Search results

From GDPRhub
  • Article 8 GDPR (category GDPR Articles)
    the information society service(s)." According to Article 4(25) GDPR, which in turn refers to Article 1(1) of Directive (EU) 2015/1535, an "information
    19 KB (1,335 words) - 13:56, 24 October 2023
  • between Article 21(3) GDPR and Article 17 GDPR on the right to erasure must be considered. The tight relationship between Article 21(3) and Article 17(1)(c)
    49 KB (5,993 words) - 06:22, 16 June 2023
  • subject (Article 12(2) GDPR), respond and communicate the measures taken (Article 12(3) and (4) GDPR), the principle of freedom from costs (Article 12(5)
    61 KB (8,488 words) - 15:47, 18 March 2024
  • Article 5 GDPR (category GDPR Articles)
    consent under Article 6(4) GDPR and further processing for a compatible purpose under Article 6(4) GDPR. See the commentary on Article 6(4) GDPR for details
    51 KB (6,355 words) - 08:25, 18 April 2024
  • listed in Article 83(4), (5) and (6) GDPR. This specifically refers to violations of Articles 8, 11, 25 to 39, 41(4), 42, 43 of the GDPR (paragraph 4), Articles
    55 KB (7,622 words) - 14:04, 7 November 2023
  • Article 25 GDPR (category GDPR Articles)
    Protection Regulation (GDPR): A Commentary, Article 25 GDPR, p. 577 (Oxford University Press 2020). EDPB, 'Guidelines 4/2019 on Article 25 Data Protection by
    43 KB (4,675 words) - 06:43, 16 June 2023
  • Article 4 GDPR (category GDPR Articles) (section (4) Profiling)
    such as profiling (see also Article 4(4) GDPR); Restriction (marking for limited further processing, see also Article 4(3) GDPR), such as deactivation of
    125 KB (16,328 words) - 16:01, 8 March 2024
  • evaluating the effectiveness of security measures (Article 32(1)(d) GDPR). According to Article 4(5) GDPR, "pseudonymisation" means the processing of personal
    41 KB (5,197 words) - 12:17, 17 April 2024
  • categories of data established in Article 9(2)(a) GDPR, Article 9(2)(c) GDPR, Article 9(2)(g) GDPR and Article 9(2)(i) GDPR directly correlate with a specific
    44 KB (5,905 words) - 14:00, 24 October 2023
  • Article 28 GDPR (category GDPR Articles) (section (c) Measures required by Article 32 GDPR)
    mechanism referred to in Article 63 GDPR (Article 28(8) GDPR). The Commission has made use of its power under Article 28(7) GDPR and published standard contractual
    72 KB (9,140 words) - 13:12, 2 June 2023
  • Article 2 GDPR (category GDPR Articles) (section (4) Directive 2000/31/EC)
    further discussed, in Article 4(1) GDPR. Any information that relates to an identified or identifiable natural person falls under the GDPR, this also includes
    34 KB (4,652 words) - 12:07, 12 November 2023
  • reliance on Article 6(1)(f) GDPR or at least exercise the right to object under Article 21 GDPR. If the legal basis is Article 6(1)(f) GDPR (i.e. 'legitimate
    71 KB (9,532 words) - 13:30, 6 March 2024
  • (e.g. Article 25 (1) and (2), Article 28(1), Article 32(1) GDPR, Article 89(1) GDPR). These measures can also be regarded as measures under Article 24(1)
    30 KB (3,458 words) - 10:31, 25 April 2024
  • exercise on their behalf all rights foreseen under Articles 77 and 78 GDPR and Article 20 of L. 4624/2019. The mandate shall be given with a specific written
    23 KB (2,039 words) - 08:15, 25 April 2024
  • Article 49 GDPR (category GDPR Articles)
    adequacy decision pursuant to Article 45 GDPR shall be used, when it exists; second, appropriate safeguards under Article 46 GDPR, such as binding corporate
    29 KB (3,500 words) - 08:54, 27 March 2023
  • Article 35 GDPR (category GDPR Articles) (section (4)(5) Specifications through DPAs)
    freedoms of individuals", as stated in Article 35(1) and further elucidated in Article 35(3) and Article 35(4) GDPR. The WP29 developed a list of criteria
    52 KB (7,297 words) - 08:05, 18 July 2023
  • Article 94 GDPR (category Article 94 GDPR)
    under the GDPR. → You can find all related decisions in Category:Article 94 GDPR Kühling, Raab, in Kühling, Buchner, GVO BDSG, Article 94 GDPR, margin numbers
    13 KB (530 words) - 09:40, 3 October 2023
  • Article 97 GDPR (category Article 97 GDPR)
    recitals for Article 97 GDPR. Article 97 GDPR imposes a "comprehensive reporting obligation" upon the Commission. The first paragraph of Article 97 GDPR sets out
    16 KB (778 words) - 08:24, 19 October 2023
  • possible "legitimate interest" under Article 6(1)(f) GDPR. Equally to Article 6(1)(c) GDPR, Article 6(2) and (3) GDPR require that Union or Member State
    108 KB (17,005 words) - 15:39, 18 March 2024
  • Article 99 GDPR (category Article 99 GDPR)
    European Union. 2. It shall apply from 25 May 2018. There is no relevant recital for Article 99 GDPR. Article 99 GDPR sets out the dates of the Regulation's
    12 KB (295 words) - 08:25, 19 October 2023
  • a "filing system" within the meaning of Article 4(6) GDPR. See also Article 2(1) GDPR on the scope of the GDPR when it comes to non-automated filing systems
    73 KB (9,896 words) - 15:46, 18 March 2024
  • Regulation (GDPR), Article 91 GDPR, p. 1263 (Oxford University Press 2020). Tosoni, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article
    25 KB (2,482 words) - 10:04, 19 March 2024
  • Article 45 GDPR (category GDPR Articles) (section Article 45 and Schrems II)
    in Category:Article 45 GDPR Kuner, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 45 GDPR, p. 774 (Oxford
    43 KB (5,641 words) - 14:58, 28 April 2022
  • conduct under Article 83 GDPR should be excluded from penalties issued under Article 84 GDPR is debated. Whilst the wording of the GDPR is simply unclear
    19 KB (1,477 words) - 14:12, 7 November 2023
  • Article 72 GDPR (category Article 72 GDPR)
    dispute resolution under Article 65(3)(1) GDPR and for consistency decisions in the urgency procedure under Article 66(4) GDPR is necessary, as these are
    22 KB (2,266 words) - 08:26, 17 October 2023
  • Article 14 GDPR (category Article 14 GDPR) (section Relationship with Article 13 GDPR)
    with Article 13, Article 14 GDPR gives expression to the principle of transparency enshrined in Article 5(1)(a) GDPR and further defined in Article 12 GDPR
    47 KB (5,644 words) - 17:49, 5 March 2024
  • Article 12 GDPR (category GDPR Articles) (section (4) Failure to act on the request)
    are dealt with in Article 12(6) GDPR. It is unclear why Article 12(2) GDPR refers to Articles 15 to 22 GDPR, while Article 11(2) GDPR only refers to Articles
    76 KB (11,304 words) - 08:37, 4 March 2024
  • controller (as defined under Article 4(7) GDPR) and a processor (as defined under Article 4(8) GDPR). As noted above, Article 79 GDPR imposes a two-stage cumulative
    31 KB (3,550 words) - 11:11, 29 November 2023
  • Article 41 GDPR (category GDPR Articles) (section (4) Role of the monitoring body)
    clear from the wording of Article 41(1) GDPR. Article 41(1) GDPR does not define accreditation. Nonetheless, Article 41(2) GDPR provides a criterion against
    30 KB (2,720 words) - 14:02, 28 July 2023
  • access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), notification obligation
    44 KB (4,896 words) - 06:25, 16 June 2023
  • Article 88 GDPR (category Article 88 GDPR)
    opening clause under Article 88(1) GDPR, any rules introduced must meet the criteria imposed by Article 88(2) GDPR. Lastly, Article 88(3) GDPR imposes an obligation
