Search results
From GDPRhub
- DSB (Austria) - 2020-0.111.488 (category Article 5(1)(a) GDPR)Regulation, hereinafter : "GDPR"), OJ No. L 119 of 04.05.2016 S1, the following administrative offense (s) committed: In any case, from **. February 2020 until8 KB (1,048 words) - 13:50, 12 May 2023
- CNPD (Luxembourg) - Délibération n° 17FR/2021 (category Article 5(1)(c) GDPR)headquarters of [S1] and a second system is operated from the site of [S2]. The video surveillance system installed at the administrative headquarters of [S1] is composed44 KB (6,212 words) - 08:28, 16 June 2021
- ArbG Düsseldorf - 9 Ca 6557/18 (category Article 6(1)(c) GDPR)December 9, 2018 (Annex S1, pages 314 et seq. DA), the attorney-at-law sent the defendant's attorney-at-law to the plaintiff's attorney-at-law, a letter58 KB (9,364 words) - 13:51, 16 December 2021
- Article 6 GDPR (section (1) Legal basis for processing)concept of "explicit consent" in Articles 9(1)(a), 22(2)(c) and 49(1)(a) GDPR. See the commentary on Article 9(1)(a) GDPR for explicit consent. Generally108 KB (17,005 words) - 15:39, 18 March 2024
- Article 5 GDPR (section (1) Principles)Article 5(1)(b) does not foresee a certain form of documentation, but Articles 5(2) or 30(1)(a) GDPR require documentation and Articles 6(1)(a), 13(1)(c) and51 KB (6,355 words) - 08:25, 18 April 2024
- Article 58 GDPR (section (1) Investigative powers)controller’s (or processor’s) premises in accordance with Article 58(1)(f) GDPR. The search is not restricted to the business premises but a judge’s authorization46 KB (5,825 words) - 11:12, 7 November 2023
- Article 15 GDPR (section (1) The Right of Access)further details see Article 14(1)(d) GDPR. Similar to the ex-ante information in Article 13(1)(e) and 14(1)(e) GDPR, Article 15(1)(c) GDPR requires the controller73 KB (9,896 words) - 15:46, 18 March 2024
- Article 4 GDPR (section (1) Personal data)(Nomos 2018). Recital 70 GDPR. Recital 71 sentence 1 GDPR. Recital 71 sentence 1 GDPR. Recital 28 sentence 1 GDPR, such as Hansen, in Simitis, Hornung, Spieker125 KB (16,328 words) - 16:01, 8 March 2024
- alternative means of communication which suit the data subject's specific needs. Under Article 12(1) GDPR, information “shall be provided in writing, or by other76 KB (11,304 words) - 08:37, 4 March 2024
- Article 13 GDPR (section (1) Information the controller shall provide at the time personal data is obtained)GDPR embodies the principle of transparency in Article 5(1)(a) GDPR, outlining the controller's obligation to actively provide clear and comprehensive information71 KB (9,532 words) - 13:30, 6 March 2024
- Article 17 GDPR (section (1) Right to erasure)data subject’s private life, and second, the public’s interest in accessing the information, which may vary depending on the data subject’s role in public61 KB (8,488 words) - 15:47, 18 March 2024
- non-material damage. Article 32(1) GDPR reflects the principle of integrity and confidentiality enshrined in Article 5(1)(f) GDPR. The controller and the41 KB (5,197 words) - 12:17, 17 April 2024
- Article 9 GDPR (section (1) General prohibition of processing of special categories of personal data)subsume the corresponding legal basis contained in Article 6(1)(a) GDPR, 6(1)(d) GDPR and 6(1)(e) GDPR respectively, and would require no additional correlation44 KB (5,905 words) - 14:00, 24 October 2023
- Article 83 GDPR (section (1) Administrative fine)identification of sanctionable conduct(s) and infringment(s). For a detailed analysis we refer to paragraph (1). Determination of the starting point of55 KB (7,622 words) - 14:04, 7 November 2023
- public interest in the case of Article 6(1)(e) and the controller's legitimate interest in the case of Article 6(1)(f). In other words, there is a balancing49 KB (5,993 words) - 06:22, 16 June 2023
- Article 14 GDPR (section (1) Information the controller shall provide when personal data has not been obtained from the data subject)Article 13(1)(a) GDPR. Given the identical wording, see commentary on Article 13(1)(b) GDPR. Given the identical wording, see commentary on Article 13(1)(c) GDPR47 KB (5,644 words) - 17:49, 5 March 2024
- Article 25 (1) and (2), Article 28(1), Article 32(1) GDPR, Article 89(1) GDPR). These measures can also be regarded as measures under Article 24(1) since they30 KB (3,458 words) - 10:31, 25 April 2024
- Article 25 GDPR (section (1) Data protection by design)individual rights. These criteria have the same meaning as in Article 24(1) and Article 32(1). The "nature" of the processing consists of its “the inherent characteristics”43 KB (4,675 words) - 06:43, 16 June 2023
- Article 28 GDPR (section (e) Assisting with the controller's obligation to respond to data subject's requests)possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III; (f) assists72 KB (9,140 words) - 13:12, 2 June 2023
- May 2020 (Version 1.1), pp. 7-8 (available here). EDPB, ‘Guidelines 05/2020 on consent under Regulation 2016/679’, 4 May 2020 (Version 1.1), pp. 8-9 (available31 KB (3,489 words) - 16:00, 8 March 2024
- Article 33 GDPR regulates the controller and processor's obligations in case of data breach. Pragraph 1 imposes an obligation on controllers to notify the54 KB (6,536 words) - 08:22, 16 June 2023
- enforcement of the GDPR are SA's main tasks. They summarise the core idea of SA's activities. All other tasks entailed in Article 57(1) GDPR can be understood60 KB (7,796 words) - 20:12, 1 April 2024
- Article 35 GDPR (section (1) Mandatory DPIA)legitimate purpose(s) (Article 5(1)(b)); lawfulness of processing (Article 6); adequate, relevant and limited to what is necessary data (Article 5(1)(c)); limited52 KB (7,297 words) - 08:05, 18 July 2023
- to Article 32(1) GDPR would be an example of such an obligation. It is also important to stress that, without prejudice to the processor's liability under33 KB (4,215 words) - 09:57, 19 March 2024
- ng provision of Article 56(1) GDPR. In such cases, the LSA, i.e. the SA of the place where the controller's or processor's main or sole establishment is35 KB (4,017 words) - 16:04, 18 March 2024
- Article 56 GDPR (section (1) Designation of the Lead Supervisory Authority (LSA) and the Cooperation Mechanism)processor’s lead supervisory authority, version 2.1, Section 2.2, available here. Guidelines 8/2022 on identifying a controller or processor’s lead supervisory55 KB (7,446 words) - 22:28, 1 April 2024
- Article 30(1)(a) states it should contain the name and contact details of the controller and, where applicable, the joint controller(s), the controller's representative31 KB (3,327 words) - 15:31, 5 June 2023
- with Article 33(1) GDPR. Thus, since the supervisory authority should be aware of the data breach, it can also be involved in the controller’s procedure for37 KB (3,962 words) - 15:20, 16 June 2023
- Article 2 GDPR (section (1) Material scope)information onto a form. The form is stored in the hospital's old paper filing system, where each patient's papers are stored according to surname and first name34 KB (4,652 words) - 12:07, 12 November 2023
- guide the reviewer’s decision. Otherwise, it would be completely impossible to express one's own point of view. Pursuant to Article 12(1), which expressly31 KB (4,768 words) - 06:24, 16 June 2023
