Search results
From GDPRhub
- Data Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 577 (Oxford University Press 2020). Although Article 25(1) mentions that the measures43 KB (4,675 words) - 06:43, 16 June 2023
- mechanism referred to in Article 63 GDPR (Article 28(8) GDPR). The Commission has made use of its power under Article 28(7) GDPR and published standard contractual72 KB (9,140 words) - 13:12, 2 June 2023
- HDPA (Greece) - 20/2023 (category Article 25(1) GDPR)registered letter in violation of article 15 (1) cond. 12 par. 2, 3 and 4 GDPR and c) 30,000 euros for violation of Article 25 (1) GDPR because it did not in practice6 KB (634 words) - 17:48, 17 July 2023
- HDPA (Greece) - 25/2023 (category Article 25(1) GDPR)processing of personal data meets the legal requirements, in breach of Article 25(1) GDPR. Finally, the DPA stated that the response to the access request was6 KB (694 words) - 14:25, 20 January 2024
- Garante per la protezione dei dati personali (Italy) - 9485681 (category Article 25(1) GDPR)Vodafone S.p.A in violation of the following GDPR provisions: Article 5(1) and Article 5(2) and Article 25(1): for failing to implement control systems of7 KB (810 words) - 15:52, 6 December 2023
- Helsingin hallinto-oikeus (Finland) - 3620/2023 (category Article 25(1) GDPR)the GDPR. In light of this, the Court agreed with the DPA that the controller had violated Article 5(1)(a) GDPR, Article 12 GDPR, Article 13 GDPR, Article22 KB (3,193 words) - 10:34, 29 February 2024
- Tietosuojavaltuutetun toimisto (Finland) - 4356/532/19 (category Article 25(1) GDPR)on final judgments did not comply with Article 25(1) GDPR. Pursuant to Article 58(2)(b) and Article 58(2)(d) GDPR, the DPA reprimanded the controller for43 KB (6,671 words) - 08:49, 27 January 2022
- Tietosuojavaltuutetun toimisto (Finland) - 834/532/18 (category Article 25(1) GDPR)on final judgments did not comply with Article 25(1) GDPR. Pursuant to Article 58(2)(b) and Article 58(2)(d) GDPR, the DPA reprimanded the controller for43 KB (6,677 words) - 08:47, 27 January 2022
- APD/GBA (Belgium) - 53/2020 (category Article 25(1) GDPR)comply with section 5.1(b) of the MDR, and for failure to comply with section 5.1(a) of the MDR. and 5.1(b), 6.1, 25.1 and 25.2, 32.1 and 32.4 of the MDR35 KB (5,853 words) - 16:58, 12 December 2023
- Tietosuojavaltuutetun toimisto (Finland) - 8493/161/21 (category Article 25(1) GDPR)the controller had violated Article 5(1)(a) GDPR, Article 12 GDPR, Article 13 GDPR, Article 15 GDPR and Article 25(1) GDPR. As a result, the DPA issued52 KB (7,936 words) - 22:32, 2 March 2024
- Tietosuojavaltuutetun toimisto (Finland) - 8211/161/19 (category Article 25(1) GDPR)this from happening, in violation with Article 24(1), Article 24(2), and Article 25(1) GDPR. According to Article 24(4) of the Finish Data Protection Act42 KB (6,579 words) - 08:46, 27 January 2022
- BlnBDI (Berlin) - C-807/21 - Deutsche Wohnen (category Article 83 GDPR)necessary. For the intentional infringement of Article 25(1) GDPR and Article 5(1)(a), (c), and (e) GDPR, the authority imposed a pecuniary penalty of €147 KB (936 words) - 16:39, 12 December 2023
- UODO (Poland) - ZSPR.421.2.2019 (category Article 25(1) GDPR)(f), Article 5(2), Article 6(1), Article 7(1), Article 24(1), Article 25(1), Article 32(1)(b), Article 32(1)(c) and Article 32(1)(b), Article 32(1)(c) and71 KB (11,304 words) - 10:01, 17 November 2023
