 58(2)(b) and Article 58(2)(d) GDPR, the DPA reprimanded the controller for
    43 KB (6,677 words) - 08:47, 27 January 2022
  • violated Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, Article 9 GDPR and Article 25(2) GDPR. As a result, and in accordance with Article 58(2)(d) GDPR, the
    60 KB (9,117 words) - 14:46, 24 January 2024
  • violated Article 5(1)(e) GDPR and Article 25(2) GDPR. As a result, the DPA issued a reprimand to the controller in accordance with Article 58(2)(b) GDPR. Pursuant
    77 KB (12,352 words) - 07:20, 23 April 2024
  • ANSPDCP (Romania) - 18.01.2023 (category Article 58(2)(d) GDPR)
    commercial messages. Consequently, pursuant to its powers under Article 58(2)(d) GDPR, the DPA ordered the controller to take technical and organizational
    5 KB (519 words) - 15:13, 13 December 2023
  • HDPA (Greece) - 43/2019 (category Article 58(2)(d) GDPR)
    the GDPR within 1 month starting from the receipt of this decision; c)ordered the company comply with the Article 5(1)(a) GDPR and Article 5(2) GDPR, as
    5 KB (459 words) - 15:39, 6 December 2023
  • ANSPDCP (Romania) - Vodafone România SA 1 (category Article 58(2)(d) GDPR)
    confidentiality as laid down in Article 5(1)(d) and (f) GDPR read in conjunction with the principle of accountability according to Article 5(2) GDPR. The ANSPDCP imposed
    5 KB (608 words) - 15:21, 13 December 2023
  • Commissioner (Cyprus) - 11.17.001.007.125 (category Article 58(2)(d) GDPR)
    game company to bring its processing operations into compliance with Article 12(2) GDPR as it found they should implement additional modalities to facilitate
    3 KB (221 words) - 16:51, 6 December 2023
  • unlawful. As per Article 58(2) d, the Finnish DPA ordered the housing cooperative to bring the personal data processing activities in line with GDPR. The decision
    3 KB (355 words) - 13:05, 3 March 2024
  • corrective powers under Article 58(2) GDPR, namely 58(2)(d) and (g) GDPR, may be exercised by the DPA on its own motion. Article 58(2)(c) GDPR, on the other hand
    6 KB (683 words) - 15:27, 27 March 2024
  • ANSPDCP (Romania) - Fine to Dante Internațional SA (category Article 58(2)(d) GDPR)
    imposed two corrective measures on the controller according to Article 58(2)(c) and (d) GDPR and the fine of 14,420.4 lei, the equivalent of the amount of
    4 KB (414 words) - 11:04, 6 February 2024
  • took place. Therefore, as per Article 58 (2) (b), DPA issued a reprimand to the controller as per and, as per Article 58 (2) (d), ordered the controller to
    4 KB (488 words) - 13:08, 3 March 2024
  • according to Article 58(2)(d). Share blogs or news articles here! The decision below is a machine translation of the Romanian original. Please refer to the
    4 KB (456 words) - 15:18, 13 December 2023
  • Romanian DPA (ANSPDCP) fined leasing company €15,000 for violation of Article 32(1) and (2) GDPR after investigating a data breach reported by the company, where
    6 KB (732 words) - 15:17, 13 December 2023
  • enshrined in Article 5(1)(c) GDPR. The Finish DPA further ordered the controller to bring its processing activities into compliance under Article 58(2)(d) GDPR
    13 KB (1,873 words) - 13:06, 3 March 2024
  • subjects had not suffered any financial harm. Furthermore, as per Article 58(2)(c) and (d) GDPR, the DPA ordered the controller to comply with the data subjects’
    4 KB (359 words) - 13:03, 3 March 2024
  • reprimand to the controller in accordance with Article 58(2)(b) GDPR. Pursuant to Article 58(2)(d) GDPR, the DPA also ordered the controller to erase the
    15 KB (2,137 words) - 20:18, 27 March 2024
  • processing operations in line with the provisions of the GDPR in accordance with Article 58 (2) (d). Share blogs or news articles here! The decision below
    12 KB (1,810 words) - 13:07, 3 March 2024
  • BAC (Bulgaria) - 2606/2021 (category Article 58(2)(d) GDPR)
    CPDP issued NRA an order under Article 58(2)(d) supra Article 57(1)(a) and Article 83(2)(a), (c), (d), (f) and (g) of the GDPR for undertaking suitable technical
    13 KB (1,761 words) - 09:58, 14 December 2023
  • considered appropriate in accordance with Article 31(1)(b) GDPR and Article 32(2) GDPR. Pursuant to Article 58(2)(d) GDPR, the DPA ordered the controller to identify
    17 KB (2,339 words) - 13:39, 12 January 2024
  • reprimand to the controller in accordance with Article 58(2)(b) GDPR. Pursuant to Article 58(2)(d) GDPR, the DPA also ordered the controller to bring its
    21 KB (3,204 words) - 13:37, 12 January 2024
  • subject's rights, such as the right to object according to Article 21 GDPR. Pursuant to Article 58(2)(d) GDPR, the DPA ordered the controller to ensure that data
    21 KB (3,097 words) - 13:40, 12 January 2024
  • infringements of Article 5(1)(c), Article 5(1)(e) and Article 6(1)(f) the DPC issued a reprimand to Airbnb pursuant to Article 58(2)(b) of the GDPR. In addition
    17 KB (2,411 words) - 09:25, 27 November 2023
  • violated Article 5(1)(c) GDPR, Article 25(2) GDPR and Section 29(4) of the Finnish Data Protection Act. As a result, and in accordance with Article 58(2)(d)
    25 KB (3,651 words) - 09:37, 3 April 2024
  • AEPD (Spain) - PS/00322/2020 (category Article 58(2)(d) GDPR)
    the GDPR, pursuant to Articles 58(2)(b) and (d) respectively. For the violation of Article 5(1)(f), it issued a fine of €10000, pursuant to Article 58(2)(i)
    26 KB (3,840 words) - 14:28, 13 December 2023
  • NAIH (Hungary) - NAIH/2020/2000/5 (category Article 58(2)(d) GDPR)
    by the above Registry, (1) and (2) and Article 13.II.The Authority instructs the Obliged Pursuant to Article 58 (2) (d) of the General Data Protection
    24 KB (3,815 words) - 10:11, 17 November 2023
  • notified in accordance with the data protection regulation, article 58, subsection 2, letter d. Failure to comply with an order can - unless a higher penalty
    25 KB (3,660 words) - 08:42, 14 September 2022
  • violated Article 5(1)(c) GDPR, Article 5(1)(e) GDPR, Article 12(2) GDPR, Article 12(6) GDPR and Article 25(2) GDPR. In accordance with Article 58(2)(c) GDPR
    31 KB (4,693 words) - 11:50, 6 March 2024
  • AKI (Estonia) - 2.1.-1/22/1396 (category Article 58(2)(d) GDPR)
    RESOLUTION Article 56 (1) and (2) point 8, § 58 (1) of the Personal Data Protection Act (hereafter IKS) and Article 58 (1) point d and (2) points d, e and
    34 KB (5,305 words) - 08:40, 29 June 2023
  • Art 4 (11) GDPR. In accordance with Art 58(2)(d), the Finnish DPA instructs the controller to align its process to obtain consent with the GDPR provisions
    29 KB (4,610 words) - 13:07, 3 March 2024
  • Datatilsynet (Norway) - 21/02873 (category Article 12(2) GDPR)
    In an Article 60 GDPR procedure, the Norwegian DPA ordered an HR-services provider, pursuant to Article 58(2)(d) GDPR, to provide the data subject with
    13 KB (1,583 words) - 16:20, 6 December 2023
  • minimisation, pursuant to Article 58(2)(d). The Garante also fined the company €20000 for its breach of Articles 5(1)(a) and (c) GDPR. In determining the amount
    33 KB (5,342 words) - 15:52, 6 December 2023
  • AEPD (Spain) - EXP202105669 (category Article 58(2)(d) GDPR)