- to include the DPO's 'contact details', i.e. exactly the same wording used in Article 13(1)(b) GDPR. If one were to follow Apple's suggested reading, after43 KB (4,904 words) - 12:59, 21 July 2023
- Article 23 GDPR (section (1) Restrictions)subject’s rights, but not deny them. The grounds for restrictions are exhaustively listed in Article 23(1) GDPR. These grounds, listed in Article 23(1)(a)-(c)44 KB (4,896 words) - 06:25, 16 June 2023
- subject’s data by the controller triggers a data subject’s right under Article 13 and 14 GDPR. We reject a strict literal interpretation of Article 79(1) GDPR31 KB (3,550 words) - 11:11, 29 November 2023
- CJEU: The CJEU has clarified in C-132/21 that "Article 77(1), Article 78(1) and Article 79(1) of Regulation (EU) 2016/679 [...] must be interpreted as33 KB (3,641 words) - 09:51, 19 March 2024
- exercise of a SA's investigative powers under Articles 58(1)(a), (b), (c), (e) and (f) GDPR; decisions following the exercise of a SA's corrective powers30 KB (3,874 words) - 10:46, 7 December 2023
- independence and expertise in data protection matters. Paragraph 1 ensures the DPO's timely and proper involvement in any data protection issues. Paragraph29 KB (2,951 words) - 14:19, 25 July 2023
- Article 46 GDPR (section (1) Scope)Article 46 - Transfers subject to appropriate safeguards 1. In the absence of a decision pursuant to Article 45(3), a controller or processor may transfer34 KB (3,646 words) - 08:53, 27 March 2023
- objection of a SA (Article 65(1)(a) GDPR), when there are different views on which SA is the lead SA (“LSA”) (Article 65(1)(b) GDPR), and where a SA is33 KB (4,185 words) - 16:09, 2 November 2023
- prior authorization, irrespective of the requirements of paragraph 1. Article 36(1) GDPR establishes an obligation for the controller to consult the DPA31 KB (3,646 words) - 08:51, 21 July 2023
- Article 39 GDPR (section (1) DPO's Tasks)to management or the appropriate authority. Articles 39(1)(d) and (e) GDPR lay down the DPO’s obligations in relation to the Data Protection Authorities23 KB (2,165 words) - 15:10, 27 July 2023
- restricted under paragraph 1, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment32 KB (3,730 words) - 08:43, 7 March 2024
- version=1.0 https://www.garanteprivacy.it/documents/10160/0/Bilancio+di+previsione+2019+-+Sintetico.xlsx/700e5df5-f7c3-6510-1bd5-ef90e9824f17?version=1.07 KB (808 words) - 08:17, 16 February 2023
- Act (Zakon o varstvu osebnih podatkov (ZVOP-1)) which stayed in force for more than 4 years after the GDPR’s entrance into force. Responding to requests10 KB (1,242 words) - 10:51, 6 February 2024
- Article 26 GDPR (section (1) Joint controllership)data on another party’s behalf and on this party’s documented instructions (you are a sub-processor). According to Article 26(1) of the GDPR, joint controllers37 KB (3,915 words) - 12:49, 24 May 2023
- Article 3 GDPR (section (1) Establishment in the Union)the Union. Whereas the mere accessibility of the controller's, processor's or an intermediary's website in the Union, of an email address or of other contact37 KB (4,635 words) - 13:29, 24 October 2023
- after IP completion day, the court is not bound (EUWA s 6(1)) but "may have regard" to them (EUWA s 6(2)). (4) The position is different in a "relevant court"18 KB (2,488 words) - 15:22, 14 December 2021
- However, Article 5(1)(d) GDPR gives the controller some leeway to continue processing inaccurate data - see more details under Article 5(1)(d) GDPR. Article23 KB (2,489 words) - 23:24, 6 March 2024
- necessary to protect an interest which is essential for the data subject's or another person's vital interests, including physical integrity or life, if the data29 KB (3,500 words) - 08:54, 27 March 2023
- an advisory role. Articles 70(1)(a) and 70(1)(t) GDPR grant the EDPB an important and new role regarding the Regulation’s consistency mechanism. In particular27 KB (3,038 words) - 12:19, 11 October 2023
- the territory of the European Union (in breach of Article 27(1) GDPR). In such situations s SA may ask the competent authorities of the country of the processor35 KB (3,971 words) - 21:34, 1 April 2024
- tie, the President's vote shall prevail. Decisions are published except for cases where there is impediment of a DPA's member. The DPA’s response or decision23 KB (2,039 words) - 08:15, 25 April 2024
- Article 8 GDPR (section (1) Material scope)May 2020 (Version 1.1), p. 28 (available here). EDPB, ‘Guidelines 05/2020 on consent under Regulation 2016/679’, 4 May 2020 (Version 1.1), p. 27 (available19 KB (1,335 words) - 13:56, 24 October 2023
- burdened by data protection rules. Article 85(1) GDPR sets out a legal framework to reconcile the data subject’s right to data protection with the performance33 KB (3,748 words) - 14:25, 7 November 2023
- of Article 88(1) GDPR. Therefore, for a comprehensive overview of the term ‘more specific’, please refer to section 2.1 below. Article 88(1) GDPR establishes32 KB (3,228 words) - 13:32, 30 November 2023
- organisation or association referred to in paragraph 1 of this Article, independently of a data subject’s mandate, has the right to lodge, in that Member State26 KB (2,575 words) - 15:50, 9 November 2023
- Article 20 GDPR (section (1) Right to data portability)pursuant to point (a) of Article 6(1) or point (a) of Article 9(2) or on a contract pursuant to point (b) of Article 6(1); and (b) the processing is carried40 KB (5,349 words) - 07:05, 1 June 2023
- referred to in paragraph 1 within the period referred to in paragraph 3. 7. The supervisory authority referred to in paragraph 1 shall take utmost account23 KB (2,079 words) - 16:07, 2 November 2023
- set out in Article 51(1) and 52 GDPR, Article 54(1)(a) GDPR repeats that these should be legislated for through a Member State's domestic law. Under the34 KB (3,649 words) - 13:19, 30 October 2023
- up. Indeed, the wording of Article 40(1) establishes that they “shall encourage” this (emphasis added). Article 40(1) GDPR clarifies that codes of conduct44 KB (5,008 words) - 14:50, 28 July 2023
- Article 75 GDPR (section (1) The Secretariat)outlines the secretariat's responsibilities, which take on a primarily administrative function. Including the secretariat within the GDPR's legislative rubric20 KB (1,347 words) - 14:21, 17 October 2023
- controller is subject, under Article 6(1)(c) GDPR. In line with the general objectives of the GDPR, as outlined in Article 1 GDPR Article 16 TFEU, SAs are also27 KB (2,604 words) - 14:24, 16 January 2024
- seconding supervisory authority's authorisation, confer powers, including investigative powers on the seconding supervisory authority's members or staff involved22 KB (1,915 words) - 13:46, 15 January 2024
- Article 41 GDPR (section (1) The monitoring body)the code of conduct. This is clear from the wording of Article 41(1) GDPR. Article 41(1) GDPR does not define accreditation. Nonetheless, Article 41(2) GDPR30 KB (2,720 words) - 14:02, 28 July 2023
- Article 68 GDPR (section (1) Legal personality)accordance with that Member State’s law, must act as representative to the Board. While the Commission may participate in the EDPB’s meetings and activities, it20 KB (1,632 words) - 10:01, 11 October 2023