    32 KB (3,228 words) - 13:32, 30 November 2023
  • Article 75 GDPR (category Article 75 GDPR) (section (4) Memorandum of Understanding)
    Protection Regulation (GDPR), Article 75 GDPR, p. 1105 (Oxford University Press 2020). Dix, in Kühling, Buchner, DS-GVO BDSG, Article 75 GDPR, margin number 6
    20 KB (1,347 words) - 14:21, 17 October 2023
  • access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction (Article 18 GDPR), notification (Article 19 GDPR) or data
    46 KB (5,825 words) - 11:12, 7 November 2023
  • Article 77 GDPR (category GDPR Articles)
    compliance with the GDPR under Article 58(2)(d) GDPR or even ban it under Article 58(2)(f) GDPR. Therefore, complaints under Article 77 GDPR should extend to
    33 KB (3,641 words) - 09:51, 19 March 2024
  • Article 52 GDPR (category GDPR Articles) (section (4) Sufficient resources)
    incompatible with the office. Article 52(4) GDPR and Article 52(6) GDPR establish the framework for SAs financial governance. Article 52(4) GDPR stipulates that SAs
    47 KB (5,594 words) - 22:45, 1 April 2024
  • Article 64 GDPR (category Article 64 GDPR) (section (4) Communication obligations)
    64(2) GDPR). The remaining paragraphs of Article 64(3)-(8) GDPR lay down substantive rules and a detailed procedure for the EDPB’s opinions. Article 64(1) GDPR
    23 KB (2,079 words) - 16:07, 2 November 2023
  • Article 51 GDPR (category GDPR Articles) (section (2) Consistent application of the GDPR)
    right to data protection. Article 51 GDPR is closely connected to Article 4(21) (definition of SA), Article 52 (independence), Article 53 (General conditions
    27 KB (2,604 words) - 14:24, 16 January 2024
  • Article 3 GDPR (category GDPR Articles) (section Opening clauses under the GDPR)
    in Category:Article 3 GDPR EDPB, ‘Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)’, 12 November 2019 (Version 2.1), p. 4 (available here)
    37 KB (4,635 words) - 13:29, 24 October 2023
  • Article 26 GDPR (category GDPR Articles)
    provisions such as Article 30(4) for the record of processing or Article 40(11) for the register of approved codes of conduct, Article 26 does not explicitly
    37 KB (3,915 words) - 12:49, 24 May 2023
  • difference between Article 42(1) GDPR and Article 42(2) GDPR is that in the former, the applicant for certification is subject to the GDPR, while in latter
    27 KB (2,452 words) - 14:26, 28 July 2023
  • of such processing (see Article 5(1)(b) GDPR), the requirement to have a legitimate basis laid down by law (see Article 6(1) GDPR), the right to access and
    48 KB (5,978 words) - 15:57, 1 February 2024
  • performance. Article 7 GDPR regulates the "conditions for consent". It specifies the definition of consent set out in Article 4(11) GDPR and, by integrating
    31 KB (3,489 words) - 16:00, 8 March 2024
  • Article 56 GDPR (category GDPR Articles) (section Without prejudice to Article 55 GDPR)
    GDPR are Article 4(7) GDPR (definition of controller), Article 4(8) GDPR (definition of processor), Article 4(16) GDPR (definition of main establishment)
    55 KB (7,446 words) - 22:28, 1 April 2024
  • Article 39 GDPR (category GDPR Articles)
    from any of the GDPR’s protections. → You can find all related decisions in Category:Article 39 GDPR Just as Article 38 GDPR, Article 39 GDPR also shows similarities
    23 KB (2,165 words) - 15:10, 27 July 2023
  • requirements. Although Article 40(5) GDPR mentions that the competent DPA will be determined through the application of Article 55 GDPR, the GDPR does not provide
    44 KB (5,008 words) - 14:50, 28 July 2023
  • Article 90 GDPR (category Article 90 GDPR)
    accordance with Article 58(1) GDPR. Article 90 GDPR was drafted with a view to regulate potential conflicts between the application of the GDPR on the one hand
    18 KB (1,599 words) - 12:26, 29 April 2022
  • Article 82 GDPR (category GDPR Articles) (section Infringement of the GDPR)
    meaning of Article 4(7) and (8) GDPR can be liable for compensation. A claim for damages first requires an infringement of the GDPR. Article 82 GDPR does not
    33 KB (4,215 words) - 09:57, 19 March 2024
  • relevance of Article 29 GDPR were rooted in the fact that Article 28(3)(b) GDPR already seems to cover much of the scope of Article 29 GDPR. More specifically
    13 KB (674 words) - 13:15, 2 June 2023
  • Article 54 GDPR (category GDPR Articles)
    provided for in Article 52(3) GDPR and Articles 53(3) and 53(4) GDPR. For more information on SA members and staff, please refer to Article 52(2) GDPR (SA members)
    34 KB (3,649 words) - 13:19, 30 October 2023
  • Article 31 GDPR (category GDPR Articles) (section Supporting provision to Article 58 GDPR)
    burdens. This reading of Article 31 GDPR is supported by the language of Article 83(4)(a) GDPR which categorises Article 31 GDPR as an 'obligation' of the
    22 KB (2,042 words) - 14:29, 20 November 2023
  • resolution mechanism under Article 65 GDPR in connection with Article 63 GDPR is triggered (Article 60 (4) GDPR). Article 60(2) GDPR clarifies that also in
    35 KB (4,017 words) - 16:04, 18 March 2024
  • Article 59 GDPR (category GDPR Articles)
    Marsch, DS-GVO/BDSG, Article 59 GDPR, margin numbers 4 and 5 (Nomos 2022). Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 59 GDPR, margin number 8 (Nomos
    15 KB (718 words) - 15:31, 19 October 2023
  • Article 20 GDPR (category GDPR Articles) (section (4) Rights of third parties)
    refusal to take action on a data subject’s request (Article 12(4)). The first sentence of Article 20(3) GDPR clarifies that the exercise of the right to data
    40 KB (5,349 words) - 07:05, 1 June 2023
  • Article 66 GDPR (category Article 66 GDPR) (section (4) Procedure)
    62(7) GDPR, the reference to the EDPB is mandatory. The authority addressed under Article 66(1)-(2) GDPR is the CSA within the meaning of Article 4(22) GDPR
    20 KB (1,590 words) - 16:11, 2 November 2023
  • Article 67 GDPR (category Article 67 GDPR)
    Category:Article 67 GDPR See EDPB, State of Play - IMI for GDPR purposes, 27 June 2018 (available here). See EDPB, 2019 Annual Report, Section 4.3.1 (available
    15 KB (810 words) - 16:13, 2 November 2023
  • Article 96 GDPR (category Article 96 GDPR)
    protected by Article 96 GDPR if it is found to be incompatible with other GDPR provisions. → You can find all related decisions in Category:Article 96 GDPR It follows
    13 KB (450 words) - 08:22, 19 October 2023
  • Article 19 GDPR (category GDPR Articles)
    disclosed to per Article 4(9) GDPR. Article 19 does not establish any specific time requirement for notification. However, since the purpose of Article 19 is to
    19 KB (1,436 words) - 12:35, 12 May 2023
  • Article 69 GDPR (category Article 69 GDPR)
    proposed amendments to the GDPR (pursuant to Article 70(1)(b) GDPR). Although not explicitly mentioned in Article 69(2) GDPR, the requirement that the Board
    18 KB (1,327 words) - 12:36, 14 December 2023
  • Article 87 GDPR (category Article 87 GDPR)
    process them. This was already the case under Article 8(7) of the DPD, the precursor of Article 87 GDPR. In many Member States, the processing of NIN and
    15 KB (660 words) - 09:37, 1 December 2023
  • Article 76 GDPR (category Article 76 GDPR)
    Article 76 GDPR, p. 1111-1112 (Oxford University Press 2020). Docksey, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 76 GDPR, p.