    regulated in article 32 of the GDPR, which regulates the security of the treatment. IV. Article 5.1.f) of the GDPR Article 5.1.f) of the GDPR establishes
    45 KB (6,998 words) - 12:58, 13 December 2023
  • circumstances of the specific case (art. 58, par. 2, letter i) Regulation). 4. Order for an injunction. Pursuant to art. 58(2)(i) of the Regulation and art. 166(3)
    34 KB (5,420 words) - 15:51, 6 December 2023
  • DSB (Austria) - D130.206/0006-DSB/2019 (category Article 58(2)(d) GDPR)
    in line with Article 13 GDPR. On the DSB's request, the controller declared R*** Hotels GmbH as its representative under Article 27 GDPR and sent a reply
    40 KB (6,007 words) - 13:59, 12 May 2023
  • AEPD (Spain) - PS/00029/2020 (category Article 58(2)(d) GDPR)
    under Article 58(2)(b) GDPR. The Authority ordered the Health Service to carry out a DPIA and bring its processing operations in line with the GDPR within
    44 KB (6,943 words) - 13:49, 13 December 2023
  • to the controller in accordance with Article 58(2)(b) GDPR. Pursuant to Article 58(2)(d) GDPR, the DPA also ordered the controller to comply with the principles
    54 KB (8,279 words) - 13:53, 21 March 2024
  • Personvernnemnda (Norway) - 2022-13 (21/00481) (category Article 58(2)(d) GDPR)
    controller) about €352,555 (NOK 4,000,000) for violating Article 5(1)(f) GDPR, Article 24 GDPR and Article 32 GDPR after a serious ransomware attack led to highly
    45 KB (6,913 words) - 12:13, 15 March 2023
  • controller had violated Article 5(1)(f) GDPR, Article 17(1) GDPR, Article 25(1) GDPR, Article 32(1) GDPR and Article 32(2) GDPR. As a result, the DPA issued
    56 KB (8,980 words) - 08:47, 4 March 2024
  • reprimand to the controller in accordance with Article 58(2)(b) GDPR. Pursuant to Article 58(2)(d) GDPR, the DPA also ordered the controller to define
    61 KB (9,477 words) - 13:38, 12 January 2024
  • AEPD (Spain) - PS/00201/2019 (category Article 58(2)(d) GDPR)
    The AEPD then issued the MCP with a warning under Article 83(5)(b) and pursuant to Article 58(2)(d) ordered the MCP to adapt its information provision
    54 KB (9,019 words) - 14:10, 13 December 2023
  • constituted a violation of Articles 123(2) and 132-ter of the Italian Privacy Code. Applying Articles 58(2)(d) and (2)(i), the Garante ordered Iliad to adapt
    58 KB (9,448 words) - 15:50, 6 December 2023
  • AEPD (Spain) - PS/00025/2019 (category Article 58(2)(d) GDPR)
    third parties (article 83.2.k, of the RGPD in relationwith article 76.2.b, of the LOPDGDD)SAWIn accordance with articles 58.2 and 83.2 of the RGPD, previously
    88 KB (14,301 words) - 13:48, 13 December 2023
  • (2016/679) Article 5 (1) (a), Article 12 (1), (2) and (6) , Article 13, Article 15 (1) (h), (3) and (4), Article 58 (2) (c) and (d) subparagraphs Article 34 (1)
    41 KB (6,220 words) - 09:48, 17 November 2023
  • HDPA (Greece) - 44/2019 (category Article 58(2)(d) GDPR)
    internal compliance and accountability according to Article 5(1) GDPR, Article 5(2) GDPR and Article 6(1) GDPR. Since the company had totally ignored the its
    127 KB (21,184 words) - 15:39, 6 December 2023
  • Company itself, pursuant to Article 58, paragraph 2, letter i), of the Regulation, Article 166, paragraph 7, of the Code and Article 18 of Law no. 689/1981
    129 KB (21,020 words) - 15:49, 6 December 2023
  • reasons the Italian DPA, with the power conferred by Article 58(2)(d) and (f) and Article 83(3) and (5) GDPR, imposed to Fastweb multiple corrective measures
    131 KB (21,014 words) - 15:55, 6 December 2023
  • Persónuvernd (Island) - 2022020363 (category Article 58(2)(d) GDPR)
    administrative fine in the amount of 2,000,000 ISK on the controller under Article 83(2)(a) GDPR and Article 83(2)(g) GDPR. This is just one of five decisions
    142 KB (22,881 words) - 12:42, 16 January 2024
  • AEPD (Spain) - EXP202211775 (category Article 6(1) GDPR)
    homeowner’s association. The DPA fined the controller $300 under Article 58(2)(d) GDPR and ordered that the cameras be removed or reoriented so that they
    2 KB (174 words) - 12:40, 13 December 2023
  • with Article 58 section 2 C, the DPA ordered the controller to delete the data subject’s data in accordance with Article 17 GDPR. Pursuant to Article 58(2)(d)
    4 KB (424 words) - 13:05, 3 March 2024
  • ANSPDCP (Romania) - 24.04.2023 (category Article 12(3) GDPR)
    violated Article 12(3) and Article 21 GDPR by not respecting the data subject's objection. Based on its powers pursuant to Article 58(2)(i) GDPR, the DPA
    6 KB (707 words) - 15:15, 13 December 2023
  • context of employment as per Article 88 GDPR. For these reasons, the Garante: - With the power conferred by Article 58(2)(i) GDPR, imposed a fine of €20,000
    4 KB (460 words) - 15:53, 6 December 2023
  • within the meaning of Article 4(15) GDPR and Article 9(1) GDPR. Processing of sensitive data requires a legal basis under Article 9(2) GDPR. In the present case
    13 KB (1,847 words) - 15:52, 11 December 2023
  • IDPC (Malta) - EDPBI:MT:OSS:D:2022:341 (category Article 58(2)(d) GDPR)
    access request (Article 15 GDPR). Therefore, the controller violated Article 12(2) GDPR. The DPA reprimanded the controller (Article 58(2)(b) GDPR) and ordered
    8 KB (958 words) - 13:00, 9 November 2022
  • AZOP (Croatia) - Decision 04-07-2022 (category Article 58(1) GDPR)
    space. The DPA found a violation of Article 6(1) GDPR and ordered the controller, pursuant to Article 58(2)(d) GDPR, to adjust the location of the cameras
    14 KB (2,038 words) - 15:20, 30 October 2023
  • instruction to ensure compliance with the GDPR, the ANSPDCP did not explicitly refer to Article 58(2)(d) GDPR but it can be assumed that the instruction
    5 KB (572 words) - 14:37, 18 May 2022
  • ANSPDCP (Romania) - 31.01.2024 (category Article 58(2)(d) GDPR)
    investigation, in accordance with Article 58(2)(d) GDPR, the DPA also imposed on the controller the corrective measure to provide and communicate all the
    7 KB (830 words) - 16:14, 14 February 2024
  • provisions of Article 32(1)(b) GDPR and Article 32(2) GDPR. The DPA fined the processor €2,000 for this data breach. Under the Article 58(2)(d) GDPR it was decided
    8 KB (948 words) - 16:44, 15 November 2022
  • DPC - Tusla Child and Family Agency (category Article 58(2)(d) GDPR)
    compliance with Article 32(1) and issued reprimands in respect of the infringements, pursuant to Articles 58(2)(b), (d), and (i) GDPR respectively. Procedure
    6 KB (761 words) - 21:06, 24 February 2021
  • AEPD (Spain) - PS-00563-2022 (category Article 58(2)(d) GDPR)
    that a fine of €2,000 be set for the infringement of Article 13 GDPR as defined in Article 83(5) GDPR. Pursuant to Article 58(2)(d) GDPR the Spanish DPA
    8 KB (1,017 words) - 09:54, 18 January 2024
  • which the data are processed. At the same time, pursuant to art. 58 para. (2) lit. d) from the RGPD, the following corrective measures were ordered against
    9 KB (1,206 words) - 13:59, 4 September 2022
  • CNIL (France) - 2c1s196162814 (category Article 58(2)(d) GDPR)