- Article 47 GDPR (section (1) Binding Corporate Rules)the company’s internal complaint mechanism, cooperation duties with the DPAs, as well as liability and jurisdiction provisions (Articles 47(1)(b), 47(2)(d)29 KB (2,823 words) - 15:15, 28 April 2022
- (Article 24(1) RoP). This provision ensures the EDPB's flexibility and ability to act. The EDPB also made use of the authorisation in Article 76(1) GDPR and22 KB (2,266 words) - 08:26, 17 October 2023
- following their deliberations. Article 53(1) names four possible appointing bodies. These are a Member State's (i) parliament, (ii) government, (iii) head29 KB (2,894 words) - 23:06, 1 April 2024
- secrecy are laid down in the EDPB's Rules of Procedure (“RoP”). Article 33(1) RoP stipulates that in “accordance with Art 76 (1) GDPR”, discussions of the Board15 KB (787 words) - 08:17, 19 October 2023
- Article 1 GDPR (section (1) Subject-matter)function as guiding principles to interpreting the GDPR. Article 1(1) establishes the GDPR's two main aims. First, it aims at protecting natural persons with28 KB (3,831 words) - 16:21, 14 March 2024
- concerning the interpretation of Article 28(1) of Directive 95/46/EC ("DPD"), the Regulation's predecessor. Article 28(1) DPD established the existence of supervisory47 KB (5,594 words) - 22:45, 1 April 2024
- processing of the data in question by the recipients. Indeed, under Article 5(1)(d) and 17(1) GDPR, each recipient is individually responsible for correcting, deleting19 KB (1,436 words) - 12:35, 12 May 2023
- require the data subject’s identification remain applicable, including, but not limited to, security of processing (Article 32(1) GDPR) and the general principles20 KB (1,854 words) - 16:32, 8 March 2024
- not apparent why the principle laid down in Article 72(1) GDPR should be deviated from. Article 72(1) GDPR stipulates that the Board shall take decisions19 KB (1,530 words) - 14:23, 12 October 2023
- itself does not impose any formal restrictions on the Article's applicability. Article 81(1) GDPR requires that the competent court of a Member State to27 KB (2,619 words) - 14:52, 16 November 2023
- bodies may not interfere in the EDPB's functioning. This arrangement stands in stark contrast to that of the Board's predecessor, the Article 29 Working18 KB (1,327 words) - 12:36, 14 December 2023
- just before the deadline of 1 month. That means that if you want to appeal a decision, you've only one month to do so as there's a delay of 2 month after8 KB (824 words) - 22:52, 27 February 2024
- Article 92 GDPR (section (1) Delegated acts)delegation of power. At first glance, Article 92 GDPR's wording seems to be in conflict with Article 290(1) TFEU, but in actuality it is not. Article 92(2)19 KB (1,525 words) - 08:18, 19 October 2023
- Article 71 - Reports 1. The Board shall draw up an annual report regarding the protection of natural persons with regard to processing in the Union and15 KB (1,196 words) - 08:15, 19 October 2023
- Article 45 GDPR (section (1) Adequacy Decision)take account of obligations arising from the third country's or international organisation's participation in multilateral or regional systems in particular43 KB (5,641 words) - 14:58, 28 April 2022
- Article 97 - Commission reports 1. By 25 May 2020 and every four years thereafter, the Commission shall submit a report on the evaluation and review of16 KB (778 words) - 08:24, 19 October 2023
- 91 - Existing data protection rules of churches and religious associations 1. Where in a Member State, churches and religious associations or communities25 KB (2,482 words) - 10:04, 19 March 2024
- Article 89 GDPR (section (1) Mandatory Appropriate Safeguards for Archiving Purposes in the Public Interest, Scientific or Historical Research Purposes,...)research. In addition, it should take into account the Union's objective under Article 179(1) TFEU of achieving a European Research Area. Scientific research29 KB (3,695 words) - 13:44, 21 March 2024
- supervisory authority’s request is to further the performance of its tasks. Following from this, the content and scope of a supervisory authority’s request is constricted22 KB (2,042 words) - 14:29, 20 November 2023
- Representatives of controllers or processors not established in the Union 1. Where Article 3(2) applies, the controller or the processor shall designate25 KB (2,418 words) - 14:11, 24 May 2023
- this section! You can help us filling this section! There are two options: 1) a "recurso de reposicion" to ask the AEPD to reconsider its decision or 2)4 KB (386 words) - 15:29, 3 September 2021
- and the EPD is to be found in Recital 10 and Article 1(2) EPD. Article 1(2) EPD provides that the EPD's provisions serve to "particularise and complement20 KB (1,539 words) - 08:21, 19 October 2023
- Article 99(1) GDPR, which entered the Regulation into force on 25 May 2016, generating a two-year transition period between the Regulation's entry into13 KB (530 words) - 09:40, 3 October 2023
- Article 74 GDPR (section (1) Tasks of the Chair)Article 74 - Tasks of the Chair 1. The Chair shall have the following tasks: (a) to convene the meetings of the Board and prepare its agenda; (b) to notify15 KB (808 words) - 09:44, 17 October 2023
- Article 99 - Entry into force and application 1. This Regulation shall enter into force on the twentieth day following that of its publication in the Official12 KB (295 words) - 08:25, 19 October 2023
- criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when17 KB (1,768 words) - 15:41, 18 March 2024
- Article 93 GDPR (section (1) Implementing acts)margin number 1 (C.H. Beck 2020, 3rd Edition). Ehmann, in Ehman, Selmayr, Datenschutz-Grundverordnung, Article 93 GDPR, margin number 1 (C. H. Beck 201817 KB (1,096 words) - 08:19, 19 October 2023
- Article 42 - Certification 1. The Member States, the supervisory authorities, the Board and the Commission shall encourage, in particular at Union level27 KB (2,452 words) - 14:26, 28 July 2023
- secrecy 1. Member States may adopt specific rules to set out the powers of the supervisory authorities laid down in points (e) and (f) of Article 58(1) in18 KB (1,599 words) - 12:26, 29 April 2022
- the adoption of final measures regarding Facebook Ireland Limited, p.42, s. 4.2.1(available here).15 KB (810 words) - 16:13, 2 November 2023
- processing of personal data (see Article 5(1)(a) GDPR), the need to limit the purpose of such processing (see Article 5(1)(b) GDPR), the requirement to have a48 KB (5,978 words) - 15:57, 1 February 2024
- Article 43 GDPR (section (1-5) The certification body)Article 43 - Certification bodies 1. Without prejudice to the tasks and powers of the competent supervisory authority under Articles 57 and 58, certification22 KB (1,634 words) - 14:40, 28 July 2023
- https://www.dsb.gv.at/dam/jcr:ee7b155a-0a1f-4d00-98e9-902314c7022d/Datenschutzbericht%202022.pdf Report: Europe’s governments are failing the GDPR by Brave11 KB (1,468 words) - 13:27, 14 May 2023
- Article 66 - Urgency procedure 1. In exceptional circumstances, where a supervisory authority concerned considers that there is an urgent need to act in20 KB (1,590 words) - 16:11, 2 November 2023
