Search results

From GDPRhub
  • controller's behalf should be established. In particular, the controller should be obliged to implement appropriate and effective measures and be able to demonstrate
    51 KB (6,355 words) - 08:25, 18 April 2024
  • consent must be distinguishable from other matters in any written declaration, can be withdrawn at any time and the provision of a contract may not be made conditional
    108 KB (17,005 words) - 15:39, 18 March 2024
  • this will usually be printed. There is no duty to provide the information in a format that can be kept by the data subject, it must only be "provided". It
    76 KB (11,304 words) - 08:37, 4 March 2024
  • subject be concise, easily accessible and easy to understand, and that clear and plain language and, additionally, where appropriate, visualisation be used
    73 KB (9,896 words) - 15:46, 18 March 2024
  • pseudonymisation, which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable
    125 KB (16,328 words) - 16:01, 8 March 2024
  • the data subject should be determined by reference to the nature, scope, context and purposes of the processing. Risk should be evaluated on the basis of
    41 KB (5,197 words) - 12:17, 17 April 2024
  • it can be assumed that the SAs may be given additional powers, but that the existing powers may not be restricted. A contrary view cannot be derived from
    46 KB (5,825 words) - 11:12, 7 November 2023
  • processing to be carried out. The description of personal data used should be as precise as possible, while still being concise. Usually this can be achieved
    71 KB (9,532 words) - 13:30, 6 March 2024
  • criteria should be used. According to Voigt and von dem Bussche, “the former should be the case, as otherwise the obligation would be too much of a burden
    61 KB (8,488 words) - 15:47, 18 March 2024
  • the infringement to be punished is to this code of conduct, the less this criterion may be taken into account. Otherwise, there would be a violation of the
    55 KB (7,622 words) - 14:04, 7 November 2023
  • Interest of a Natural Person The processing of personal data should also be regarded to be lawful where it is necessary to protect an interest which is essential
    44 KB (5,905 words) - 14:00, 24 October 2023
  • referred to in paragraphs 1 and 2 shall be explicitly brought to the attention of the data subject and shall be presented clearly and separately from any
    49 KB (5,993 words) - 06:22, 16 June 2023
  • order to be effective, data protection must be implemented ex ante. Hence, the controller must define the privacy requirements that need to be taken into
    43 KB (4,675 words) - 06:43, 16 June 2023
  • controller's behalf should be established. In particular, the controller should be obliged to implement appropriate and effective measures and be able to demonstrate
    30 KB (3,458 words) - 10:31, 25 April 2024
  • circumstances of the case. Where personal data can be legitimately disclosed to another recipient, the data subject should be informed when the personal data are first
    47 KB (5,644 words) - 17:49, 5 March 2024
  • consent should be given for all of them. If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise
    31 KB (3,489 words) - 16:00, 8 March 2024
  • their agreement must be the same as those of the SCCs. The SCCs will often leave some blank spaces to be filled in or options to be selected by the parties
    72 KB (9,140 words) - 13:12, 2 June 2023
  • information can be obtained; (c) describe the likely consequences of the personal data breach; (d) describe the measures taken or proposed to be taken by the
    54 KB (6,536 words) - 08:22, 16 June 2023
  • involved in processing shall be liable for the damage caused by processing which infringes this Regulation. A processor shall be liable for the damage caused
    33 KB (4,215 words) - 09:57, 19 March 2024
  • nnees.be/introduire-une-requete-une-plainte In Dutch: https://www.gegevensbeschermingsautoriteit.be/verzoek-klacht-indienen The complaint can be sent by
    9 KB (993 words) - 07:10, 28 July 2022
  • may be relevant. The fact that personal data is publicly available may be considered as a factor in the assessment if the data was expected to be further
    52 KB (7,297 words) - 08:05, 18 July 2023
  • Each legally binding measure of the supervisory authority should be in writing, be clear and unambiguous, indicate the supervisory authority which has
    60 KB (7,796 words) - 20:12, 1 April 2024
  • the supervisory authorities concerned shall be deemed to be in agreement with that draft decision and shall be bound by it. 7. The lead supervisory authority
    35 KB (4,017 words) - 16:04, 18 March 2024
  • individual and may be influenced by practicality or efficiency aspects, in addition to legal considerations. Some of these aspects may be, legal costs, procedural
    33 KB (3,641 words) - 09:51, 19 March 2024
  • personal data shall be adapted to the principles and rules of this Regulation in accordance with Article 98. 4. This Regulation shall be without prejudice
    34 KB (4,652 words) - 12:07, 12 November 2023
  • subjects should be directly notified of the relevant breach. When communicating a breach to data subjects, dedicated messages should be utilized, separate
