Search results

From GDPRhub
  • access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), notification obligation
    44 KB (4,896 words) - 06:25, 16 June 2023
  • prevention (Article 23(1)(a-j) GDPR) allow for far fewer GDPR restrictions than those granted by freedom of expression. Article 85(2) GDPR poses one condition
    33 KB (3,748 words) - 14:25, 7 November 2023
  • CJEU - C-620/19 - J & S Service (category Article 23(1)(j) GDPR)
    scope of the GDPR which protects the personal data of natural persons. On the merits, he found that the limitation in Article 23(1)(j) GDPR applies to the
    5 KB (573 words) - 11:16, 4 October 2023
  • BVerwG - 10 C 4.20 (category Article 23(1)(j) GDPR)
    Information Acts and the GDPR. Due to the questions of EU law raised by the case with regard to Article 23(1)(e) GDPR and Article 23(1)(j) GDPR, the BVerwG had
    37 KB (6,075 words) - 08:46, 20 July 2022
  • BGH - VI ZB 39/18 (category Article 23(1)(j) GDPR)
    democratic society as required under Article 23(1)(j) GDPR. Moreover, the exception provided for under Article 6(4) GDPR which allows processing for different
    53 KB (8,894 words) - 15:56, 22 March 2022
  • OLG Schleswig - 9 Wx 23/21 (category Article 23(1) GDPR)
    out in Article 23(1) GDPR. § 21(2) TTDSG serves the enforcement of civil claims and thus pursues an objective mentioned in Article 23(1)(j) GDPR, which
    29 KB (4,683 words) - 18:37, 6 April 2022
  • Article 58 GDPR (category GDPR Articles) (section (1) Investigative powers)
    access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction (Article 18 GDPR), notification (Article 19 GDPR) or data
    46 KB (5,825 words) - 11:12, 7 November 2023
  • categories of data established in Article 9(2)(a) GDPR, Article 9(2)(c) GDPR, Article 9(2)(g) GDPR and Article 9(2)(i) GDPR directly correlate with a specific
    44 KB (5,905 words) - 14:00, 24 October 2023
  • flows by the SA pursuant to Article 58(2) GDPR or failure to provide access in violation of Article 58(1) GDPR. Article 83(6) GDPR is a superfluous provision
    55 KB (7,622 words) - 14:04, 7 November 2023
  • commentary to Article 60 GDPR, Article 61 GDPR, Article 62 GDPR, Article 63 GDPR, Article 64 GDPR, Article 65 GDPR, Article 66 GDPR and Article 56 GDPR. The SA
    60 KB (7,796 words) - 20:12, 1 April 2024
  • Article 47 GDPR (category GDPR Articles) (section (1) Binding Corporate Rules)
    to personal data (Article 47(2)(n) GDPR; a duty for the group to have data protection audits on regular basis (Article 47(2)(j) GDPR); and to designate
    29 KB (2,823 words) - 15:15, 28 April 2022
  • leeway exists only in cases of Article 64(2) GDPR but not the context of Article 70(2) GDPR. According to Article 70(3) GDPR, the EDPB is obligated to “forward
    27 KB (3,038 words) - 12:19, 11 October 2023
  • between Article 21(3) GDPR and Article 17 GDPR on the right to erasure must be considered. The tight relationship between Article 21(3) and Article 17(1)(c)
    49 KB (5,993 words) - 06:22, 16 June 2023
  • Article 40 GDPR (category GDPR Articles) (section (1) Drawing up codes of conduct)
    up. Indeed, the wording of Article 40(1) establishes that they “shall encourage” this (emphasis added). Article 40(1) GDPR clarifies that codes of conduct
    44 KB (5,008 words) - 14:50, 28 July 2023
  • provided for in Article 6(1)(a) GDPR or, as the case may be, Article 9(2)(a) GDPR, and consent is withdrawn according to Article 7(3) GDPR, data must be
    61 KB (8,488 words) - 15:47, 18 March 2024
  • or infringes the GDPR or any other applicable laws, including national ones. See commentary under Article 77 GDPR. Article 78(1) GDPR establishes both
    30 KB (3,874 words) - 10:46, 7 December 2023
  • Court of Appeal of Brussels - 2019/AR/1600 (category Article 5(1)(c) GDPR)
    connection with the violation of article/and 5.1. c); 6.1.; 13.1. (c);13.1(e) and13.2(a)AVG: r PAGE 01-00001582885-0002-0033-01- □1-� r L _JCourt of Appeal Brussels
    60 KB (9,144 words) - 16:17, 22 March 2022
  • OLG Schleswig - 17 U 15/21 (category Article 6(1)(e) GDPR) (section Article 6(1)(e) GDPR)
    processing by the defendant can only be Article 6 (1) sentence 1 lit e) DSGVO (see b) or Article 6 (1) sentence 1 lit f) DSGVO (see c), the requirements
    51 KB (8,215 words) - 09:55, 13 May 2022
  • DSB (Austria) - D124.1177/0006-DSB/2019 (category Article 5(1)(e) GDPR) (section Article 17(1)(d) GDPR)
    cites Articles 5(1)(b) and (e), 9(2)(j), 89(1) GDPR and Section 7(1)(1) and (2)(1) GDPR. In particular, it follows from Article 9(2)(j) GDPR that the processing
    31 KB (4,648 words) - 13:56, 12 May 2023
  • CJEU - C-77/21 - Digi (category Article 5(1)(b) GDPR)
    regarding Articles 5(1)(b) GDPR and 5(1)(e) GDPR and held that national courts had to determine, using the factors of Article 6(4) GDPR, whether further processing
    49 KB (7,800 words) - 09:22, 5 January 2024
  • OLG Köln - 15 U 126/19 (category Article 17(1)(d) GDPR)
    to injunctive relief from § 29 para. 1 sentence 1 no. 2 BDSG old version, but from § 29 para. 1 sentence 1 no. 1 BDSG old version, although the "basic
    121 KB (20,412 words) - 15:58, 10 March 2022
  • HDPA (Greece) - 56/2021 (category Article 13 GDPR)
    processing of personal data (Article 5(1) of the GDPR), must, in accordance with Article 12(1) of the GDPR. 1 of the GDPR, must take appropriate measures
    54 KB (8,916 words) - 15:22, 22 February 2022
  • Court of Appeal of Brussels - 2022/AR/549 (category Article 17(3)(e) GDPR)
    lawfulness, the Litigation Chamber concludes that Article 5.1.a. of the GDPR in conjunction with Article 6 of the GDPR have not been complied with with regard to
    37 KB (5,765 words) - 09:53, 14 December 2023
  • CNIL (France) - SAN-2020-014 (category Article 9 GDPR)
    breach of Article 32 of the GDPR has occurred. B. On the failure to notify the data breach to the CNIL 32. Pursuant to Article 33 (1) of the GDPR, in the
    26 KB (4,050 words) - 17:10, 6 December 2023
  • AEPD (Spain) - EXP202105344 (category Article 6(1) GDPR)
    claimed party, for the alleged infringement of Article 6.1 of the RGPD, typified in Article 83.5 of the GDPR. FIFTH: Notification of the aforementioned start-up
    22 KB (3,319 words) - 13:00, 13 December 2023
  • CJEU - C-268/21 - Norra Stockholm Bygg (category Article 6(3) GDPR)
    proportionality of the measure under Article 6(4) GDPR, in accordance with the objectives referred to in Article 23(1) GDPR. It recalled that these objectives
    9 KB (1,372 words) - 10:12, 7 June 2023
  • CNIL (France) - SAN-2023-0076 (category Article 5(1)(b) GDPR)
    instance, the controller sought to rely upon Article 6(1)(e) GDPR and Article 9(2)(j) GDPR. Article 6(1)(e) GDPR establishes a lawful basis for the processing
    19 KB (2,826 words) - 17:01, 6 December 2023
  • EFTA Court - Joined Cases E-11/19 and E-12/19 (category Article 58(2)(j) GDPR)
    point (e) of Article 6(1) of the GDPR. 48 If a data subject has objected to the data processing, it follows from Article 21(1) of the GDPR that compelling
    59 KB (8,242 words) - 10:47, 17 March 2021
  • IMY (Sweden) - DI-2020-11373 (category Article 44 GDPR)
    million) kroner for violation of Article 44 of the data protection regulation. 1 Description of the supervisory matter 1.1 The processing The Swedish Privacy
    113 KB (12,773 words) - 15:20, 6 December 2023
  • Court of Appeal of Brussels - 2022/AR/556 (category Article 5(1)(b) GDPR)
    35.1 and 35.7; Under Article 100, § 1, 5° of the LCA, to impose a reprimand _for violations of Articles 30.1.a) and 30.1.d},; Pursuant to Article 108(1)
    83 KB (13,694 words) - 09:53, 14 December 2023
  • UODO (Poland) - DKN.5112.7.2020 (category Article 5(1)(a) GDPR)
    Survey". Justification . Pursuant to Article 78 paragraph 1, Article 79 paragraph 1 point 1 and Article 84 paragraph 1 point 1-4 of the Act of 10 May 2018 on
    29 KB (4,687 words) - 09:56, 17 November 2023
  • CNIL (France) - SAN-2019-005 (category Article 5(1)(e) GDPR)
    violates Article 32 GDPR. Retaining personal data of an applicant for a lease after another applicant has been selected also violates Article 5(1)(e) GDPR
    41 KB (6,558 words) - 17:09, 6 December 2023
  • AEPD (Spain) - EXP202201721 (category Article 6(1) GDPR)
    the violation of the GDPR: violation of article 6.1, violation typified in its article 83.5.a). IV Secondly, article 32 of the GDPR “Security of processing”
    79 KB (12,408 words) - 13:24, 13 December 2023
  • Court of Appeal of Brussels - 2020/AR/813 (category Article 5(1)(c) GDPR)
    Therefore the controller violated Article 5(1)(a) and (2), Article 6(1), Article 12(1), Article 13(1)(b) and (c) GDPR. The DPA imposed a fine of €50.000
    85 KB (12,340 words) - 15:30, 19 August 2022
  • AEPD (Spain) - EXP202105680 (category Article 9 GDPR)
    very serious in article 72.1. e) from the LOPDGDD, with 10,000 euros. -article 13 of the GDPR, in accordance with article 83.5 b) of the GDPR, and for the
    66 KB (10,558 words) - 13:14, 13 December 2023
  • APD/GBA (Belgium) - 39/2020 (category Article 5(1)(f) GDPR)
    obtained from them, as required under Article 14(1)(a) AVG and Article 14(2)(c)(e) and point (f) AVG; c. article 12 j° article 14 AVG, in view of the defendant
    62 KB (10,509 words) - 16:58, 12 December 2023
  • Court of Appeal of Brussels - 2020/AR/1333 (category Article 5(1)(a) GDPR)
    5- □ 1-i; -J L ..J Brussels-2020 Court of Appeal / AR / 1333 p. 3 breach of articles 5.1.a} and 5.1.b), 6.1, 25.1 and 25.2, 32.1 and 32.4 of the GDPR read
    51 KB (7,792 words) - 11:43, 24 January 2022
  • Court of Appeal of Brussels - 2020/AR/1111 (category Article 3(1) GDPR)
    ofcontroller (article 4.7 of the GDPR), the scope of the GDPR (article3.1 of the GDPR), the right to erasure (article 17 of the GDPR) and its powers (article 58.2of
    37 KB (5,919 words) - 08:54, 20 August 2021
  • Commissioner (Cyprus) - 17.05.23 (category Article 5(1)(c) GDPR)
    found violations of Articles 5(1)(c) and 6 GDPR and Article 29(1) of Law 125(I)/2018. Concerning the violation of Article 29(1) of Law 125(I)/2018, the DPA
    31 KB (4,973 words) - 16:50, 6 December 2023
  • CNIL (France) - SAN-2020-012 (category Article 26(1) GDPR)
    in the same article 83. 111. Article 83 of the GDPR, as referred to in Article 20, paragraph III, of the Data Protection Act, provides: 1. Each supervisory
    93 KB (14,936 words) - 17:09, 6 December 2023
  • APD/GBA (Belgium) - 75/2023 (category Article 6(1)(f) GDPR)
    paying profiles. II.4. Article 12(1),(2) and (3), Article 17, Article 19, Article 24(1) and Article 25(1) AVG 63. Article 12 (1) GDPR stipulates that the
    77 KB (11,604 words) - 08:55, 29 June 2023
  • NAIH (Hungary) - NAIH/2020/6484 (category Article 15(1)(a) GDPR)
    the general rule of Article 15 (1) (a), c) and d) of the GDPR by not giving substantive, specific answers to the request under Article 15 and by sharing
    27 KB (4,159 words) - 10:13, 17 November 2023
  • UODO (Poland) - ZSPU.421.3.2019 (category Article 5(1)(a) GDPR)
    provided for in Article 5(1)(a), (e) and (f), Article 5(2), Article 24(1) and (2), Article 28(3), Article 30(1)(d) and (f) and Article 32(1) of the General
    58 KB (9,357 words) - 10:02, 17 November 2023
  • AEPD (Spain) - PS/00001/2021 (category Article 5(1)(f) GDPR)
    enshrined in Article 25 GDPR. Additionally, the AEPD concluded that the controller had violated Article 5(1)(f) GDPR, noting that although the GDPR does not
    270 KB (43,335 words) - 12:39, 13 December 2023
  • Court of Appeal of Brussels - 2023/AR/801 (category Article 96 GDPR)
    Appeal considered that Article 96 GDPR does not provide a time limit for the validity of international agreements concluded prior GDPR and that a ban on some
    11 KB (1,467 words) - 09:40, 6 July 2023
  • Hoge Raad - 21/00241 (category Article 6(1)(c) GDPR)
    accordance with the provisions of Article 6(1)(c), Article 6(1)(f) GDPR, or both provisions? 2.     Does the answer to Question 1 mean: a)      that the person
    29 KB (4,605 words) - 17:00, 15 December 2021
  • Gerechtshof Amsterdam - 200.251.466/01 (category Article 21 GDPR)
    request under Article 21 GDPR can be made at any time and several times. It also found that a provisional measure can be granted under Article 21 GDPR if an urgent
    19 KB (3,021 words) - 15:48, 15 March 2022
  • APD/GBA (Belgium) - 04/2021 (category Article 5(1) GDPR)
    of the GDPR: art. 5.1 a, 12.1, 13, 14, 6, 7, 5.1.c in conjunction with 25, 5.2, 28.3, 31, 37 and 38 AVG. 63. With regard to Article 5 (1) (a) GDPR, the defendant
    113 KB (18,732 words) - 16:50, 12 December 2023
  • of articles 38.1, 38.3, 39.1 a) and 39.1 b) of the GDPR; - to issue an injunction against Company A to comply with Article 38.1 of the GDPR, within four
    66 KB (9,458 words) - 19:42, 4 September 2021
  • EWHC (UK)- QB- Soriano v Forensic News LLC (category Article 3(1) GDPR)
    conferred by article 79(2) of the GDPR. This is the relevant provision for the purposes of para 3.1(20) of CPR Practice Direction 3B. Article 79(2) provides:
    108 KB (18,178 words) - 11:57, 29 November 2021
  • CNIL (France) - SAN-2020-009 (category Article 5(1)(a) GDPR)
    with the principle of fair and transparent processing contained in Article 5(1)(a) GDPR? Is the information relating to personal data processing operations
    48 KB (7,404 words) - 17:09, 6 December 2023
  • principles to the GDPR;
 
 (b) The effect (if any) of the remaining claims – Article 5(1)(f) GDPR (the data security principle), the Article 8 claim and
    46 KB (7,676 words) - 10:45, 7 December 2021
  • APD/GBA (Belgium) - 82/2020 (category Article 6(1) GDPR)
    artikel 100, §1, 2° WOG de buitenvervolgingstelling bevelen, of de klacht seponeren overeenkomstig artikel 95, §1, 1° of artikel 100, §1, 1° WOG (naargelang
    124 KB (18,772 words) - 17:01, 12 December 2023
  • AEPD (Spain) - PS/00069/2020 (category Article 6(1)(a) GDPR)
    consent of the respective data subject, therefore infringing Article 6(1)(a) GDPR. On 23 October 2019, a complaint was lodged before a court relating to
    20 KB (3,066 words) - 13:55, 13 December 2023
  • APD/GBA (Belgium) - 36/2021 (category Article 5(1) GDPR)
    approved appeal of Article 5(1)(a), Article 12(1), Article 13(1) and Article 13(2). The appeal for Article 5(1)(c), Article 6(1) and Article 8 GDPR was not approved
    62 KB (9,417 words) - 16:57, 12 December 2023
  • AEPD (Spain) - PS/00189/2020 (category Article 58(2) GDPR)
    (LOPDGDD) in its article 72.1 m), under the rubric “Infractions considered very grave ”provides: "1. In accordance with the provisions of article 83.5 of Regulation
    22 KB (3,343 words) - 14:08, 13 December 2023
  • Court of Appeal of Brussels - 2019/AR/1006 (category Article 16 GDPR)
    updates. In the near future step 1 PAGE □1-□□□□149307□-□□□3-□□22- □1-□1-� L _J' Court of Appeal Brussels -2019/AR/1006 -p. 4 13-1 the Bank X from the current
    59 KB (9,290 words) - 09:10, 5 May 2024
  • AEPD (Spain) - EXP202100282 (category Article 6(1) GDPR)
    S.A.U. with NIF A-65559296, for the alleged violation of article 6.1. GDPR typified in article 83.5.a) of the aforementioned RGPD. C / Jorge Juan, 6 www
    27 KB (4,108 words) - 13:32, 13 December 2023
  • AEPD (Spain) - PS/00214/2022 (category Article 6(1) GDPR)
    legal bases of contract (Article 6(1)(b) GDPR), legal obligation (Article 6(1)(c) GDPR) and legitimate interest (Article 6(1)(f) GDPR) and determined that
    131 KB (20,916 words) - 12:38, 13 December 2023
  • AEPD (Spain) - PS/00206/2020 (category Article 6 GDPR)
    thealleged infringement of Article 6 of the RGPD, typified in Article 83.5 a) of the RGPDand considered very serious in 72.1.a), for the purposes of prescription
    20 KB (3,078 words) - 14:10, 13 December 2023
  • Data Protection 23. The claimant relies on Article 82, as supplemented by s.168 of the Data Protection Act 2018. Article 82 of the UK-GDPR provides data
    61 KB (8,986 words) - 08:40, 22 February 2022
  • AEPD (Spain) - PS/00452/2019 (category Article 6(1)(a) GDPR)
    pursuant to Article 47(1) and 48.1 of Law 39/2015 of 1 October, on the limitation of the infringement of article 6.1 of the RGPD typified in article 83.5 a)
    25 KB (4,037 words) - 14:55, 13 December 2023
  • AEPD (Spain) - PS/00278/2020 (category Article 5(1)(a) GDPR)
    images, in violation of Article 5(1)(a) GDPR? The Spanish DPA (AEPD) found that the defendant's conduct violated Article 5(1)(a) GDPR, as a broader principle
    28 KB (4,592 words) - 14:25, 13 December 2023
  • NAIH (Hungary) - NAIH/2020/3479 (category Article 5(1)(d) GDPR)
    proceedings Article 77 (1) and Article 22 (b) of the General Data Protection Regulation. may be submitted in the case provided for in Under Article 77 (1) of the
    30 KB (4,563 words) - 10:12, 17 November 2023
  • AEPD (Spain) - EXP202206302 (category Article 6 GDPR)
    functions assigned to the control authorities in article 57.1 and the powers granted in the article 58.1 of Regulation (EU) 2016/679 (General Data Protection
    28 KB (4,608 words) - 13:27, 13 December 2023
  • NAIH (Hungary) - NAIH/2020/193/8 (category Article 5(1)(d) GDPR)
    been deleted by the employer upon request pursuant to Article 16, Article 17 and Article 5(1)(d) GDPR (inaccuracy of personal data). Therefore, the employer
    58 KB (9,413 words) - 10:11, 17 November 2023
  • AEPD (Spain) - PS/00240/2019 (category Article 5(1)(b) GDPR)