- their work. The President shall exercise the employer’s rights over the public officials and the NAIH's employees. Based on constitutional provision, the Act7 KB (821 words) - 14:16, 7 March 2024
- engagement working on the DPA's guidance service over the phone. About 58% are women and 42% men. Historical numbers (Datatilsynet's annual report 2021): 2021:10 KB (1,078 words) - 06:40, 26 March 2023
- its Member State in accordance with Article 55(1). In that case, the urgent need to act under Article 66(1) shall be presumed to be met and require an urgent24 KB (2,181 words) - 11:46, 15 January 2024
- Article 84 - Penalties 1. Member States shall lay down the rules on other penalties applicable to infringements of this Regulation in particular for infringements19 KB (1,477 words) - 14:12, 7 November 2023
- provision is aimed at reinforcing the processor’s obligations to only act in line with the controller’s instructions, as well as at clarifying that these13 KB (674 words) - 13:15, 2 June 2023
- that point, it is important to note that Article 13(1)(f) GDPR, Article 14(1)(f) GDPR, Article 15(1)(c) GDPR and Article 15(2) GDPR, make specific reference21 KB (1,831 words) - 08:51, 27 March 2023
- Article 6(1)(c) GDPR (i.e. processing is necessary for compliance with a legal obligation to which the controller is subject) or Article 6(1)(e) GDPR (i22 KB (2,177 words) - 10:01, 19 March 2024
- in the same sector, it may be a good idea to check the proccessing in one's own organisation in this regard as well. The activity reports usually also15 KB (718 words) - 15:31, 19 October 2023
- Saxony's procedural law, "Lower Saxony Administrative Procedure Act", is Niedersächsisches Verwaltungsverfahrensgesetz - NVwVfG. Corresponding § 1(1) NVwVfG5 KB (465 words) - 08:57, 9 January 2024
- Of the 1,046 complaints that were resolved from 1. 1. 2018 to 24. 5. 2018 the DPC has only made 12 formal decisions, which is equivalent to 1,1% of the8 KB (1,034 words) - 14:13, 20 August 2021
- for the companies in their compliance work. On 1 October 2020, it publishes a small report helping the SME's to implement correctly GDPR: Report in French9 KB (993 words) - 07:10, 28 July 2022
- the Act of 1 August 2018 on the organisation of the National Data Protection Commission and the general data protection framework; the Act of 1 August 201810 KB (1,199 words) - 10:14, 19 October 2022
- Acts relating to data protection in a manner which corresponds with the GDPR's regulatory framework. Given that data protection affects several different15 KB (943 words) - 09:58, 8 November 2023
- between them. This way, Article 50 GDPR expands the exhortation under Article 57(1)(g) GDPR that calls for cooperation between EU DPAs, across borders. This provision17 KB (1,142 words) - 15:41, 28 April 2022
- on the organisation and functioning of of support services for the CNPD [1]. Regulation n.º 301/2020, of March 31, on the value of fees to provide GDPR5 KB (531 words) - 13:25, 3 May 2023
- in three distinct circumstances, as outlined below. First, under Article 64(1) GDPR, the consistency mechanism is triggered when a supervisory authority15 KB (851 words) - 06:55, 29 April 2022
- The funding for 2022 is €1,486,803. Historical numbers: 2021: €1,226,404 2020: €1,053,392 The DVI has 33 employees as per 1st October 2022 out of totally6 KB (544 words) - 04:39, 11 October 2022
- Relationship with previously concluded Agreements → Chapter 1: General provisions Article 1: Subject-matter and objectives Article 2: Material scope Article13 KB (450 words) - 08:22, 19 October 2023
- Processing of the national identification number → Chapter 1: General provisions Article 1: Subject-matter and objectives Article 2: Material scope Article15 KB (660 words) - 09:37, 1 December 2023
- Transfers or disclosures not authorised by Union law → Chapter 1: General provisions Article 1: Subject-matter and objectives Article 2: Material scope Article14 KB (716 words) - 15:19, 28 April 2022
- for example, the Commission's legal service. It therefore, has its own legal service who goes to Court in the institutions's behalf. The Supervision and8 KB (1,078 words) - 12:58, 10 May 2024
- to § 25(1)(2) LDSG and § 40(1) BDSG for complaints in the private sector within Baden-Württemberg. Complaints can be filed online on the LfDI's website4 KB (275 words) - 11:13, 8 May 2022
- 209/83, 1 BvR 269/83, 1 BvR 362/83, 1 BvR 420/83, 1 BvR 440/83, 1 BvR 484/83 (in DE) (Abstract in EN) - ECLI:DE:BVerfG:1983:rs19831215.1bvr020983 Translated:18 KB (1,831 words) - 13:49, 3 November 2022
- https://www.uoou.cz/organizacni-struktura/ds-1063/archiv=0&p1=1059 Information about the law governing the DPA's activity can be found here. Complaints are governed5 KB (441 words) - 09:34, 17 September 2022
- your complaint which is being herewith attached for your record. Next Steps: 1. A preliminary assessment of your complaint will be conducted to determine4 KB (483 words) - 08:17, 12 July 2022
- to approve the Government's candidate for the position of the President. The Structure of the Slovak DPA: President President´s office Vice-President DPO9 KB (1,006 words) - 07:13, 7 July 2021
- help us by filling in this section! Annual reports are published on BayLDA's website.2 KB (174 words) - 13:49, 23 December 2021
- resides in Stockholm and is in charge of enforcing the GDPR in Sweden. On 1 January 2021, the Swedish data protection authority changed their name from4 KB (356 words) - 11:51, 20 October 2022
- 01008 Vitoria, Álava, Spain Webpage: https://www.avpd.euskadi.eus/s04-5213/es/ Email: [1] Phone: +34 945 016 230 Twitter: https://twitter.com/avpd_dbeb Official3 KB (195 words) - 13:21, 15 September 2021
- Article 57(1)(f) of the GDPR, each supervisory authority is required on its territory to handle complaints which, in accordance with Article 77(1) of that12 KB (1,780 words) - 17:22, 10 March 2022
- list of results displayed following a search made on the basis of a person’s name. In March 2010, Mario Costeja Gonzalez, a Spanish national, lodged a complaint16 KB (2,423 words) - 13:03, 1 June 2023
- the Union. Whereas the mere accessibility of the controller's, processor's or an intermediary's website in the Union, of an email address or of other contact182 KB (24,065 words) - 13:40, 9 July 2021
- DSB (Austria) - 2021-0.586.257 (category Article 4(1) GDPR)basis: Art. 4 (1), (2), (7) and (8), Art. 5, Art. 44, Art. 46 (1) and (2) (c), Art. 51 (1), Art. 57 (1) (d) and (f), Art. 77 (1), Art. 80 (1) and Art. 93108 KB (17,097 words) - 13:52, 12 May 2023
- CJEU - C-230/14 - Weltimmo (section Questions 1-6)State? Can Article 4(1)(a) of [Directive 95/46], read in conjunction with recitals 18 to 20 of its preamble and Articles 1(2) and 28(1) thereof, be interpreted13 KB (1,888 words) - 13:07, 1 June 2023
- possible here. Subparagraph (1)(b) therefore has to be written as #1b! Example: [[Article 6 GDPR#1b|Article 6(1)(b)]] becomes Article 6(1)(b) and links to Article17 KB (2,510 words) - 13:56, 24 April 2023
- Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 1) (category Article 5(1)(c) GDPR)and letter f., Article 5, paragraph Article 6 (1) (a) Article 32 (1), (1), (33) 1 and 35, para. 1. Below is a more detailed review of the case and a justification48 KB (7,442 words) - 10:24, 12 September 2022