    personal data. The DPA also issued a formal notice pursuant of Article 58(2)(d) GDPR and Article 20.II of the French Data Protection Act to limit the retention
    13 KB (1,877 words) - 12:06, 4 January 2023
  • Datatilsynet (Denmark) - 2021-432-0056 (category Article 58(2)(d) GDPR)
    freedoms that could not be mitigated, and referred to Article 36(1) GDPR and Article 36(2) GDPR. The DPA ordered the municipality to: Change the data processing
    16 KB (2,135 words) - 16:52, 14 September 2022
  • ВАС - 6307/27.06.2022 (category Article 58(2)(d) GDPR)
    violation of Article 32 GDPR since the controller did not implement the measures necessary to prevent such disclosure. Under Article 58 (2)(d) GDPR, Speedy
    19 KB (2,875 words) - 10:08, 22 November 2022
  • Datatilsynet (Denmark) - 2020-442-8862 (category Article 58(2)(d) GDPR)
    to Article 58(2)(a) and ordered the controller to bring its processing operations into compliance with the GDPR, pursuant to Article 58(2)(d) GDPR. Share
    24 KB (3,735 words) - 17:29, 23 February 2022
  • Finnish DPA therefore instructed the controller in accordance with Article 58(2)(d) GDPR to bring the processing operations in line with the rules on the
    26 KB (4,068 words) - 14:27, 24 February 2022
  • Datatilsynet (Denmark) - 2021-31-4871 (category Article 58(2)(d) GDPR)
    6(1)(a) GDPR and 4(11) GDPR. Therefore, the controller violated Articles 5(2) and 5(1)(a) GDPR. The DPA ordered the controller, pursuant to Article 58(2)(d)
    29 KB (4,447 words) - 16:32, 3 November 2023
  • IDPC (Malta) - CDP/IMI/LSA/17/2022 (category Article 12(1) GDPR)
    In an Article 60 GDPR procedure, the DPA of Malta reprimanded a controller (Article 58(2)(b) GDPR) for requesting the data subject to sign an agreement
    7 KB (825 words) - 13:19, 9 November 2022
  • Datatilsynet (Denmark) - 2021-31-5553 (category Article 58(2)(d) GDPR)
    6(1)(a) GDPR and 4(11) GDPR and did therefore violate Articles 5(2) and 5(1)(a) GDPR. The DPA ordered the controller pursuant to Article 58(2)(d) GDPR to ensure
    32 KB (4,997 words) - 14:09, 22 February 2023
  • Datatilsynet (Norway) - 20/02144 (category Article 58(2)(d) GDPR)
    32(2) GDPR for insufficient risk assessment of security measures in the MyPostNord service, and ordered the controller, pursuant to Article 58(2)(d) GDPR
    38 KB (5,449 words) - 14:08, 18 January 2023
  • IMY (Sweden) - DI-2020-10696 (category Article 58(2)(d) GDPR)
    erasure request pursuant of Article 58(2)(d) GDPR. Also, the DPA ordered the controller pursuant of Article 58(2)(d) GDPR to provide the data subject information
    57 KB (6,743 words) - 13:54, 1 February 2023
  • Datatilsynet (Denmark) - 2021-432-0063 (category Article 58(2)(d) GDPR)
    cf. Article 35 of the Data Protection Regulation. The order is announced in accordance with the data protection regulation, article 58, subsection 2, letter
    35 KB (5,141 words) - 14:34, 28 September 2022
  • Datatilsynet (Norway) - 21/02293 (category Article 58(2)(d) GDPR)
    data protection regulation article 6 no. 1 letter f. 2. Pursuant to the Personal Protection Regulation article 58 no. 2 letter d, Recover AS is ordered to
    39 KB (5,691 words) - 08:12, 14 September 2022
  • 6(1)(a) GDPR. The Italian DPA ordered the controller to erase personal data and stop the processing pursuant to Article 58(2)(d) and (f) GDPR. The DPA
    40 KB (6,513 words) - 13:47, 3 May 2023
  • AEPD (Spain) - PS-00371-2021 (category Article 58(2)(d) GDPR)
    according to Article 83(4)(a) GDPR. However, the AEPD imposed no fines in either of the two violations. Instead, according to Article 58(2)(d) GDPR, the AEPD
    46 KB (7,141 words) - 13:00, 18 January 2024
  • Pursuant to Article 58(2)(d) of the GDPR, the DPA ordered Associazione Rousseau to comply with the provisions of Article 28(3)(g) of the GDPR by ensuring
    40 KB (6,510 words) - 16:53, 26 May 2022
  • to Articles 114 and 157 of the Privacy Code. Pursuant to Article 58(2)(i) GDPR and 83 GDPR, the DPA imposed an administrative fine of €6,000.00, and an order
    41 KB (6,437 words) - 12:47, 8 February 2023
  • NAIH (Hungary) - NAIH-3734-15/2023 (category Article 58(2)(d) GDPR)
    violated Article 6 (1) point f) of the GDPR. (61) The Authority grants the Requester's request and, based on Article 58 (2) point d) of the GDPR, instructs
    48 KB (7,721 words) - 11:09, 10 January 2024
  • of fairness pursuant to Article 5(1)(a) GDPR.” Summary of Envisaged Action The DPC made an order pursuant to Article 58(2)(d) GDPR, requiring Meta IE to
    21 KB (3,005 words) - 14:16, 1 February 2023
  • third parties. In addition, through the authority identified in Article 58(2)(d) GDPR, the Italian DPA orders PagoPA S.p.A to adopt the appropriate technical
    54 KB (8,704 words) - 13:10, 23 June 2021
  • of fairness pursuant to Article 5(1)(a) GDPR”. Summary of Envisaged Action The DPC made an order pursuant to Article 58(2)(d) GDPR, requiring Meta IE to
    21 KB (3,069 words) - 14:17, 1 February 2023
  • Datatilsynet (Norway) - 23/00708 (category Article 58(2)(d) GDPR)
    per Article 57(1)(a) GDPR, Article 57(1)(h) GDPR, cf. Article 58(1)(a) GDPR, Article 58(1)(b) GDPR, Article 58(1)(e) GDPR and Article 58(1)(f) GDPR. The
    59 KB (8,718 words) - 14:50, 20 December 2023
  • NAIH (Hungary) - NAIH-924-10/2021 (category Article 58(2)(d) GDPR)
    Applicant concerned infringes Article 12 (2) of the General Data Protection Regulation and Article 25 (2) and Article 58 (2) (d) of the General Data Protection
    56 KB (8,760 words) - 13:16, 25 August 2021
  • NAIH (Hungary) - NAIH-2857-20/2021 (category Article 58(2)(d) GDPR)
    Union Article 58 of the General Data Protection Regulation in particular by alerting the controller or processor. In accordance with Article 58 (2) (d) of
    79 KB (12,495 words) - 11:03, 21 January 2022
  • access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction (Article 18 GDPR), notification (Article 19 GDPR) or data
    46 KB (5,825 words) - 11:12, 7 November 2023
  • controller, pursuant to Article 58(2)(d) GDPR, ordering the controller to bring its processing activities in line with the GDPR. The DPA also imposed an
    91 KB (14,709 words) - 13:02, 14 December 2022
  • BVwG - W214 2219800-3 (category Article 58(2)(d) GDPR)
    of the data subject ('storage limitation');'. Article 58(2)(d) of the GDPR reads: "Article 58 Powers (2) Each supervisory authority shall have all of the
    83 KB (13,846 words) - 09:39, 10 September 2021
  • WSA Warsaw - II SA/Wa 2378/20 (category Article 58(2)(d) GDPR)
    found that the company violated Article 7 (3) GDPR, Article 12 (2) GDPR, Article 17 (1)(b)GDPR and Article 24 (1) GDPR, by failing to implement appropriate
    92 KB (15,312 words) - 09:57, 10 September 2021
  • APD/GBA (Belgium) - 34/2020 (category Article 5(1)(b) GDPR)
    GDPR and Article 66.2 WOG); and • compliance with the transparency obligations (Article 12 GDPR) and the te provide information (Article 13 GDPR). Page
    82 KB (13,250 words) - 16:57, 12 December 2023
  • measures, as per Article 58(2)(d) GDPR, have been adopted, obliging the controller to complete implementation of relevant technical and organizational measures