    given that Article 6(1), Article 5(1)(a), Article 5(1)(d), Article 5(1)(c), and Article 14 GDPR were infringed in connection to Article 5(1)(b), the AEPD
    602 KB (102,229 words) - 14:21, 13 December 2023
  • the exceptional circumstances of Article 23 (1) e GDPR in conjunction with Sections 32c (1) No. 1, 32b (1) sentence 1 No 1 a, sentence 2, § 32 paragraph 2
    97 KB (16,519 words) - 09:57, 22 February 2023
  • CNIL (France) - SAN-2020-015 (category Article 32(1) GDPR)
    private doctor for violating Article 32 GDPR by making his patients' health data freely accessible on the web, and Article 33 GDPR by not notifying the DPA
    29 KB (4,374 words) - 16:03, 19 January 2024
  • AEPD (Spain) - PS/00085/2021 (category Article 6(1)(a) GDPR)
    A80907397, for the alleged violation of article 6.1. GDPR typified in article 83.5.a) of the aforementioned RGPD. 1. APPOINT Mr. D.D.D. as instructor. and
    28 KB (4,350 words) - 13:57, 13 December 2023
  • AEPD (Spain) - PS/00484/2020 (category Article 6(1)(a) GDPR)
    messages. Is this a violation of Article 6(1)(a) GDPR? The AEPD held that this behaviour was a violation of Article 6(1)(a) GDPR and fined Vodafone €100,000
    27 KB (4,189 words) - 14:44, 13 December 2023
  • AEPD (Spain) - EXP202203969 (category Article 6(1) GDPR)
    infringement of article 6.1 of the GDPR, infringement typified in article 83.5 of the aforementioned Regulation 2016/679. II breached obligation Article 6.1 of the
    45 KB (7,135 words) - 13:08, 13 December 2023
  • is covered by Article 6, clause 1 (c) of the AVG and not by Article 6, clause 6 (f) of the AVG. The BKR itself refers to Article 6, clause 1 (f) of the GCG
    91 KB (15,371 words) - 15:11, 5 October 2021
  • AEPD (Spain) - EXP202200367 (category Article 5(1)(a) GDPR)
    in the article 57.1 and the powers granted in article 58.1 of the Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in
    57 KB (8,117 words) - 10:35, 13 December 2023
  • AEPD (Spain) - PS/00060/2020 (category Article 58(1)(a) GDPR)
    personal data under Article 15 GDPR? The Spanish DPA held that the airline company had not complied with the right to access in Article 15 GDPR when it refused
    23 KB (3,695 words) - 13:53, 13 December 2023
  • AEPD (Spain) - PS/00356/2020 (category Article 6(1) GDPR)
    commerce (hereinafter LSSI), as provided in article 43.1 of said Law. II Article 85 of Law 39/2015, of October 1, on Administrative Procedure Common of Public
    26 KB (3,848 words) - 14:31, 13 December 2023
  • AEPD (Spain) - EXP202203996 (category Article 15 GDPR)
    in accordance with the provisions of section 2 of article 56 in in relation to section 1 f) of article 57, both of Regulation (EU) 2016/679 of the European
    26 KB (4,017 words) - 12:37, 13 December 2023
  • GHAL - 200.186.790/01 (category Article 6(1)(b) GDPR)
    terminated, must be assessed in the light of Article 6 GDPR and not Article 10 GDPR. Article 6(1)(f) GDPR provides a sufficient basis for processing. The
    50 KB (8,219 words) - 12:42, 4 March 2022
  • APD/GBA (Belgium) - 34/2020 (category Article 5(1)(b) GDPR)
    Justification 3.1.1. Regarding the purpose limitation findings (Article 5.1 b) GDPR) and the lawfulness of processing (Article 6.1 GDPR) 12. In its report
    82 KB (13,250 words) - 16:57, 12 December 2023
  • RvS - 201902417/1/A2 (category Article 6(1)(e) GDPR)
    time, which is a violation of the GDPR. As to the claim for damages, the CoS notes that though Article 82(1) of the GDPR states that full compensation for
    37 KB (5,721 words) - 12:41, 16 September 2021
  • Rb. Gelderland - AWB 19/2901 (category Article 6(1)(b) GDPR)
    this purchase contract (Article 6(1)(b) GDPR). Therefore, the processing is compatible with the GDPR. In the Netherlands, as of 1 July 2018 a passenger who
    17 KB (2,610 words) - 16:18, 10 March 2022
  • CNIL (France) - SAN-2019-010 (category Article 5(1)(c) GDPR)
    investigations the CNIL found five breaches of the GDPR: -         Violation of the right to object, Article 21(2) GDPR: no procedure was implemented to ensure effectively
    62 KB (10,001 words) - 17:09, 6 December 2023
  • meaning that no violation of Article 5(1)(e) GDPR could be established. Integrity and confidentiality - Article 5(1)(f) GDPR As explained above, the DPA
    429 KB (58,279 words) - 09:12, 2 November 2022
  • AEPD (Spain) - PS/00266/2019 (category Article 13 GDPR)
    referred to as the ISESA), as provided for in Article 43.1 of the said Act. II Article 85 of Law 39/2015 of 1 October 1995 on the Common Administrative Procedure
    28 KB (4,459 words) - 14:23, 13 December 2023
  • AEPD (Spain) - PS/00268/2019 (category Article 13 GDPR)
    specific enough and did not comply with Article 13 GDPR. Does the lack of precision enough to infrige Article 13 GDPR? The AEPD found that the information
    28 KB (4,435 words) - 14:23, 13 December 2023
  • CNPD (Luxembourg) - Délibération n° 47FR/2021 (category Article 5(1)(c) GDPR)
    the processing is based on Article 6(1)(a) or on Article 9, (c) where the processing is based on Article 6(1)(a) or Article 9(2)(a), the existence of the
    69 KB (11,315 words) - 13:30, 19 January 2022
  • DSB (Austria) - 2020-0.605.768 (category Article 41(1) GDPR)
    Para. 1 GDPR, which pursuant to Art. 57 Para. 1 lit. q GDPR in conjunction with Section 2 (2) of the ÜStAkk-V can be submitted to this. On point 1 (partial
    19 KB (2,799 words) - 13:52, 12 May 2023
  • Gerechtshof Amsterdam - 200.258.736/01 (category Article 15 GDPR)
    referred to as ABN AMRO. 1.2 1.2 [Appellants] lodged an appeal with the Court of Appeal on 1 May 2019, received at the Court Registry on 1 May 2019, against the
    41 KB (7,150 words) - 12:30, 4 October 2021
  • that a valid legal basis would be either Article 6(1)(c) GDPR, or Article 6(1)(d) GDPR or Article 9(2)(b) GDPR. The Data protection authority (the UOOU)
    25 KB (3,096 words) - 17:48, 25 November 2021
  • AEPD (Spain) - PS/00291/2019 (category Article 6(1)(a) GDPR)
    Sections 1.1 and 1.2 of the first stipulation and section 2.2 of the second stipulation of the aforementioned contract state "FIRST.- OBJECT: 1.1 The purpose
    33 KB (5,396 words) - 14:26, 13 December 2023
  • AEPD (Spain) - PS/00182/2020 (category Article 6(1) GDPR)
    of October 1, of the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged violation of Article 6.1 of the RGPD
    21 KB (3,154 words) - 14:07, 13 December 2023
  • CNPD (Portugal) - Deliberação 2022/1072 (category Article 9(1) GDPR)
    therefore violated Articles 9(1) GDPR out of negligence. The DPA fined the controller €1,600,000 pursuant of Article 83(5)(a) GDPR and considered this a high
    163 KB (27,222 words) - 16:54, 6 December 2023
  • Datatilsynet (Denmark) - 2021-442-12980 (category Article 32(1) GDPR)
    In an Article 60 GDPR procedure, the Danish DPA reprimanded Danske bank for a violation of Article 32(1) GDPR. A technical error resulted in the unauthorised
    10 KB (1,214 words) - 11:39, 22 March 2024
  • Commissioner (Cyprus) - 11.17.001.008.001 (category Article 5(1)(f) GDPR)
    subparagraphs b '. y '. d 'and e' of par. 1 of article 5 as well as of article 6 par. 1ΓΚΠΔ ... ». 3. Reasoning 3.1. The data contained in an insurance policy
    61 KB (9,412 words) - 16:52, 6 December 2023
  • details. 201907720/1/A3. Date of judgment: 9 December 2020 SECTION ADMINISTRATIVE LAW Judgment on the appeals of: 1. [appellant under 1], residing at [place
    19 KB (3,135 words) - 12:38, 16 September 2021
  • NAIH (Hungary) - NAIH/2020/34/3 (category Article 12(2) GDPR)
    right of access under Article 15 GDPR? By denying the complainant access, did the respondent infringe Articles 12(1) or 12(2) GDPR? The NAIH that the complainant's
    48 KB (7,727 words) - 10:11, 17 November 2023
  • AEPD (Spain) - PS/00219/2019 (category Article 5(1)(d) GDPR)
    commerce (hereinafter LSSI), as provided in article 43.1 of said Law. II Article 85 of Law 39/2015, of October 1, on Administrative Procedure Common of Public
    37 KB (5,785 words) - 14:11, 13 December 2023
  • AEPD (Spain) - PS/00104/2020 (category Article 5(1)(f) GDPR)
    violation of articles 5.1.f, of the RGPD -as set out in Article 83(5)(a) of the said regulation and 5(1)(f) in relation to Article 32(1)(b) and (c) - specified
    36 KB (6,022 words) - 13:59, 13 December 2023
  • APD/GBA (Belgium) - 149/2023 (category Article 5(1)(a) GDPR)
    to in Article 5(1) LRN, under which the controller did not fall in. Therefore, the controller breached Article 5(1)(a) GDPR and Article 6(1) GDPR, in conjunction
    113 KB (17,325 words) - 08:50, 19 March 2024
  • APD/GBA (Belgium) - 02/2021 (category Article 6 GDPR)
    Motifs 3.1 Compétence de la Chambre de Résolution des Litiges (Article 2 AVG ; Article 4 WOG) 55. Conformément à l'article 2, paragraphe 1, de l'AVG,
    96 KB (15,396 words) - 16:50, 12 December 2023
  • AEPD (Spain) - PS/00168/2020 (category Article 6(1) GDPR)
    violation of Article 6(1) GDPR? AEPD considered that the documentation provided offers evidence that Vodafone violated Article 6(1) of the GDPR, by processing
    22 KB (3,568 words) - 14:06, 13 December 2023
  • AEPD (Spain) - PS/00173/2020 (category Article 5(1)(d) GDPR)
    RESOLVES:FIRST: IMPOSE BBB , with NIF *** NIF.1 , for a violation of the article5.1.d) of the RGPD, typified in article 83.5 of the RGPD, a penalty of € 3,000
    22 KB (3,424 words) - 14:06, 13 December 2023
  • APD/GBA (Belgium) - 33/2020 (category Article 5(1)(c) GDPR)
    by the defendant under Article 6(1) GDPR? Did the controller infringe the data minimisation principle under Article 5(1)(c) GDPR? Did the controller commit
    39 KB (6,551 words) - 16:56, 12 December 2023
  • AEPD (Spain) - EXP202200439 (category Article 6(1) GDPR)
    constitutes sensitive data within the meaning of Article 9 GDPR. The DPA alluded to Article 9(1) GDPR which prohibits the processing of these special categories
    36 KB (5,608 words) - 13:01, 13 December 2023
  • ensure the protection of the interests referred to in Article 23(1). objectives referred to in Article 23(1), the controller shall take into account when assessing
    92 KB (14,873 words) - 09:03, 20 August 2021
  • OLG Köln - 15 U 89/19 (category Article 17(3) GDPR)
    with Art. 2 para. 1, Art. 1 para. 1 GG, Art. 17 para. 1 lit. d) DSGVO, because her personal data is stored according to Art. 6 para. 1 lit. f. DSGVO had
    143 KB (24,273 words) - 15:59, 10 March 2022
  • IMY (Sweden) - DI-2020-11368 (category Article 44 GDPR)
    may not be based on Article 45. Article 46.1 provides, among other things, that in the absence of a decision in accordance with Article 45.3 a personal data
    115 KB (12,842 words) - 08:38, 5 July 2023
  • AEPD (Spain) - EXP202204530 (category Article 6(1) GDPR)
    regulated in article 6 of the GDPR. The assumptions that allow the processing of personal data to be considered lawful listed in article 6.1 of the GDPR: 1. Treatment
    26 KB (3,971 words) - 13:26, 13 December 2023
  • AEPD (Spain) - PS/00308/2020 (category Article 5(1)(a) GDPR)
    party, breach Article 6(1) GDPR? The Spanish DPA (AEPD) referred to the principle of lawfulness, fairness and transparency (Article 5(1)(a)), as well as
    25 KB (4,016 words) - 14:27, 13 December 2023
  • APD/GBA (Belgium) - 10/2019 (category Article 5(1)(b) GDPR)
    been taken up in Article 5(1)(b) of the GDPR under the Principles relating to the processing of personal data (Chapter II). Article 5(1)(b) of the RGPD
    32 KB (5,190 words) - 16:51, 12 December 2023
  • AEPD (Spain) - EXP202204492 (category Article 6(1) GDPR)
    provisions of article 58.2.i) of the GDPR, for the alleged infringement of article 6.1 of the GDPR, typified in article 83.5.b) of the GDPR. SECOND: APPOINT
    26 KB (3,867 words) - 10:44, 13 December 2023
  • AEPD (Spain) - EXP202105923 (category Article 5(1)(d) GDPR)
    controller violated Article 5(1)(d) GDPR ("accuracy"), but a more natural conclusion would be to find a violation of Article 32(1)(d) GDPR ("adoption of adequate
    26 KB (3,846 words) - 12:42, 13 December 2023
  • AEPD (Spain) - PS/00132/2020 (category Article 6(1) GDPR)
    supply data, without the consent of the data subject, a breach of Article 6 (1) GDPR? The Spanish DPA held that the processing of data relating to electricity
    24 KB (3,939 words) - 14:03, 13 December 2023
  • AEPD (Spain) - PS/00405/2019 (category Article 6(1) GDPR)
    significant (Article 83(2)(b) GDPR). - basic personal identifiers were affected (name, identification number, the line identifier) (Article 83(2)(g) GDPR). The
    24 KB (3,887 words) - 14:34, 13 December 2023
  • AEPD (Spain) - PS/00188/2020 (category Article 5(1)(f) GDPR)
    violation of Article 5 (1) (f) GDPR? The Spanish DPA held that were clear indications that the defendant infringed Article 5 (1) (f) GDPR, principles relating
    24 KB (3,907 words) - 14:08, 13 December 2023
  • AEPD (Spain) - PS/00406/2020 (category Article 6(1)(f) GDPR)
    violation of article 6.1. f) of the RGPD, in relation with article 20.1 c) of the LOPDGDD, typified in article 83.5.a) of the cited GDPR That by writing
    36 KB (5,582 words) - 14:35, 13 December 2023
  • AEPD (Spain) - PS/00433/2020 (category Article 58(2)(c) GDPR)
    the authority ofcontrol pursuant to Article 58 (2), or failure to provide access in breachof article 58, paragraph 1. "Organic Law 3/2018, on the Protection
    23 KB (3,592 words) - 14:40, 13 December 2023
  • Hoge Raad - ECLI:NL:PHR:2023:935 (redirect from Hoge Raad - 23/00030) (category Article 5(1)(c) GDPR)
    the Strijp-S housing complex in Eindhoven. It's agreed 1 Facts 1.6 1.7 1.8 1.9 1.10 1.11 1.12 1.13 1.14 that [plaintiff] directly to PME Investment Services
    103 KB (17,620 words) - 10:13, 29 November 2023
  • CNIL (France) - SAN-2022-025 (category Article 4(11) GDPR)
    specified in the same Article 83." 112. Under Article 83 of the GDPR, as referred to in Article 20(III) of the Data Protection Act: "1. Each supervisory authority
    82 KB (13,463 words) - 17:03, 6 December 2023
  • AEPD (Spain) - EXP202100897 (category Article 6(1) GDPR)
    basis for the processing (Article 21(1) GDPR). Finally, the DPA fined the controller €12,000 for a violation of Article 6(1) GDPR due to the lack of a valid
    72 KB (11,671 words) - 13:34, 13 December 2023
  • Rb. Noord-Nederland - C/ 18/189406/HA ZA 19-6 (category Article 5(1)(f) GDPR)
    loss of control of personal data and a breach of Article 5(1)(f) GDPR, Article 6 GDPR and Article 32(2) GDPR. The first complainant is a company that is engaged
    105 KB (18,002 words) - 16:24, 10 March 2022
  • This behaviour was in violation of Article 31 GDPR. Thirdly, Company B was found to be in violation of Article 32(1) GDPR. This provision imposes an obligation
    55 KB (9,079 words) - 16:57, 6 December 2023
  • applicable to the controller, including Articles 5(1)(a) and 6 GDPR. As a matter of fact, Articles 5(1)(a) and 6 GDPR set general principles and conditions of processing
    49 KB (7,758 words) - 15:44, 6 December 2023
  • obligation according to Article 25(1) of the General Data Protection Regulation, because the controller had failed to implement Article 5(1)(a) of the General
    71 KB (11,552 words) - 13:40, 12 January 2024
  • CNPD (Portugal) - Deliberação 2021/533 (category Article 9 GDPR)
    2016 (General Data Protection Regulation - GDPR), in conjunction with Article 3, Article 4(2) and Article 6(1)(b), all of which are applicable to the processing
    30 KB (4,708 words) - 16:56, 6 December 2023
  • AEPD (Spain) - EXP202102430 (category Article 32 GDPR)
    functions assigned to the control authorities in the article 57.1 and the powers granted in article 58.1 of the Regulation (EU) C/ Jorge Juan, 6 www.aepd.es
    33 KB (4,835 words) - 13:26, 13 December 2023
  • for fraud prevention under Article 6(1)(f) GDPR. Did the company’s policy breach Article 6 or any other articles of the GDPR? The Garante held that the
    33 KB (5,342 words) - 15:52, 6 December 2023
  • LG Feldkirch - 57 Cg 30/19b - 15 (category Article 9(1) GDPR)
    and GDPR? Is a prediction of a political affiliation a "special category of data" under Article 9(1) GDPR? How much are the damages under Article 82 GDPR
    69 KB (11,077 words) - 16:48, 7 March 2022
  • AEPD (Spain) - EXP202203914 (category Article 6(1) GDPR)
    correspond would be for the infringement of article 6.1 of the GDPR, typified in article 83.5 a) of the GDPR, the sanction that would correspond would be
    37 KB (5,914 words) - 10:42, 13 December 2023
  • CE - N° 430810 (category Article 6(1)(a) GDPR)
    referred to in Article 64(1) or does not follow the opinion of the Committee issued under Article 64". 8. The investigation shows that, on 1 June 2018, the
    42 KB (6,800 words) - 09:50, 10 September 2021
  • AEPD (Spain) - PS/00179/2020 (category Article 32(1) GDPR)
    as established in article 5 of the GDPR. The security of personal data is regulated in articles 32, 33 and 34 of the GDPR. III The GDPR defines personal
    100 KB (16,401 words) - 14:07, 13 December 2023
  • Datatilsynet (Denmark) - 2019-441-3399 (category Article 34(1) GDPR)
    in accordance with Article 32 (2) of the Regulation. 2nd 3.3. Article 33 (1) of the Data Protection Regulation 1 and Article 34 (1). 1 The Data Inspectorate
    27 KB (4,231 words) - 16:38, 6 December 2023
  • IMY (Sweden) - DI-2020-11397 (category Article 44 GDPR)
    of personal data of data subjects guaranteed by Article 44 GDPR and consequently breached Article 44 GDPR. The DPA issued a fine of 300,000 SEK (approx.