    15 KB (787 words) - 08:17, 19 October 2023
  • Regulation (GDPR): A Commentary, Article 38 GDPR, p. 707 (Oxford University Press 2020). Bergt, in Kühling, Buchner, DS-GVO BDSG, Article 38 GDPR, margin number
    29 KB (2,951 words) - 14:19, 25 July 2023
  • than 400,000 customers. Other notable GDPR fines include its £18.4 million fine against Marriott International and £1.25 million fine against Ticketmaster
    18 KB (2,488 words) - 15:22, 14 December 2021
  • Article 43 GDPR (category GDPR Articles)
    Recital 167 GDPR and Article 291 TFEU, the aim of implementing acts is to “ensure uniform conditions for implementing” the GDPR. In its GDPR Certification
    22 KB (1,634 words) - 14:40, 28 July 2023
  • Article 16 GDPR (category GDPR Articles)
    please refer to Article 19 GDPR. If the controller declines to rectify the data, they must provide reasons for their decision (Article 12(4) GDPR). The data
    23 KB (2,489 words) - 23:24, 6 March 2024
  • Article 68 GDPR (category Article 68 GDPR) (section (4) Joint representative)
    decisions pursuant to Article 65 GDPR (Article 70(1)(t) GDPR). Article 68 GDPR is the first of nine Articles (Articles 68-76 GDPR) governing the EDPB set
    20 KB (1,632 words) - 10:01, 11 October 2023
  • requirements of data minimization (Article 5(1)(c) GDPR) and storage limitation (Article 5(1)(e) GDPR). Under Article 30(1)(f) GDPR, where possible, the controller
    31 KB (3,327 words) - 15:31, 5 June 2023
  • with the GDPR (Article 31 GDPR). Direct liability of the representative is limited to the obligations set out in Article 30 and Article 58(1)(a) GDPR. Article
    25 KB (2,418 words) - 14:11, 24 May 2023
  • Article 95 GDPR (category Article 95 GDPR)
    situation, Article 95 GDPR will not be relevant, and the GDPR applies as normal. Notably, Recital 173 GDPR, which relates to Article 95 GDPR, omits reference
    20 KB (1,539 words) - 08:21, 19 October 2023
  • meaning Recital 86 GDPR). However, Article 34 GDPR does not provide a specific deadline of 72 hours as is the case in Article 33 GDPR. Instead, timelines
    37 KB (3,962 words) - 15:20, 16 June 2023
  • standards of clarity (Article 61(3) GDPR). Requests are imperative and, subject to specific exceptions (Article 61(4) and (5) GDPR), must be fulfilled and
    24 KB (2,181 words) - 11:46, 15 January 2024
  • objections pursuant to Article 92(5) GDPR. Article 92(5) GDPR imposes a further condition for the delegation of power, in line with Article 290(2)(b) TFEU. A
    19 KB (1,525 words) - 08:18, 19 October 2023
  • Article 98 GDPR (category Article 98 GDPR)
    accordance with Article 98'. → You can find all related decisions in Category:Article 98 GDPR The CJEU has yet to rule on Article 98 GDPR. Nonetheless, the
    15 KB (943 words) - 09:58, 8 November 2023
  • access (Article 15 GDPR), rectification (Article 16 GDPR), deletion (Article 17 GDPR), restriction of processing (Article 18 GDPR), objection (Article 21 GDPR)
    34 KB (3,646 words) - 08:53, 27 March 2023
  • Article 62 GDPR (category Article 62 GDPR) (section (4) Responsibility and liability)
    Member State in relation to damage referred to in Article 62(4) GDPR. According to Article 62(7) GDPR, if the lead SA does not invite the SA to take part
    22 KB (1,915 words) - 13:46, 15 January 2024
  • Article 74 GDPR (category Article 74 GDPR)
    decisions in Category:Article 74 GDPR For more on this point, see Article 72 GDPR. Dix in Kühling, Buchner, DS-GVO BDSG, Article 74 GDPR, margin number 7 (C
    15 KB (808 words) - 09:44, 17 October 2023
  • Article 10 GDPR (category GDPR Articles)
    from Article 6(1) GDPR and comply with the principles enshrined in Article 5 GDPR. Additionally, the processing will still be subject to other GDPR provisions
    17 KB (1,768 words) - 15:41, 18 March 2024
  • Article 70 GDPR (category Article 70 GDPR) (section (4) Consultation of interested parties)
    leeway exists only in cases of Article 64(2) GDPR but not the context of Article 70(2) GDPR. According to Article 70(3) GDPR, the EDPB is obligated to “forward
    27 KB (3,038 words) - 12:19, 11 October 2023
  • Article 48 GDPR (category GDPR Articles)
    subject to the GDPR or, in cases where they are not established in the EU, act within the material and territorial scope of the GDPR. Article 48 GDPR refers to
    14 KB (716 words) - 15:19, 28 April 2022
  • unlike delegated acts made under Article 92 GDPR. Article 93(2) GDPR explicitly provides for the application of Article 5 of Regulation (EU) No 182/2011
    17 KB (1,096 words) - 08:19, 19 October 2023
  • Article 71 GDPR (category Article 71 GDPR)
    practices published under Article 70(3) GDPR. Though Article 70(3) GDPR already obliges the EDPB to make these public, Article 71(2) GDPR ensures that the public
    15 KB (1,196 words) - 08:15, 19 October 2023
  • Article 73 GDPR (category Article 73 GDPR)
    simple majority principle under Article 72(1) GDPR would have applied regardless of Article 73(1) GDPR. In addition, the GDPR explicitly legislates for a simple
    19 KB (1,530 words) - 14:23, 12 October 2023
  • Article 63 GDPR (category Article 63 GDPR)
    to in Article 46(2)(d) GDPR, contractual clauses referred to in Article 46(3)(a) GDPR, or binding corporate rules within the meaning of Article 47 GDPR
    15 KB (851 words) - 06:55, 29 April 2022
  • Article 33 GDPR (category GDPR Articles) (section (4) Notification in phases)
    can carry out a notification in phases under Article 33(4) GDPR (see below). Under Article 33(3)(b) GDPR, the supervisory authority must be given the contact
    54 KB (6,536 words) - 08:22, 16 June 2023
  • on Article 36(4), it is still disputed whether the outcome of the procedure rather resembles that of Article 58(3)(a) GDPR or Article 58(3)(b) GDPR. See
    31 KB (3,646 words) - 08:51, 21 July 2023
  • Article 44 GDPR (category GDPR Articles)
    important to note that Article 13(1)(f) GDPR, Article 14(1)(f) GDPR, Article 15(1)(c) GDPR and Article 15(2) GDPR, make specific reference to transfers of personal
    21 KB (1,831 words) - 08:51, 27 March 2023
  • Article 50 GDPR (category GDPR Articles)
    exchange of knowledge between them. This way, Article 50 GDPR expands the exhortation under Article 57(1)(g) GDPR that calls for cooperation between EU DPAs
    17 KB (1,142 words) - 15:41, 28 April 2022
  • and interpretation as in Article 22(3) GDPR. → You can find all related decisions in Category:Article 22 GDPR Article 20 of GDPR proposal, COM(2012) 11 final
    31 KB (4,768 words) - 06:24, 16 June 2023
  • organisation-fined-for-gdpr-rule-breach-1.4255692?mode=amp https://www.irishlegal.com/article/tusla-fined-40-000-in-second-gdpr-breach https://www.dataprotection
    8 KB (1,034 words) - 14:13, 20 August 2021
  • Article 53 GDPR (category GDPR Articles) (section (4) Dismissal of SA members)