    38 KB (5,724 words) - 15:47, 6 December 2023
  • VG Köln - 13 L 1707/21 (category Article 58(2) GDPR)
    enforceable order against the Job Centre under Article 58(2)(d) GDPR to bring its processing into compliance with the GDPR and re-designate the dismissed DPO. The
    15 KB (2,273 words) - 15:58, 18 March 2022
  • Article 5 GDPR (category GDPR Articles) (section (d) Accuracy)
    consent under Article 6(4) GDPR and further processing for a compatible purpose under Article 6(4) GDPR. See the commentary on Article 6(4) GDPR for details
    51 KB (6,355 words) - 08:25, 18 April 2024
  • flows by the SA pursuant to Article 58(2) GDPR or failure to provide access in violation of Article 58(1) GDPR. Article 83(6) GDPR is a superfluous provision
    55 KB (7,622 words) - 14:04, 7 November 2023
  • administrative penalty fee: 1) Article 5, Paragraph 1, subparagraphs d and a; 2) Article 13; 3) paragraph 3 of Article 12; and 4) Article 15(1). Viking Line Oy
    149 KB (24,224 words) - 12:20, 2 January 2023
  • possible "legitimate interest" under Article 6(1)(f) GDPR. Equally to Article 6(1)(c) GDPR, Article 6(2) and (3) GDPR require that Union or Member State
    108 KB (17,005 words) - 15:39, 18 March 2024
  • based on Article 3, paragraph 2, Article 5, paragraph 1 a), f) of GDPR subsection, Article 6(1), Article 9(2), Article 58(2)(d), GDPR Article 23 and Article
    22 KB (3,276 words) - 11:46, 26 July 2023
  • AEPD (Spain) - PS/00003/2020 (category Article 5(1)(c) GDPR)
    to the complaint (Article 83 (2) (f) GDPR), not linking the activity of the offender to the processing of personal data (Article 76 (2) (b) LOPDGD), the
    50 KB (7,524 words) - 13:44, 13 December 2023
  • Datatilsynet (Denmark) - 2023-431-0001 (category Article 58(2)(d) GDPR)
    breached Article 6(1)(e) GDPR and ordered all 53 municipalities to bring their processing in line with Article 5(1)(a) GDPR, Article 6(1) GDPR, by ensuring
    158 KB (25,068 words) - 12:28, 14 February 2024
  • Datatilsynet (Denmark) - 2023-432-0016 (category Article 9(2)(a) GDPR)
    with Article 9(2)(a) GDPR and Article 6(1)(a) GDPR. Thus, the Danish DPA held that the processing was also not following the principles of Article 5(1)
    46 KB (7,192 words) - 12:37, 19 December 2023
  • ANSPDCP (Romania) - Fine to Farmacia Ardealul SRL (category Article 32(1)(d) GDPR)
    of RON 12,424 (approximately €2,500). At the same time, the DPA imposed a corrective measure based on Article 58(2)(d) GDPR and ordered the controller to
    5 KB (572 words) - 09:37, 6 July 2023
  • IP (Slovenia) - 07141-9/2023/10 (category Article 58(2) GDPR)
    deletion request of the data in question, breaching Article 17(1) GDPR. Pursuant to Article 58(2)(d) GDPR, the DPA ordered the controller to remedy the irregularities
    6 KB (553 words) - 14:57, 6 December 2023
  • basis of Article 6(1)(e) GDPR - public interest - or the legal basis of Article 6(1)(f) GDPR - legitimate interest. Moreover, Article 21(3) GDPR specifically
    5 KB (621 words) - 13:51, 21 February 2023
  • GDPR. As result, the controller was fined approximately €5,000 (RON 24,745). Furthermore, using their powers laid down in Article 58(2)(d) GDPR , the DPA
    5 KB (668 words) - 09:34, 26 November 2021
  • ANSPDCP (Romania) - 13.03.2023 (category Article 12 GDPR)
    9871 (approximately €2000) for these violations. In accordance with Article 58(2)(d) GDPR, the DPA also imposed corrective measures. First, the DPA ordered
    6 KB (786 words) - 12:38, 21 March 2023
  • data transmitted, stored or otherwise processed." As such, under Article 58(2)(d) GDPR, the controller was ordered to take into account the risk assessment
    7 KB (866 words) - 14:23, 21 December 2022
  • DSB (Austria) - D130.1178 2023-0.631.894 (category Article 7(3) GDPR)
    the wording of Article 77(1) GDPR and from Article 58(2)(d) GDPR that national DPAs only have competence to take action with respect to GDPR violations that
    6 KB (787 words) - 16:19, 16 February 2024
  • DPC (Ireland) - IN-20-8-1 (category Article 45 GDPR)
    with Chapter V of the GDPR. Therefore, it requested the Irish DPA to adopt against Meta an order pursuant to Article 58(2)(d) GDPR. The EDPB also established
    7 KB (952 words) - 10:22, 24 May 2023
  • ANSPDCP (Romania) - 23.03.2023 (category Article 5(2) GDPR)
    9,798.6 (approximately €2000). In accordance with Article 58(2)(d) GDPR, the DPA also imposed corrective measures. First, it ordered the data controller
    8 KB (1,015 words) - 07:23, 5 April 2023
  • APD/GBA (Belgium) - 24/2021 (category Article 35(2) GDPR)
    the basis of article 6.1 e) GDPR read together with articles 5.2 GDPR and 24.1 GDPR. 3) Violation of Articles 12.1, 12.6, 13.1 and 13.2 GDPR: the Inspection
    110 KB (18,238 words) - 16:56, 12 December 2023
  • further details see Article 14(1)(d) GDPR. Similar to the ex-ante information in Article 13(1)(e) and 14(1)(e) GDPR, Article 15(1)(c) GDPR requires the controller
    73 KB (9,896 words) - 15:46, 18 March 2024
  • APD/GBA (Belgium) - 04/2021 (category Article 5(1) GDPR)
    before May 25, 2018. 2.2. Consent and the lawfulness of the processing (Article 4, point 11, Article 6 (1) in conjunction with Article 7 GDPR) 121. With regard
    113 KB (18,732 words) - 16:50, 12 December 2023
  • the DPA ordered the controller under Article 58(2)(d) GDPR to bring is processing into compliance with the GDPR by: reviewing and updating the technical
    9 KB (1,228 words) - 14:38, 22 June 2022
  • ANSPDCP (Romania) - 21.08.2023 (category Article 25 GDPR)
    under Article 83(2) and (3) GDPR. As such, Uipath SRL was fined 346,598 RON, equivalent to €70,000. In addition, pursuant to Article 58(2)(d) GDPR, the
    10 KB (1,393 words) - 14:16, 5 September 2023
  • evaluating the effectiveness of security measures (Article 32(1)(d) GDPR). According to Article 4(5) GDPR, "pseudonymisation" means the processing of personal
    41 KB (5,197 words) - 12:17, 17 April 2024
  • commentary to Article 60 GDPR, Article 61 GDPR, Article 62 GDPR, Article 63 GDPR, Article 64 GDPR, Article 65 GDPR, Article 66 GDPR and Article 56 GDPR. The SA
    60 KB (7,796 words) - 20:12, 1 April 2024
  • reference, see Article 143 of the Code). However, detailed time-limits can be found in Regolamento n. 2/2019 cited above. Under Article 154 of the Code
    7 KB (808 words) - 08:17, 16 February 2023
  • DPC (Ireland) - IN-21-2-5 (category Article 5(1)(f) GDPR)
    pursuant to Article 58(2)(b) GDPR. In accordance with article 83 GDPR, and taking into account the factors outlined in Article 58(2)(i) GDPR, the DPC also
    13 KB (1,849 words) - 02:28, 23 February 2023
  • Datatilsynet (Denmark) - 2021-7329-0052 (category Article 26 GDPR)
    Articles 5(2) and 24(1) GDPR as to how it demonstrates its compliance with the GDPR. This order is notified pursuant to Article 58(2)(d) GDPR. According
    104 KB (14,260 words) - 13:54, 9 June 2023
  • Article 13 GDPR (category GDPR Articles) (section (d) Legitimate interests)
    reliance on Article 6(1)(f) GDPR or at least exercise the right to object under Article 21 GDPR. If the legal basis is Article 6(1)(f) GDPR (i.e. 'legitimate