    121 KB (13,722 words) - 15:16, 5 July 2023
  • AEPD (Spain) - PS/00303/2020 (category Article 6(1) GDPR)
    commerce (hereinafter LSSI), as provided in article 43.1 of said Law. II Article 85 of Law 39/2015, of October 1, on Administrative Procedure Common of Public
    29 KB (4,480 words) - 14:27, 13 December 2023
  • AEPD (Spain) - PS/00135/2021 (category Article 6(1) GDPR)
    violated Article 6(1)GDPR, for processing personal data without a legal basis. Hence, the AEPD decided to fine Telefónica for the violation of Article 6(1)GDPR
    30 KB (4,631 words) - 13:00, 13 December 2023
  • AEPD (Spain) - PS/00068/2020 (category Article 6(1) GDPR)
    have breached the lawfulness of processing principle as per article 6(1) GDPR, as well as article 20 of the Spanish Law on Personal Data Protection and Guarantee
    27 KB (4,106 words) - 13:55, 13 December 2023
  • AEPD (Spain) - PS/00379/2019 (category Article 6 GDPR)
    an alleged violation of article 6 of the GDPR typified as an infringement of basic principles for processing in article 83.5 GDPR. In determining the amount
    26 KB (4,235 words) - 14:33, 13 December 2023
  • AEPD (Spain) - PS/00009/2020 (category Article 6(1) GDPR)
    Vodafone España, S.A.U. (the defendant) for the infringement of Article 6(1) of the GDPR, as the defendant agreed to an early voluntary payment of the corresponding
    27 KB (4,150 words) - 13:45, 13 December 2023
  • AEPD (Spain) - PS/00008/2020 (category Article 6(1) GDPR)
    commerce (hereinafter LSSI), as provided in the article 43.1 of said Law. II Article 85 of Law 39/2015, of October 1, of the Administrative Procedure Common of
    27 KB (4,408 words) - 13:45, 13 December 2023
  • GHAL - 200.307.462 (category Article 10 GDPR)
    assessment pursuant to Article 35 of the GDPR and, depending on the outcome, also have to consult the AP beforehand (Article 36 of the GDPR). In addition, as
    28 KB (4,573 words) - 10:04, 14 December 2023
  • AEPD (Spain) - EXP202105333 (category Article 6(1) GDPR)
    in the article 57.1 and the powers granted in article 58.1 of the Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and C/
    49 KB (7,973 words) - 13:25, 13 December 2023
  • GHSHE (Netherlands) - 200.274.447 01 (category Article 5 GDPR)
    concerns the following in this appeal. 3.1.1. [the employee] , born on [date of birth] 1964, was employed on 1 September 1986 joined Trigion's legal predecessor
    60 KB (10,118 words) - 15:12, 5 October 2021
  • AEPD (Spain) - PS/00227/2020 (category Article 6(1) GDPR)
    Articles 6 and 13 GDPR? The AEPD decided to impose, for infringement of Article 6 GDPR, a fine of € 10000 and, for infringement of Article 13 GDPR, a fine of
    46 KB (7,230 words) - 14:20, 13 December 2023
  • AEPD (Spain) - EXP202204881 (category Article 6(1) GDPR)
    for the alleged infringement of Article 6.1 of the GDPR, typified in Article 83.5 of the GDPR. SIXTH: On January 23, 2023, DIGI requests a copy of the
    55 KB (9,017 words) - 10:46, 13 December 2023
  • CNPD (Luxembourg) - Délibération n° 18/FR/2022 (category Article 5(1)(b) GDPR)
    processing was therefore in breach of Article 5(1)(a) and Article 6(1)(c) of the GDPR. The DPA also ruled out Article 6(1)(f) on the grounds of domestic law:
    76 KB (11,147 words) - 16:58, 6 December 2023
  • NAIH (Hungary) - NAIH-2020-2546-5 (category Article 5(1)(c) GDPR)
    health data, recorded in copies Article 6 (1) of the GDPR and, in the case of health data, Article 9 of the GDPR. Article 1 (1); (3) did not provide clear
    72 KB (11,159 words) - 10:09, 17 November 2023
  • GHDHA - 200.274.807 / 01 (category Article 6(1)(f) GDPR)
    her life. Her objection to processing follows from Article 21(1) GDPR. ING argues that Article 21(1) GDPR cannot be relied on in this case because it applies
    29 KB (4,710 words) - 12:25, 4 October 2021
  • AEPD (Spain) - PS/00430/2020 (category Article 6(1) GDPR)
    his/her consent. The DPA first outlined Article 6(1)(a) and (b) GDPR, Articles 4(11) GDPR on consent, as well as Article 6 of the Spanish Data Protection Law
    31 KB (4,738 words) - 14:39, 13 December 2023
  • AEPD (Spain) - PS/00341/2020 (category Article 6(1) GDPR)
    principles are found under Article 5(1)(a) and Article 5(2) GDPR respectively]. The Spanish DPA even made reference to Recital 40 GDPR on the legality of processing
    32 KB (4,831 words) - 14:31, 13 December 2023
  • Court of Appeal of Brussels - 2021/AR/163 (category Article 83 GDPR)
    have entered into a breacha / 'article 14.1-2 combined' article 12.3, article 6, article 5.1, c) and articles 5.2 and 24.1-2 of the RGPO. It is therefore
    72 KB (11,389 words) - 08:59, 20 August 2021
  • AEPD (Spain) - PS/00183/2022 (category Article 5(1)(d) GDPR)
    "Principles of Data Protection", article 4.1 of the LOPDGDD determines: "4. Data accuracy. 1. In accordance with article 5.1.d) of Regulation (EU) 2016/679
    63 KB (10,203 words) - 13:01, 13 December 2023
  • controller was in breach of Article 38(1) GDPR at the time of the investigation. Regarding the breach of Article 39(1)(b) GDPR, the CNPD concurred with the
    81 KB (11,895 words) - 16:58, 6 December 2023
  • RvS - 201901006/1/A2 (category Article 79 GDPR)
    that this would also be contrary to the AVG. Article 82 of the AVG 12. Article 82 of the AVG reads as follows: 1. Any person who has suffered material or non-material
    34 KB (5,179 words) - 07:10, 7 April 2020
  • Datatilsynet (Norway) - 20/02375 (category Article 6(1)(f) GDPR)
    rating, breaching Article 6(1) GDPR, and required the company to implement a policy for conducting credit ratings per Article 24 GDPR. A person lodged a
    40 KB (5,943 words) - 18:54, 5 March 2022
  • UODO (Poland) - DKN.5131.6.2020 (category Article 33(1) GDPR)
    Article 57 (1) (a), Article 58 (2) (e) and (i), Article 83 (1) - (3) and Article 83 (4) (a) in connection with Article 33 (1) and Article 34 (1), (2) and
    66 KB (10,785 words) - 10:00, 17 November 2023
  • AEPD (Spain) - PS/00205/2021 (category Article 6(1) GDPR)
    constitutes personal data according with Article 4(1) GDPR therefore its processing falls within the scope of GDPR. The DPA also analysed whether the controller
    28 KB (4,527 words) - 12:35, 13 December 2023
  • Datatilsynet (Norway) - 20/02291 (category Article 5(1)(f) GDPR)
    patient data cf. Article 32 GDPR and Article 5(1)(f) GDPR and inadequate internal controls cf. Article 24 GDPR and Article 5(2) GDPR. Østfold Hospital
    45 KB (6,645 words) - 14:40, 28 March 2022
  • Datatilsynet (Norway) - 20/02147 (category Article 24(1) GDPR)
    the lack of security routines, thus breaching Article 32(1)(b) cf. Article 5 GDPR, Article 35 and Article 24(1), respectively. Teachers at two junior high
    24 KB (3,591 words) - 18:57, 5 March 2022
  • data under the GDPR. The Italian DPA started an investigation concerning potential violations of Articles 5(1)(a), 6, 13, 28(1) and 35 GDPR. The Italian
    87 KB (14,104 words) - 15:45, 6 December 2023
  • CNIL (France) - SAN-2020-003 (category Article 5(1)(c) GDPR)
    principle, namely the breaches of articles 5-1-c), 5 -1 e), 13, 32 and 35-1 of the GDPR; no breach of Article 6 of the GDPR and of Directive 2002/58 / EC of the
    61 KB (10,028 words) - 17:09, 6 December 2023
  • PHR - 22/01253 (category Article 23 GDPR)
    personal data in that assessment pursuant to Article 15(1) GDPR. However, Article 23(1)(i) GDPR and Article 41 UAVG provide the possibility of a restriction
    241 KB (42,617 words) - 14:14, 13 September 2022
  • AEPD (Spain) - PS/00348/2020 (category Article 5(1)(a) GDPR)
    claimant’s signature constitute a breach under the GDPR? The AEPD held that Vodafone violated Article 6(1) GDPR, as they had processed the claimant’s data without
    38 KB (5,648 words) - 14:31, 13 December 2023
  • the DPA held that the controller had violated Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, Article 6 GDPR and Section 3 of the Finnish Act on the Protection
    39 KB (6,038 words) - 17:39, 29 April 2024
  • AEPD (Spain) - EXP202203956 (category Article 6(1) GDPR)
    entity has violated article 6 of the GDPR, for carrying out a processing of personal data without legitimacy. II Article 6.1 of the GDPR establishes the assumptions
    52 KB (8,323 words) - 13:17, 13 December 2023
  • IMY (Sweden) - DI-2020-11370 (category Article 44 GDPR)
    be established on Article 45. Article 46.1 provides, among other things, that in the absence of a decision in accordance with Article 45.3 a personal data
    131 KB (14,752 words) - 08:36, 5 July 2023
  • IP - 0610-376/2020/35 (category Article 13(1) GDPR)
    pursuant to Article 54 of ZVOP-1, points (a), (d) and (f) of Article 58 (2) of the General Regulation, Articles 29 and 32 of the ZIN and Article 221 ZUP,
    110 KB (17,995 words) - 11:15, 22 April 2021
  • engines (see Annex 1 to note of 9 January 2019, p. 1); b) to be "aware of the dispersion of data on 12.12.2018" (see note of 9 January 2019, p. 1) and to have
    34 KB (4,967 words) - 15:46, 6 December 2023
  • Datatilsynet (Norway) - 20/01865 (category Article 4(1) GDPR)
    under Article 4(1) GDPR. These statistics even included health data which qualify as a special category of personal data under Article 9(1) GDPR. The Datatilsynet
    19 KB (2,942 words) - 09:03, 14 September 2023
  • AEPD (Spain) - EXP202206735 (category Article 6 GDPR)
    according to article 4.1 of the GDPR, is data personnel and their protection, therefore, is the subject of said Regulation. In article 4.2 of the GDPR defines
    75 KB (12,421 words) - 13:23, 13 December 2023
  • AEPD (Spain) - EXP202204515 (category Article 6(1)(a) GDPR)
    commercial SMS on your mobile line ***PHONE.1. In this sense, article 21 of the LSSI provides the following: "1. The sending of advertising or promotional
    20 KB (3,159 words) - 13:20, 13 December 2023
  • Rb. Den Haag - C/09/581973/KG ZA 19/1024 (category Article 82 GDPR)
    be referred to respectively as '[plaintiff]' and '[the State]'. 1 The proceedings 1.1. The course of the procedure is evidenced by - the summons with productions;
    20 KB (3,086 words) - 16:15, 10 March 2022
  • GHAL - 200.256.387 (category Article 6(1)(c) GDPR)
    basis under Article 6(1)(c) GDPR, the Court found that the data subject cannot exercise his right to object pursuant to Article 21(1) GDPR. Secondly, the
    27 KB (4,289 words) - 07:57, 7 March 2022
  • AEPD (Spain) - EXP202211953 (category Article 5(1)(a) GDPR)
    adequate information under Article 13 GDPR, and for the processing of personal data in a manner contrary to Article 5(1)(a) of the GDPR. A data subject submitted
    85 KB (13,042 words) - 12:42, 13 December 2023
  • Datatilsynet (Norway) - 20/01879 (category Article 32(1)(b) GDPR)
    highly sensitive personal data exposed, thus breaching Article 32(1)(b) GDPR and Article 32(2), cf. Article 24. An employee in a municipal health care center
    30 KB (4,302 words) - 18:53, 5 March 2022
  • relation to the requirements prescribed by Article 12.1 of the GDPR (transparency obligation) and by Article 13 of the GDPR (right to information). The Head of
    82 KB (11,472 words) - 16:58, 6 December 2023
  • Commissioner (Cyprus) - 11.17.001.010.045 (category Article 5(1)(c) GDPR)
    that the article’s publication was in violation of Article 5(1)(c) GDPR, Article 6(1)(f) GDPR, when read in line with Article 85 GDPR. Article 5(1)(c) outlines
    74 KB (12,375 words) - 10:07, 4 October 2023
  • AEPD (Spain) - PS/00197/2020 (category Article 5(1)(b) GDPR)
    Articles 6(1)(b), 5(1)(b) and 5(1)(c) GDPR? The Spanish DPA (AEPD) deemed itself competent under Article 58(2) GDPR in conjunction with Article 47 of the
    129 KB (21,793 words) - 14:09, 13 December 2023
  • AEPD (Spain) - PS/00315/2020 (category Article 28 GDPR)
    03/31/2020, a written letter is sent to the respondent, *** ADDRESS.1, *** LOCALITY.1 (*** PROVINCE.1), address of the Mer- cantil, giving result "Returned to Origin
    62 KB (10,401 words) - 14:35, 21 November 2023
  • AEPD (Spain) - EXP202201681 (category Article 13 GDPR)
    provided in article 5.1.f) and 32.1 of the GDPR (LCEur 2016, 605). It should be noted that the GDPR, without prejudice to the provisions of its article 83, contemplates
    195 KB (30,495 words) - 12:40, 13 December 2023
  • RvS - 201905319/1/A3 (category Article 12(6) GDPR)
    Act and, subsequently, the GDPR. Request for compensation in case his data is processed unlawfully is also in line with the GDPR. The facts that this may
    21 KB (3,337 words) - 10:08, 16 December 2020
  • AEPD (Spain) - E/10529/2021 (category Article 45 GDPR)
    e7141c720c53441c2483c; has_js=1; _gid=GA1.2.1837808855.1597415922; _gat=1 Upgrade-Insecure-Requests 1 If-None-Match" 1597405902-1" Cache-Control max-age=0”
    44 KB (6,642 words) - 10:34, 13 December 2023
  • AEPD (Spain) - PS/00028/2022 (category Article 5(1)(f) GDPR)
    entity has violated article 6 of the GDPR, for carrying out a processing of personal data without legitimacy. II Article 6.1 of the GDPR establishes the assumptions
    58 KB (9,301 words) - 12:39, 13 December 2023
  • BVwG - W258 2217446-1 (category Article 4(1) GDPR)
    personal data under Article 9(1) GDPR. Their processing would require the data subjects' explicit consent under Article 9(2)(a) GDPR and § 151(4) GewO,
    79 KB (12,652 words) - 09:41, 10 September 2021
  • section 1, subsection 1, section 14, subsections 1–2, section 15, subsections 1 and 3. and subsection 4, 3 points, section 16, subsection 1, section 18
    46 KB (7,394 words) - 14:08, 21 March 2024
  • AEPD (Spain) - PS/00247/2019 (category Article 32(2) GDPR)
    employee of the entity - infringes Article 32. 2 and 32.4 of the RGPD, an infringement punishable under Article 83.4.a of the GDPR. Assessing the circumstances
    39 KB (6,720 words) - 14:22, 13 December 2023
  • APD/GBA (Belgium) - 145/2023 (category Article 4(1) GDPR)
    Service and transferred to the Disputes Chamber pursuant to article 62, § 1 j° article 92, 1° WOG. 10. On 7 February 2020, the Disputes Chamber invites
    39 KB (6,247 words) - 09:14, 15 November 2023
  • AEPD (Spain) - PS/00381/2019 (category Article 5(1)(f) GDPR)
    breach of Article 5(1)(f) GDPR. Was the publication of the census copies a breach of the data integrity and confidentiality principle under Article 5(1)(f) GDPR
    22 KB (3,479 words) - 14:33, 13 December 2023
  • CNIL (France) - SAN-2020-013 (category Article 6 GDPR)
    derogant rule, based on the interpretation of Article 95 GDPR in the line of the Rec (173) GDPR and Article 1(2) and 15a of the ePrivacy Directive. The CNIL
    82 KB (13,424 words) - 17:10, 6 December 2023
  • DSB (Austria) - DSB-D130.1174 (category Article 5(1)(a) GDPR)
    amended: Article 3,, Article 4, number 11,, Article 7,, Article 51, paragraph one,, Article 12, paragraph 3,, Article 17,, Article 19,, Article 57, paragraph
    86 KB (14,497 words) - 13:42, 3 April 2024
  • CNPD (Luxembourg) - Délibération n° 21FR/2021 (category Article 5(1)(c) GDPR)
    company was not compliant with Article 13 GDPR. The CNPD held that the controller infringed Article 5(1)(c) GDPR and Article 13 GDPR and decided to: - impose
    52 KB (7,520 words) - 13:13, 20 July 2021
  • AEPD (Spain) - EXP202105693 (category Article 6(1) GDPR)
    against the controller. Based on Article 72(1)(b) of the national data protection law, and Articles 83(1) and 83(2) GDPR, the DPA considered aggravating
    49 KB (7,579 words) - 13:15, 13 December 2023
  • Rb. Midden-Nederland - UTR 21/3403 (category Article 23(1)(e) GDPR)
    had been unlawful because Article 6(1)(e) GDPR provided a valid legal basis and there was no violation of Article 6(4) GDPR. The controller is the Minister
    23 KB (3,541 words) - 11:29, 8 June 2022
  • Datatilsynet (Norway) - 20/01516 (category Article 32(1)(b) GDPR)
    title of documents containing sensitive information was a breach of Article 32(1)(b) GDPR, highlighting that the breach was reported to the municipality by
    26 KB (3,885 words) - 08:43, 7 May 2022
  • Datatilsynet (Denmark) - 2019-31-2071 (category Article 15(1) GDPR)
    Protection Act) § 22. The provisions of Articles 13(1) to (3), Article 14(1), Article 15 and Article 34 of the Data Protection Regulation shall not apply
    26 KB (3,820 words) - 16:22, 6 December 2023
  • AEPD (Spain) - PS/00198/2020 (category Article 6(1) GDPR)
    (the defendant) for the infringement of Article 6(1) of the GDPR, as the defendant agreed to an early and guilty voluntary payment of the corresponding
    24 KB (3,769 words) - 14:10, 13 December 2023
  • Officer (DPO) under Section 4 of Chapter 4 of the GDPR (see in particular Article 37 GDPR to Article 39 GDPR). One of these audit proceedings concerned a Luxembourg
    26 KB (3,862 words) - 17:41, 25 June 2022
  • Hoge Raad - 20/02950 (category Article 10 GDPR)
    According to the data subject, it follows from Article 47 of the Charter of Fundamental Rights and Article 79 GDPR, that they should not be ordered to pay those
    16 KB (2,553 words) - 11:36, 2 March 2022
  • EWCA - Soriano v Forensic News LLC & Ors (category Article 3(1) GDPR) (section Article 3(1))
    of GDPR Article 5(1)(a) (processing must be fair, lawful and satisfy a condition under Article 6), Article 5(1)(d) (data must be accurate), Article 10
    122 KB (20,830 words) - 10:42, 12 January 2022