    Regulation (GDPR): A Commentary, Article 53 GDPR, p. 888 (Oxford University Press 2020). Boehm, in Kühling, Buchner, DS-GVO BDSG, Article 54 GDPR, margin numbers
    29 KB (2,894 words) - 23:06, 1 April 2024
  • Category:Article 11 GDPR Georgieva, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 11 GDPR, p. 395
    20 KB (1,854 words) - 16:32, 8 March 2024
  • Article 47 GDPR (category GDPR Articles)
    other DPAs concerned. The BCR Lead the submits, following Article 64(1) GDPR and Article 64(4) GDPR, a draft decision to the EDPB. The EDPB, in turn, issues
    29 KB (2,823 words) - 15:15, 28 April 2022
  • Article 80 GDPR (category GDPR Articles) (section Requirements under Article 80(1) GDPR)
    complaint under Article 77(1) GDPR on behalf of the data subject and to represent the them before all supervisory authorities (“SA”) (Article 4(21) GDPR). Secondly
    26 KB (2,575 words) - 15:50, 9 November 2023
  • lead SA (“LSA”) (Article 65(1)(b) GDPR), and where a SA is not following an opinion of the EDPB (Article 6(1)(c) GDPR). Article 65(1)(a) GDPR addresses the
    33 KB (4,185 words) - 16:09, 2 November 2023
  • or infringes the GDPR or any other applicable laws, including national ones. See commentary under Article 77 GDPR. Article 78(1) GDPR establishes both
    30 KB (3,874 words) - 10:46, 7 December 2023
  • that purpose. Article 89(4) GDPR makes it clear that the derogations to the GDPR are only available for processing specified in Article 89 GDPR, and not for
    29 KB (3,695 words) - 13:44, 21 March 2024
  • and (3) GDPR), inform him or her about the measures taken (Article 12(3) and (4) GDPR), the right to receive this service free of charge (Article 12(5) GDPR)
    32 KB (3,730 words) - 08:43, 7 March 2024
  • Article 55 GDPR (category GDPR Articles)
    which would be competent under Article 55(1) GDPR, as provided in Article 56 GDPR in connection with Article 60 GDPR. For more information see commentary
    35 KB (3,971 words) - 21:34, 1 April 2024
  • Article 86 GDPR (category Article 86 GDPR) (section The GDPR remains applicable)
    Press 2020). Spiecker et al., GDPR Article-by-Article Commentary (2023), p 1090. Spiecker et al., GDPR Article-by-Article Commentary (2023), p 1090. CJEU
    22 KB (2,177 words) - 10:01, 19 March 2024
  • categories of data under Article 9 GDPR or data relating to criminal convictions and offences under Article 10 GDPR. Article 37(2) GDPR allows for the designation
    43 KB (4,904 words) - 12:59, 21 July 2023
  • commentary to Article 60 GDPR, Article 61 GDPR, Article 62 GDPR, Article 63 GDPR, Article 64 GDPR, Article 65 GDPR, Article 66 GDPR and Article 56 GDPR. The SA
    60 KB (7,796 words) - 20:12, 1 April 2024
  • Article 1 GDPR (category GDPR Articles)
    about the scope of the term 'personal data' under Article 4(1) GDPR. Non-EU citizens can rely on the GDPR as its application is generally independent of nationality
    28 KB (3,831 words) - 16:21, 14 March 2024
  • Article 81 GDPR (category GDPR Articles) (section Scope of Article 81 GDPR)
    explicit wording of Article 81 GDPR does not limit its application to proceedings instigated either under Article 78 GDPR or Article 79 GDPR. Secondly, the
    27 KB (2,619 words) - 14:52, 16 November 2023
  • into force of the GDPR. Spiecker et al., GDPR Article-by-Article Commentary (2023), p 1073. Spiecker et al., GDPR Article-by-Article Commentary (2023)
    33 KB (3,748 words) - 14:25, 7 November 2023
  • Spain the GDPR is developed by the Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD). Article 7.2 LOPDGDD
    15 KB (1,875 words) - 16:18, 13 July 2022
  • IMY (Sweden) - DI-2020-11397 (category Article 44 GDPR)
    of penalty fee Page 24 of 25 The Swedish Privacy Agency Diary number: DI-2020-11397 25(25) Date: 2023-06-30 4 Appeal reference 4.1 How to Appeal If you want
    121 KB (13,722 words) - 15:16, 5 July 2023
  • CNIL (France) - SAN-2020-012 (category Article 4(7) GDPR)
    the fine, the criteria specified in the same article 83. 111. Article 83 of the GDPR, as referred to in Article 20, paragraph III, of the Data Protection
    93 KB (14,936 words) - 17:09, 6 December 2023
  • Infringement of Article 6 and 9 GDPR qualifies for the maximum amount for administrative fines as set out in Article 83(5) GDPR: 20,000,000 € or 4% of the total
    18 KB (2,375 words) - 16:17, 6 December 2023
  • necessary. For the intentional infringement of Article 25(1) GDPR and Article 5(1)(a), (c), and (e) GDPR, the authority imposed a pecuniary penalty of €14
    7 KB (936 words) - 16:39, 12 December 2023
  • obligation of the controller (Article 6 (1) (c)) or to perform a public interest task or exercise public authority paragraph (e)). Article 6 (3) of the Data Protection
    41 KB (6,555 words) - 08:37, 4 March 2024
  • monitor the functioning of decisions adopted on the basis of Article 25(6) or Article 26(4) of Directive 95/46/EC. In its adequacy decisions, the Commission
    182 KB (24,065 words) - 13:40, 9 July 2021
  • HDPA (Greece) - 20/2023 (category Article 12(4) GDPR)
    registered letter in violation of article 15 (1) cond. 12 par. 2, 3 and 4 GDPR and c) 30,000 euros for violation of Article 25 (1) GDPR because it did not in practice
    6 KB (634 words) - 17:48, 17 July 2023
  • APD/GBA (Belgium) - 53/2020 (category Article 25(1) GDPR)
    compatible by virtue of a legal provision (see Article 6.4. of the RGPD). Based on the criteria in section 6.4 of the EDR: there is no link between the two
    35 KB (5,853 words) - 16:58, 12 December 2023
  • BVwG - W258 2217446-1 (category Article 4(1) GDPR)
    personal data under Article 9(1) GDPR. Their processing would require the data subjects' explicit consent under Article 9(2)(a) GDPR and § 151(4) GewO, ordered
    79 KB (12,652 words) - 09:41, 10 September 2021
  • administrative fine for the infringement of Article 6(1) or Article 6(1)(b) GDPR meet the requirements of Article 4(24) GDPR. 504. The EDPB decides that the relevant
    53 KB (8,413 words) - 14:10, 30 January 2023
  • AEPD (Spain) - PS/00240/2019 (category Article 5(1)(b) GDPR)
    Therefore, given that Article 6(1), Article 5(1)(a), Article 5(1)(d), Article 5(1)(c), and Article 14 GDPR were infringed in connection to Article 5(1)(b), the
    602 KB (102,229 words) - 14:21, 13 December 2023
  • OLG Schleswig - 17 U 15/21 (category Article 6(1)(e) GDPR) (section Article 6(1)(e) GDPR)
    defendant within the meaning of Article 4 of the GDPR. The defendant is therefore a controller within the meaning of Art. 4 No. 7 GDPR. b. 44 The Senate is convinced
    51 KB (8,215 words) - 09:55, 13 May 2022
  • the inspected with section 4 of chapter 4 of the GDPR. 3. […] the inspectorate [is active in the field of transport] […]. 4. The controlled has approximately
    66 KB (9,458 words) - 19:42, 4 September 2021
  • IMY (Sweden) - DI-2020-11370 (category Article 44 GDPR)