- The civil procedure is mainly regulated in the Law 1/2000, of 7 January, on Civil Proceedings (Ley 1/2000, de 7 de enero, de Enjuiciamiento Civil). Spanish15 KB (1,875 words) - 16:18, 13 July 2022
- CJEU - C-154/21 - RW v Österreichische Post (category Article 5(1)(a) GDPR)of the controller's obligation to inform all recipients of the exercise of the rights that the data subject has under Articles 16, 17(1) and 18 GDPR. The8 KB (992 words) - 17:03, 4 February 2023
- CNIL (France) - SAN-2020-012 (category Article 26(1) GDPR) (section The Google’s partially flawed opposition mechanism)information stored in the user's terminal equipment or the recording of information in the user's terminal equipment: 1 ° Either, for the sole purpose93 KB (14,936 words) - 17:09, 6 December 2023
- balance of the controller’s interest and the fundamental rights and freedoms of users which call for protection under Article 1(1) Directive 95/46. Share9 KB (1,113 words) - 13:10, 1 June 2023
- Datatilsynet (Norway) - 20/02136 (category Article 6(1) GDPR)of its users. Also note the Spanish DPA's decision for Grindr, which contradicts several of the Norwegian DPA's findings. Share blogs or news articles here18 KB (2,375 words) - 16:17, 6 December 2023
- Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 2) (category Article 5(1)(a) GDPR)subsection 1, letters c and f, and Article 5, subsection 1, letter a, cf. Article 6, subsection 1, and Article 32, subsection 1, Article 33, subsection 1, and75 KB (11,733 words) - 16:33, 21 August 2022
- Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 3) (category Article 35(1) GDPR)subsection 1, letters c and f, and Article 5, subsection 1, letter a, cf. Article 6, subsection 1, and Article 32, subsection 1, Article 33, subsection 1, and117 KB (18,075 words) - 10:19, 12 September 2022
- accordance with clause 5.1.1 b of the terms of Google's processing of personal data for Google's advertising products and also Google's terms and conditions113 KB (12,773 words) - 15:20, 6 December 2023
- CJEU - Joined Cases C‑26/22 and C‑64/22 - SCHUFA (category Article 6(1) GDPR)Wiesbaden doubted the HBDI’s line of argument and referred the following questions to the CJEU under Article 267 TFEU: (1) Is Article 77(1) of [the GDPR], read15 KB (2,180 words) - 08:23, 13 December 2023
- 15 (3) sentence 1 of the GDPR (question 1). Is this also a specification or modification of the general right of access under Article 15(1) of the GDPR and51 KB (8,592 words) - 07:03, 2 November 2021
- defined in paragraph 39 of Part 4 Schedule 1. In particular, the policy document must (1) explain the controller's procedures for ensuring compliance with14 KB (2,011 words) - 15:42, 25 November 2020
- CJEU - C-13/16 - Rīgas satiksme (category Article 6(1)(f) GDPR)A minor passenger had suddenly opened the cab's door, which scraped the side of a tram. The taxi driver's insurer refused to pay out on the basis that the5 KB (749 words) - 12:58, 1 June 2023
- List of results List of results by case List of documents Search result: 1 case(s) 1 documents analysed Deutsche WohnenCase C-807/21 Reports of Cases Information7 KB (936 words) - 16:39, 12 December 2023
- Matters (1) Prosecutor’s offices Courts of appeal (15) Prosecutor’s offices High Court of Cassation and Justice Prosecutor’s Office Romania's judicial16 KB (2,260 words) - 19:26, 30 November 2021
- Court of Appeal of Brussels - 2019/AR/1600 (category Article 5(1)(c) GDPR)with the violation of article/and 5.1. c); 6.1.; 13.1. (c);13.1(e) and13.2(a)AVG: r PAGE 01-00001582885-0002-0033-01- □1-� r L _JCourt of Appeal Brussels60 KB (9,144 words) - 16:17, 22 March 2022
- violated the applicant's rights, 8&168Abs. 1S.1GWB. The invitee is to be excluded from the award procedure pursuant to section 57(1) no. 4 VgV because the62 KB (10,113 words) - 12:48, 17 August 2022
- LG Köln - 33 O 376/22 (category Article 6(1)(b) GDPR)application 1.b., from §§ 1, 3 para. 1 no. 1, 4 UKlag in conjunction with §§ 307 para. 1, para. 2 no.1 in conjunction with Art. 5 para. 1 lit. a), Art66 KB (9,990 words) - 12:30, 29 January 2024
- Personvernnemnda (Norway) - 2021-20 (20/01648) (category Article 5(1)(a) GDPR)Ordinance Article 5 No. 1 letter a and c, 6, 12 Nos. 1 and 13. " The reason for the reduction in the size of the fee was the company's difficult financial31 KB (5,018 words) - 18:44, 5 March 2022
- Norges Høyesterett - 2021-2403-A (category Article 5(1)(a) GDPR)(2018) §1, GDPR A4, GDPR A5 (1) Judge Thyness: Questions and background of the case (2) The case concerns the validity of the Privacy Board's decision46 KB (7,024 words) - 06:18, 6 March 2022
- to Article 22(1) of the Labour Code, the employer requires from a person applying for employment to provide personal data including: name(s) and surname;9 KB (1,215 words) - 16:58, 18 May 2021
- accordance with clause 5.1.1 b of the terms of Google's processing of personal data for Google's advertising products and also Google's terms and conditions115 KB (12,842 words) - 08:38, 5 July 2023
- How to add a new decision (section Applied Law(s))Article 6(1)(a) and 4(11) GDPR in a case concerning the requirements of consent). Always use the most specific sub-paragraph (e.g. Article 6(1)(a) GDPR17 KB (2,638 words) - 11:18, 19 February 2024
- accordance with clause 5.1.1 b of the terms of Google's processing of personal data for Google's advertising products and also Google's terms and conditions121 KB (13,722 words) - 15:16, 5 July 2023
- basis of Article 6(1)(b): “...there is a risk that the Draft Decision’s failure to establish Meta IE's infringement of Article 6(1)(b) GDPR, pursuant to53 KB (8,413 words) - 14:10, 30 January 2023
- processing by the defendant can only be Article 6 (1) sentence 1 lit e) DSGVO (see b) or Article 6 (1) sentence 1 lit f) DSGVO (see c), the requirements of which51 KB (8,215 words) - 09:55, 13 May 2022
- used. 30EDPB's Recommendations 01/2020, point 128; IMY's translation. 31 EDPB's Recommendations 01/2020, point 77; IMY's translation. 32EDPB's Recommendations131 KB (14,752 words) - 08:36, 5 July 2023
- Tietosuojavaltuutetun toimisto (Finland) - 4680/182/18 (category Article 9(1) GDPR)subsection 1 point 1 of the Data Protection Act. According to Section 6, Subsection 1, Clause 1 of the Data Protection Act, Article 9, Section 1 of the Data49 KB (7,496 words) - 14:44, 24 January 2024
- BVwG - W258 2217446-1 (category Article 4(1) GDPR)from the following assessment of the evidence: 2.1 The finding under 1.1 is based on the complainant's unobjectionable submissions and a consistent view79 KB (12,652 words) - 09:41, 10 September 2021
- Personvernnemnda (Norway) - 2018-14 (15/01355) (category Article 5(1)(a) GDPR) (section The Board's decision)that the website's legitimate interest is based on the public's interests in the choice of health personnel. The doctor's interest must be regarded as purely144 KB (23,058 words) - 18:48, 5 March 2022
- CJEU - C‑307/22 - Copies of Medical Records (category Article 15(1) GDPR)require the practitioner to provide a free copy of the patient's personal data when the patient's request is for a purpose other than those mentioned in the10 KB (1,478 words) - 11:17, 2 November 2023