- BlnBDI (Berlin) - 711.412.1 (category Article 25(1) GDPR)coming into force of the GDPR, the DPA found that the company still did not comply. How do Article 5(1)(e) and Article 25(1) GDPR apply to archives? The8 KB (965 words) - 16:38, 12 December 2023
- HDPA (Greece) - 64/2022 (category Article 25(1) GDPR)of natural persons who decisions, in accordance with the provisions of the GDPR. The DPA examined the rules for the removal of identification data displayed3 KB (199 words) - 20:46, 13 December 2022
- HDPA (Greece) - 4/2022 (category Article 25(1) GDPR)HDPA held that COSMOTE violated Article 25(1) GDPR, because the processing for statistical purposes under Article 89(1) GDPR should have been done with anonymised11 KB (1,274 words) - 10:37, 23 February 2022
- Commissioner (Cyprus) - 11.17.001.008.029 (category Article 25(1) GDPR)Commissioner held that CYTA violated articles 5 (1), 24 (1) and (2), 25 (1) and (2) and 32 of the GDPR and instructed CYTA to establish such security measures3 KB (193 words) - 16:52, 6 December 2023
- HDPA (Greece) - 30/2023 (category Article 25(1) GDPR)violation of article 5 par. 1 item. e' of the GDPR, b) reprimanded the OASA for the violations of the provisions of article 25 par. 1 and article 35 par. 1 of the6 KB (623 words) - 09:08, 25 October 2023
- HDPA (Greece) - 61/2022 (category Article 25(1) GDPR)information provided to data subjects was less than that required by the GDPR, and the information was not provided in an intelligible and easily accessible6 KB (663 words) - 15:31, 6 December 2023
- HDPA (Greece) - 50/2021 (category Article 25(1) GDPR)information in accordance with Article 13 GDPR. In addition, the HDPA found that the Ministry violated the obligation of Article 35(9) GDPR in relation to the expression5 KB (548 words) - 09:23, 12 October 2022
- AZOP (Croatia) - Decision 21-07-2022 (A1 telecommunications) (category Article 25(1) GDPR)€283,000). It held that the controller violated Articles 25(1), 32(1)(b), 32(1)(d) and 32(2) GDPR by not taking appropriate technical and organizational7 KB (855 words) - 15:30, 30 October 2023
- AZOP (Croatia) - Decision 18-05-2023 (category Article 25(1) GDPR)was fined €380,000 for violating Articles 6(1), 13(1) and (2), and 25(1) and (2) and 32(1)(a) and (d) GDPR. A sports betting agency, acting as the controller9 KB (1,276 words) - 15:25, 30 October 2023
- AZOP (Croatia) - Decision 28-08-2019 (category Article 25(1) GDPR)of Article 5, Article 6, and Article 25 GDPR. It ordered the controller to comply with the data subject's erasure request pursuant to Article 17(1)(d)16 KB (2,373 words) - 15:31, 30 October 2023
- CNIL (France) - MED-2019-027 (category Article 25(1) GDPR)design and default. The CNIL ordered the Ministry to comply with Article 24 and 25 GDPR regarding the collection and further processing of personal data21 KB (3,274 words) - 17:08, 6 December 2023
- Tietosuojavaltuutetun toimisto (Finland) - 3831/161/21 (category Article 25(1) GDPR)Finnish DPA found a retail chain to have breached Article 5(1)(e) GDPR, Article 25(1) GDPR and Article 25(2) GDPR for its lengthy storage of purchase behaviour61 KB (9,477 words) - 13:38, 12 January 2024