    of Chapter V GDPR. The complaint was transferred to the Swedish DPA in its quality of lead supervisory authority pursuant to Article 56 GDPR. Following the
    131 KB (14,752 words) - 08:36, 5 July 2023
  • VK Baden-Württemberg - 1 VK 23/22 (category Article 44 GDPR)
    within the meaning of Article 4 no. 2 of the GDPR and the term "transfer" within the meaning of Article 44 et seq. of the GDPR. GDPR had to be differentiated
    62 KB (10,113 words) - 12:48, 17 August 2022
  • the controller had violated Article 5(1)(a) GDPR, Article 12 GDPR, Article 13 GDPR, Article 15 GDPR and Article 25(1) GDPR. As a result, the DPA issued
    52 KB (7,936 words) - 22:32, 2 March 2024
  • Rb. Rotterdam - C/10/576074/HA RK 19-694 (category Article 15(3) GDPR)
    assessment framework 4.4. The right of access previously laid down in Article 12 of the Privacy Directive 95/46 has now been included in Article 15 of the AVG
    15 KB (2,504 words) - 16:27, 10 March 2022
  • according to Article 9(2)(a) GDPR. On the basis of the information gathered, the DPA held that the controller had violated Article 9 GDPR. As a result
    49 KB (7,496 words) - 14:44, 24 January 2024
  • DSB (Austria) - 2021-0.586.257 (category Article 4(1) GDPR)
    website controller qualifies as controller (Article 4(7) GDPR) and Google LLC as processor (Article 4(8) GDPR) for data processing in connection with Google
    108 KB (17,097 words) - 13:52, 12 May 2023
  • AEPD (Spain) - EXP202206735 (category Article 6 GDPR)
    according to article 4.1 of the GDPR, is data personnel and their protection, therefore, is the subject of said Regulation. In article 4.2 of the GDPR defines
    75 KB (12,421 words) - 13:23, 13 December 2023
  • BVwG - W211 2210458-1/10 (category Article 4(7) GDPR)
    para. 1 of the GDPR. To 2): c) Article 50b (2) DSG 2000 (for the period prior to 25 May 2018) (d) Article 13(3) DSG (for the period from 25 May 2018) To
    92 KB (15,435 words) - 16:00, 22 March 2022
  • the GDPR. In light of this, the Court agreed with the DPA that the controller had violated Article 5(1)(a) GDPR, Article 12 GDPR, Article 13 GDPR, Article
    22 KB (3,193 words) - 10:34, 29 February 2024
  • of data protection required under Article 25 GDPR, in particular in view of the obligation arising from Article 25 GDPR to implement appropriate technical
    429 KB (58,279 words) - 09:12, 2 November 2022
  • UODO (Poland) - ZSPR.421.2.2019 (category Article 25(1) GDPR)
    (f), Article 5(2), Article 6(1), Article 7(1), Article 24(1), Article 25(1), Article 32(1)(b), Article 32(1)(c) and Article 32(1)(b), Article 32(1)(c) and
    71 KB (11,304 words) - 10:01, 17 November 2023
  • violated Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, Article 9 GDPR and Article 25(2) GDPR. As a result, and in accordance with Article 58(2)(d) GDPR, the
    60 KB (9,117 words) - 14:46, 24 January 2024
  • LG Köln - 33 O 376/22 (category Article 6(1)(b) GDPR)
    protection within the meaning of Article 45 of the GDPR and without appropriate safeguards within the meaning of Article 46 of the GDPR. Furthermore, the plaintiff
    66 KB (9,990 words) - 12:30, 29 January 2024
  • CJEU - C-77/21 - Digi (category Article 6(4) GDPR)
    regarding Articles 5(1)(b) GDPR and 5(1)(e) GDPR and held that national courts had to determine, using the factors of Article 6(4) GDPR, whether further processing
    49 KB (7,800 words) - 09:22, 5 January 2024
  • Vodafone S.p.A in violation of the following GDPR provisions: Article 5(1) and Article 5(2) and Article 25(1): for failing to implement control systems
    7 KB (810 words) - 15:52, 6 December 2023
  • HDPA (Greece) - 26/2023 (category Article 15 GDPR)
    under Article 15 GDPR." The DPA rejected the request for review. Genealogical research on a family surname did not fall within the scope of Article 15 GDPR
    14 KB (2,181 words) - 11:27, 13 September 2023
  • fairness of processing (Article 5(1)(a) GDPR), data minimisation (Article 5(1)(c) GDPR), and data protection by default (Article 25(2) GDPR). The DPA suggested
    73 KB (11,237 words) - 05:34, 21 July 2022
  • VGH Baden-Württemberg - 1 S 397/19 (category Article 5(1)(d) GDPR)
    force: "According to Article 16 sentence 1 GDPR, every data subject has the right to request the controller (see Article 4(7) GDPR) to correct incorrect
    112 KB (19,310 words) - 08:08, 23 June 2022
  • this from happening, in violation with Article 24(1), Article 24(2), and Article 25(1) GDPR. According to Article 24(4) of the Finish Data Protection Act,
    42 KB (6,579 words) - 08:46, 27 January 2022
  • Court of Appeal of Brussels - 2019/AR/1600 (category Article 5(1)(c) GDPR)
    violation of Article 6(1) GDPR; 2. Did not provide the complainant with enough information prior to the processing, in violation of Article 13 GDPR; 3. Processed
    60 KB (9,144 words) - 16:17, 22 March 2022
  • HDPA (Greece) - 28/2023 (category Article 58(2) GDPR)
    council in Greece to cease their processing activities, under Article 58(2) GDPR and Article 15(8) of Law 4624/2019, because of an unresolved data breach
    9 KB (1,211 words) - 20:32, 8 January 2024
  • GDPR, Article 9 GDPR, Article 10 GDPR, Article 30 GDPR and Article 34 GDPR, as well as the provision of the PDPA governing processing of personal data
    10 KB (1,440 words) - 08:54, 17 January 2020
  • Protection Act 2019 sets exceptions in Article 9(1) GDPR, Article 15 GDPR, Article 16 GDPR, Article 18 GDPR and Article 21 GDPR for scientific or historical research
    10 KB (1,037 words) - 14:52, 10 July 2020
  • on final judgments did not comply with Article 25(1) GDPR. Pursuant to Article 58(2)(b) and Article 58(2)(d) GDPR, the DPA reprimanded the controller for
    43 KB (6,671 words) - 08:49, 27 January 2022
  • on final judgments did not comply with Article 25(1) GDPR. Pursuant to Article 58(2)(b) and Article 58(2)(d) GDPR, the DPA reprimanded the controller for
    43 KB (6,677 words) - 08:47, 27 January 2022
  • particular, § 25 TTDSG defines privacy protections for terminal equipment and is to be understood as an implementation of Article 5(3) ePD. § 25(1) TTDSG mandates
    18 KB (1,831 words) - 13:49, 3 November 2022
  • AEPD (Spain) - EXP202100764 (category Article 83(4) GDPR)
    ends and means of such activity, by virtue of article 4.7 of the GDPR. Article 4 section 12 of the GDPR broadly defines “violations of security of personal
    34 KB (5,184 words) - 13:22, 13 December 2023
  • AEPD (Spain) - EXP202201721 (category Article 83(4)(a) GDPR)
    violated Article 6 and Article 32 GDPR. The DPA seems to consider the authentication procedure itself as "processing" and therefore Article 32 GDPR applies
    79 KB (12,408 words) - 13:24, 13 December 2023
  • Pursuant to Article 83 GDPR in conjunction with Article 4 No. 7 and 8 GDPR, fines for violations of the GDPR pursuant to Article 83(4) to (6) GDPR are not