- Delo, R (On the Application Of) v The Information Commissioner - 2023 EWCA Civ 1141 (category Article 57(1)(f) GDPR)Commissioner is not obliged to reach a decision on every complaint in light of Art 57(1)(f) UK GDPR. The data subject made an access request (DSAR) to Wise Payments9 KB (1,191 words) - 08:44, 23 January 2024
- Tietosuojavaltuutetun toimisto (Finland) - 6689/186/20 (category Article 5(1) GDPR)Finnish Data Protection Ombudsman's opinion on the lawfulness of the processing of their personal data by the City of Helsinki's Social services and healthcare41 KB (6,555 words) - 08:37, 4 March 2024
- CJEU - C-77/21 - Digi (category Article 5(1)(b) GDPR)The CJEU answered preliminary questions regarding Articles 5(1)(b) GDPR and 5(1)(e) GDPR and held that national courts had to determine, using the factors49 KB (7,800 words) - 09:22, 5 January 2024
- referred to as [applicant] and the State. 1 The procedure 1.1. An application dated 30 January 2019, with productions 1 to 10, was received at the Registry of14 KB (2,154 words) - 16:27, 10 March 2022
- prohibited those companies from 1) making – in the general terms of use – the use of Facebook subject to the processing the user’s ‘off-Facebook data’ and 2)8 KB (1,231 words) - 08:22, 6 July 2023
- exceptions in Article 9(1) GDPR, Article 15 GDPR, Article 16 GDPR, Article 18(1)(a) GDPR, Article 18(1)(b) GDPR, Article 18(1)(d) GDPR, Article 20 GDPR10 KB (1,037 words) - 14:52, 10 July 2020
- CJEU - C-132/21 - Nemzeti Adatvédelmi és Információszabadság Hatóság (category Article 77(1) GDPR)The CJEU held that the remdies in Articles 77(1), 78(1) and 79(1) GDPR can be exercised concurrently with and independently of each other, even when referring9 KB (1,308 words) - 12:54, 28 June 2023
- CNIL (France) - SAN-2019-005 (category Article 5(1)(e) GDPR)Éric PÉRÈS on February 1, 2019 as rapporteur on the basis of Article 47 of the Law of January 6, 1978. By letter dated February 1, 2019, the President of41 KB (6,558 words) - 17:09, 6 December 2023
- secured in Chapter 2 § 1 in the Instrument of Government and Chapter 2 § 1 of The Fundamental Law on Freedom of Expression, and Chapter 1 § 1 in the Fundamental7 KB (793 words) - 14:08, 1 October 2021
- before which the CNIL's decisions are challenged, pursuant to Article R 311-1, par. 4 of the Code of Administrative Justice. Any CNIL's decision can be challenged10 KB (1,108 words) - 09:37, 29 September 2021
- GDPR was caused by third parties outside of the controller's control? 5) Does Article 82(1) and (2) GDPR allow the anxiety caused by a hacking attack to13 KB (1,963 words) - 11:04, 5 January 2024
- AEPD (Spain) - PS/00240/2019 (category Article 5(1)(b) GDPR)fined Equifax, a credit ranking agency, €1,000,000 for failing to comply with Article 5(1)(a), 5(1)(b), 5(1)(c), 5(1)(d) and with Article 14 GDPR. The authority602 KB (102,229 words) - 14:21, 13 December 2023
- when it’s necessary for duties or rights under labour law following § 6. Personal data can be processed on the basis of Article 6(1)(e) if it’s needed for8 KB (1,064 words) - 12:53, 23 June 2023
- Act, ZDR-1) and in “Zakon o evidencah na področju dela in socialne varnosti (Labour and Social Security Registers Act, ZEPDSV). The employee's consent to4 KB (391 words) - 09:57, 17 May 2021
- The DSG 1978 introduced the Constitutional Right to Data Protection in § 1 DSG. Austria also gave the ECHR constitutional status, whereby the Right to8 KB (721 words) - 09:32, 24 April 2024
- защита на личните данни), promulgated with State Gazette No. 1/ 4.01.2002 and entered into force 1.01.2002). Bulgarian law does not define legal entities as10 KB (1,440 words) - 08:54, 17 January 2020
- processed by a social network through transmission from the company’s or individual’s website. Share blogs or news articles here!6 KB (492 words) - 13:09, 1 June 2023
- defendant: IAB Europe Interlocutory decision 01/2021 - 3/6 1. Facts and procedural history 1. Several complaints have been lodged against Interactive Advertising19 KB (2,707 words) - 16:50, 12 December 2023
- DSB (Austria) - Austrian Postal Service (category Article 6(1)(f) GDPR)business. The penalty imposed for the identified violations of Articles 5(1), 6(1) and (4) and 9 of the GDPR is not final, as the defendant has appealed against8 KB (611 words) - 16:12, 6 December 2023
- application of art. 5, paragraph 8, of Regulation no. 1/2000 on the organization and functioning of the Guarantor's office, which provides that «In cases of particular14 KB (2,049 words) - 07:46, 1 August 2023
- personal data, within the meaning of Directive 95/46? If the answer to Question 1 is that all or some of such information may be personal data within the meaning6 KB (766 words) - 21:17, 5 March 2024
- Freedom - La Ligue des Droits de l'Homme - the defendant: IAB Europe 1. Justification 2 1. Pursuant to the agreement concluded between the parties, as ratified8 KB (1,156 words) - 16:56, 12 December 2023
- us fill this section! In Luxembourg the GDPR is implemented by the Loi du 1er août 2018. You can help us fill this section! You can help us fill this section2 KB (121 words) - 23:46, 14 January 2020
- Helsingin hallinto-oikeus (Finland) - 116/2024 (category Article 5(1)(a) GDPR)Section 6(1)(1) of the Finnish Data Protection Act, according to which insurance institutions may, despite the general prohibition in Article 9(1) GDPR, process41 KB (6,133 words) - 10:29, 25 March 2024
- Tietosuojavaltuutetun toimisto (Finland) - 8493/161/21 (category Article 5(1)(a) GDPR)commissioner's office has responded to the doctor's clinic's message on the same day and pointed out that the data protection commissioner's office has not52 KB (7,936 words) - 22:32, 2 March 2024
- VGH Baden-Württemberg - 1 S 397/19 (category Article 5(1)(d) GDPR)treaties (1) or the national provisions of § 173 sentence 1 VwGO in conjunction with § 173 sentence 1 VwGO. § 328 ZPO or §§ 108 f. FamFG (2). 53 (1) The judgment112 KB (19,310 words) - 08:08, 23 June 2022
- Tietosuojavaltuutetun toimisto (Finland) - 3216/452/17 (category Article 5(1)(a) GDPR)subsection 1, point 1 of the Data Protection Act. According to Section 6, Subsection 1, Clause 1 of the Data Protection Act, Article 9, Section 1 of the Data60 KB (9,117 words) - 14:46, 24 January 2024
- UODO (Poland) - ZSPR.421.2.2019 (category Article 5(1)(f) GDPR)Article 6(1), Article 7(1), Article 24(1), Article 25(1), Article 32(1)(b), Article 32(1)(c) and Article 32(1)(b), Article 32(1)(c) and Article 32(1)(d). d71 KB (11,304 words) - 10:01, 17 November 2023
- Datatilsynet (Norway) - 21/03530 (category Article 6(1)(b) GDPR)consequence, Meta’s assessment of the elements of Article 6(1)(f) has been skewed correspondingly. 7.2.1.3. Necessity We find Meta’s assertion of necessity99 KB (14,431 words) - 16:20, 6 December 2023
- Helsingin hallinto-oikeus (Finland) - 3620/2023 (category Article 5(1)(a) GDPR)violated Article 5(1)(a) GDPR, Article 12 GDPR, Article 13 GDPR, Article 15 GDPR and Article 25(1) GDPR by not implementing the data subject's access request22 KB (3,193 words) - 10:34, 29 February 2024