    71 KB (9,532 words) - 13:30, 6 March 2024
  • categories of data established in Article 9(2)(a) GDPR, Article 9(2)(c) GDPR, Article 9(2)(g) GDPR and Article 9(2)(i) GDPR directly correlate with a specific
    44 KB (5,905 words) - 14:00, 24 October 2023
  • provided for in Article 6(1)(a) GDPR or, as the case may be, Article 9(2)(a) GDPR, and consent is withdrawn according to Article 7(3) GDPR, data must be
    61 KB (8,488 words) - 15:47, 18 March 2024
  • OVG Hamburg - 5 Bs 152/20 (category Article 58(2) GDPR)
    service. Finally, in June 2020, the DPA issued a decision based on Article 58(2)(d) GDPR. The property company filed an application for interim relief against
    45 KB (7,219 words) - 13:48, 24 January 2022
  • pursuant to Article 58(2)(b) GDPR and ordered the controller to bring its processing operations in compliance with the GDPR, pursuant to Article 58(2)(d) GDPR
    16 KB (2,293 words) - 17:30, 23 February 2022
  • AKI (Estonia) - 2.1.-5/22/22012 (category Article 6(1)(d) GDPR)
    controller processed personal data without a legal basis. Pursuant to Article 58(2)(d) GDPR, the DPA ordered the controller to stop publishing posts containing
    18 KB (2,695 words) - 12:21, 31 January 2023
  • Article 14 GDPR (category Article 14 GDPR) (section Relationship with Article 13 GDPR)
    with Article 13, Article 14 GDPR gives expression to the principle of transparency enshrined in Article 5(1)(a) GDPR and further defined in Article 12 GDPR
    47 KB (5,644 words) - 17:49, 5 March 2024
  • nung, Article 33 GDPR, margin number 15 (C.H. Beck 2018, 2nd edition). König, Schaupp, in Knyrim, Der Datkomm, Article 79 GDPR, margin number 58/1 (rdb
    54 KB (6,536 words) - 08:22, 16 June 2023
  • Persónuvernd (Iceland) - Case no. 2021122409 (category Article 5(1)(f) GDPR)
    4(1) GDPR. Moreover, it noted that all processing of personal data has to comply with Article 6 GDPR and the principles of Article 5(1) GDPR, which also included
    19 KB (2,776 words) - 15:39, 6 December 2022
  • AKI (Estonia) - 2.1.-4/22/2585 (category Article 5 GDPR)
    subsection 1, subsection 2 clause 8, § 58 subsection 1 of the Personal Data Protection Act and personal data on the basis of Article 58(2)(d) of the General Regulation
    19 KB (2,941 words) - 09:40, 11 January 2023
  • access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), notification obligation
    44 KB (4,896 words) - 06:25, 16 June 2023
  • from Articles 13(2)(b) and 14(2)(c) GDPR. However, Article 21(4) GDPR specifies that the right to object under Article 21(1) and 21(2) GDPR (i.e. the right
    49 KB (5,993 words) - 06:22, 16 June 2023
  • Datatilsynet (Norway) - 21/03656 (category Article 12(2) GDPR)
    having infringed Article 14 GDPR by failing to provide all of the relevant information required therein. Pursuant to Article 58(2)(d) GDPR, Datatilsynet orders
    63 KB (8,745 words) - 13:33, 27 April 2022
  • Article 16 GDPR (category GDPR Articles)
    However, Article 5(1)(d) GDPR gives the controller some leeway to continue processing inaccurate data - see more details under Article 5(1)(d) GDPR. Article
    23 KB (2,489 words) - 23:24, 6 March 2024
  • DVI (Latvia) - LocateFamily administrācija (category Article 5(1)(b) GDPR)
    based on Article 3, Clause 2, Article 5, Clause 1 of the Data Regulation "a", "b" and point 2, Article 6, point 1, point "a", Article 7, Article 27, point
    25 KB (3,679 words) - 11:30, 2 August 2023
  • DPA found that the controller violated Article 5(1)(c) and Article 25 GDPR. In accordance with Article 58(2)(d) GDPR, the DPA ordered the controller to bring
    20 KB (3,195 words) - 15:22, 2 March 2022
  • Article 30 GDPR (category GDPR Articles) (section (d) Categories of recipients)
    applicability of Article 49(1) GDPR, the documentation of suitable safeguards (Article 30(2)(c) GDPR). See commentary under Article 30(1)(e) GDPR. The processor's
    31 KB (3,327 words) - 15:31, 5 June 2023
  • access. See comment under Article 33(3)(d) of the GDPR. As indicated by the phrase “at least” found under Article 34(2) GDPR, this list of information
    37 KB (3,962 words) - 15:20, 16 June 2023
  • Article 2 GDPR (category GDPR Articles) (section Option 2: Part of a filing system)
    elements in Article 2(1) are fulfilled, the GDPR applies unless the processing falls under one of the exemptions named in Article 2(2)(a) to (d) GDPR. The first
    34 KB (4,652 words) - 12:07, 12 November 2023
  • access (Article 15 GDPR), rectification (Article 16 GDPR), deletion (Article 17 GDPR), restriction of processing (Article 18 GDPR), objection (Article 21 GDPR)
    34 KB (3,646 words) - 08:53, 27 March 2023
  • from any of the GDPR’s protections. → You can find all related decisions in Category:Article 39 GDPR Just as Article 38 GDPR, Article 39 GDPR also shows similarities
    23 KB (2,165 words) - 15:10, 27 July 2023
  • AEPD (Spain) - PS/00140/2020 (category Article 58(2)(d) GDPR)
    according to Article 58(2)(d) GDPR. First, the AEPD established that the GDPR was applicable under Article 3(1) GPDR or, if not, at least Article 3(2)(a) GDPR
    390 KB (63,154 words) - 07:08, 9 June 2022
  • APD/GBA (Belgium) - 07/2024 (category Article 5(1)(c) GDPR)
    the GDPR: i. Articles 5.1.a) and 5.2, as well as Article 6.1 GDPR; ii. Articles 12.1 and 12.2, Article 15.1, Article 5.2, Article 24.1, and Article 25.1
    350 KB (51,369 words) - 09:25, 31 January 2024
  • clear from the wording of Article 41(1) GDPR. Article 41(1) GDPR does not define accreditation. Nonetheless, Article 41(2) GDPR provides a criterion against
    30 KB (2,720 words) - 14:02, 28 July 2023
  • must also be involved in the drafting of the DPIA under Article 35(2) GDPR and Article 39(1)(c) GDPR, and their advice should be recorded by the controller
    52 KB (7,297 words) - 08:05, 18 July 2023
  • contrast to Article 23(1)(e) GDPR, which sets out strict requirements for the Union or Member State's law restricting GDPR rights, Article 18(2) GDPR does not
    32 KB (3,730 words) - 08:43, 7 March 2024
  • Article 54 GDPR (category GDPR Articles) (section (d) Duration of the term)
    provided for in Article 52(3) GDPR and Articles 53(3) and 53(4) GDPR. For more information on SA members and staff, please refer to Article 52(2) GDPR (SA members)
    34 KB (3,649 words) - 13:19, 30 October 2023
  • Article 36 GDPR (category GDPR Articles) (section (2) Procedural aspects)
    deadline of Article 36(1) GDPR, and it is still disputed whether the outcome of the procedure rather resembles that of Article 58(3)(a) GDPR or Article 58(3)(b)
    31 KB (3,646 words) - 08:51, 21 July 2023
  • Regulation (GDPR): A Commentary, Article 49 GDPR, p. 846 (Oxford University Press 2020). EDPB, ‘Guidelines 2/2018 on derogations of Article 49 under Regulation
    29 KB (3,500 words) - 08:54, 27 March 2023
  • reasoned in accordance with Article 4(24) GDPR and, after conducting its own assessment of the factors under Article 83(2) GDPR, found that the proposed fine
    468 KB (51,340 words) - 14:10, 30 January 2023