  • CNIL (France) - SAN-2020-008 (category Article 5(1)(e) GDPR)
    violation of Article 12 GDPR ? Are the following practices an infringement on data subjects' information right as described in Article 12 GDPR ? Spreading
    104 KB (16,646 words) - 17:09, 6 December 2023
  • Persónuvernd (Iceland) - 2020061951 (category Article 5(1) GDPR)
    defined in the first paragraph. Article 4 of the Act, cf. Points 2 and 4 Article 3 of the Act and points 1 and 2. Article 4 of the Regulation. According
    44 KB (7,044 words) - 08:42, 13 December 2021
  • be answered on 23/04/2019 and also forwarded to the Court of Occupation (Document 26}." r PAGE □1-□□□□ 1429503- □□□4-□□ 15-□2-□1-;i L _J,Court of appeal
    31 KB (4,878 words) - 13:23, 31 March 2022
  • NAIH (Hungary) - NAIH/2020/2555 (category Article 4(1) GDPR)
    Pursuant to Article 60 (2), a request to initiate an official data protection procedure may be made in the case provided for in Article 77 (1) of the General
    33 KB (5,033 words) - 10:12, 17 November 2023
  • UODO (Poland) - ZSZZS.440.768.2018 (category Article 5(1)(c) GDPR)
    connection with Article 5 paragraph 1 point c, Article 9 paragraph 1, Article 58 paragraph 2 point f, point g and point i and with Article 83 paragraph 2
    32 KB (5,139 words) - 10:02, 17 November 2023
  • UODO (Poland) - ZSPR.421.2.2019 (category Article 5(1)(f) GDPR)
    (f), Article 5(2), Article 6(1), Article 7(1), Article 24(1), Article 25(1), Article 32(1)(b), Article 32(1)(c) and Article 32(1)(b), Article 32(1)(c) and
    71 KB (11,304 words) - 10:01, 17 November 2023
  • AEPD (Spain) - PS/00025/2019 (category Article 6(1) GDPR)
    " *** DIRECCION.2 *** *** LOCALIDAD.1 CCAA.1 " . In section“ NIF ” the *** NIF.1. And in the section " Telephone 1" the mobile number*** PHONE . 2. The
    88 KB (14,301 words) - 13:48, 13 December 2023
  • APD/GBA (Belgium) - 138/2022 (category Article 5(1)(a) GDPR)
    an infringement of Article 5 (1) a), b) and c) and (2) of the GDPR and Article 24 (1) of the GDPR; and - an infringement of article 8 of the law of 21
    43 KB (6,274 words) - 08:57, 29 June 2023
  • AEPD (Spain) - PS/00059/2020 (category Article 28 GDPR)
    having knowledge of the following: 1.1 In general, marketing actions can be classified attending to several criteria. 1.1.1. Campaigns managed directly by
    287 KB (48,336 words) - 13:53, 13 December 2023
  • Court of Appeal - (2021) IECA 53 (category Article 4(11) GDPR)
    these allegations, she placed reliance upon Recitals 1, 4 and 7 together of Article 4(11) of GDPR. Whelan J., has stated the evidence indicates that the disclosure
    136 KB (23,256 words) - 13:47, 29 April 2021
  • Officer (DPO) under Section 4 of Chapter 4 of the GDPR (see in particular Article 37 GDPR to Article 39 GDPR). One of these audit proceedings concerned a Luxembourg
    56 KB (8,326 words) - 16:57, 6 December 2023
  • UODO (Poland) - DKN.5131.7.2020 (category Article 33(1) GDPR)
    breach and had failed to do so within the timeframe set out in Article 33(1) of the GDPR, meaning that the company had breached this provision. Consequently
    50 KB (8,066 words) - 10:00, 17 November 2023
  • DSB (Austria) - 2020-0.550.322 (category Article 5(1)(a) GDPR)
    other legal basis for processing under Article 6 GDPR, the controller had violated Article 5(1)(a) and Article 6(1) GDPR. Taking into account the low income
    26 KB (4,098 words) - 13:51, 12 May 2023
  • Based on 20 of 23 working days in the relevant period, this amounts to an amount of 20/23 x € 3,297.00 x 1.08 = € 3,096.31 gross in salary, 20/23 x € 4,110
    30 KB (4,770 words) - 12:39, 10 November 2022
  • RVS - 201907404/1/A3 (category Article 23(1)(d) GDPR)
    it deemed the restrictions on the right of access (Article 15 GDPR]) according to Article 23(1)(h) GDPR legitimate after a reasonable balancing of the public
    40 KB (5,988 words) - 12:51, 9 December 2021
  • Rb. Amsterdam - 8598127 KK EXPL 20-357 (category Article 6(1)(f) GDPR)
    the data could be processed under the legitimate interest basis (ARTICLE 6(1)(f) GDPR). The tribunal weighted the different interests at stake and decided
    27 KB (4,437 words) - 09:17, 22 August 2020
  • NAIH (Hungary) - NAIH/2020/32/4 (category Article 5(1) GDPR)
    basis of Article 58(2)(b) of the GDPR because its processing activities infringed Articles 5(1)(a)(b) and (c), 6(1), 12(1)-(5), 15(1) and 17(1) of the GDPR
    75 KB (12,586 words) - 10:10, 17 November 2023
  • Rb. Den Haag - AWB - 20 5680 (category Article 23(1)(i) GDPR)
    him. Article 23 of the GDPR and Article 41 of the UAVG specify the restrictions on the right of access. What do the parties on appeal think? 3.1. Plaintiff
    12 KB (1,765 words) - 15:30, 12 January 2022
  • questions: 1° Should Article 72.2 of the e-Privacy Directive 2002/58/EC, read in conjunction with Article 2(f) of that directive and with Article 95 of the
    67 KB (10,544 words) - 09:24, 10 September 2021
  • WSA Warsaw - II SA/Wa 1899/20 (category Article 6(1)(a) GDPR)
    in point 1 of the judgment pursuant to Article 145 § 1 of the Act on Administrative Law. 1 of the judgment pursuant to Article 145 § 1 item. 1c of the Act
    30 KB (4,806 words) - 10:59, 19 May 2021
  • UODO (Poland) - ZSPR.421.3.2018 (category Article 4(1) GDPR)
    pursuant to Art. 14 par. 5 lit. b GDPR? The President of UODO found that: 1) The applicable provision is the Art. 14 GDPR since the data controller collects
    52 KB (8,444 words) - 10:01, 17 November 2023
  • RvS (Netherlands) - 202001625/1/A3 (category Article 4 GDPR)
    for the performance of the contract.” It compared Article 7(b) Directive 95/46/EC to Article 6(1)(b) GDPR and found that the two are “almost identical”. Hence
    31 KB (4,864 words) - 09:50, 26 November 2021
  • Rb. Midden-Nederland - ECLI:NL:RBMNE:2023:6043 (category Article 12(3) GDPR)
    € 184 to the plaintiff for paid justice. This statement was made by Mr. J.J.J. Catsburg, judge, in the presence of Mr. L.E. - L.E. Mollerus, clerk. The
    11 KB (1,582 words) - 10:36, 6 December 2023
  • Federation pursuant to Article 58(2)(f) of the General Data Protection Regulation. Pursuant to Article 58(2)(j) and Article 66(1) of the General Data Protection
    32 KB (4,844 words) - 11:44, 11 October 2023
  • Datatilsynet (Denmark) - 2019-32-0988 (category Article 5(1)(e) GDPR)
    Agency's decision 3.1. Authorization to record telephone conversations 3.1.1. Pursuant to Article 9 (1) of the Data Protection Regulation 1, there is in principle
    45 KB (7,151 words) - 16:24, 6 December 2023
  • personal data within the meaning of Article 4, opening words and (1) of the AVG. Based on Article 2, paragraph 1 and Article 3, paragraph 2, of the AVG, the
    38 KB (6,339 words) - 17:14, 12 December 2023
  • APD/GBA (Belgium) - 51/2024 (category Article 5(1)(a) GDPR)
    6GDPR,Article 5.1.b),Article 5.1.a)j°Article 13andArticle 27 GDPR due to the current processing activities. 23. The purpose of this decision is to inform the
    19 KB (2,807 words) - 11:02, 17 April 2024
  • VG Hamburg - 21 K 1802/21 (category Article 4(1) GDPR)
    HmbKrebsRG Article 9 (1) GDPR, Article 6 (1) GDPR, Article 5 (1) in conjunction with Articles 12, 13 and/or Article 14 GDPR and/or Article 5 (1) (in particular
    115 KB (18,479 words) - 16:31, 25 January 2023
  • DSB (Austria) - 2021-0.586.257 (category Article 4(1) GDPR)
    identifier) pursuant to Article 4(1) of the GDPR. c) Combination with other elements The fulfillment of Article 4(1) of the GDPR becomes even more apparent
    108 KB (17,097 words) - 13:52, 12 May 2023
  • AEPD (Spain) - PS/00269/2019 (category Article 5(1)(f) GDPR)
    infringement of article 5.1.f), in relation to article 6.1, of the RGPD. The infringement of article 5.1.f) of the RGPD is typified in article 83.5.a) of the
    30 KB (4,761 words) - 14:24, 13 December 2023
  • Rb. Noord-Holland - AWB-20 4638 (category Article 15(1) GDPR)
    at €1,068 (1 point for submitting the notice of appeal, 1 point for appearing at the hearing, with a value per point of € 534 and weighting factor 1). Furthermore
    16 KB (2,267 words) - 11:58, 11 August 2021
  • CNPD (Luxembourg) - Délibération n° 13FR/2023 (category Article 5(1)(b) GDPR)
    their employees. The DPA found a violation of Article 5(1)(b) GDPR, Article 5(1)(c) GDPR and Article 13 GDPR. Following a visit to the premises of two public
    96 KB (13,984 words) - 16:57, 6 December 2023
  • APD/GBA (Belgium) - 81/2020 (category Article 5(1)(c) GDPR)
    subjects required by Article 12.2. of the GDPR. 8.1.3. As for the breach of the principle of minimization (article 5.1 c) of the GDPR) 8.1.3.1. In view of the
    127 KB (21,484 words) - 17:01, 12 December 2023
  • CE - 440376 (category Article 23(1) GDPR)
    collected for other purposes which would be incompatible with Article 5(1)(b) GDPR and Article 6(4) GDPR. The CE dismissed that claimed by recalling that both
    33 KB (5,152 words) - 14:48, 12 January 2022
  • Datatilsynet (Denmark) - 2020-832-0028 (category Article 5 GDPR)
    controller was. Article 22 of the Danish Data Protection Act serves as a restriction of Article 15 GDPR based on Article 23 GDPR. However, Article 22 of the
    31 KB (4,887 words) - 13:45, 14 July 2022
  • Datatilsynet (Denmark) - 2020-422-0026 (category Article 5 GDPR)
    is processed pursuant to Article 6, paragraph 1 of the Data Protection Regulation. 1, letter e, Article 9, subsection 2, letter j, and § 10 of the Data Protection
    24 KB (3,668 words) - 14:53, 14 September 2022
  • RVS - 202105980/1/A3 (category Article 15 GDPR)
    Authorities to receive the information as referred to in Article 15, paragraph 1 a to h GDPR." 3.1. The Division agrees with the judgment of the District
    15 KB (2,191 words) - 16:02, 19 April 2023
  • provides as follows: (1) This section applies where, after a data subject makes a complaint under section 165 or Article 77 of the UK GDPR, the Commissioner—
    26 KB (3,926 words) - 09:58, 14 December 2023
  • VwGH - Ro 2021/04/0033 (category Article 6(1)(a) GDPR)
    processing pursuant to Article 6(1) GDPR even if the data protection authority had only based its investigation on Article 6(1)(a) GDPR. The controller operates
    36 KB (5,727 words) - 11:02, 7 April 2022
  • VG Gießen - 4 K 252/19.GI (category Article 15(1) GDPR)
    affected" within the meaning of Art. 15 para. 1 GDPR. The right to information under Article 15.1 of the GDPR is also not transferred to the insolvency administrator
    35 KB (5,815 words) - 15:51, 17 March 2022
  • VG Neustadt an der Weinstraße - 3 L 763/22.NW (category Article 6(1)(e) GDPR)
    court upheld Article 6(1)(e) GDPR as the legal basis for the processing of personal data. Furthermore, according to the court, Article 9(2)(j) GDPR states that
    54 KB (8,511 words) - 09:03, 16 December 2022
  • APD/GBA (Belgium) - 31/2022 (category Article 5(1)(a) GDPR)
    would be based 5. 1, a) GDPR, Article 6, Article 12.1 GDPR and Article 14.1 a) GDPR. 67. Moreover, a controller, in this case defendant 1, cannot suffice
    84 KB (12,933 words) - 16:46, 12 December 2023
  • Commissioner (Cyprus) - 11.17.001.008.229 (category Article 5(2) GDPR)
    violation of Article 5(2) GPDR since the controller failed to demonstrate compliance with Article 5(1) GDPR and a violation of Article 44 GDPR since the controller
    56 KB (8,616 words) - 15:31, 6 March 2024
  • LG Bonn - 29 OWi 1/20 (category Article 32(1) GDPR)
    83(4)(a) GDPR in conjunction with [Article 32(1) GDPR. Article 32 (1) GDPRby failing, at least with gross negligence, to ensure processes for sufficient authentication
    58 KB (9,577 words) - 08:06, 16 September 2021
  • APD/GBA (Belgium) - 85/2022 (category Article 5(1)(e) GDPR)
    consent was given obtained (potential violation of Article 6.1 a) GDPR): ▪ Article 6.1 a) GDPR and Article 129 of the law on electronic communication (WEC)
    171 KB (24,826 words) - 15:55, 18 June 2022
  • AEPD (Spain) - PS/00128/2020 (category Article 6(1)(b) GDPR)
    breach of Article 13 GDPR? The AEPD held that the facts complained of involving the violation by the City Council of the provisions of Article 13 of the
    39 KB (5,912 words) - 14:02, 13 December 2023
  • Rb. Rotterdam - C/10/587469 / HA RK 19-1473 (category Article 9(1) GDPR)
    jurisprudence/literature, 1 hour studying documents/file, 1 hour consulting with [name of defendant] , 1 hour letters/e-mail various, 1 hour preparing the hearing
    24 KB (3,918 words) - 16:29, 10 March 2022
  • Datatilsynet (Norway) - 20/01626 (category Article 5(1)(a) GDPR)
    processing as per Article 5(1)(b), nor legal grounds as per Article 6. In sum, the DPA found that NIF had breached Article 5(1)(a), (c) and (f), Article 6, and Article
    50 KB (8,081 words) - 18:52, 5 March 2022
  • Court of Appeal of Brussels - 2020/AR/329 (category Article 57(1)(f) GDPR)
    submits that Article 77 AVG 2, interpreted in the light of Articles 1, 51(1) and 57 AVG, recitals 7, 10 and 141 AVG, Article 8 Charter and Article 16 TFEU,
    48 KB (7,560 words) - 09:03, 20 August 2021
  • BAG - 2 AZR 296/22 (category Article 17(1)(d) GDPR)
    law of the Member States. Article 6 paragraph 1 subparagraph 1 letter e in conjunction with Paragraph 3 sentence 1 letter b GDPR was missing (para. 24 f
    49 KB (8,060 words) - 13:00, 5 September 2023
  • AEPD (Spain) - EXP202307898 (category Article 21 GDPR)
    With regard to limitation periods, article 72.1.k) of the LOPDGDD, establishes: "1. Based on what is established in article 83.5 of the Regulation (EU) 2016/679
    37 KB (5,591 words) - 14:51, 10 April 2024
  • Rb. Rotterdam - C/10/655051 KG ZA 23-243 (category Article 28(3) GDPR)
    mrs. J.G. Reus, T.J.M. de Weerd and A.M. van Aerde in Amsterdam. Parties are hereinafter referred to as Blauw and Nebu. 1. The case in brief 1.1. Blauw
    33 KB (5,443 words) - 06:20, 26 April 2023
  • Rb. Amsterdam - KG ZA 23-440 (category Article 21(1) GDPR)
    ING against the processing of his personal data on the basis of Article 21 paragraph 1 GDPR due to his specific situation. Now that ING has rejected that
    12 KB (1,771 words) - 13:53, 18 July 2023
  • ICO - Monetary Penalty on Ticketmaster UK Limited (category Article 5(1)(f) GDPR)
    obligations under Article 5(1)(f) and Article 32 of GDPR. Article 5 (1) : Ticketmaster has failed to comply with the requirements of GDPR including to process
    130 KB (21,195 words) - 13:52, 25 April 2021
  • GHDHA - 200.290.360-01 (category Article 23(1)(i) GDPR)
    legislative measure that serves one of the objectives listed in Article 23, namely Article 23(1)(i) GDPR. After all, the Court of first instance notes, “compliance
    35 KB (5,770 words) - 07:13, 4 April 2022
  • proceeding personal data under Article 5(1)(a) GDPR. Lursoft claim to be have such a legal basis under Article 6(1)(c) GDPR. However, this was rejected by
    90 KB (14,351 words) - 16:10, 6 December 2023
  • CBB - 20/935 (category Article 17 GDPR)
    connection with a possible exceeding of the reasonable term. Considerations 1.1 At the request of the appellant, the Foundation was registered in the trade
    13 KB (1,931 words) - 11:36, 10 November 2022
  • assessment 4.1 ING has requested the Subdistrict Court on the basis of the provisions of Article 7:671 b paragraph 1 under a and Article 7:669 paragraph
    27 KB (4,150 words) - 13:42, 27 July 2022
  • Datatilsynet (Denmark) - 2020-432-0034 (category Article 5(1)(f) GDPR)
    of Article 5 of the Data Protection Regulation. Article 6 (1) (a) and (c) and Article 6 (1) 1, letter e, and the Data Protection Act § 11, para. 1. However
    40 KB (6,369 words) - 16:39, 6 December 2023
  • AP (The Netherlands) - 26.11.2020 (category Article 32(1) GDPR)
    pursuant to article 32(1) of the GDPR. The AP disagrees. The conclusion of the AP that OLVG does not comply with article 32(1) of the GDPR by not meeting
    67 KB (11,415 words) - 17:15, 12 December 2023
  • Number: 2019/211CA Circuit Court Record Number: 2018/5134 Noonan J. Haughton J. Ní Raifeartaigh J. IN THE MATTER OF THE DATA PROTECTION ACTS, 1988 AND 2003 AND
    64 KB (9,589 words) - 16:15, 1 June 2022
  • UODO (Poland) - DKE.561.20.2022 (category Article 58(1)(a) GDPR)
    pursuant to Article 83(5)(e) GDPR. Second, the DPA considered the non-compliance with the summons to breach breach of Article 58(1)(a) and (e) GDPR. The delay
    43 KB (6,878 words) - 10:55, 10 January 2024
  • regulation[1] article 5, subsection 2, cf. Article 5, subsection 1, letters c and f, and Article 5, subsection 1, letter a, cf. Article 6, subsection 1, and
    117 KB (18,075 words) - 10:19, 12 September 2022
  • AEPD (Spain) - PS/00178/2021 (category Article 5(1)(f) GDPR)
    of the article 5.1.f) of the RGPD, typified in article 83.5 of the RGPD, considered very serious for the purposes of prescription in article 72.1.i) of
    20 KB (3,078 words) - 14:26, 24 November 2022
  • complaint hearing, the bB (OZ 23 to W245 2252208-1), the BF1 (OZ 24 to W245 2252208-1) and BF2 (OZ 25 to W245 2252208-1) Observations. In these observations
    158 KB (26,392 words) - 08:25, 7 June 2023
  • DPC (Ireland) - IN-19-7-6 (category Article 17 GDPR)
    limitation under Article 5(1)(b) of the GDPR and the principle of lawfulness fairness and transparency under Article 5(1)(a) of the GDPR. ii. In relation
    513 KB (85,155 words) - 13:25, 8 July 2023