    36 KB (5,810 words) - 13:09, 21 January 2022
  • APD/GBA (Belgium) - 81/2020 (category Article 5(1)(c) GDPR)
    they are processed (article 5.1 e) of the GDPR). 8.1.4. As for breaches of Articles 5.2. and 24 of the GDPR 88. Article 24.1 of the GDPR which covers Chapter
    127 KB (21,484 words) - 17:01, 12 December 2023
  • Court of Appeal of Brussels - 2022/AR/549 (category Article 17(3)(e) GDPR)
    lawfulness, the Litigation Chamber concludes that Article 5.1.a. of the GDPR in conjunction with Article 6 of the GDPR have not been complied with with regard to
    37 KB (5,765 words) - 09:53, 14 December 2023
  • Datatilsynet (Denmark) - 2018-32-0357 (category Article 4(11) GDPR) (section 4. Legal basis)
    the data subject's consent in Article 4(11), and the basic principle of legality, reasonableness and transparency in Article 5(1)(a). Furthermore, Datatilsynet
    65 KB (9,767 words) - 16:22, 6 December 2023
  • CNIL (France) - SAN-2019-005 (category Article 5(1)(e) GDPR)
    violates Article 32 GDPR. Retaining personal data of an applicant for a lease after another applicant has been selected also violates Article 5(1)(e) GDPR
    41 KB (6,558 words) - 17:09, 6 December 2023
  • HDPA (Greece) - 37/2020 (category Article 4(7) GDPR)
    in-depth discussion HE THOUGHT ACCORDING TO THE LAW. 1. According to the article. That’s 4 bets.7 of General Regulation (EU) 2016/679 on the protection of individuals
    14 KB (2,127 words) - 15:37, 6 December 2023
  • HDPA (Greece) - 38/2020 (category Article 4(7) GDPR)
    address from my list of recipients, in accordance with the provisions of Article 18 GDPR. 4) He proceeded to remove the recipient’s e-mail address from the list
    14 KB (2,070 words) - 15:38, 6 December 2023
  • AP (The Netherlands) - 26.11.2020 (category Article 32(1) GDPR)
    that the letter in question referred to Article 58(1)(a) of the GDPR and Article 5:16 in conjunction with Article 5:17 of the Awb does not make this any
    67 KB (11,415 words) - 17:15, 12 December 2023
  • AEPD (Spain) - EXP202201746 (category Article 83(4) GDPR)
    infringement of Article 32 GDPR. Therefore, the Spanish DPA issued a warning sanction for each violation of Article 5(1)(f) and Article 32 GDPR. AEPD highlighted
    62 KB (9,703 words) - 13:05, 13 December 2023
  • violated Article 5(1)(e) GDPR and Article 25(2) GDPR. As a result, the DPA issued a reprimand to the controller in accordance with Article 58(2)(b) GDPR. Pursuant
    77 KB (12,352 words) - 07:20, 23 April 2024
  • LG Köln - 28 O 138/22 (category Article 82 GDPR)
    and Art. 25 GDPR. In addition, the defendant also violated the principles of "Privacy by Design" and "Privacy by Default" laid down in Art. 25 GDPR, since
    39 KB (6,362 words) - 14:01, 22 June 2023
  • CNIL (France) - SAN-2020-009 (category Article 5(1)(a) GDPR)
    and 13 GDPR? Is the information provided to data subjects throughout the subscription process in compliance with the provisions of Article 13 GDPR? Does
    48 KB (7,404 words) - 17:09, 6 December 2023
  • AEPD (Spain) - PS/00001/2021 (category Article 5(1)(f) GDPR)
    enshrined in Article 25 GDPR. Additionally, the AEPD concluded that the controller had violated Article 5(1)(f) GDPR, noting that although the GDPR does not
    270 KB (43,335 words) - 12:39, 13 December 2023
  • AEPD (Spain) - E/10529/2021 (category Article 45 GDPR)
    that the controller had not violated Article 45 GDPR nor any of the subsequent Articles from Chapter V of the GDPR. The AEPD took into account that the
    44 KB (6,642 words) - 10:34, 13 December 2023
  • AEPD (Spain) - EXP202105680 (category Article 9 GDPR)
    very serious in article 72.1. e) from the LOPDGDD, with 10,000 euros. -article 13 of the GDPR, in accordance with article 83.5 b) of the GDPR, and for the
    66 KB (10,558 words) - 13:14, 13 December 2023
  • APD/GBA (Belgium) - 149/2023 (category Article 5(1)(a) GDPR)
    meaning of article 4.19 of the GDPR – (article 13.1. c) of the GDPR) and does not mention the data retention periods personal data processed (article 13.2.
    113 KB (17,325 words) - 08:50, 19 March 2024
  • AEPD (Spain) - EXP202205353 (category Article 5(1)(f) GDPR)
    the alleged violation of article 5.1.f) of the GDPR and article 32 of the GDPR, typified in article 83.5 and 83.4 of the GDPR. The initiation agreement
    22 KB (3,386 words) - 16:05, 13 December 2023
  • AEPD (Spain) - EXP202210525 (category Article 6(1) GDPR)
    according to article 4.1 of the GDPR, is data personnel and their protection, therefore, is the subject of said Regulation. In article 4.2 of the GDPR defines
    22 KB (3,427 words) - 13:26, 13 December 2023
  • OVG Sachsen-Anhalt - 1 M 49/23 (category Article 53(1) GDPR)
    this regulation in accordance with Article 57 (1) (a) GDPR and which has the powers in accordance with Article 58 GDPR. For this reason alone, there was
    14 KB (1,999 words) - 14:20, 18 July 2023
  • CNIL (France) - SAN-2022-025 (category Article 4(11) GDPR)
    none of the exceptions in Article 82 of the Data Protection Act were applicable, and Apple had to obtain consent (Article 4(11) GDPR) before using the identifiers
    82 KB (13,463 words) - 17:03, 6 December 2023
  • AEPD (Spain) - EXP202105344 (category Article 6(1) GDPR)
    with article 4.1 of the RGPD, is a personal data. nal and its protection, therefore, is the subject of said regulation. In article 4.2 of the GDPR defines
    22 KB (3,319 words) - 13:00, 13 December 2023
  • the GDPR sees in Individual provisions stipulate a risk-based approach (e.g. Art. 24 Para. 1 and Para. 2, Art. Article 25(1), Article 30(5), Article 32(1)
    158 KB (26,392 words) - 08:25, 7 June 2023
  • HDPA (Greece) - 4/2022 (category Article 25(1) GDPR)
    under Article 35(7) GDPR, for not complying with the principle of transparency under Article 5(1) GDPR and for not anonymising the data under Article 25(1)
    11 KB (1,274 words) - 10:37, 23 February 2022
  • APD/GBA (Belgium) - 31/2020 (category Article 5(1)(c) GDPR)
    this case under Article 6(1)(a) or 6(1)(c)? If Article 6(1)(a) applies, do the requirements for parental consent under Article 8 GDPR also apply? Did the
    48 KB (7,926 words) - 16:56, 12 December 2023
  • AP (The Netherlands) - 25.11.2021 (category Article 5(1)(a) GDPR)
    fairness principle, violating Article 5(1)(a) in conjunction with Article 6(1)(e) GDPR, and Article 6 in conjunction with Article 8 Personal Data Protection
    87 KB (11,601 words) - 17:08, 12 December 2023
  • AEPD (Spain) - EXP202205104 (category Article 6(1) GDPR)
    claimed party, for the alleged infringement of Article 6.1 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Notification of the Commencement Agreement
    26 KB (4,147 words) - 13:27, 13 December 2023
  • AZOP (Croatia) - Decision 28-08-2019 (category Article 4(1) GDPR)