- HmbBfDI (Hamburg) - Vermerk: Abdingbarkeit von TOMs (category Article 25(1) GDPR)even though Article 32 GDPR stipulates such a technical measure for certain emails. It is important to note that only Article 6(1)(a) GDPR allows for such30 KB (4,562 words) - 15:27, 6 December 2023
- APD/GBA (Belgium) - 03/2021 (category Article 25(1) GDPR)fulfilled. The school breaches Article 6(1)(b) in combination with Article 6(4) and Article 6(1) Articles 24 and 25 GDPR Furthermore, as the school continued32 KB (4,880 words) - 16:50, 12 December 2023
- UODO (Poland) - DKN.5130.2815.2020 (category Article 25(1) GDPR)and Article 58(2)(b) in connection with Article 5(1)(f), Article 24(1), Article 25(1), Article 32(1) and (2) of 2 of Regulation EU 2016/679 of the European37 KB (5,819 words) - 09:58, 17 November 2023
- APD/GBA (Belgium) - 74/2020 (category Article 25(1) GDPR)the basis of Article 58, paragraph 2, point b) GDPR and Article 100, §1, 5 ° WOG to be reprimanded for the infringement of Article 25 (1) GDPR; b. on the82 KB (12,100 words) - 17:01, 12 December 2023
- AEPD (Spain) - PS/00268/2022 (category Article 25(1) GDPR)According to Article 72.1 LOPDGDD, the violation of data processing principles under Article 5 GDPR was considered very serious. Considering Article 25(1) GDPR63 KB (9,551 words) - 12:33, 13 December 2023
- Court of Appeal of Brussels - 2020/AR/1333 (category Article 25(1) GDPR)5- □ 1-i; -J L ..J Brussels-2020 Court of Appeal / AR / 1333 p. 3 breach of articles 5.1.a} and 5.1.b), 6.1, 25.1 and 25.2, 32.1 and 32.4 of the GDPR read51 KB (7,792 words) - 11:43, 24 January 2022
- Tietosuojavaltuutetun toimisto (Finland) - 4282/161/21 (category Article 25(1) GDPR)controller had violated Article 5(1)(f) GDPR, Article 17(1) GDPR, Article 25(1) GDPR, Article 32(1) GDPR and Article 32(2) GDPR. As a result, the DPA issued56 KB (8,980 words) - 08:47, 4 March 2024
- APD/GBA (Belgium) - 136/2023 (category Article 25(1) GDPR)violating Article 5(1)(f) GDPR, Article 5(1)(a) GDPR, Article 5(2) GDPR, Article 12 GDPR, Article 13 GDPR, Article 14 GDPR, Article 24(1) GDPR, and Article58 KB (9,184 words) - 16:49, 12 December 2023
- UODO (Poland) - DKN.5101.25.2020 (category Article 25(1) GDPR)with Art. 5 sec. 1 lit. f, art. 24 sec. 1, art. 25 sec. 1, art. 32 sec. 1 lit. d, art. 32 sec. 2, art. 33 paragraph. 1 and art. 34 sec. 1 of the Regulation63 KB (10,088 words) - 09:52, 17 November 2023
- NAIH (Hungary) - NAIH-2020/2204/8 (category Article 25(1) GDPR)(2) § 23, § 25, 25 / G. § (3), (4) and (6), 25 / H. § (2) paragraph 25 / M. § (2), 25 / N. §, 51 / A. § (1), Articles 52-54. §- in Section 55 (1) - (2), Sections60 KB (9,820 words) - 10:08, 17 November 2023
- NAIH (Hungary) - NAIH/2020/66/21 (category Article 25(1) GDPR)regard to Client 1 that data management - infringed Article 25 (1) to (2) of the General Data Protection Regulation, - infringed Article 32 (1) (b) of the General67 KB (10,492 words) - 10:11, 17 November 2023
- UODO (Poland) - DKN.5130.1354.2020 (category Article 25(1) GDPR)expressed in Article 5 (1 ) (a)) f, and reflected in the obligations set out in Article 24 (1), Article 25 (1), Article 32 (1 ) (b ) and (d) and Article 32 (2)74 KB (11,513 words) - 09:58, 17 November 2023
- UODO (Poland) - DKN.5130.2024.2020 (category Article 25(1) GDPR)sec. 1 lit. a) and art. 58 sec. 2 lit. i) in connection with Art. 5 sec. 1 lit. f), art. 24 sec. 1, art. 25 sec. 1, art. 28 sec. 1 and 3 and article. 3275 KB (12,104 words) - 09:58, 17 November 2023