    37 KB (3,962 words) - 15:20, 16 June 2023
  • other establishment should be considered to be the main establishment. The main establishment of a controller in the Union should be determined according to
    55 KB (7,446 words) - 22:28, 1 April 2024
  • communications, including by e-mail, fax or telephone. The complaint shall be signed by the data subject or, on his or her behalf, by a third sector body
    7 KB (808 words) - 08:17, 16 February 2023
  • Although there does not seem to be a specific requirement for the decision to be formalised in a particular way, it should at least be distinguishable from other
    31 KB (4,768 words) - 06:24, 16 June 2023
  • also be assessed. In particular, following the EDPB reading, a proposed restriction should be supported by evidence describing the problem to be addressed
    44 KB (4,896 words) - 06:25, 16 June 2023
  • should be verifiable by means of its records. Thus, in order for the keeping of records to be meaningful, it will be necessary for the controller to be able
    31 KB (3,327 words) - 15:31, 5 June 2023
  • it should be pointed out that the safeguards mentioned in the provision constitute an alternative system of data transfer and can therefore be additional
    34 KB (3,646 words) - 08:53, 27 March 2023
  • health data in order to be able to effectively provide healthcare. In this instance, the processing of data should be considered to be part of a hospital’s
    43 KB (4,904 words) - 12:59, 21 July 2023
  • Principles of Data Processing Any processing of personal data should be lawful and fair. It should be transparent to natural persons that personal data concerning
    23 KB (2,489 words) - 23:24, 6 March 2024
  • operations are designed. In any case, the DPO shall be involved at a stage when fundamental decisions can still be taken. Among others, the early involvement is
    29 KB (2,951 words) - 14:19, 25 July 2023
  • Member State concerned shall be competent. In such cases Article 56 does not apply. 3. Supervisory authorities shall not be competent to supervise processing
    35 KB (3,971 words) - 21:34, 1 April 2024
  • risk. The outcome of the assessment should be taken into account when determining the appropriate measures to be taken in order to demonstrate that the processing
    31 KB (3,646 words) - 08:51, 21 July 2023
  • public hearing. Under specific conditions the hearing may be secret. For an administrative fine to be issued, a prior invitation of the defendant (or his representative
    23 KB (2,039 words) - 08:15, 25 April 2024
  • principle be ensured by technical means in such a manner that the personal data are not subject to further processing operations and cannot be changed.
    32 KB (3,730 words) - 08:43, 7 March 2024
  • scientific or historical research purposes or statistical purposes should be considered to be compatible lawful processing operations. The legal basis provided
    17 KB (1,768 words) - 15:41, 18 March 2024
  • determine whether a processing activity can be considered to monitor the behaviour of data subjects, it should be ascertained whether natural persons are tracked
    37 KB (4,635 words) - 13:29, 24 October 2023
  • mentioned above, derogations from Article 49 GDPR may be used. Additionally, Article 44 GDPR must be also be complied with, meaning that any transfer based on
    29 KB (3,500 words) - 08:54, 27 March 2023
  • shall be brought before the courts of the Member State where the controller or processor has an establishment. Alternatively, such proceedings may be brought
    31 KB (3,550 words) - 11:11, 29 November 2023
  • requirements for 85(1) to be fulfilled. While not outlined, the academic commentary agrees that Article 85(1) should not be read as requiring member states
    33 KB (3,748 words) - 14:25, 7 November 2023
  • pursued need to be demonstrated; (iii) the processing has to be subject to independent oversight; and (iv) effective remedies need to be available to the
    43 KB (5,641 words) - 14:58, 28 April 2022
  • subject be concise, easily accessible and easy to understand, and that clear and plain language and, additionally, where appropriate, visualisation be used
    37 KB (3,915 words) - 12:49, 24 May 2023
  • the controller or the processor and may be addressed by any supervisory authority. The representative should be explicitly designated by a written mandate
    22 KB (2,042 words) - 14:29, 20 November 2023
  • as well as any other person which would be adversely affected by the decision, must be afforded the right to be heard in relation to the subject matter
    33 KB (4,185 words) - 16:09, 2 November 2023
  • supervisory authority should be brought before the courts of the Member State where the supervisory authority is established and should be conducted in accordance
    30 KB (3,874 words) - 10:46, 7 December 2023
  • they may be developed to “calibrate the obligations of controllers and processors” according to Recital 98 GDPR. As such, codes are intended to be an additional
    44 KB (5,008 words) - 14:50, 28 July 2023
View (previous 50 | ) (20 | 50 | 100 | 250 | 500)