  • imposition of an administrative fine (7.2). Accordingly, the DPC made an order pursuant to Article 58(2)(d) GDPR, requiring Whatsapp IE to bring processing
    32 KB (4,686 words) - 14:17, 1 February 2023
  • Article 28 GDPR (category GDPR Articles) (section (c) Measures required by Article 32 GDPR)
    mechanism referred to in Article 63 GDPR (Article 28(8) GDPR). The Commission has made use of its power under Article 28(7) GDPR and published standard contractual
    72 KB (9,140 words) - 13:12, 2 June 2023
  • Article 64 GDPR (category Article 64 GDPR) (section (2) An optional opinion of the EDPB)
    a binding dispute resolution procedure in accordance with Article 65 GDPR. Article 64(2) GDPR allows any SA, the EDPB Chair or the Commission to request
    23 KB (2,079 words) - 16:07, 2 November 2023
  • Article 50 GDPR (category GDPR Articles)
    exchange of knowledge between them. This way, Article 50 GDPR expands the exhortation under Article 57(1)(g) GDPR that calls for cooperation between EU DPAs
    17 KB (1,142 words) - 15:41, 28 April 2022
  • controller and an order (pursuant to Article 58(2)(d) GDPR) to bring the data processing operations in compliance with the GDPR. Share your comments here! Share
    34 KB (5,187 words) - 07:49, 13 July 2023
  • subject rights, and hence is not contrary to Article 12(5) GDPR. Consequently, and pursuant to Article 58(2)(d) GDPR, the Finnish DPA ordered the controller
    34 KB (5,367 words) - 08:14, 18 May 2022
  • Protection Regulation (GDPR), Article 75 GDPR, p. 1105 (Oxford University Press 2020). Dix, in Kühling, Buchner, DS-GVO BDSG, Article 75 GDPR, margin number 6
    20 KB (1,347 words) - 14:21, 17 October 2023
  • Article 47 GDPR (category GDPR Articles) (section (2) Minimum Content)
    and jurisdiction provisions (Articles 47(1)(b), 47(2)(d), 47(2)(e), 47(2)(g), 47(2)(i), 47(2)(l) GDPR); a duty for the EU BCR member to accept responsibility
    29 KB (2,823 words) - 15:15, 28 April 2022
  • Article 43 GDPR (category GDPR Articles)
    with the examination procedure referred to in Article 93(2). You can help us fill this section! Article 43 GDPR explains the procedure involved in establishing
    22 KB (1,634 words) - 14:40, 28 July 2023
  • under Articles 58(1)(d) or 58(3)(a) and 58(3)(b) GDPR do not qualify as decisions and cannot be subject to legal actions under Article 78(1) GDPR. A data subject
    30 KB (3,874 words) - 10:46, 7 December 2023
  • difference between Article 42(1) GDPR and Article 42(2) GDPR is that in the former, the applicant for certification is subject to the GDPR, while in latter
    27 KB (2,452 words) - 14:26, 28 July 2023
  • Article 10 GDPR (category GDPR Articles)
    accordance with the GDPR’s principles and with appropriate safeguards when the LED is not directly applicable. Article 2(2)(d) GDPR excludes any processing
    17 KB (1,768 words) - 15:41, 18 March 2024
  • controllers have violated Article 5(1)(a), Article 6(1), Article 13, paragraphs 1 and 2, Article 25, Article 32, paragraphs 1 and 2, and Articles 44 and 46
    44 KB (6,748 words) - 16:10, 21 March 2023
  • exercise on their behalf all rights foreseen under Articles 77 and 78 GDPR and Article 20 of L. 4624/2019. The mandate shall be given with a specific written
    23 KB (2,039 words) - 08:15, 25 April 2024
  • Article 19 GDPR (category GDPR Articles)
    definition for "processing" in Article 4(2) GDPR). If data is been made public, the applicable provision is Article 17(2) GDPR, provided that all requirements
    19 KB (1,436 words) - 12:35, 12 May 2023
  • Article 4 GDPR (category GDPR Articles) (section (2) Processing)
    (see Article 52 GDPR) and shall be provided with various competencies (Articles 55, 56 GDPR), tasks (Article 57 GDPR) and powers (Article 58 GDPR). For
    125 KB (16,328 words) - 16:01, 8 March 2024
  • Article 63 GDPR (category Article 63 GDPR)
    to in Article 46(2)(d) GDPR, contractual clauses referred to in Article 46(3)(a) GDPR, or binding corporate rules within the meaning of Article 47 GDPR
    15 KB (851 words) - 06:55, 29 April 2022
  • organisation), Article 45(5) GDPR (revocation, change of such determinations); Articles 46(2)(c) and (d) GDPR (standard protection clauses); Article 47(3) GDPR (formats
    17 KB (1,096 words) - 08:19, 19 October 2023
  • Article 70 GDPR (category Article 70 GDPR) (section (2) Time limit)
    leeway exists only in cases of Article 64(2) GDPR but not the context of Article 70(2) GDPR. According to Article 70(3) GDPR, the EDPB is obligated to “forward
    27 KB (3,038 words) - 12:19, 11 October 2023
  • deals with processing within the scope of the GDPR. Part 2 deals with processing outside of the scope of the GDPR. Part 3 deals with processing by competent
    18 KB (2,488 words) - 15:22, 14 December 2021
  • objections pursuant to Article 92(5) GDPR. Article 92(5) GDPR imposes a further condition for the delegation of power, in line with Article 290(2)(b) TFEU. A delegated
    19 KB (1,525 words) - 08:18, 19 October 2023
  • reprimand to the controller under Article 58(2)(b) GDPR and an order to the controller pursuant to Article 58(2)(d) GDPR to bring the processing operations
    49 KB (7,658 words) - 11:36, 26 April 2023
  • constituting a breach of Article 12(2) GDPR and Article 12(3) GDPR, as well as Article 15 GDPR, Article 17 GDPR and Article 21(2) GDPR. Thus, the calls carried
    63 KB (9,986 words) - 12:04, 11 October 2023
  • Article 40 GDPR (category GDPR Articles) (section (2) Associations and other bodies)
    requirements. Although Article 40(5) GDPR mentions that the competent DPA will be determined through the application of Article 55 GDPR, the GDPR does not provide
    44 KB (5,008 words) - 14:50, 28 July 2023
  • controller to be in violation of Article 5(1)(a) GDPR, Article 6 GDPR, Article 9 GDPR, Article 12 GDPR and Article 13 GDPR and started a procedure to adopt
    77 KB (12,282 words) - 16:43, 12 December 2023
  • AEPD (Spain) - PS/00587/2021 (category Article 5(1)(f) GDPR)
    to violation of article 5.1.f) of the GDPR. VII Classification of the infringement of article 5.1.f) of the GDPR Article 83.5 of the GDPR provides the following:
    81 KB (12,762 words) - 12:51, 29 November 2022
  • After considering the objections in light of Article 4(24) GDPR and the factors outlined in Article 83(2) GDPR the EDPB instructed the DPC to impose an administrative
    289 KB (33,568 words) - 15:00, 1 February 2023
  • AEPD (Spain) - PS/00003/2021 (category Article 12(2) GDPR)
    pursuant to Article 58(2) GDPR. Moreover, it ordered the controller to bring its processing operations into compliance pursuant to Article 58(2)(d) GDPR. On sharing
    115 KB (18,312 words) - 11:58, 16 March 2022
  • days (Article 58(2)(d) GDPR) and to, within 20 days of this deadline, communicate the measures taken to comply with the order (Article 58(1)(a) GDPR). Share
    128 KB (20,856 words) - 12:32, 14 March 2023
  • above-mentioned decision of October 2, 2020 was amenable to a remedy pursuant to Section 68 (2) AVG. D.2. ruling point 2. a) a) General information on the
    108 KB (17,097 words) - 13:52, 12 May 2023