  • AEPD (Spain) - PS/00501/2021 (category Article 6(1) GDPR)
    commerce (hereinafter LSSI), as provided in article 43.1 of said Law. II Article 85 of Law 39/2015, of October 1, on Administrative Procedure Common to Public
    26 KB (3,914 words) - 12:38, 2 February 2022
  • Rb. Gelderland - C/05/404834 / HA ZA 22-245 (category Article 15(3) GDPR)
    rejected the claim under Article 15 GDPR on this point. Regarding the residual recordings, the Court pointed out that Article 15(3) GDPR gives the data subject
    36 KB (5,830 words) - 09:54, 23 November 2022
  • NAIH (Hungary) - NAIH/2020/1154/9 (category Article 6(1)(f) GDPR)
    Regulation, Article 6 (1) (f)Article 13 (2) (f) and Article 14 (2) (g), Article 14 (1) andArticle 15 (1) (h) and Article 21 (1)infringement of Article 18 (1) (a)
    192 KB (30,170 words) - 10:11, 17 November 2023
  • publication of the press release of 17 June 2020 infringed Article 54(2) GDPR and Article 48(1) and Article 64(3) WOG. This press release described that the DPA
    206 KB (30,485 words) - 09:54, 14 December 2023
  • WSA Warsaw (Poland) - II SA/Wa 2227/19 (category Article 2(1) GDPR)
    considered whether the Polish DPA correctly applied Article 5(1)(c) and (f) of the GDPR and whether the GDPR provisions would be applied at all in the given
    38 KB (5,603 words) - 14:17, 20 September 2021
  • APD/GBA (Belgium) - 62/2022 (category Article 33(1) GDPR)
    therefore infringed Article 30.1 of the AVG. On 23 September 2021, the Dispute Tribunal decides, on the basis of Article 95, § 1, 1° and Article 98 of the CPC
    58 KB (9,477 words) - 18:41, 1 June 2022
  • AEPD (Spain) - PS/00388/2022 (category Article 32(1) GDPR)
    has not violated the article 15 of the GDPR, infringement typified in article 83.5 a) of the GDPR. IV. Secondly, article 32 of the GDPR "Security of treatment"
    72 KB (11,730 words) - 08:54, 19 July 2023
  • RvS - 201902699/1/A2 (category Article 79 GDPR)
    award compensation for immaterial damages. Article 82 of the AVG 16. Article 82 of the AVG reads as follows: 1. Any person who has suffered material or non-material
    37 KB (5,696 words) - 07:22, 7 April 2020
  • AEPD (Spain) - PS/00189/2021 (category Article 6(1) GDPR)
    Vodafone processed personal data without a legal basis according to Article 6(1) GDPR. The complainant has been a victim of identity theft with the data
    23 KB (3,387 words) - 09:55, 22 September 2021
  • Rb. Midden-Nederland - C/16/531572 / KG ZA 21-672 (category Article 23(1)(d) GDPR)
    consulted before processing, pursuant to Article 36 GDPR. Fourth, the Court noted that, pursuant to Article 10 GDPR and Article 31 Implementation Act, the IP addresses
    59 KB (9,649 words) - 08:09, 20 October 2022
  • assessment Scope of right of access according to Article 15 GDPR 3.1. The purpose of Article 15 of the GDPR is to enable a data subject to become aware of
    21 KB (2,968 words) - 10:13, 6 May 2021
  • APD/GBA (Belgium) - 105/2023 (category Article 5(1)(a) GDPR)
    ((articles 5. 1, a) GDPR , 12.1 GDPR and 14.1 a) and c) GDPR) and how the accountability obligation was fulfilled (art 5.2 GDPR and 24 GDPR). The parties
    102 KB (15,787 words) - 07:39, 6 September 2023
  • Commissioner (Cyprus) - 11.17.001.009.048 (category Article 9(2) GDPR)
    data under Article 9 GDPR, which can only be lawful if one of the exceptions of Article 9(2) GDPR apply. With respect to Article 9(2)(h) GDPR, the DPC held
    44 KB (7,042 words) - 13:53, 31 January 2024
  • GHARL - 21/00910 (category Article 6(1)(c) GDPR)
    minimization principle (Article 5(1)(c) GDPR), since the processing was based on a legal obligation pursuant to Article 6(1)(c) GDPR. Share your comments
    23 KB (3,625 words) - 15:11, 3 August 2022
  • Datatilsynet (Denmark) - 2021-31-5523 (category Article 17 GDPR)
    of personal data under Article 17(1)(c) GDPR. Consequently, the DPA reprimanded the controller for violating Article 17(1)(c) GDPR and ordered it to delete
    12 KB (1,651 words) - 20:05, 7 September 2022
  • referred to in Article 33(1) of the AVG.15 15 File note 1, Notification of personal data breach 7-2-2019. P 5. 3.4.3 Assessment Article 33(1) of the AVG provides
    77 KB (12,915 words) - 17:15, 12 December 2023
  • Rb. Rotterdam - ROT 22/2125 (category Article 23(1)(d) GDPR)
    personal data. Last, the controller generally referred to Article 13(4), Article 14(5) and Article 23 GDPR for possible non-disclosure. The data subject found
    18 KB (2,609 words) - 15:20, 21 March 2023
  • FG München - 15 K 1212/19 (category Article 12(1) GDPR)
    federal government or a state (Article 23 (1) e GDPR in conjunction with Sections 32c (1) no. 1, 32b (1) sentence 1 no. 1 b AO). According to media reports
    98 KB (16,511 words) - 08:37, 9 May 2022
  • AEPD (Spain) - PS/00126/2021 (category Article 6(1) GDPR)
    negligence of the infringement (Article 83(2)(b) GDPR) the impact on basic personal identifiers (Article 83(2)(g) GDPR) Share your comments here! Share
    26 KB (3,922 words) - 13:10, 9 June 2021
  • APD/GBA (Belgium) - 60/2023 (category Article 5(1)(a) GDPR)
    (2) GDPR (accountability) II.1.1. Article 5, paragraph 1, a) (lawfulness) j° Article 6, paragraph 1 GDPR II.1.1.1. Findings in the Inspection Report 11
    39 KB (5,541 words) - 08:17, 6 June 2023
  • UODO (Poland) - DKN.5131.59.2022 (category Article 33(1) GDPR)
    should have notified the DPA under Article 33(1) GDPR and the data subjects affected by the breach under Article 34(1) GDPR. Regarding the corrective measure
    108 KB (17,728 words) - 07:57, 25 April 2024
  • VG Wiesbaden - 6 K 361/21.WI (category Article 6(1)(f) GDPR)
    assessed according to Article 6(1)(f) GDPR and Article 9 GDPR. Second, lawyers are data controllers within the meaning of Article 4(7) GDPR with regard to their
    37 KB (6,025 words) - 16:24, 15 November 2023
  • be equivalent to a DPIA under Article 35 GDPR. For this reason, the AP held that the controller violated Article 35(1) GDPR. In this, the AP considered it
    55 KB (8,007 words) - 09:50, 24 January 2024
  • BVwG - W211 2210458-1/10 (category Article 2(1) GDPR)
    according to To 1): € 1.200,00 To 2): € 300,00 To 3): € 300,00 . . . In total: € 1.800 To 1): 3 days To 2): 1 day To 3): 1 day ... In total: 5 days Ad 1): Art.
    92 KB (15,435 words) - 16:00, 22 March 2022
  • personal data breach to comply with Article 32 GDPR and by reference to the principle set down in Article 5(1)(f) GDPR. In particular, this request concerned
    142 KB (23,134 words) - 15:51, 19 July 2021
  • CNPD (Luxembourg) - Délibération n°24FR/2021 (category Article 5(1)(c) GDPR)
    according to which the non-compliance with Article 5.1.c) of the GDPR with regard to 9 See CNPD Guidelines (Point 4.1.), Available at: https://cnpd.public.lu/fr/dossiers-
    58 KB (8,226 words) - 07:35, 22 July 2021
  • AEPD (Spain) - EXP202206805 (category Article 5(1)(a) GDPR)
    in the article 57.1 and the powers granted in article 58.1 of the Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in
    37 KB (5,879 words) - 07:09, 4 October 2023
  • Datatilsynet (Norway) - 20/02225 (category Article 6(1)(f) GDPR)
    dissuasive" as per Article 83(1). In addition to a breach of Article 6(1)(f), the lack of organisational measures pursuant to Article 5(2) was weighted
    45 KB (7,286 words) - 18:55, 5 March 2022
  • Datainspektionen - DI-2019-9432 (category Article 5(1)(f) GDPR)
    current personal data processing has violated Article 5 (1) (f), Article 32.1 and 32.2 and Article 33.1 and 33.5 of the Data Protection Regulation. The
    59 KB (8,959 words) - 11:43, 7 April 2022
  • AEPD (Spain) - PS/00148/2019 (category Article 6 GDPR)
    offence against privacy included in Article 197(1) of the Spanish Criminal Code, with the aggravating circumstance from Article 197(5) of being data related to
    48 KB (7,550 words) - 14:05, 13 December 2023
  • parties will hereinafter be referred to as [plaintiff] and Nijestee. 1 Proceedings 1.1 The course of the procedure is evidenced by - the summons - the conclusion
    16 KB (2,062 words) - 09:31, 23 May 2020
  • AEPD (Spain) - PS/00070/2019 (category Article 5(1)(a) GDPR)
    referred to Article 5(1)(a) (principle of lawfulness, fairness and transparency), Article 12(1), Article 7, Article 13 and Article 14 GDPR, the corresponding
    422 KB (70,184 words) - 13:56, 13 December 2023
  • NAIH (Hungary) - NAIH-2020/2204/8 (category Article 15(1) GDPR)
    subjects to Under the conditions set out in Article 15 (1) and (3) of the GDPR, thereby infringing the GDPR Article 25 (1). III.3.2. Designed to handle requests
    60 KB (9,820 words) - 10:08, 17 November 2023
  • UODO (Poland) - ZSPR.421.7.2019 (category Article 5(1)(a) GDPR)
    violation of the provisions of Article 5(1)(a), Article 6(1), Article 7(3), Article 12(2), Article 17(1)(b) and Article 24(1) of Regulation 2016/679 imposes
    60 KB (9,815 words) - 10:02, 17 November 2023
  • AEPD (Spain) - PS/00193/2021 (category Article 6(1) GDPR)
    infringement of article 6.1 of the RGPD that establishes the assumptions that allow the processing of personal data to be considered lawful. Article 6 of the
    27 KB (4,223 words) - 10:01, 22 September 2021
  • consultation. of the Guarantor pursuant to article 36 of the Regulation "(article 110 of the Code, article 9, paragraph 2, letter j) and par. 4 of the Regulation)
    97 KB (15,437 words) - 11:27, 16 August 2022
  • DSB (Austria) - 2023-0.594.826 (category Article 2(1) GDPR)
    under Article 3 GDPR was also fulfilled, as the controller had an official seat in Vienna. In general, the material scope under Article 2(1) GDPR would
    56 KB (8,692 words) - 14:58, 10 April 2024
  • AEPD (Spain) - PS/00416/2019 (category Article 6 GDPR)
    an infractionof article 6 of the RGPD, typified in article 83.5.a) and classified as very serious toprescription effects in article 72.1.b) of the LOPDGDD
    206 KB (32,869 words) - 14:36, 13 December 2023
  • FG Nürnberg - 3 K 596/22 (category Article 6(1) GDPR)
    legislator used the open clause of Article 6(1)(c) and (e) GDPR, in combination with Article 6(2) and Article 6(3) GDPR, to create a legal basis for the
    38 KB (6,277 words) - 08:12, 18 May 2023
  • Datatilsynet (Denmark) - 2023-832-0081 (category Article 10 GDPR)
    specifically mention GDPR provisions. However, the case is based on the concept of ‘criminal information’, which is regulated by Article 10 GDPR. This provision
    12 KB (1,708 words) - 08:02, 27 September 2023
  • CPDP (Bulgaria) - PNN-01-33/2022 (category Article 32 GDPR)
    the GDPR introduces a prohibition on their processing (Article 9(1) GDPR), while allowing for explicit and limitative exceptions (Article 9(2) GDPR). In
    71 KB (11,948 words) - 17:01, 8 February 2023
  • articles 28(1) and 24(1) of Regulation (EU) 2016/679, and 19 Reprimand for the violation of Article 36(4) of Regulation (EU) 2016/679 and Article 13(1) of Law
    53 KB (8,451 words) - 22:10, 28 February 2024
  • RvS - 201905087/1/A2 (category Article 6(1)(f) GDPR)
    notes that though Article 82(1) of the GDPR states that full compensation for actual non-material damage resulting from breaches of the GDPR must take place
    33 KB (5,123 words) - 07:17, 15 September 2020
  • Rb. Oost-Brabant - C/01/356292 / KG ZA 20-141 (category Article 6(1)(e) GDPR)
    that the GDPR applies to the request for removal. The request shall be based on Article 21 in conjunction with Article 79 of the GDPR and Article 35(2) of
    18 KB (2,804 words) - 16:26, 10 March 2022
  • UODO (Poland) - DKN.5131.49.2021 (category Article 33(1) GDPR)
    notified in accordance with Article 34 GDPR. Therefore, the DPA found that the controller violated Article 33(1) and Article 34(1) GDPR and imposed a fine of
    63 KB (10,380 words) - 08:26, 17 October 2023
  • AP (The Netherlands) - 16.06.2020 (category Article 9(1) GDPR)
    of (sensitive) personal data in Article 9(1) GDPR are closely linked to the ideas behind discrimination law. The GDPR assumes that this type of information
    54 KB (8,224 words) - 17:07, 12 December 2023
  • AEPD (Spain) - PS/00135/2020 (category Article 13 GDPR)
    portability of the data; (c) where the processing is based on Article 6(1)(a) or Article 9(2)(a) the existence of the right to withdraw consent in at any
    47 KB (7,756 words) - 14:04, 13 December 2023
  • WSA Kielce - I SA/Ke 31/21 (category Article 34(1) GDPR)
    of a driving licence - pursuant to Article 102(1)(4) of the Act on Vehicle Drivers in connection with Article 7(1)(1) and (2) of the Act of 20 March 2015
    27 KB (4,470 words) - 07:46, 24 August 2023
  • to appoint a Data Protection Officer (DPO), in line with Article 37(1) GDPR. Article 37(1) GDPR envisages two situations where private controllers (such
    35 KB (4,974 words) - 10:52, 2 December 2021
  • Datatilsynet (Norway) - 21/03126 (category Article 33(1) GDPR)
    deadline set out in Article 33(1) GDPR. 6. Datatilsynet’s Assessment 6.1. Findings of an Infringement of Article 33(1) GDPR 6.1.1. Introduction As noted
    133 KB (19,309 words) - 05:16, 24 March 2023
  • AEPD (Spain) - EXP202211618 (category Article 6(1) GDPR)
    the alleged violation of articles 32.1 and 5.1.f) of the GDPR, typified in article 83.4.a) and 83.5.a) of the GDPR, with warning. Receipt by the claimant
    33 KB (5,018 words) - 13:23, 2 August 2023
  • presented the matter Applicable law Article 4 (7) and (8), Article 28 (3), Article 58 (2) (b) and (i), Article 83 (1), (2), (4) (a) of the EU General Data
    40 KB (6,315 words) - 11:13, 22 September 2021
  • CNPD (Luxembourg) - Délibération n° 17FR/2021 (category Article 5(1)(c) GDPR)
    non-compliance with the requirements of Article 5.1.c) of the GDPR and non-compliance with the requirements of article 5.1.e) of the GDPR. 10. On February 28, 2020,
    44 KB (6,212 words) - 08:28, 16 June 2021
  • NAIH (Hungary) - NAIH-642-4/2022 (category Article 5(1)(c) GDPR)
    €7,80) for the breach of Articles 5(1)(b)(c) GDPR, 6(1) GDPR, 12(1) GDPR, 7(2) GDPR, 9(1) GDPR, 13 GDPR and 14 GDPR. Independent of any instructions from
    73 KB (11,498 words) - 15:22, 29 August 2023
  • DSB (Austria) - DPA 2023-0.594.826 (category Article 2(1) GDPR)
    under Article 3 GDPR was also fulfilled, as the controller had an official seat in Vienna. Moreover, the material scope under Article 2(1) GDPR also applied
    56 KB (8,709 words) - 14:27, 10 April 2024
  • AEPD (Spain) - PS/00427/2021 (category Article 6(1) GDPR)
    commerce (hereinafter LSSI), as provided in article 43.1 of said Law. II Article 85 of Law 39/2015, of October 1, on Administrative Procedure Common to Public
    23 KB (3,593 words) - 16:23, 26 January 2022
  • Rb. Noord-Holland - HAA 19/4807 (category Article 12(3) GDPR)
    notice of inability to attend. Considerations 1. The court ruled in the appeal case without a hearing. Article 8:54 of the General Administrative Law Act
    14 KB (2,262 words) - 22:02, 3 August 2020
  • Datatilsynet (Denmark) - 2019-431-0031 (category Article 6(1)(f) GDPR)
    to data portability; when treatment is based on Article 6 (1) Article 9 (1) (a) or Article 9 (1) Article 2 (2) (a), the right to withdraw consent at any
    35 KB (5,528 words) - 08:12, 24 January 2022
  • AEPD (Spain) - PS/00188/2021 (category Article 6(1) GDPR)
    for: processing personal data without a legal basis, in breach of Article 6(1) GDPR: €70,000 and; not complying with their obligation to erase the data
    33 KB (5,242 words) - 11:42, 11 August 2021
  • AEPD (Spain) - PS/00200/2021 (category Article 6(1) GDPR)
    claimed, by the alleged violation of Article 6.1 of the RGPD, typified in Article 83.5.a) of the aforementioned GDPR. FIFTH: Having been notified of the
    23 KB (3,787 words) - 09:50, 5 August 2021
  • AEPD (Spain) - PS/00433/2021 (category Article 6(1) GDPR)
    alleged violation of article 6.1 of the RGPD, sanctioned in accordance with the provisions of article 83.5.b) of the aforementioned GDPR and considered for
    27 KB (4,079 words) - 12:37, 9 February 2022
  • Datatilsynet (Norway) - 0/02422 (category Article 5(1)(e) GDPR)
    October 2022. 18See Art. 60(6) GDPR. 3 4. Legal Background 4.1. Scope of Application of the GDPR Under Article 2(1) GDPR, the Regulation: “[…] applies to
    162 KB (24,007 words) - 19:41, 15 February 2023
  • AEPD (Spain) - PS/00180/2021 (category Article 6 GDPR)
    commerce (hereinafter LSSI), according to Article 43.1 of said Law provides. SECOND: Article 85 of Law 39/2015, of October 1, on the Procedure Common Administrative
    26 KB (3,947 words) - 10:42, 21 July 2021
  • UODO (Poland) - DKN.5131.43.2022 (category Article 5(2) GDPR)
    the controller was in breach of Article 33(1) GDPR, Article 33(3) GDPR, Articles 34(1) and 34(2) GDPR, and Article 5(2) GDPR, Firstly, the Polish DPA held
    57 KB (9,261 words) - 08:13, 25 October 2023
  • DVI (Latvia) - LocateFamily administrācija (category Article 5(1)(b) GDPR)
    based on Article 3, Clause 2, Article 5, Clause 1 of the Data Regulation "a", "b" and point 2, Article 6, point 1, point "a", Article 7, Article 27, point
    25 KB (3,679 words) - 11:30, 2 August 2023
  • AP (The Netherlands) - 24.02.2022 (category Article 13(1)(e) GDPR)
    requirements of article 24 and 32, paragraph 1, AVG and further elaborated in article32, paragraph2, preamble, FISHOrdinancesBIO standards5.1.1,5.1.1.1and5.1.2.1.