- Personvernnemnda (Norway) - 2021-18 (20/02059) (category Article 5(1)(d) GDPR)8 (1) and (5) of Directive 95/46 or in Article 9 (1), Article 10 (1) and Article 10 of Regulation 2016/679, the infringement of the data subject's fundamental36 KB (5,859 words) - 06:40, 6 July 2022
- HDPA (Greece) - 30/2020 (category Article 4(1) GDPR)that the respondent's installed and operational video surveillance system (that includes two cameras, one at the entrance of the latter's property and one20 KB (2,519 words) - 15:36, 6 December 2023
- Tietosuojavaltuutetun toimisto (Finland) - 7285/183/18 (category Article 5(1)(a) GDPR)power of attorney to exercise the data subject's right of access. Next, the DPA held that Article 6(1)(1) of the Finnish Data Protection Act (Tietosuojalaki)73 KB (11,237 words) - 05:34, 21 July 2022
- protected by articles 10 (general right to privacy), 11 (inviolability of one's body), and 13 (secrecy of correspondence) of the constitution. Provisions of7 KB (764 words) - 07:50, 6 May 2024
- HDPA (Greece) - 34/2023 (category Article 5(1)(c) GDPR)data subject's personal data in violation of Article 5(1)(c) GDPR and Article 15(1) GDPR. Firstly, the DPA found a violation of Article 5(1)(c) GDPR, as6 KB (695 words) - 16:39, 9 January 2024
- Garante per la protezione dei dati personali (Italy) - 9485681 (category Article 15(1) GDPR)these facts, Italy’s DPA found Vodafone S.p.A in violation of the following GDPR provisions: Article 5(1) and Article 5(2) and Article 25(1): for failing to7 KB (810 words) - 15:52, 6 December 2023
- APD/GBA (Belgium) - 53/2020 (category Article 5(1)(a) GDPR)comply with section 5.1(b) of the MDR, and for failure to comply with section 5.1(a) of the MDR. and 5.1(b), 6.1, 25.1 and 25.2, 32.1 and 32.4 of the MDR35 KB (5,853 words) - 16:58, 12 December 2023
- Tietosuojavaltuutetun toimisto (Finland) - 8211/161/19 (category Article 5(1)(d) GDPR)companies use that information to determine the debtor’s creditworthiness, by assessing the debtor’s ability and/or willingness to pay, after which they can42 KB (6,579 words) - 08:46, 27 January 2022
- LG Magdeburg - 9 O 1571/20 (category Article 6(1) GDPR)6 Para. 1 S.1 f) GDPR are not met. Legally, the Authorization to transmit data from debtors to credit agencies, according to Art. 6 Para. 1 S. 1 f and Para27 KB (4,216 words) - 13:26, 8 January 2024
- HDPA (Greece) - 23/2020 (category Article 4(1) GDPR)Audiovisual Media and Communication S.A. [NCAM S.A.]. The HEDNO S.A. denied the issuing of such a certificate. The company's response to the application focused9 KB (1,089 words) - 15:35, 6 December 2023
- Helsingin hallinto-oikeus (Finland) - 117/2024 (category Article 9(1) GDPR)Section 6(1)(1) of the Finnish Data Protection Act, according to which insurance institutions may, despite the general prohibition in Article 9(1) GDPR, process22 KB (3,290 words) - 10:29, 25 March 2024
- Authority (APO below}, what it does on June 17, 2020 » 1• 1 Impugned Decision, Exhibit 36, §§ 1 - 24. 1 PAGE 01-00003026497-0006-0025-02-01-� L_JCourt of Appeal37 KB (5,765 words) - 09:53, 14 December 2023
- Datatilsynet (Denmark) - 2018-32-0357 (category Article 5(1)(a) GDPR) (section 2.1. The complainant's remarks)complainant prior to DMI's change of the institute's procedure for obtaining consent has been justified, as well as whether the institute's current processing65 KB (9,767 words) - 16:22, 6 December 2023
- OGH - 6Ob35/21x (category Article 4(1) GDPR)processing the claimant's data. Do data on the "affinity for a political party" qualify constitute personal data under Article 4(1) GDPR? If so, do they27 KB (4,090 words) - 09:54, 10 September 2021
- Datatilsynet (Norway) - 20/02178 (category Article 5(1)(a) GDPR)000 only because of the DPA's long case processing time. In 2019, a company enabled automatic forwarding of an employee's emails during a sick leave, because7 KB (802 words) - 18:53, 17 May 2022
- ANSPDCP (Romania) - Fine against Telekom Romania mobile communications S.A. 2 (category Article 32(1) GDPR)controller TELEKOM ROMANIA MOBILE COMMUNICATIONS S.A. and found a violation of the provisions of art. 32 para. (1) and para. (2) of the General Regulation on7 KB (900 words) - 15:18, 13 December 2023
- BVwG - W211 2210458-1/10 (category Article 2(1) GDPR)according to To 1): € 1.200,00 To 2): € 300,00 To 3): € 300,00 . . . In total: € 1.800 To 1): 3 days To 2): 1 day To 3): 1 day ... In total: 5 days Ad 1): Art.92 KB (15,435 words) - 16:00, 22 March 2022
- LAG Hessen - 9 Sa 1431/19 (category Article 15(1) GDPR)employed by the defendant from February 1, 2015 under an oral employment contract for a net amount of EUR 1,100.00 (EUR 1,475.00 gross) with a working time of32 KB (5,093 words) - 16:07, 11 September 2022
- DSB (Austria) - D124.1177/0006-DSB/2019 (category Article 5(1)(e) GDPR) (section Article 17(1)(d) GDPR)complainant. Specifically, the DSB cites Articles 5(1)(b) and (e), 9(2)(j), 89(1) GDPR and Section 7(1)(1) and (2)(1) GDPR. In particular, it follows from Article31 KB (4,648 words) - 13:56, 12 May 2023
- CJEU - C-667/21 - Krankenversicherung Nordrhein (category Article 5(1)(f) GDPR)information from the data subject's doctor in the form of a medical report, which was then distributed to the data subject's coworkers. The data subject believed14 KB (1,916 words) - 16:03, 2 February 2024
- OLG Nürnberg - 8 U 2907/21 (category Article 15(1) GDPR)paragraph 1 sentence 1, 818 paragraph 1 and 2 BGB and the defendant owes neither the surrender of uses nor the reimbursement of pre-court attorney's fees.24 KB (3,847 words) - 15:19, 11 September 2022
- Tietosuojavaltuutetun toimisto (Finland) - 4356/532/19 (category Article 5(1)(a) GDPR)controller's credit register because of three cases, requested the DPA to order controller to delete their personal data from the controller’s credit information43 KB (6,671 words) - 08:49, 27 January 2022
- Tietosuojavaltuutetun toimisto (Finland) - 834/532/18 (category Article 5(1)(a) GDPR)controller's credit register because of four cases, requested the DPA to order controller to delete their personal data from the controller’s credit information43 KB (6,677 words) - 08:47, 27 January 2022
- HDPA (Greece) - 32/2020 (category Article 5(1) GDPR)pertaining to human dignity (Article 2(1) Greek Constitution) and to the right to freely form one's personality (Article 5(1) Greek Constitution). The HDPA focused12 KB (1,464 words) - 15:37, 6 December 2023
- Administrative Court. 3. Legal Assessment 3.1. To dismiss the complaint 3.1.1. In accordance with Art. 15 Para. 1 GDPR, the data subject has the right to request48 KB (7,816 words) - 11:04, 29 July 2022
- HDPA (Greece) - 4/2020 (category Article 15(1) GDPR)The controller also ignored HDPA's previous order to comply with the parent's request, thus violating Article 15(1) and (4) GDPR as well as the principle18 KB (2,865 words) - 15:33, 6 December 2023
- AEPD (Spain) - EXP202203969 (category Article 6(1) GDPR)ESPAÑA, S.A.U. 02/08/2023 DEUTSCHE requirement to DEUTSCHE BANK, S.A.E. 02/08/2023 Request TELEFÓNICA MOVILES to TELEFÓNICA MÓVILES ESPA- ÑA, S.A.U. 02/09/202345 KB (7,135 words) - 13:08, 13 December 2023