  • elements. Infringement of Article 6 and 9 GDPR qualifies for the maximum amount for administrative fines as set out in Article 83(5) GDPR: 20,000,000 € or 4%
    18 KB (2,375 words) - 16:17, 6 December 2023
  • are dealt with in Article 12(6) GDPR. It is unclear why Article 12(2) GDPR refers to Articles 15 to 22 GDPR, while Article 11(2) GDPR only refers to Articles
    76 KB (11,304 words) - 08:37, 4 March 2024
  • Regulation (GDPR), Article 91 GDPR, p. 1263 (Oxford University Press 2020). Tosoni, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article
    25 KB (2,482 words) - 10:04, 19 March 2024
  • Article 27 GDPR (category GDPR Articles) (section (2) Exemptions)
    with the GDPR (Article 31 GDPR). Direct liability of the representative is limited to the obligations set out in Article 30 and Article 58(1)(a) GDPR. Article
    25 KB (2,418 words) - 14:11, 24 May 2023
  • Protection Ordinance Article 5, paragraph Article 5 (2) 1, letter c and letter f., Article 5, paragraph Article 6 (1) (a) Article 32 (1), (1), (33) 1 and
    48 KB (7,442 words) - 10:24, 12 September 2022
  • interests under Article 6(1)(f) GDPR. On the erasure obligations under Article 17 GDPR, the CJEU held that under Article 17(1)(d) GDPR SCHUFA will be under
    15 KB (2,180 words) - 08:23, 13 December 2023
  • protection regulation's article 5, subsection 2, cf. Article 5, subsection 1, letter a, Article 24, cf. Article 28, subsection 1, Article 35, subsection 1, as
    117 KB (18,075 words) - 10:19, 12 September 2022
  • AEPD (Spain) - PS/00240/2019 (category Article 5(1)(d) GDPR)
    Therefore, given that Article 6(1), Article 5(1)(a), Article 5(1)(d), Article 5(1)(c), and Article 14 GDPR were infringed in connection to Article 5(1)(b), the
    602 KB (102,229 words) - 14:21, 13 December 2023
  • in the Member States. Example: Article 6(1)(a) GDPR Example: Not Art. 6 Abs 1 Lit a GDPR or Article 6 GDPR or GDPR Article 6, Sec 1(a) Recitals are also
    17 KB (2,510 words) - 13:56, 24 April 2023
  • CNIL (France) - SAN-2020-012 (category Article 4(7) GDPR)
    the fine, the criteria specified in the same article 83. 111. Article 83 of the GDPR, as referred to in Article 20, paragraph III, of the Data Protection
    93 KB (14,936 words) - 17:09, 6 December 2023
  • CJEU - C-40/17 - Fashion ID (category Article 80 GDPR)
    arguing that it wasn’t a controller within the definition set out under Article 2(d) Directive 95/46 and that NRW did not have legal standing to bring a class
    6 KB (492 words) - 13:09, 1 June 2023
  • UODO (Poland) - ZSPR.421.2.2019 (category Article 58(2)(i) GDPR)
    relation to Article 5(1)(a) and (f), Article 5(2), Article 6(1), Article 7(1), Article 24(1), Article 25(1), Article 32(1)(b), (c), (d), (d), (e) and (f)
    71 KB (11,304 words) - 10:01, 17 November 2023
  • imposed on OpenAI a temporary limitation of processing pursuant to Article 58(2)(f) GDPR. Such limitation concerns all processing operations involving data
    14 KB (2,049 words) - 07:46, 1 August 2023
  • AEPD (Spain) - EXP202206626 (category Article 5(1)(c) GDPR)
    particular case". According to the provisions of article 83.2 of the GDPR, the measure provided for in article 58.2 d) of the aforementioned Regulation is compatible
    35 KB (5,475 words) - 13:21, 13 December 2023
  • VK Baden-Württemberg - 1 VK 23/22 (category Article 44 GDPR)
    within the meaning of Article 4 no. 2 of the GDPR and the term "transfer" within the meaning of Article 44 et seq. of the GDPR. GDPR had to be differentiated
    62 KB (10,113 words) - 12:48, 17 August 2022
  • HDPA (Greece) - 6/2020 (category Article 58(2)(b) GDPR)
    conferred on it by the provisions of Article 58 of the GDPR and Article 15 of Law 4624/2019. 2. As Article 5 of the GDPR defines the processing principles
    29 KB (4,557 words) - 15:33, 6 December 2023
  • AEPD (Spain) - EXP202210525 (category Article 6(1) GDPR)
    according to article 4.1 of the GDPR, is data personnel and their protection, therefore, is the subject of said Regulation. In article 4.2 of the GDPR defines
    22 KB (3,427 words) - 13:26, 13 December 2023
  • AEPD (Spain) - EXP202205104 (category Article 6(1) GDPR)
    relation to letter k) of article 83.2 of the GDPR, the LOPDGDD, in its article 76, "Sanctions and corrective measures" establishes that: "2. In accordance with
    26 KB (4,147 words) - 13:27, 13 December 2023
  • AEPD (Spain) - EXP202203969 (category Article 6(1) GDPR)
    to DEUTSCHE BANK SAE requirement 02/17/2023 Allegations of D.D.D. 02/17/2023 Response to D.D.D. 02/24/2023 Response to HOLALUZ-CLIDOM SA requirement 03/03/2023
    45 KB (7,135 words) - 13:08, 13 December 2023
  • exemption is based on Article 85(2) GDPR. According to Article 26(3) of the 2018 Act, certain GDPR provisions (listed in Article 26(9)) will not apply
    14 KB (2,011 words) - 15:42, 25 November 2020
  • Helsingin hallinto-oikeus (Finland) - 3620/2023 (category Article 5(1)(a) GDPR)
    the GDPR. In light of this, the Court agreed with the DPA that the controller had violated Article 5(1)(a) GDPR, Article 12 GDPR, Article 13 GDPR, Article
    22 KB (3,193 words) - 10:34, 29 February 2024
  • APD/GBA (Belgium) - 06/2019 (category Article 58(2)(i) GDPR)
    (e) and 13(2)(a) GDPR. Thus, it ordered the controller to comply with the GDPR. In addition it fined € 10,000 under Article 58(2)(i) GDPR for the violation
    20 KB (3,137 words) - 16:51, 12 December 2023
  • AEPD (Spain) - EXP202105680 (category Article 9 GDPR)
    person.” Article 9.2 of the GDPR however means that: “Section 1 will not apply when one of the following circumstances occurs:” which cover article 9.2.a) to
    66 KB (10,558 words) - 13:14, 13 December 2023
  • AEPD (Spain) - PS/00451/2019 (category Article 6(1)(f) GDPR)
    regard to article 83.2 (k) of the RGPD, the LOPDGDD, article 76, "Sanctions and corrective measures", provides: "2. In accordance with Article 83(2)(k) of
    26 KB (4,231 words) - 14:44, 13 December 2023
  • AEPD (Spain) - EXP202206735 (category Article 6 GDPR)
    particular". According to the provisions of article 83.2 of the GDPR, the measure provided for in article 58.2.d) of the aforementioned Regulation is compatible
    75 KB (12,421 words) - 13:23, 13 December 2023
  • the controller had violated Article 5(1)(a) GDPR, Article 12 GDPR, Article 13 GDPR, Article 15 GDPR and Article 25(1) GDPR. As a result, the DPA issued
    52 KB (7,936 words) - 22:32, 2 March 2024
  • AEPD (Spain) - EXP202202164 (category Article 5(1) GDPR)
    the procedure, in accordance with the provisions in the aforementioned article 58.2 d) of the RGPD, according to which each control authority may “order the
    29 KB (4,482 words) - 14:06, 5 March 2024
  • AEPD (Spain) - EXP202105344 (category Article 6(1) GDPR)
    with article 4.1 of the RGPD, is a personal data. nal and its protection, therefore, is the subject of said regulation. In article 4.2 of the GDPR defines
    22 KB (3,319 words) - 13:00, 13 December 2023
  • AEPD (Spain) - EXP202105644 (category Article 5(1)(f) GDPR)
    with the provided for in article 58.2.b) of the RGPD, for the alleged infringement of article 5.1.f) of the RGPD, typified in article 83.5.a) of the RGPD.