    179 KB (22,957 words) - 17:07, 12 December 2023
  • provided to the interested parties based on Article 13 GDPR and to non-contactable persons based on Article 14 GDPR. The information notice includes the right
    115 KB (18,087 words) - 14:11, 17 April 2024
  • Rb. Rotterdam - C/10/603827 / KG ZA 20-816 (category Article 4(1) GDPR)
    [defendant 1] and [defendant 2]. 1. The procedure 1.1. The course of the procedure is evidenced by: - the summons of September 14, 2020 with exhibits 1 to 24
    26 KB (3,882 words) - 08:30, 27 May 2021
  • APD/GBA (Belgium) - 87/2023 (category Article 17(1) GDPR)
    territorial scope of the GDPR, Article 3 of the GDPR is assumed of two different cases. In the first case (Article 3.1 of the GDPR), the data processing carried
    21 KB (2,987 words) - 20:10, 4 July 2023
  • CNPD (Luxembourg) - 10FR/2023 (category Article 37(1)(a) GDPR)
    DPA, as provided by Article 37(1)(a) GDPR and Article 37(7) GDPR. The DPA noted that pursuant to the entry into force of the GDPR, public bodies were obliged
    23 KB (3,112 words) - 11:34, 3 January 2024
  • Rb. Den Haag - C/09/585239/ KG ZA 19/1221 (category Article 6(1)(c) GDPR)
    satisfoactory answers. Thus, Article 15 GDPR was not violated. Furthermore, the judge ruled that the e-screener did not infringed Article 22 GDPR. Indeed, the judge
    77 KB (12,441 words) - 12:12, 4 October 2021
  • NAIH (Hungary) - NAIH-5361-1/2022 (category Article 15(1) GDPR)
    pursuant to Article 58 (2) (b) GDPR condemns the Applicant as data controller for violating Article 12 of the GDPR. and Article 15 (1) and (3) of the GDPR. The
    50 KB (8,064 words) - 14:42, 29 June 2022
  • AEPD (Spain) - PS/00245/2019 (category Article 5(1)(a) GDPR)
    Articles 5(1)(a) GDPR and 13 GDPR. On the other hand, they disagreed with the infringement of Article 5(1)(a) GDPR in relation to Article 9(1) GDPR with regard
    116 KB (18,941 words) - 14:21, 13 December 2023
  • Rb. Zeeland-West-Brabant - AWB- 20 6846 (category Article 12(3) GDPR)
    Court considered that pursuant to Article 12(3) GDPR, data controllers must provide data subjects with information on Article 15 to 22 requests without delay
    12 KB (1,755 words) - 15:01, 10 November 2020
  • Persónuvernd (Iceland) - 2020092288 (category Article 5 GDPR)
    and finally version 1.1 has been released on the 22nd s.m. It is also stated that there was also a version between version 1.0.4 and 1.1 made updates to the
    125 KB (20,768 words) - 13:06, 22 December 2021
  • UODO (Poland) - DKN.5131.31.2021 (category Article 5(1)(a) GDPR)
    controller violated Article 33(1) GDPR by failing to inform the DPA of the data breach. Second, the DPA held that the controller violated Article 28(1), (3) and
    105 KB (17,237 words) - 09:22, 10 May 2023
  • Rb. Amsterdam - AMS 22/1414 (category Article 17 GDPR)
    regarded as a request under the General Data Protection Regulation (GDPR). Article 34 of the Gdpr Implementation Act states that a decision on such a request by
    12 KB (1,857 words) - 14:27, 20 April 2022
  • AEPD (Spain) - EXP202202837 (category Article 6(1) GDPR)
    (Considering 40 GDPR), Article 6.1 of the GDPR is therefore applicable and not RD 1720/2007 used by the defendant. Thus, the aforementioned article 6.1 GDPR establishes
    58 KB (8,995 words) - 13:00, 13 December 2023
  • questions to the Court of Justice of the European Union: 1. Should Article 55(3) of the GDPR be interpreted as meaning that “processing operations of courts
    36 KB (5,806 words) - 08:45, 8 September 2021
  • AEPD (Spain) - PS/00140/2021 (category Article 5 GDPR)
    A50715366, for the alleged violation of article 6.1. of the GDPR typified in article 83.5.a) of the aforementioned RGPD. 1. APPOINT D. B.B.B. as instructor.
    28 KB (4,254 words) - 11:30, 16 June 2021
  • Rb. Rotterdam - ROT 19/1395 (category Article 5(1)(c) GDPR)
    status of the plaintiff according to Article 17(1)(d) GDPR. The Court recalled that deletion request under Article 17(1)(d) must be granted if the personal
    17 KB (2,674 words) - 16:30, 10 March 2022
  • AEPD (Spain) - PS/00301/2020 (category Article 5(1)(d) GDPR)
    B28905784, for an infringement of the article 5.1.d) of the GDPR, in accordance with article 83.5 a) of the GDPR, with a fine of 10,000 euros (ten honey
    28 KB (4,554 words) - 11:33, 30 June 2021
  • AEPD (Spain) - PS/00505/2021 (category Article 6(1) GDPR)
    RESOLVES: FIRST: IMPOSE A.A.A., with NIF ***NIF.1, for an infraction of article 6.1.a) of the RGPD, typified in article 83.5.a) of the RGPD, a fine of €2,000 (two
    28 KB (4,283 words) - 09:43, 24 March 2022
  • AEPD (Spain) - PS/00177/2021 (category Article 13 GDPR)
    commerce (hereinafter LSSI), as provided in article 43.1 of said Law. II Article 85 of Law 39/2015, of October 1, on Administrative Procedure Common of Public
    29 KB (4,484 words) - 12:28, 7 July 2021
  • (2016/679) Article 12(1), 2, 3, 4 and 6, Article 5(1)(c), Article 15, Article 17, Article 25, Article 58(2)(b) and (d), Article 83 paragraphs 1, 2, 3, 4
    139 KB (22,397 words) - 21:48, 13 July 2022
  • AEPD (Spain) - PS-00507-2022 (category Article 4(1) GDPR)
    were initiated, based on Article 63 and Article 64 LPACAP and an infringement of Article 6(1) GDPR typified in Article 83(5) GDPR. After the proceedings
    49 KB (7,832 words) - 10:54, 22 January 2024
  • UODO (Poland) - DKN.5130.2024.2020 (category Article 5(1)(f) GDPR)
    sec. 1 lit. a) and art. 58 sec. 2 lit. i) in connection with Art. 5 sec. 1 lit. f), art. 24 sec. 1, art. 25 sec. 1, art. 28 sec. 1 and 3 and article. 32
    75 KB (12,104 words) - 09:58, 17 November 2023
  • ICO (UK) - Cabinet Office (category Article 5(1)(f) GDPR)
    in the sum of £500,000. Breaches of GDPR Contravention of Article 5(1)(f) of the GDPR 47. Article 5(1)(f) of the GDPR has been contravened as the Cabinet
    79 KB (10,566 words) - 10:48, 7 December 2021
  • ArbG Düsseldorf - 9 Ca 6557/18 (category Article 6(1)(c) GDPR)
    Para. 1 Hs. 1 E. has expired due to fulfillment, § 362 Para. 1 BGB. The defendant answered the question in the letter dated November 27, 2018 ad 1. The
    58 KB (9,364 words) - 13:51, 16 December 2021
  • RVS - 202004314/1/A3 (category Article 4(1) GDPR)
    2016/679 (hereinafter: the GDPR). In view of Article 34 of the GDPR Implementation Act, this is a decision within the meaning of Article 1:3 of the General Administrative
    46 KB (7,313 words) - 11:27, 3 March 2022
  • UODO (Poland) - DOKE.561.1.2023 (category Article 58(1)(a) GDPR)
    information and granting it access to personal data in accordance with Article 58 (1)(a) and (e) GDPR. The data subject filed a complaint with the Polish DPA, claiming
    45 KB (7,312 words) - 21:50, 8 August 2023
  • EDPB - Binding Decision 2/2022 - 'Instagram' (category Article 5(1)(c) GDPR)
    the performance of a contract (Article 6(1)(b) GDPR) and for legitimate interest (Article 6(1)(f) GDPR). Article 6(1)(b) GDPR In its original draft decision
    276 KB (38,206 words) - 09:46, 20 January 2023
  • the data subject’s consent under Article 6(1)(a) GDPR but on compliance with legal obligations under Article 6(1)(c) GDPR and that the data subject did not
    39 KB (6,517 words) - 14:54, 17 March 2022
  • APD/GBA (Belgium) - 57/2023 (category Article 5(1) GDPR)
    violation of: 1. Article 5 (1) (a) and (2) and Article 6 (1) GDPR; 2. Article 5, Article 24 (1) and 25 (1) and (2) GDPR; 3. Article 12 paragraph 1, paragraph
    99 KB (15,129 words) - 09:21, 31 May 2023
  • Rb. Midden-Nederland - C/16/530061 / KG ZA 21-617 (category Article 6(1)(f) GDPR)
    concerns Article 9 AVG instead of Article 10 AVG and Article 9 AVG does not apply to criminal personal data (see legal ground 4.23 and MvT to Article 22 UAVG)
    38 KB (6,263 words) - 16:40, 15 June 2022
  • RvS - 202100165/1/A3 (category Article 17(3)(e) GDPR)
    the GDPR, a controller may first assess, in view of the system and the text of that Article, whether the exception in Article 17(3)(e) of the GDPR applies
    27 KB (4,241 words) - 11:28, 28 July 2022
  • Datatilsynet (Norway) - 20/01813 (category Article 5(1)(f) GDPR)
    personal data under Article 32 GDPR, Article 24, Article 5(1)(f) and Article 5(2), as well as § 26(1) of the Personal Data Act and §§ 22 and 23 of the Health
    36 KB (5,150 words) - 17:58, 31 October 2021
  • NAIH (Hungary) - NAIH-180-16/2022 (category Article 6(1) GDPR)
    grounds for processing under Article 6(1) GDPR. Finally, the NAIH held that the controller was in breach of Article 12(2) GDPR for mis-registering the data
    57 KB (9,033 words) - 16:35, 27 April 2022
  • AEPD (Spain) - PS-00446-2023 (category Article 6(1) GDPR)
    violates the principle of legality enshrined in article 6.1 of the RGPD, typified in article 83.5 a) of the GDPR. SAW In order to establish the administrative
    34 KB (5,141 words) - 09:28, 8 March 2024
  • ICO (UK) - HIV Scotland (category Article 5(1)(f) GDPR)
    under the GDPR. 14. By Article 57(1) of the GDPR, it is the Commissioner'task to monitor and enforce the application of the GDPR. 15. By Article 58(2)(d)of
    55 KB (6,916 words) - 07:27, 26 October 2021
  • Protection Regulation 11 Article 5, paragraph 2, letter b GDPR 12 Article 4, under 1 GDPR 13 Marginal number 76 in the summons
    52 KB (7,412 words) - 10:12, 2 June 2021
  • AEPD (Spain) - EXP202205932 (category Article 6(1) GDPR)
    basis under Article 6(1) GDPR. In light of this, the DPA issued a fine of €70,000 to másLUZ Energía (SIE) by virtue of Article 83(5) GDPR for unlawful
    32 KB (4,952 words) - 13:11, 13 December 2023
  • ICO (UK) - Tuckers Solicitors LLP (category Article 5(1)(f) GDPR)
    for by Article 51 of the GDPR. 17. By Article 57(1) of the GDPR, it is the Commissioner's task to monitor and enforce the application of the GDPR. 18. By
    87 KB (10,588 words) - 14:32, 16 March 2022
  • VG Gelsenkirchen - 20 K 6392/18 (category Article 12(5) GDPR)
    Art. 23 (1) lit. e) GDPR, to be contradicted. Because this standard does not meet the requirements of the optional opening clause of Art. 23 Para. 1 lit
    98 KB (16,595 words) - 15:50, 17 March 2022
  • APD/GBA (Belgium) - 165/2023 (category Article 5(1)(f) GDPR)
    violation of: 1. Article 5.1.f) and 5.2 of the GDPR, Article 24.1 of the GDPR, Article 25.1 of the GDPR and Articles 32.1 and 32.2 GDPR; 2. Articles 35.1, 35.2
    67 KB (9,908 words) - 11:09, 10 January 2024
  • OGH - 6Ob138/20t (category Article 23(1)(e) GDPR)
    permissible under Article 23 GDPR, or must the principle of chargeability remain inapplicable as a national law contrary to Article 23 GDPR? The Supreme Court
    43 KB (6,891 words) - 09:03, 24 February 2021
  • Persónuvernd (Island) - 2020061901 (category Article 5(1)(a) GDPR)
    of item 1. Paragraph 1 and paragraph 2 Article 8 and Article 9 Act no. 90/2018, cf. point a, paragraph 1 and paragraph 2 Article 5 and paragraph 1 Article
    96 KB (15,858 words) - 07:29, 12 July 2023
  • Commissioner (Cyprus) - 1.17.001.007.270 (category Article 5(1)(a) GDPR)
    rescission of X's membership, AAEA had violated Article 5(1)(a) GDPR, Article 6(1) GDPR and Article 9(1) GDPR. The Commissioner therefore decided to impose
    64 KB (10,097 words) - 08:07, 27 October 2021
  • AEPD (Spain) - PS/00261/2021 (category Article 6(1) GDPR)
    October 1, of the Common Administrative Procedure of the Public Administrations (in hereinafter, LPACAP), for the alleged violation of Article 6.1 of the
    34 KB (5,536 words) - 19:04, 16 May 2022
  • UODO (Poland) - DKN. 5131.27.2022 (category Article 33(1) GDPR)
    accordance with the law (Article 2 of the Act on land and mortgage registers and mortgage and Article 20 (1) point 1 and Article 24 section 2 of the Geodetic
    80 KB (13,127 words) - 07:57, 14 September 2022
  • Datatilsynet (Norway) - 18/02140 (category Article 5(1)(f) GDPR)
    technical and organisational measures required by Article 5(1)(f) and Article 32(1)(a) and Article 32(1)(b). This case got a lot of media attention in Norway
    54 KB (8,041 words) - 12:50, 26 January 2022
  • Datatilsynet (Norway) - 21/00872 (category Article 5(1)(a) GDPR)
    DPA held that the controller had violated Article 6(1) GDPR and Article 6(3) GDPR, thus also Article 5(1)(a) GDPR, for lack of legal basis for publishing
    27 KB (4,145 words) - 08:21, 27 June 2022
  • DVI (Latvia) - SIA "Fitsypro" (category Article 58(1)(b) GDPR)
    No. 1 and Request No. 2 the requested information, which was requested from SIA on the basis of Article 58, Clause 1 e) of GDPR and FPDAL Article 5, Part
    29 KB (4,404 words) - 07:53, 23 August 2023
  • RvS - 202100045/1/A3 (category Article 6(1)(f) GDPR)
    against Article 6(1)(f) of the GDPR. Now that this processing cannot be based on another legal basis as referred to in Article 6(1) of the GDPR, the AP
    29 KB (4,532 words) - 14:30, 17 August 2022
  • UODO (Poland) - DKN.5131.8.2022 (category Article 5(1)(f) GDPR)
    the laptop theft, in breach of Article 32(1) GDPR. Moreover, the DPA found a violation of Articles 24(1) and 25(1) GDPR because the controller failed to
    48 KB (7,609 words) - 12:24, 23 November 2022
  • failed to comply with Articles 5 (1)(f) and 32(1) and (2) of the UK GDPR. Article 5 (1)(f) and 32(1) and (2) of the UK GDPR 1546. The Commissioner finds that
    54 KB (7,579 words) - 16:44, 7 May 2024
  • ICO (UK) - Mermaids (category Article 5(1)(f) GDPR)
    approximately €29,250 on Mermaids for its violation of Article 5(1)(f), Article 32(1) and Article 32(2) of the GDPR. Share your comments here! Share blogs or news
    58 KB (7,695 words) - 09:00, 28 July 2021
  • LG Köln - 28 O 221/21 (category Article 6(1)(f) GDPR)
    to erasure under Article 17(1)(a), (c) or (d) GDPR, because the controller was processing the data lawfully under Article 6(1)(f) GDPR and the processing
    30 KB (4,765 words) - 14:30, 29 June 2022
  • Persónuvernd (Island) - Mál nr. 2022050993 (category Article 6(1)(c) GDPR)
    has been ensured, cf. 1., 2., 3. and 6. number. Paragraph 1 Article 8 of the Act and points a, b, c and f of paragraph 1. Article 5 of the regulation. The
    30 KB (4,852 words) - 08:56, 30 January 2024
  • AEPD (Spain) - EXP202104896 (category Article 9(2) GDPR)
    infringement of article 6.1 of the GDPR, in accordance with article 83.5.a) of the GDPR, and for the purposes of prescription in article 72.1.b) of the LOPDGDD
    103 KB (17,238 words) - 13:27, 3 April 2023
  • LAG Düsseldorf - 12 Sa 18/23 (category Article 82 GDPR)
    tried to base the processing on contract (Article 6(1)(b) GDPR) or legitimate interest (Article 6(1)(f) GDPR), the requirement of necessity was not met
    102 KB (17,108 words) - 09:44, 15 February 2024
  • AEPD (Spain) - PS/00499/2022 (category Article 5(1)(c) GDPR)
    infringement of article 5.1.c) of the GDPR, typified in article 83.5 of the GDPR, and for the alleged infringement of article 13, typified in article 83.5.b) of
    55 KB (8,912 words) - 13:18, 16 May 2023