- Datatilsynet (Norway) - 20/02375 (category Article 6(1)(f) GDPR)legal grounds for this in Article 6(1)(f) GDPR, pursuing a third party's legitimate interest. After receiving the DPA's notification of a fine, the company40 KB (5,943 words) - 18:54, 5 March 2022
- subject has objected to its processing pursuant to Article 21(1) of the GDPR (Article 17(1)(a), (c)(1) and (d) of the GDPR). A request for erasure would therefore39 KB (6,244 words) - 09:40, 10 September 2021
- HDPA (Greece) - 18/2020 (category Article 5(1)(a) GDPR)Article 5(1) GDPR. 5. In the present case, New York College S.A. is the controller since it is proven that it has processed the complainant’s personal data12 KB (1,733 words) - 15:34, 6 December 2023
- HDPA (Greece) - 25/2023 (category Article 5(1) GDPR)Article 15(1) GDPR. For the above reasons, the Hellenic DPA issued a total fine of €210.000 and instruct (the controller) to satisfy the complainant's right6 KB (694 words) - 14:25, 20 January 2024
- Personvernnemnda (Norway) - 2021-03 (category Article 5(1)(a) GDPR)close A's external access to the employer's server, as well as initiated forwarding of all incoming e-mails from A's e-mail box to the department head's e-mail25 KB (4,046 words) - 18:37, 5 March 2022
- the transmitted data (see point II.1.3 or II.1.3.1) at least in combination, personal data according to Art. 4 Z 1 DSGVO. For the lack of an appropriate158 KB (26,392 words) - 08:25, 7 June 2023
- HDPA (Greece) - 31/2023 (category Article 5(1)(c) GDPR)DEYA X violated GDPR's data minimization principle Article 5(1)(c) by sharing an employee's personal and health data with multiple recipients without proper61 KB (10,257 words) - 10:15, 1 November 2023
- Datatilsynet (Norway) - 20/01790 (category Article 5(1)(a) GDPR)the public: 0117 OSLO Offl §13 cf. Fvl §13 no. 1 Their reference Our reference Date 9135764/1 20 / 01790-1 (19/01267) / EHN 22.12.2020 Decision on the imposition49 KB (7,646 words) - 07:56, 7 March 2022
- AP (The Netherlands) - 26.11.2020 (category Article 32(1) GDPR)Chapter 5 contains the operative part and the legal remedies clause. 1. Introduction 1.1 Legal entities involved and reason for investigation OLVG is a foundation67 KB (11,415 words) - 17:15, 12 December 2023
- APD/GBA (Belgium) - 31/2020 (category Article 5(1)(c) GDPR)infringement of Article 5.1 c) AVG has been proven. f)Transparent information (Article 5.1(a); Article 12.1. and Article 13.1. and 13.2. AVG) 43.The complainant48 KB (7,926 words) - 16:56, 12 December 2023
- third-party action (1.). On the complainant's side, his general right of personality (Article 2.1 in conjunction with Article 1.1 of the Basic Law) in133 KB (21,944 words) - 15:59, 22 March 2022
- OLG Dresden - 4 U 1905/21 (category Article 15(1) GDPR)April 1st, 2017 to March 1st, 2020, a total of €1,438.56 28 - in the statutory contribution surcharge G...: 36 monthly payments of €4.00 from April 1st, 201740 KB (6,325 words) - 16:12, 18 May 2022
- UODO (Poland) - ZSPU.421.3.2019 (category Article 5(1)(a) GDPR)Article 57(1)(a), Article 58(2)(d) and (i) in connection with Article 5(1)(a), (e) and (f) and (2), Article 24(1) and (2), Article 28, Article 30(1)(d) and58 KB (9,357 words) - 10:02, 17 November 2023
- BVwG - W214 2233132-1/13E (category Article 15(1)(c) GDPR)the relevant court act and are undisputed. 3. Legal Assessment 3.1. To I to A) 3.1.1. Legal situation: Art. 12 of Regulation (EU) 2016/679 of the European47 KB (7,519 words) - 09:28, 13 February 2024
- offer of services of the Information Society. Without prejudice to Article 8(1) GDPR, for child under the age of fourteen, consent is only valid if provided6 KB (757 words) - 13:53, 16 August 2022
- APD/GBA (Belgium) - 06/2019 (category Article 5(1)(c) GDPR)concerning the violation of Articles 5.1. c); 6.1. ; 13.1. c); 13.1. e) and 13.2. a) of the GDR:- pursuant to Article 100, § 1, 9° of the ICA, to order the respondent20 KB (3,137 words) - 16:51, 12 December 2023
- HDPA (Greece) - 11/2024 (category Article 17(1) GDPR)June 2017, Satakunnan M a r k k i n a p ö r s s i O y k a i S a t a m e d i a O y k a t a F i n l a n d i a s § 165). Also, in the same recent decision,36 KB (5,761 words) - 17:19, 22 April 2024
- AEPD (Spain) - PS/00451/2019 (category Article 6(1)(f) GDPR)respondent dated January 3, 2019. On April 1, 2019, the Director of the Spanish Data Protection Agency, granted the claimant's appeal for reconsideration. SECOND:26 KB (4,231 words) - 14:44, 13 December 2023
- OVG Sachsen-Anhalt - 1 M 49/23 (category Article 53(1) GDPR)be issued, Art. 33 Para. 1 M 158/10 -, resolution of September 14, 2012 - 1 M 94/12 - and resolution of October 25, 2012 - 1 M 103/12 -, each juris). The14 KB (1,999 words) - 14:20, 18 July 2023
- AEPD (Spain) - EXP202105644 (category Article 5(1)(f) GDPR)against the company COMERCIALIZADORA REGULADA GAS & POWER, S.A., belonging to NATURGY ENERGY GROUP, S.A. with NIF A08015497 (hereinafter, the claimed party)27 KB (4,121 words) - 15:06, 13 December 2023
- Tietosuojavaltuutetun toimisto (Finland) - TSV/26/2020 (category Article 5(1)(e) GDPR)com Oyj's customers can actually be considerably long. 14. According to the controller's view, it is good customer service and in the customer's interest77 KB (12,352 words) - 07:20, 23 April 2024
- Datatilsynet (Norway) - 20/01648 (category Article 5(1)(a) GDPR)(Datatilsynet) held that the controller had breached Articles 5(1)(a) and (c), 6, 12(1) and 13 GDPR and for this fined the controller NOK 100,000 (approximately7 KB (801 words) - 06:28, 6 March 2022
- AEPD (Spain) - EXP202201721 (category Article 6(1) GDPR)the defendant's office located in the ***ADDRESS.1, in ***LOCALITY.2 (***LOCALITY.1) requesting the withdrawal of funds from the claimant's account, failing79 KB (12,408 words) - 13:24, 13 December 2023
- contents Nos. 1, 3, 4, 5 and 83, as well as content No. 64. 1 SPMT-ARISTA is an external service for prevention and protection at work, which since 1 January131 KB (22,429 words) - 16:57, 12 December 2023
- VG Wiesbaden - 6 K 788/20.WI (category Article 15(1)(h) GDPR)wording of Articles 21 (1) sentence 1, 22 (1) and 4 no. 4 of the GDPR as well as recitals 71 p. 1, 2 and 72 can be interpreted as follows. 1, 2 and 72 can be52 KB (8,534 words) - 12:58, 15 December 2021
- AEPD (Spain) - EXP202202164 (category Article 5(1) GDPR)of the GDPR. SECOND: APPOINT R.R.R. as instructor. and, as secretary, to S.S.S. indicating that any of them may be challenged, if applicable, in accordance29 KB (4,482 words) - 14:06, 5 March 2024
- AEPD (Spain) - EXP202209511 (category Article 6(1) GDPR)***NIF.1, for a violation of Article 6.1 and another of article 13 of the RGPD, typified in Article 83.5 letters a) and b) of the RGPD, a fine of €1,500 (€122 KB (3,257 words) - 13:28, 13 December 2023
- for 1: 1,000 euros 74 Application for 2: 1,000 euros 75 application for 3a: 3,000 euros 76 Application for 3b: 1,000 euros 77 Application for 4: 1,00039 KB (6,362 words) - 14:01, 22 June 2023
- AEPD (Spain) - EXP202209001 (category Article 5(1)(c) GDPR)focused beyond the private property of the controller's, violating Article 5(1)(c) and 13 GDPR. On 1st of August 2022, the data subject submitted a complaint22 KB (3,303 words) - 13:28, 13 December 2023