    violation of Article 5, Article 6, and Article 25 GDPR. It ordered the controller to comply with the data subject's erasure request pursuant to Article 17(1)(d)
    16 KB (2,373 words) - 15:31, 30 October 2023
  • board of the building lawful in accordance with Articles 5, 6, 12, 13, 25, and 32 GDPR? The ANSPDCP first held that the processing of the image coming from
    6 KB (779 words) - 15:16, 13 December 2023
  • APD/GBA (Belgium) - 03/2021 (category Article 6(4) GDPR)
    fulfilled. The school breaches Article 6(1)(b) in combination with Article 6(4) and Article 6(1) Articles 24 and 25 GDPR Furthermore, as the school continued
    32 KB (4,880 words) - 16:50, 12 December 2023
  • AEPD (Spain) - EXP202102430 (category Article 83(4) GDPR)
    the claimed party, for the alleged violation of Article 32 of the RGPD, typified in Article 83.4 of the GDPR. Once the initiation agreement was notified,
    33 KB (4,835 words) - 13:26, 13 December 2023
  • Court of Appeal of Brussels - 2020/AR/1333 (category Article 25(1) GDPR)
    people affected and the level of damage the elves suffered (article 83.2.4 of the GDPR) 4.1.4. The Data Protection Authority should have taken into account
    51 KB (7,792 words) - 11:43, 24 January 2022
  • AEPD (Spain) - EXP202105644 (category Article 5(1)(f) GDPR)
    controller €80,000: €50,000 for the violation of Article 5(1)(f) GDPR and €30,000 for the violation of Article 32 GDPR. The original fine of €80,000 was reduced
    27 KB (4,121 words) - 15:06, 13 December 2023
  • CNIL (France) - MED-2019-027 (category Article 25(1) GDPR)
    design and default. The CNIL ordered the Ministry to comply with Article 24 and 25 GDPR regarding the collection and further processing of personal data
    21 KB (3,274 words) - 17:08, 6 December 2023
  • NAIH (Hungary) - NAIH-2020/2204/8 (category Article 12(4) GDPR)
    3, 4, 6, 11, 12, 13, 16, 17, 21, 23-24. Section 4 (5), Section 5 (3) to (5), (7) and (8), Section 13 (2) § 23, § 25, 25 / G. § (3), (4) and (6), 25 / H
    60 KB (9,820 words) - 10:08, 17 November 2023
  • Data Protection Regulation (2016/679) Article 12 (4), Article 17 (3), Article 21 (2) and (3), Article 25 (2), Article 58 (2) (b) Section 2 of the Health Care
    20 KB (3,108 words) - 13:02, 3 March 2024
  • AKI (Estonia) - 2.1-3/20/172 (category Article 16 GDPR)
    Page 4 4 (7) On November 8, 2015, I filed a complaint with the Data Protection Inspectorate (AKI) and demanded that the AKI rapidly implement Article 58
    28 KB (4,711 words) - 10:30, 13 December 2023
  • APD/GBA (Belgium) - 136/2023 (category Article 25(1) GDPR)
    violating Article 5(1)(f) GDPR, Article 5(1)(a) GDPR, Article 5(2) GDPR, Article 12 GDPR, Article 13 GDPR, Article 14 GDPR, Article 24(1) GDPR, and Article
    58 KB (9,184 words) - 16:49, 12 December 2023
  • CNIL (France) - SAN-2020-014 (category Article 9 GDPR)
    obligation of Article 32 GDPR? - Does the fact that this health data is not encrypted constitute a breach of the security obligation under Article 32 GDPR? - Does
    26 KB (4,050 words) - 17:10, 6 December 2023
  • AEPD (Spain) - PS/00187/2020 (category Article 25 GDPR)
    by the alleged violation of Article 32 of the RGPD, Article 5.1.f) of the RGPD, Article 25 of the RGPD, typified in Article 83.5 of the RGPD. FOURTH: On
    51 KB (7,770 words) - 14:08, 13 December 2023
  • HDPA (Greece) - 3/2022 (category Article 4(7) GDPR)
    the meaning of Article 4(7) GDPR. Furthermore, the erasure or destruction of personal data is a form of processing based on Article 4(2) GDPR. The DPA has
    11 KB (1,492 words) - 13:09, 23 November 2022
  • AP (The Netherlands) - 23.09.2021 (category Article 32(1) GDPR)
    increase or decrease. 4.4 Conclusion The AP sets the total fine at €400,000. 8For the justification, see paragraphs 4.3.1 and 4.3.2. 24/25Date Unidentified
    66 KB (8,861 words) - 17:08, 12 December 2023
  • UODO (Poland) - DKN.5101.25.2020 (category Article 25(1) GDPR)
    DATA PROTECTION OFFICE Warsaw, November 12, 2020 DECISION DKN.5101.25.2020 Based on Article. 104 § 1 of the Act of 14 June 1960 Code of Administrative Procedure
    63 KB (10,088 words) - 09:52, 17 November 2023
  • Finnish DPA found a retail chain to have breached Article 5(1)(e) GDPR, Article 25(1) GDPR and Article 25(2) GDPR for its lengthy storage of purchase behaviour
    61 KB (9,477 words) - 13:38, 12 January 2024
  • HDPA (Greece) - 39/2020 (category Article 4(7) GDPR)
    under the GDPR and needs to establish a valid legal basis to process personal data. Unsolicited political communication is regulated with Article 11 L. 3471/2006
    56 KB (7,755 words) - 15:39, 6 December 2023
  • APD/GBA (Belgium) - 25/2020 (category Article 5 GDPR)
    the basis of article 92, 3° of the WOG. 14. The inspection report shall identify potential breaches of Article 5(1). 2 of the AVG, Article 6 of the AVG
    84 KB (14,035 words) - 16:56, 12 December 2023
  • LAG Hessen - 9 Sa 1431/19 (category Article 15(1) GDPR)
    stipulated by the labor court, § 15 GDPR. 1. According to Art. 99 (2) GDPR, the GDPR has been in force since May 25, 2018. It is directly applicable. According
    32 KB (5,093 words) - 16:07, 11 September 2022
  • AEPD (Spain) - PS/00268/2022 (category Article 25(1) GDPR)
    infringement of Article 5.1.f) of the RGPD, Article 33 of the RGPD, Article 25 of the RGPD and Article 32 of the RGPD, typified in Article 83.5 of the RGPD
    63 KB (9,551 words) - 12:33, 13 December 2023
  • violated Article 5(1)(c) GDPR, Article 25(2) GDPR and Section 29(4) of the Finnish Data Protection Act. As a result, and in accordance with Article 58(2)(d)
    25 KB (3,651 words) - 09:37, 3 April 2024
  • NAIH (Hungary) - NAIH/2020/66/21 (category Article 25(1) GDPR)
    organizational measures to ensure data protection by design and by default (Article 25 GDPR)? The DPA held that Robinsons-Tour and Next Time Media Agency did not
    67 KB (10,492 words) - 10:11, 17 November 2023
  • DSB (Austria) - D550.038/0003-DSB/2018 (category Article 5(1)(a) GDPR)
    prior to 25 May 2018) b) Article 13 para. 3 DSG (for the period from 25 May 2018) To 4) a) § 50d para. 1 DSG 2000 (for the period prior to 25 May 2018)
    31 KB (5,161 words) - 14:02, 12 May 2023
  • OLG Hamm - 7 U 19/23 (category Article 82 GDPR)
    contract (Article 6(1)(b) GDPR), nor could be based on legitimate interest of the controller (Article 6(1)(f) GDPR). Consent (Article 6(1)(a) GDPR) could
    130 KB (21,874 words) - 09:43, 15 February 2024
  • minimisation obligation pursuant to Article 5 of the GDPR and the data protection obligations pursuant to Article 25 of the GDPR. The Federal Administrative Court
    51 KB (8,592 words) - 07:03, 2 November 2021
  • processing carried out is in violation of Article 5(1)(f) GDPR, Article 25(1) GDPR, Article 32 GDPR and Article 35 GDPR. Especially, the controller cannot exclude