  • APD/GBA (Belgium) - 01/2024 (category Article 5(1)(c) GDPR)
    infringement of Article 5.1.b), c) and e) GDPR and Article 5.1.a) j° Article 6.1 GDPR; - on the basis of Article 58.2.c) of the GDPR and Article 95, § 1, 5° of
    38 KB (5,767 words) - 16:10, 19 March 2024
  • AEPD (Spain) - PS/00375/2022 (category Article 5(1)(b) GDPR)
    in the article 57.1 and the powers granted in article 58.1 of the Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in
    55 KB (8,720 words) - 10:46, 18 January 2024
  • NAIH (Hungary) - NAIH-13-10/2022 (category Article 5(1)(a) GDPR)
    because he violated Article 6 (1) of the General Data Protection Regulation, Article 5 (1) points a) and b), Article 5 (2) and Article 15 (3). V.2. The Authority
    51 KB (8,202 words) - 14:49, 12 October 2022
  • OLG Koblenz - 5 U 2141/21 (category Article 82 GDPR)
    court further assessed the requirements of Article 82 GDPR in length. It established that the Article 82(1) GDPR requires the data subject to have suffered
    81 KB (13,639 words) - 18:14, 7 June 2022
  • Rb. Den Haag - C-09-608582-HA RK 21-101 (category Article 6(1)(f) GDPR)
    paragraphs 1 and 2 GDPR). In this context, Defam is the controller (Article 4(7) of the GDPR). Article 6(1) of the GDPR provides that processing of personal data
    31 KB (4,916 words) - 10:19, 25 January 2022
  • LSG Niedersachsen-Bremen - L 16 SF 5/21 DS (category Article 78(1) GDPR)
    supported by the structure of Article 78 GDPR, which is strictly intertwined with Article 77 GDPR. Indeed, Article 78(2) GDPR provides the data subject with
    34 KB (5,655 words) - 14:08, 16 May 2023
  • Datatilsynet (Denmark) - 2021-431-0126 (category Article 32(1) GDPR)
    AULA itself. 3.1. Article 32 of the Data Protection Regulation It follows from the data protection regulation article 32, subsection 1, that the data controller
    21 KB (3,154 words) - 08:44, 14 September 2022
  • Rb. Amsterdam - ECLI:NL:RBAMS:2023:6456 (category Article 17 GDPR)
    the data subject made an erasure request under Article 17 GDPR and an objection under Article 21 GDPR to have their negative registration no longer processed
    20 KB (3,126 words) - 09:13, 15 November 2023
  • Korkein hallinto-oikeus (Finland) - KHO:2023:56 (category Article 5(1)(c) GDPR)
    Regulation) Article 5, paragraph 1, subparagraph c, Article 25, Article 58, paragraph 2, subparagraph d, and Article 87, Section 29, subsection 1 of the Data
    45 KB (5,016 words) - 14:14, 21 March 2024
  • AEPD (Spain) - EXP202210101 (category Article 6(1) GDPR)
    in the article 57.1 and the powers granted in article 58.1 of the Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in
    85 KB (13,823 words) - 12:51, 3 April 2024
  • not incur major costs of implementation which under Article 32(2) GDPR makes a breach of 32(1) GDPR more likely. Despite the fact that not all data was
    79 KB (9,390 words) - 09:30, 27 November 2023
  • AEPD (Spain) - PS/00459/2020 (category Article 5 GDPR)
    prescription in article 72 of the LOPDGDD and both are typified in article 83.5 of the GDPR. In this regard, article 29.5 of Law 40/2015, of October 1, on the
    40 KB (6,380 words) - 08:15, 28 July 2021
  • LArbG Baden-Württemberg - 2 Sa 16/21 (category Article 12(1) GDPR)
    According to Article 12 (1) GDPR, a controller must only take "appropriate measures" so that the notification obligation pursuant to Article 15 GDPR is fulfilled
    49 KB (8,074 words) - 08:33, 6 October 2022
  • UODO (Poland) - DKN.5131.12.2020 (category Article 5(1)(f) GDPR)
    comply with the principles under Article 5 GDPR, including the principle of integrity and confidentiality (Article 5(1)(f) GDPR). According to this principle
    74 KB (11,896 words) - 15:14, 7 March 2023
  • NAIH (Hungary) - NAIH-2857-20/2021 (category Article 5(1) GDPR)
    processing in accordance with Article 5 (1) (a) of the Data Protection Regulation in accordance with Article 12 (1) and Article 13 of the General Data Protection
    79 KB (12,495 words) - 11:03, 21 January 2022
  • UODO (Poland) - DKN.5131.42.2022 (category Article 34(1) GDPR)
    interfering with court decisions. The DPA found a breach of Article 33 GDPR and Article 34(1) and (2) GDPR resulting in a fine of €2,324. Share your comments here
    95 KB (15,337 words) - 16:38, 19 March 2024
  • Datatilsynet (Norway) - 23/00708 (category Article 5(1)(f) GDPR)
    57(1)(h) GDPR, cf. Article 58(1)(a) GDPR, Article 58(1)(b) GDPR, Article 58(1)(e) GDPR and Article 58(1)(f) GDPR. The DPA conducted their inspection on 6 September
    59 KB (8,718 words) - 14:50, 20 December 2023
  • CPDP (Bulgaria) - PPN- 01-197/2022 (category Article 5(1)(a) GDPR)
    basis of Article 10, Paragraph 1 of the Law on the Protection of personal data (PLDPR) and Art. 57, §1, b. "e" of Regulation (EU) 2016/679 (GDPR), considering
    36 KB (5,922 words) - 08:02, 18 April 2024
  • Protection Act 2018 is contrary to Article 23 of the GDPR and Article 23 of the UK GDPR: [2021] EWCA Civ 800, [2021] 1 WLR 3611 ("the Main Judgment"). We
    53 KB (8,584 words) - 16:13, 14 December 2021
  • Rb. Gelderland - C/05/404505 / HA RK 22-99 (category Article 15(1) GDPR)
    applicability of Article 22 GDPR for this reason. The Court reiterated the importance of Article 13 GDPR, Article 14 GDPR and Article 15 GDPR. Since the controller
    35 KB (5,511 words) - 13:04, 16 November 2022
  • requested prior consultation under Article 36(1) GDPR from the Dutch DPA Autoriteit Persoonsgegevens ("AP"). Article 36(1) GDPR requires a data controller to
    21 KB (3,054 words) - 10:07, 10 September 2021
  • NAIH (Hungary) - NAIH-1743/2021 (category Article 5(1) GDPR)
    to as the GDPR) in accordance with Article 5 (1) (a), a The principle of purpose limitation under Article 5 (1) (b) of the GDPR and Article 5 (1) the principle
    47 KB (7,131 words) - 11:05, 21 January 2022
  • AEPD (Spain) - PS/00312/2023 (category Article 4(1) GDPR)
    principles of treatment included in article 5 of the RGPD. We will highlight article 5.1.c) of the GDPR which states that: "1. Personal data will be c) adequate
    55 KB (8,605 words) - 17:18, 30 August 2023
  • in the GDPR and the DPA. They are obliged by Article 5(2) to adhere to the data processing principles set out in Article 5(1) of the GDPR. Article 5(2) makes
    77 KB (9,347 words) - 07:39, 13 October 2022
  • AEPD (Spain) - EXP202213792 (category Article 5(1)(c) GDPR)
    finding likely violations of Article 5(1)(c), 8, 9, 13 and 35 GDPR. The AEPD found a likely violation of Article 35 GDPR. Article 35 GPDR requires that a data
    178 KB (27,656 words) - 12:28, 7 May 2024
  • AEPD (Spain) - EXP202213323 (category Article 5(1)(c) GDPR)
    authorities in the article 57.1 and the powers granted in article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in
    176 KB (27,432 words) - 16:20, 7 May 2024
  • DVI (Latvia) - SIA "TET" (category Article 5(1)(a) GDPR)
    violation of Article 5(1)(a), (b), (d) and (e) GDPR. Furthermore, there was no legal basis for these processing operations under Article 6(1) GDPR. The DPA
    114 KB (17,942 words) - 15:46, 2 November 2022
  • hereinafter referred to as [B] , authorized representative: mr. J. M. Eerkes. 1 , The procedure is 1.1. Earlier, in the court of judgment between the parties,
    19 KB (3,309 words) - 10:50, 23 April 2021
  • NAIH (Hungary) - NAIH-7058-5/2022 (category Article 6(1) GDPR)
    processing to be unlawful. The processing violated Article 7(2) GDPR, Article 7(4) GDPR and Article 6(1)(a) GDPR. The controller was fined 2,000,000 HUF (approx
    66 KB (10,499 words) - 08:55, 10 February 2023
  • DSB (Austria) - 2021-0.518.795 (category Article 5(1)(f) GDPR)
    Administrative offense (s) after: Article 5 (1) (a), Article 9 (1) and (2) in conjunction with Article 83 (1) and (5) (a) GDPR, OJ L 2016/119, 1 as amended L 2016/314
    29 KB (4,581 words) - 10:13, 10 March 2022
  • APDCAT (Catalonia) - PS 57/2023 (category Article 5(1)(f) GDPR)
    procedure against the controller on 3 October 2023 for violating Article 5(1)(f) GDPR. On 1 January 2024, the investigator for the Catalan DPA proposed a
    52 KB (7,751 words) - 14:16, 17 April 2024
  • DSB (Austria) - 2023-0.603.142 (category Article 33(1) GDPR)
    accordance with Article 31 of the GDPR, Article 31, due to the security breach , GDPR. According to Article 83 Paragraph 4 Letter a of the GDPR, these two provisions
    76 KB (12,550 words) - 09:24, 28 February 2024
  • APD/GBA (Belgium) - 158/2022 (category Article 6(1)(a) GDPR)
    request to data erasure (Article 95(1)(5) LCA). The DPA also issued a warning (pursuant to Article 95(1)(4) LCA and Article 58(2)(a) GDPR) for the controller
    42 KB (6,128 words) - 12:47, 16 November 2022
  • DSB (Austria) - DSB-D130.217 (category Article 5(1)(d) GDPR)
    as amended: Article 3, Article 4, Article 5, Article 17, Article 51, paragraph one, Article 57, paragraph one, letter f, as well as Article 77, paragraph
    77 KB (12,447 words) - 08:22, 4 April 2024
  • Rb. Den Haag - AWB - 20 4694 (category Article 5(1)(a) GDPR)
    share their location, in violation of Article 5 GDPR, Article 6 GDPR, Article 7 GDPR, Article 13 GDPR, and Article 25 GDPR. The DPA, however, claimed that the
    22 KB (3,313 words) - 16:18, 26 January 2022
  • defense briefs of 1 June 2022 (Information pursuant to Article 13 of the GDPR for collaborators; Information pursuant to Article 13 of the GDPR for employees;
    78 KB (12,604 words) - 09:01, 7 June 2023
  • place per Article 46(2) GDPR. For these violations, the DPA reprimanded the controller and ordered it to comply with the GDPR (specifically Article 46 GDPR)
    91 KB (15,011 words) - 09:00, 5 October 2022
  • Rb. Amsterdam - C/13/702712/HA RK 21-186 (category Article 17 GDPR)
    shortened. 1.2. Rabobank has argued against this. Assessment framework 1.3. The assessment framework in this case is Article 6(1)(f) of the GDPR: “Processing
    23 KB (3,407 words) - 08:00, 8 September 2021
  • AEPD (Spain) - PS/00413/2021 (category Article 5(1)(c) GDPR)
    of the principle of legitimation (article 6.1 of the GDPR) in the first case and the principle of consent (article 6.1 of the LOPD) in the second and that
    69 KB (11,301 words) - 10:49, 23 March 2023
  • IP (Slovenia) - 0612-23/2019/19 (category Article 24 GDPR)
    purposes and means of processing, it is actually a controller. Article 24 GDPR and Article 5(2) GDPR establish the principle of responsibility, which means that
    64 KB (10,160 words) - 13:24, 27 July 2022
  • Persónuvernd - 2020010428 (category Article 5(1)(f) GDPR)
    the organisation S.Á.Á for a security breach pursuant to Article 5(1)(f) and Article 32 GDPR. The security breach resulted in the disclosure of the names
    47 KB (7,369 words) - 16:37, 19 March 2020
  • TGI Paris - N° 14/07224 (category Article 5(1)(d) GDPR)
    offered and / or concluded after July 1, 2016, articles L.211-1, L.212-3, L.212-1, L.241-1, R.212-1 / 1 °, L .111-1, L.111-2, L.111-3, L.221-5, L.221-6,
    392 KB (67,730 words) - 15:27, 17 March 2022
  • AEPD (Spain) - PS/00080/2022 (category Article 5(1)(f) GDPR)
    under Article 5(1)(f) GDPR. Furthermore, the controller was responsible for implementing appropriate security measures according to Article 32(1)(b) GDPR
    47 KB (7,265 words) - 10:05, 21 July 2022
  • CNPD (Luxembourg) - Délibération n°16FR/2021 (category Article 5(1)(c) GDPR)
    obligation to inform the persons concerned 1. On the principles 27. Pursuant to paragraph 1 of Article 12 of the GDPR, the "controller take appropriate measures
    51 KB (7,338 words) - 11:33, 16 June 2021
  • UODO (Poland) - DKN.5131.29.2022 (category Article 28(1) GDPR)
    fulfill the requirements of Article 28 GDPR. The DPA concluded that the controller failed to comply with Article 28(1)(3) and (9) GDPR by not concluding a written
    48 KB (7,612 words) - 09:46, 25 April 2024
  • the regulation of the Guarantor n. 1/2000; RAPPORTEUR prof. Pasquale Stanzione; WHEREAS 1. Inspection of the company. 1.1. As part of a complex investigation
    235 KB (38,572 words) - 10:19, 20 July 2022
  • hereinafter referred to separately [defendant sub 1] and SIN-NL and jointly [defendants c.s.]. 1 The procedure 1.1. The course of the procedure is clear: -the
    24 KB (3,863 words) - 16:19, 10 March 2022
  • objections, page 2, Ad.A.1.). 4 See in particular Articles 5.1.a) and 12 of the GDPR, see also recital (39) of the GDPR. 5 See EDPS Endorsement 1/2018 decision of
    30 KB (4,164 words) - 11:12, 16 June 2021
  • BVwG - W258 2247028-1 (category Article 58(2) GDPR)
    based on the stated justification facts (§1 Abs.2 DSG, Article 6 paragraph 1 lit. a and alternatively lit. f GDPR) was unlawful.” As a reason, the relevant
    27 KB (4,012 words) - 14:36, 2 July 2022
  • Rb. Amsterdam - AWB - 20 1863 - AMS 20/1863 (category Article 15(1) GDPR)
    internal emails and messages regarding the data subject (Articles 12 and 15(1) GDPR). He also requested access to personal data which was processed by the controller's
    24 KB (3,724 words) - 09:21, 21 December 2022
  • APD/GBA (Belgium) - 141/2022 (category Article 17 GDPR)
    under Article 10 ECHR and Article 11 of the Charter. The DPA also added the GDPR provided an exception to its own, specifically Article 17(3)(a) GDPR, ⁣ which
    25 KB (3,628 words) - 16:09, 9 November 2022
  • GHDHA - 200.291.947/01 (category Article 6(1)(f) GDPR)
    deletion request, the Court examined Article 6(1)(f), Article 17, and Article 21 GDPR. The second sentence of Article 21(1) stipulates that the controller (the
    41 KB (6,941 words) - 10:56, 17 November 2021
  • Persónuvernd (Iceland) - 2020010355 (category Article 5(1)(f) GDPR)
    failed to comply with the provisions of Article 32(1)(b) GDPR, Article 32(1)(d) GDPR and Article 5(1)(f) GDPR. Furthermore, InfoMentor did not ensure sufficient
    44 KB (7,217 words) - 10:04, 12 May 2021
  • Datatilsynet (Norway) - 18/04147 (category Article 5(1)(a) GDPR)
    violating Article 5(1) GDPR, Article 17(1)(a), Article 17(1)(d) and Article 25(1), cf. Article 5(1)(c), Article 5(1)(d), Article 5(1)(e) and Article 5(1)(f)
    47 KB (7,575 words) - 11:35, 18 November 2023
  • APD/GBA (Belgium) - 162/2022 (category Article 5(1)(a) GDPR)
    (2) GDPR; b. a breach of Article 12(1) and (6) GDPR, Article 13(1) and (2) GDPR and Article 14(1) and (2) GDPR, Article 5(2) GDPR, Article 24(1) GDPR and
    71 KB (10,426 words) - 08:21, 23 November 2022
  • Rb. Midden-Nederland - C/16/542054 / KG ZA 22-341 (category Article 6(1)(f) GDPR)
    be checked against Article 6 (1) (f) GDPR in conjunction with Article 6 (4) GDPR. This means that the interests of [claimant under 1] and [claimant under
    32 KB (5,226 words) - 09:02, 25 August 2022
  • accountability (Article 5 (2) and 24 (1), (2) GDPR), privacy by design (Article 25 (1) GDPR) and as controller towards its data processors (Article 28 GDPR). Consequently
    144 KB (23,155 words) - 15:46, 6 December 2023