- APD/GBA (Belgium) - 55/2021 (category Article 25(1) GDPR)data on the basis of Article 6.1.e GDPR ? - Did the administration sharing confidential data with a third party violates article 25 GDPR ? - Should the administration81 KB (13,211 words) - 16:59, 12 December 2023
- Garante per la protezione dei dati personali (Italy) - 9685922 (category Article 25(1) GDPR)processing carried out is in violation of Article 5(1)(f) GDPR, Article 25(1) GDPR, Article 32 GDPR and Article 35 GDPR. Especially, the controller cannot exclude119 KB (19,123 words) - 11:29, 16 August 2022
- APD/GBA (Belgium) - 82/2020 (category Article 25(1) GDPR)artikel 100, §1, 2° WOG de buitenvervolgingstelling bevelen, of de klacht seponeren overeenkomstig artikel 95, §1, 1° of artikel 100, §1, 1° WOG (naargelang124 KB (18,772 words) - 17:01, 12 December 2023
- UODO (Poland) - ZSOŚS.421.25.2019 (category Article 25(1) GDPR)5 sec. 1 lit. f, art. 5 sec. 2, art. 25 sec. 1, art. 32 sec. 1 lit. b, art. 32 sec. 1 lit. d, art. 32 sec. 2, art. 38 sec. 1, art. 39 sec. 1 lit. b and156 KB (25,012 words) - 10:01, 17 November 2023
- EDPB - Binding Decision 2/2022 - 'Instagram' (category Article 25(1) GDPR)the performance of a contract (Article 6(1)(b) GDPR) and for legitimate interest (Article 6(1)(f) GDPR). Article 6(1)(b) GDPR In its original draft decision276 KB (38,206 words) - 09:46, 20 January 2023
- DPC (Ireland) - IN-19-7-2 (category Article 25(1) GDPR)violated Article 25(1) GDPR by failing to take measures designed to implement the accuracy principle in the database, and Articles 5(2) and 24(1) GDPR by failing5 KB (620 words) - 13:13, 19 May 2021
- HDPA (Greece) - 20/2022 (category Article 12(3) GDPR)violation of article 17 in combination with article 21 par. 3 and article 12 paragraph 3 of the GDPR and article 25 paragraph 1 of the GDPR. For its judgment16 KB (2,374 words) - 11:46, 18 August 2022
- ANSPDCP (Romania) - Banca Comercială Română SA (category Article 25(1) GDPR)This amounted to a violation of Article 25(1) GDPR, Article 32(1)(b) GDPR, Article 32(1)(d) GDPR, Article 32(2) GDPR. Consequently, the DPA fined the5 KB (558 words) - 08:06, 26 September 2022
- ANSPDCP (Romania) - Raiffeisen Bank SA (category Article 25(1) GDPR)violating Article 32(4) jo Article 32(1) and (2) GDPR (security of processing). In addition, a fine of €5,000 for violating Article 25(1) GDPR (data protection14 KB (1,905 words) - 15:22, 29 November 2022
- ANSPDCP (Romania) - Fine against Bitfactor SRL (category Article 25(1) GDPR)laid down in Article 5(1)(f) GDPR. In this context, the DPA referred to Article 25(1) GDPR (data protection by design) and Recital 78 GDPR. As a result6 KB (708 words) - 08:12, 6 October 2022
- APD/GBA (Belgium) - 29/2023 (category Article 25(1) GDPR)risk analysis. Therefore, the DPC found a violation of Article 25(1), 25(2), 5(1)(b) and 5(1)(f) GDPR, ordered Meta to comply with the provisions and imposed5 KB (536 words) - 14:11, 21 March 2023
- HDPA (Greece) - 41/2022 (category Article 25(1) GDPR)thereby violating Article 13(2) GDPR. The investigated controllers did not comply with the storage limitation principle under Article 5(1) GDPR because the data14 KB (2,046 words) - 19:00, 21 September 2022