    27 KB (4,121 words) - 15:06, 13 December 2023
  • UODO (Poland) - DKN.5131.6.2020 (category Article 34(2) GDPR)
    as Article 57 (1) (a), Article 58 (2) (e) and (i), Article 83 (1) - (3) and Article 83 (4) (a) in connection with Article 33 (1) and Article 34 (1), (2)
    66 KB (10,785 words) - 10:00, 17 November 2023
  • OLG Schleswig - 17 U 15/21 (category Article 17(1)(d) GDPR) (section Article 6(1)(e) GDPR)
    entitled to erasure under Article 17(1)(d) GDPR, as the data processing was not lawful. In any case, the requirements of Article 6 GDPR were no longer met 6
    51 KB (8,215 words) - 09:55, 13 May 2022
  • AEPD (Spain) - EXP202205932 (category Article 6(1) GDPR)
    basis under Article 6(1) GDPR. In light of this, the DPA issued a fine of €70,000 to másLUZ Energía (SIE) by virtue of Article 83(5) GDPR for unlawful
    32 KB (4,952 words) - 13:11, 13 December 2023
  • HDPA (Greece) - 31/2023 (category Article 5(1)(c) GDPR)
    with the principles of article 5 par. 1 GDPR. It is no coincidence that the GDPR includes accountability (see Article 5 para. 2 GDPR) in the regulation of
    61 KB (10,257 words) - 10:15, 1 November 2023
  • Helsingin hallinto-oikeus (Finland) - 116/2024 (category Article 25(2) GDPR)
    life insurance company had breached Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, Article 9 GDPR and Article 25(2) GDPR as its as its practice was to process
    41 KB (6,133 words) - 10:29, 25 March 2024
  • pursuant to Article 5(2) GDPR in conjunction with Article 5(1)(a) GDPR. Failure to demonstrate that processing is performed in accordance with the GDPR The DPA
    75 KB (11,733 words) - 16:33, 21 August 2022
  • APD/GBA (Belgium) - 31/2020 (category Article 5(1)(c) GDPR)
    infringement of Article 5.1 c) AVG has been proven. f)Transparent information (Article 5.1(a); Article 12.1. and Article 13.1. and 13.2. AVG) 43.The complainant
    48 KB (7,926 words) - 16:56, 12 December 2023
  • AEPD (Spain) - PS/00188/2019 (category Article 5(1)(f) GDPR)
    made on 13/04/18 by the user, Ms. D.D.D., requesting the Universal Supply Point Code, located in the ***DIRECTION.2. In order to provide the CUPS code
    39 KB (6,623 words) - 14:08, 13 December 2023
  • UODO (Poland) - ZSPU.421.3.2019 (category Article 5(2) GDPR)
    and Article 57(1)(a), Article 58(2)(d) and (i) in connection with Article 5(1)(a), (e) and (f) and (2), Article 24(1) and (2), Article 28, Article 30(1)(d)
    58 KB (9,357 words) - 10:02, 17 November 2023
  • AEPD (Spain) - E/10529/2021 (category Article 45 GDPR)
    45 of the GDPR. - The person in charge cannot base the transfer of data on the clauses contractual type provided for in arts. 46.2.c and 46.2.d of the GDPR
    44 KB (6,642 words) - 10:34, 13 December 2023
  • AEPD (Spain) - EXP202301529 (category Article 17 GDPR)
    accordance with the powers that article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), grants each control authority
    20 KB (3,078 words) - 13:05, 13 December 2023
  • AEPD (Spain) - EXP202203617 (category Article 5(1)(c) GDPR)
    particular case". According to the provisions of article 83.2 of the GDPR, the measure provided for in article 58.2.d) of the aforementioned Regulation is compatible
    74 KB (11,726 words) - 13:02, 13 December 2023
  • AEPD (Spain) - EXP202205353 (category Article 5(1)(f) GDPR)
    the alleged violation of article 5.1.f) of the GDPR and article 32 of the GDPR, typified in article 83.5 and 83.4 of the GDPR. The initiation agreement
    22 KB (3,386 words) - 16:05, 13 December 2023
  • Court of Appeal of Brussels - 2019/AR/1600 (category Article 13(2)(a) GDPR)
    violation of Article 6(1) GDPR; 2. Did not provide the complainant with enough information prior to the processing, in violation of Article 13 GDPR; 3. Processed
    60 KB (9,144 words) - 16:17, 22 March 2022
  • Commissioner (Cyprus) - Α/Π 68/2017 (category Article 58(2)(i) GDPR)
    for the submitting of all the reasons for which no sanction of the GDPR Article 58 par.2(a), (b), (e) & (i) should be imposed on Cyprus Police. Eventually
    6 KB (649 words) - 16:51, 6 December 2023
  • AEPD (Spain) - EXP202201746 (category Article 5(1)(f) GDPR)
    these facts: one for the violation of article 5.1.f) RGPD, and another for article 32 GDPR. x Article 58.2 of the GDPR provides the following: “Each supervisory
    62 KB (9,703 words) - 13:05, 13 December 2023
  • Datatilsynet (Norway) - 20/02375 (category Article 6(1)(f) GDPR)
    processing time. 2. Decision on order and infringement fine The Data Inspectorate makes the following decisions: 1. Pursuant to Article 58 (2) (2) of the Privacy
    40 KB (5,943 words) - 18:54, 5 March 2022
  • regard being had to the powers provided for in Article 51(1) GDPR and those conferred by Article 58(2)(b) and (d) of that regulation? (3) Must the independence
    9 KB (1,308 words) - 12:54, 28 June 2023
  • reasoned in accordance with Article 4(24) GDPR and, after conducting its own assessment of the factors under Article 83(2) GDPR, found that the proposed fine
    53 KB (8,413 words) - 14:10, 30 January 2023
  • AEPD (Spain) - PS/00070/2019 (category Article 5(2) GDPR)
    referred to Article 5(1)(a) (principle of lawfulness, fairness and transparency), Article 12(1), Article 7, Article 13 and Article 14 GDPR, the corresponding
    422 KB (70,184 words) - 13:56, 13 December 2023
  • AEPD (Spain) - EXP202201721 (category Article 6(1) GDPR)
    to in Article 58, paragraph 2, letters a) to h) and j). In this way the corrective measures, which are all those provided for in the article 58.2 of the
    79 KB (12,408 words) - 13:24, 13 December 2023
  • pursuant to Article 17(2) DPA Act. 9. Moreover, as regards the one-stop-shop mechanism, Article 56 GDPR states: "Without prejudice to Article 55, the supervisory
    429 KB (58,279 words) - 09:12, 2 November 2022
  • AEPD (Spain) - PS/00139/2020 (category Article 58(2) GDPR)
    violation of Article 5(1)(d) of the GPRS, in relation to Article 4(1) of the LOPDGDD, which governs the principle of accuracy of personal data. IV Article 72.1
    20 KB (3,086 words) - 14:04, 13 December 2023
  • OLG Köln - 15 U 126/19 (category Article 17(1)(d) GDPR)
    pursuant to Article 17(1)(d) GDPR since the data was unlawfully processed. The defendant claimed that its activities fall under exception in (Article 85 GDPR)
    121 KB (20,412 words) - 15:58, 10 March 2022
  • 5(1)(a), (d) and (f), 9 and 32(1)(b) GDPR.” Pursuant to Article 58(2)(i), the DPA hence imposed an administrative fine as per Article 83(4) and (5) GDPR. Given
    10 KB (1,206 words) - 15:54, 6 December 2023
  • AEPD (Spain) - PS/00341/2019 (category Article 21 GDPR)
    the authority initiated proceedings for the alleged infringement of Article 5(1)(d) GDPR against the political party aforementioned. The Political party acknowledged
    26 KB (4,032 words) - 14:31, 13 December 2023
  • Datatilsynet (Norway) - 17/01281 (category Article 58(2)(b) GDPR)
    Ordinance Article 6 No. 1 letter f for this processing. Our legal basis for decisions on reprimands is the Privacy Ordinance, Article 58, No. 2, letter b
    38 KB (6,275 words) - 16:13, 6 December 2023
  • Datatilsynet (Norway) - 20/01868 (category Article 5(1)(d) GDPR)
    following decision on 18 May 2020: "Pursuant to Article 58 (2) (g) of the Privacy Ordinance, cf. Article 16 of the Privacy Ordinance, we order Sbanken to
    26 KB (4,150 words) - 16:14, 6 December 2023
  • AEPD (Spain) - PS/00433/2020 (category Article 58(2)(c) GDPR)
    flows by the authority ofcontrol pursuant to Article 58 (2), or failure to provide access in breachof article 58, paragraph 1. "Organic Law 3/2018, on the
    23 KB (3,592 words) - 14:40, 13 December 2023
  • CNPD (Portugal) - Deliberação 2022/1072 (category Article 35(2) GDPR)
    to or instead of the measures referred to in Article 58(2)(a) to (h) and (j) [..)', Article 83(2) of the GDPR recognizes the power of the national supervisory
    163 KB (27,222 words) - 16:54, 6 December 2023
  • AEPD (Spain) - PS/00060/2020 (category Article 58(2) GDPR)
    protection authority control in accordance with Article 58(2) or failure to provide access in breach of Article 58(1). The Organic Law 3/2018, on the Protection
    23 KB (3,695 words) - 13:53, 13 December 2023
  • AEPD (Spain) - EXP202201247 (category Article 58(2) GDPR)
    the census registration and payroll of Ms. B.B.B.  November 8, 2018 – D. D.D.D. (Brother of the claimant) send by mail the income 2017 (model100) from
    17 KB (2,350 words) - 13:17, 13 December 2023
  • IMY (Sweden) - DI-2020-11397 (category Article 44 GDPR)
    of personal data of data subjects guaranteed by Article 44 GDPR and consequently breached Article 44 GDPR. The DPA issued a fine of 300,000 SEK (approx.
    121 KB (13,722 words) - 15:16, 5 July 2023
  • UODO (Poland) - DKN.5112.7.2020 (category Article 58(2)(b) GDPR)
    and Article 60 of the Act of 10 May 2018 on the protection of personal data (Journal of Laws of 2019, item 1781) and pursuant to Article 58(2)(b) in connection
    29 KB (4,687 words) - 09:56, 17 November 2023
  • in particular of children was in breach of Article 5, Article 6, Article 8, Article 9, and Article 25 GDPR. Consequently, the DPA urgently imposed upon
    36 KB (5,598 words) - 10:15, 8 February 2023
View (previous 250 | ) (20 | 50 | 100 | 250 | 500)