  • APD/GBA (Belgium) - 46/2022 (category Article 5(1)(a) GDPR)
    erasure (Article 17 of the GDPR), the right to restriction (Article 18 GDPR), as well as the right of opposition (Article 21 GDPR) 91. Article 17 of the
    86 KB (12,864 words) - 06:37, 23 February 2023
  • UODO (Poland) - DKN.5131.11.2020 (category Article 33(1) GDPR)
    the Foundation. The DPA held that the Foundation violated Article 33(1), Article 34(1) GDPR by failing to notify the DPA of a personal data protection
    51 KB (8,179 words) - 12:07, 11 August 2021
  • 38.1, 38.2 and 39.1. a) of the GDPR; - to issue an injunction against the company "Company A" to come into compliance with Article 38.1 of the GDPR, within
    57 KB (8,374 words) - 08:31, 16 June 2021
  • BVwG - W298 2269087-1 (category Article 83 GDPR)
    follows: Article 83 paragraph 1, 2 and 5 lit. a GDPR:Article 83, paragraph ,, 2 and 5 lit. a, GDPR: "Article 83 General conditions for imposing fines 1. Each
    52 KB (8,464 words) - 11:50, 26 July 2023
  • AEPD (Spain) - EXP202207521 (category Article 6(1) GDPR)
    claimed party, for violation of article 6.1 of the GDPR. SAW Classification of the infringement of article 6.1 of the GDPR C/ Jorge Juan, 6 www.aepd.es 28001
    54 KB (8,747 words) - 08:36, 30 August 2023
  • Datatilsynet (Norway) - 21/03656 (category Article 55(1) GDPR)
    pursuant to Article 56(1) GDPR. 6. Datatilsynet’s Assessment 6.1. Mowi’s Failure to Respond to the Complainant’s Access Request Under Article 12(3) GDPR, controllers
    63 KB (8,745 words) - 13:33, 27 April 2022
  • CNPD (Luxembourg) - Délibération n° 35FR/2021 (category Article 5(1)(c) GDPR)
    information obligation set out in Article 13 GDPR and in breach of the principle of data minimisation set out in Article 5(1)(c) GDPR. The CNPD carried out an audit
    81 KB (11,748 words) - 10:59, 17 November 2021
  • AEPD (Spain) - EXP202204836 (category Article 15 GDPR)
    violation of article 15 of the RGPD. V Classification of the violation of article 15 of the GDPR If confirmed, the aforementioned violation of article 15 of the
    52 KB (8,320 words) - 13:18, 14 February 2024
  • VwGH - Ro 2019/04/0229 (category Article 4(7) GDPR)
    As a result, the party involved had infringed Article 5(1)(a) and (c) and Article 6(1) DSGVO, Article 50b(1) of the Data Protection Act 2000 (DSG 2000) for
    59 KB (8,848 words) - 12:41, 16 September 2021
  • EDPB - Binding Decision 1/2020 - 'Twitter' (category Article 5(1)(f) GDPR)
    infringements of Article 5(1)(f), Article 24, and Article 32 GDPR, and to the objection of the IT SA on the possible infringement of Article 5(2) GDPR, the EDPB
    183 KB (30,819 words) - 09:50, 20 January 2023
  • NAIH (Hungary) - NAIH-5802-9/2022. (category Article 5(1)(a) GDPR)
    violated Article 14(1) and (2) GDPR. Because it failed to provide clear and transparent information, the controller also violated Article 12(1) GDPR. The DPA
    120 KB (19,907 words) - 10:48, 9 November 2022
  • APD/GBA (Belgium) - 35/2024 (category Article 4(1) GDPR)
    accordance with Article 5.1.a) j° Article 6.1 of the GDPR, any processing of personal data have a legal basis. Article 6.1 of the GDPR stipulates that
    27 KB (4,006 words) - 10:14, 17 March 2024
  • OLG Nürnberg - 4 U 347/21 (category Article 12(5) GDPR)
    copy under Article 15(3) GDPR, as interpreted by the CJEU in case C-487/21, is part of the right to access of data subjects under Article 15 GDPR, which is
    35 KB (5,672 words) - 08:48, 30 January 2024
  • under article 6 GDPR. However, the Court concluded that an immediate notification sent to the data subject was not necessary under article 34 GDPR. In particular
    34 KB (5,483 words) - 11:58, 5 December 2022
  • fairness and transparency under Article 5(1)(a) GDPR, as well as the data subject’s right to information under Articles 12 and 13 GDPR, and issued a fine of €10
    41 KB (6,671 words) - 16:56, 23 March 2022
  • Court of Appeal of Brussels - 2020/AR/582 (category Article 58(2)(a) GDPR)
    In accordance with article 92 WOG, the Disputes Chamber may be seized: 1 °by the frontline service, in accordance with Article 62, § 1, for the treatment
    26 KB (3,871 words) - 07:59, 24 August 2023
  • UODO (Poland) - DKN.5131.22.2021 (category Article 5(1)(f) GDPR)
    that the controller breached Article 5(1)(f), Article 24(1), Article 25(1), Article 32(1)(b) and (d), and Article 32(2) GDPR due to a lack of a reliably
    68 KB (10,909 words) - 14:47, 25 October 2021
  • UODO (Poland) - DKN.5131.31.2022 (category Article 5(1) GDPR)
    controller €5,400 for infringements of Articles 5(1)(f) and 5(2) GDPR as well as Article 25(1) and Article 32(1) GDPR. First, the controller did not ensure adequate
    71 KB (11,306 words) - 10:51, 22 January 2024
  • AEPD (Spain) - EXP202300944 (category Article 6(1) GDPR)
    the LPBCFT before the TGSS. III Article 6.1 of the GDPR According to article 6 of the GDPR “Legitimacy of processing: 1. Treatment will only be legal if
    76 KB (11,351 words) - 09:28, 24 April 2024
  • AEPD (Spain) - PS/00259/2020 (category Article 6(1)(f) GDPR)
    transactions associated with their products ”and is broken down into points 1.1.1, 1.1.2 and 1.1.3. In all of them appears as option "No". SECOND: In view of the
    158 KB (25,857 words) - 13:56, 14 July 2021
  • UODO (Poland) - DKN.5130.2215.2020 (category Article 5(1)(f) GDPR)
    sec. 1 lit. f), art. 24 sec. 1, art. 25 sec. 1, art. 28 sec. 1 and sec. 3, art. 32 sec. 1 and 2 and article. 34 sec. 1, as well as art. 83 sec. 1-3 and
    110 KB (17,650 words) - 12:27, 29 April 2022
  • AEPD (Spain) - PS/00261/2020 (category Article 5(1)(c) GDPR)
    terms established in the article 6.1.e) of Regulation (EU) 2016/679 " It should be remembered that article 6.1.e) of the RGPD states; 1. The treatment will
    54 KB (8,837 words) - 13:34, 16 June 2021
  • Rb. Rotterdam - ROT 21/3636 (category Article 12 GDPR)
    response to an earlier VT report on 1 February 2019. Both VT reports come from the Rotterdam police unit. 1.2. On March 23, 2020, the claimant requested Safe
    44 KB (7,375 words) - 13:24, 27 April 2022
  • DSB (Austria) - DSB 2023-0.404.421 (category Article 5(1)(a) GDPR)
    limitation of Article 5(1)(b) GDPR and against the provisions of Article 5(1)(a) GDPR and Article 6(1)(f) GDPR in conjunction with Article 6(4) GDPR. Further
    40 KB (6,348 words) - 09:05, 16 November 2023
  • NAIH (Hungary) - NAIH-5114-35/2022 (category Article 5(1)(e) GDPR)
    interest. Based on Article 2 (1) of the GDPR, the GDPR must be applied to the data management in this case. GDPR Article 4, point 1: "personal data": for
    146 KB (22,679 words) - 15:52, 3 May 2023
  • NAIH (Hungary) - NAIH-85-3/2022 (category Article 5(1)(a) GDPR) (section Fine and order to comply with GDPR)
    No Article 5 (1) (a) and (b), Article 6 (1), Article 6 (4) Article 12 (1), Article 13, Article 21 (1) and (2), Article 24 (1), Article 25 Article 1 (1)
    147 KB (23,028 words) - 13:36, 28 February 2023
  • Datatilsynet (Denmark) - 2021-31-5542 (category Article 6(1)(f) GDPR)
    legitimate interests under Article 14(2)(b) GDPR, and so get the possibility to exercise their right under Article 21(1) GDPR. Therefore, the DPA reprimanded
    43 KB (6,531 words) - 14:04, 21 September 2022
  • First-tier Tribunal - Clearview AI Inc. v ICO (category Article 3(2)(b) GDPR)
    of the GDPR. In fact the activities specified within that part of the GDPR are placed within the scope of UK GDPR by Article 2(1)(a) UK GDPR: 2(1). This
    99 KB (16,103 words) - 08:41, 25 October 2023
  • Rb. Noord-Nederland - 8187989 (category Article 82(1) GDPR)
    lawyer in Groningen. 1 The process sequence 1.1. By interlocutory order dated February 18, 2020, an oral hearing was set for the case. 1.2. Due to the court's
    46 KB (7,541 words) - 15:36, 29 November 2021
  • UODO (Poland) - DKN.5131.33.2021 (category Article 34(1) GDPR)
    the breach, pursuant to the obligation expressed in Article 34 GDPR, in conjunction with Article 12 GDPR. Based on this assessment, the DPA issued an administrative
    81 KB (13,351 words) - 14:48, 2 March 2022
  • UODO (Poland) - DKN.5112.5.2021 (category Article 5(1)(a) GDPR)
    accordance with Articles 5(1)(a) and 6(1) GDPR, and in the case of health data which constitute sensitive data, also Article 9(2) GDPR. The DPA analysed whether
    82 KB (13,363 words) - 14:11, 18 January 2023
  • OGH - 6Ob19/23x (category Article 15(1)(c) GDPR)
    meet the requirement of accuracy or comprehensibility of Article 12, paragraph 1, sentence 1 GDPR. [6]                                                  
    33 KB (4,912 words) - 13:56, 10 May 2023
  • IMY (Sweden) - IMY-2022-695 (category Article 9(1) GDPR)
    constituted special categories of data according to article 9(1) GDPR. According to Article 5(2) GDPR the data controller is responsible for implementing
    43 KB (5,076 words) - 09:32, 21 November 2023
  • CPDP (Bulgaria) - PNN-01-70/2022 (category Article 24(1) GDPR)
    carried out in compliance with the GDPR. Therefore, the DPA determined that the controller violated Article 24(1) GDPR by using this safety mechanism. The
    29 KB (4,826 words) - 14:14, 6 February 2023
  • infringement of Article 33(1) GDPR, a fine of €145,600 for infringement of Article 34(1) GDPR, and a fine of €316,800 for infringement of Article 5(1)(f) GDPR. In
    153 KB (24,570 words) - 15:11, 26 March 2024
  • regulation of the Guarantor n. 1/2000; RAPPORTEUR prof. Pasquale Stanzione; WHEREAS 1. The inspection activity towards the company. 1.1. As part of a control activity
    180 KB (29,599 words) - 13:51, 28 July 2021
  • APD/GBA (Belgium) - 07/2024 (category Article 5(1)(c) GDPR)
    those involved (Article 12.1, Article 13.1 and 13.2, Article 14.1 and 14.2, Article 5.2, Article 24.1, and Article 25.1 GDPR) 57 II.4.1. Position of the
    350 KB (51,369 words) - 09:25, 31 January 2024
  • CE - N° 444937 (category Article 28 GDPR)
    data from the existing national health data system (as per Article L. 1461-1). Article L. 3131-1 of the public health code stipulates that the Health Minister
    51 KB (7,830 words) - 09:50, 29 October 2020
  • Datainspektionen - DI-2018-9274 (category Article 5(1)(b) GDPR)
    pursuant to Article 6 (1) (f) (Article 13 (1) (c)), the company or third parties legitimate interests which make the treatment necessary (Article 13 (1) (d))
    96 KB (12,267 words) - 11:43, 7 April 2022
  • BVwG - W214 2225733-1 (category Article 5 GDPR)
    §74 B-VG Art133 Para.4 DSG §1 DSG §24 GDPR Art12 GDPR Art14 GDPR Art32 GDPR Art5 GDPR Art57 GDPR Art58 GDPR Art6 GDPR Art77 GDPR Art83 VwGVG §28 paragraph
    140 KB (23,138 words) - 15:13, 19 August 2022
  • NAIH (Hungary) - NAIH-2501-10/2022 (category Article 5(1)(a) GDPR)
    according to Article 5 (1) point a) of the Data Protection Regulation principle, the purpose-related principle according to Article 5 (1) point b), Article 12 (1)
    90 KB (14,299 words) - 13:52, 2 February 2023
  • violates Article 5(1), Article 6(1) and Article 12(1) GDPR. Therefore the DE-HH SA adopted, on 10 May 2021, provisional measures under Article 66(1) GDPR, based
    188 KB (31,298 words) - 12:31, 20 January 2023
  • AEPD (Spain) - PS/00016/2022 (category Article 15 GDPR)
    of article 15 of the GDPR. V Classification of the infringement of article 15 of the GDPR The aforementioned infringement of article 15 of the GDPR supposes
    62 KB (9,829 words) - 14:09, 14 March 2023
  • CE - 449209 (category Article 55(1) GDPR)
    personal data enshrined in Article 16 § 1 of the Treaty on the Functioning of the European Union? European Union and Article 8 §1 of the Charter of Fundamental
    36 KB (5,595 words) - 16:12, 2 February 2022
  • AEPD (Spain) - PS/00003/2021 (category Article 5(1)(c) GDPR)
    definition of Article 4(16) GDPR, and therefore declared its competency to act as the lead supervisory authority under Article 56(1) GDPR. The AEPD then
    115 KB (18,312 words) - 11:58, 16 March 2022
  • function creep.23 22Guidelines 05/2020, Version 1.1., Adopted on 4 May 2020, para. 46 and 48. 23 Ibid. para. 55. 12Article 5(1)(b) GDPR sets forth the
    77 KB (11,517 words) - 10:36, 22 October 2022
  • The Garante ascertained the violation of: 1. Violation of articles 5(1) and (2), 6(1), 7, 24 and 25(1) GDPR, since Fastweb has not proceeded to implement
    131 KB (21,014 words) - 15:55, 6 December 2023
  • APD/GBA (Belgium) - 77/2023 (category Article 5(1)(a) GDPR)
    storage (Article 5.1.b, 5.1.c, 5.1.d and 5.1.e of the GDPR); - Violation of the principle of legality (article 5.1.a of the GDPR); - Violation of Article 10
    150 KB (22,339 words) - 09:50, 21 June 2023
  • APD/GBA (Belgium) - 149/2022 (category Article 5(1)(b) GDPR)
    Violations of Article 5(1)(a) GDPR and Article 6(1) GDPR The DPA held that the controller did not violate Article 5(1)(a) GDPR and Article 6(1) GDPR. The DPA
    89 KB (13,017 words) - 15:07, 2 November 2022
  • AEPD (Spain) - PS/00140/2020 (category Article 6(1)(a) GDPR)
    according to Article 58(2)(d) GDPR. First, the AEPD established that the GDPR was applicable under Article 3(1) GPDR or, if not, at least Article 3(2)(a) GDPR
    390 KB (63,154 words) - 07:08, 9 June 2022
  • EU law provisions of Article 23(1) and (2) GDPR. The court first addresses the dispute as to whether Articles 15(3)(1), 12(5)(1) GDPR constitute an independent
    123 KB (20,784 words) - 10:11, 26 November 2021
  • AEPD (Spain) - PS/00030/2021 (category Article 28 GDPR)
    Annex 1. 6.1.2. The Data Controller has notified Vodafone of any change that Annex 1 is required to be made in accordance with this Clause 6. 6.1.3. The
    73 KB (11,933 words) - 09:33, 2 June 2021
  • BVwG - W214 2219800-3 (category Article 5(1)(c) GDPR)
    determinacy (Art. 18 B-VG), the GDPR framework legislation (Art. 5, 6, 9, 12 and 23 GDPR), the constitutional provision of § 1 para. 2 GDPR, Art. 7 and 8 CFR, Art
    83 KB (13,846 words) - 09:39, 10 September 2021
  • APD/GBA (Belgium) - 101/2022 (category Article 5(1)(f) GDPR)
    arising from Article 5.2 and Article 24 GDPR whereby it is up to the defendant to demonstrate that it also acts in accordance with Article 5.1.f GDPR namely:
    88 KB (13,264 words) - 09:09, 29 June 2022
  • there had been breaches of Article 5(1)(a) and (2), Article 13(1)(f) and Article 24 of the Regulation, as explained below. 2.1 Transfers of personal data
    47 KB (7,604 words) - 07:01, 20 July 2022
  • NAIH (Hungary) - NAIH-2727-2/2022. (category Article 5(1)(b) GDPR)
    the GDPR or General Article 5 (1) (a) and (b) of the Data Protection Regulation, - Article 5 (2) of the GDPR, - Article 6 (1) of the GDPR, - Article 12
    79 KB (12,461 words) - 16:08, 22 June 2022
  • basis of Article 6(1)(b) GDPR: “...there is a risk that the Draft Decision’s failure to establish Whatsapp IE's infringement of Article 6(1)(b) GDPR, pursuant
    289 KB (33,568 words) - 15:00, 1 February 2023
View (previous 500 | ) (20 | 50 | 100 | 250 | 500)