    119 KB (19,123 words) - 11:29, 16 August 2022
  • APD/GBA (Belgium) - 07/2021 (category Article 5(1) GDPR)
    infringement of Article 5.1 b) in conjunction with Article 6.4. AVG, on article 5.1 a) in conjunction with article 6.1. AVG and on article 5.1 c) GDPR has been
    72 KB (11,208 words) - 16:51, 12 December 2023
  • EDPB - Binding Decision 2/2022 - 'Instagram' (category Article 25(1) GDPR)
    the performance of a contract (Article 6(1)(b) GDPR) and for legitimate interest (Article 6(1)(f) GDPR). Article 6(1)(b) GDPR In its original draft decision
    276 KB (38,206 words) - 09:46, 20 January 2023
  • personal data within the meaning of Article 4, opening words and (1) of the AVG. Based on Article 2, paragraph 1 and Article 3, paragraph 2, of the AVG, the
    38 KB (6,339 words) - 17:14, 12 December 2023
  • APD/GBA (Belgium) - 37/2021 (category Article 25 GDPR)
    condition of necessity is maintained under Article 6.1 b) to f) of the GDPR. The article 6.1 of the GDPR replaces Article 7 of the Directive, without the relevant
    45 KB (6,780 words) - 16:57, 12 December 2023
  • HDPA (Greece) - 50/2021 (category Article 25(1) GDPR)
    information in accordance with Article 13 GDPR. In addition, the HDPA found that the Ministry violated the obligation of Article 35(9) GDPR in relation to the expression
    5 KB (548 words) - 09:23, 12 October 2022
  • Personvernnemnda (Norway) - 2021-03 (category Article 5(1)(a) GDPR)
    Ordinance Article 6 No. 1 letter f, for failure to assess protests, cf. Article 21, and for lack of information, cf. Article 13. 2. Pursuant to Article 58 (2)
    25 KB (4,046 words) - 18:37, 5 March 2022
  • AEPD (Spain) - EXP202205932 (category Article 6(1) GDPR)
    basis under Article 6(1) GDPR. In light of this, the DPA issued a fine of €70,000 to másLUZ Energía (SIE) by virtue of Article 83(5) GDPR for unlawful
    32 KB (4,952 words) - 13:11, 13 December 2023
  • APD/GBA (Belgium) - 74/2020 (category Article 25(1) GDPR)
    2.5. Data protection by design (Article 25 GDPR) 127. In the GDPR, the European legislator has provided an article 25, containing the concepts "Data protection
    82 KB (12,100 words) - 17:01, 12 December 2023
  • APD/GBA (Belgium) - 24/2021 (category Article 25 GDPR)
    and transparency (Article 5.1 a) GDPR), purpose limitation (Article 5.1 b) GDPR) and minimum data processing (Article 5.1 c) GDPR); 4) the legal basis for
    110 KB (18,238 words) - 16:56, 12 December 2023
  • AEPD (Spain) - PS/00451/2019 (category Article 6(1)(f) GDPR)
    regard to article 83.2 (k) of the RGPD, the LOPDGDD, article 76, "Sanctions and corrective measures", provides: "2. In accordance with Article 83(2)(k)
    26 KB (4,231 words) - 14:44, 13 December 2023
  • HDPA (Greece) - 25/2022 (category Article 5(1)(a) GDPR)
    principles of article 5 par. 1 GDPR. It's not a coincidence that the GDPR includes accountability (already mentioned above article 5 par. 2 GDPR) in the regulation
    48 KB (7,803 words) - 13:29, 11 October 2022
  • AZOP (Croatia) - Decision 31-05-2022 (category Article 25 GDPR)
    school xx, which contains personal data xy, there was a violation of Article 25 i Article 32 of the General Regulation on data protection by Secondary Vocational
    17 KB (2,433 words) - 15:45, 30 October 2023
  • APD/GBA (Belgium) - 55/2021 (category Article 25(1) GDPR)
    data on the basis of Article 6.1.e GDPR ? - Did the administration sharing confidential data with a third party violates article 25 GDPR ? - Should the administration
    81 KB (13,211 words) - 16:59, 12 December 2023
  • AEPD (Spain) - EXP202206626 (category Article 5(1)(c) GDPR)
    accordance with article 4.1 of the GDPR, is data personnel and their protection, therefore, is the subject of said Regulation. In article 4.2 The GDPR defines
    35 KB (5,475 words) - 13:21, 13 December 2023
  • HDPA (Greece) - 2/2020 (category Article 12(4) GDPR)
    to as ‘GDPR’), which replaced Directive 95/56, has been applicable since 25 May 2018. In accordance with the provisions of Article 15 (1) GDPR, the data
    12 KB (1,773 words) - 15:33, 6 December 2023
  • APD/GBA (Belgium) - 82/2020 (category Article 25(1) GDPR)
    as a default choice. For that reason, there has been a breach of Article 25 of the GDPR on data protection by design and data protection by default. The
    124 KB (18,772 words) - 17:01, 12 December 2023
  • HDPA (Greece) - 7/2023 (category Article 15 GDPR)
    (definition) Article 4.1: Data subject (definition) Article 4.2: Processing (definition) Article 4.3: Restriction of processing (definition) Article 4.4 : Profiling
    9 KB (1,251 words) - 12:15, 8 May 2023
  • CE - N° 428451 (category Article 25 GDPR)
    accordance with Article L. 6113-7 of the French Public Health Code and the decree of 26 December 2018 comply with Articles 6, 9(3) and 25 GDPR? To reach the
    35 KB (5,153 words) - 16:29, 20 May 2021
  • AP (The Netherlands) - 11.03.2021 (category Article 4 GDPR)
    this processing could be based on the Article 6(1)(c) “compliance with a legal obligation” or Article 6(1)(e) GDPR “the performance of a task carried out
    5 KB (613 words) - 17:06, 12 December 2023
  • APD/GBA (Belgium) - 04/2021 (category Article 25 GDPR)
    the GDPR. According to the defendant, this partner is thus not processor within the meaning of Article 4 (8) GDPR. Consequently, Article 28 (3) GDPR does
    113 KB (18,732 words) - 16:50, 12 December 2023
  • APD/GBA (Belgium) - 34/2020 (category Article 5(1)(b) GDPR)
    May 25, 2018: assessment against the GDPR A. Identification of the controllers involved (Article 4.7 GDPR) 24. In accordance with Article 4.7 GDPR, it
    82 KB (13,250 words) - 16:57, 12 December 2023
  • UODO (Poland) - ZSOŚS.421.25.2019 (category Article 25(1) GDPR)
    DATA PROTECTION OFFICE Warsaw, August 21, 2020 DECISION ZSOŚS.421.25.2019 Based on Article. 104 § 1 of the Act of 14 June 1960 Code of Administrative Procedure
    156 KB (25,012 words) - 10:01, 17 November 2023
  • AP (The Netherlands) - 24.03.2020 (category Article 4(15) GDPR)
    unlawfully. 2.4 Administrative fine Pursuant to Article 58, paragraph 2, preamble, in conjunction with Article 83, paragraph 4, of the GDPR and article 14, third
    48 KB (7,461 words) - 17:04, 12 December 2023
  • DPA held that the controller had violated Article 5(1)(a) GDPR, Article 5(1)(c) GDPR and Article 25(2) GDPR. As a result, the DPA issued a reprimand to
    54 KB (8,279 words) - 13:53, 21 March 2024
  • CNIL (France) - SAN-2023-018 (category Article 31 GDPR)
    DPO and to cooperate with the DPA, therefore violating Article 31 GDPR and Article 37(1)(a) GDPR. On 2 June 2021, the French DPA (“CNIL”) informed a French
    22 KB (3,384 words) - 13:25, 24 January 2024
  • TGI Paris - N° 14/07224 (category Article 5(1)(d) GDPR)
    * clause n ° 12 regarding - of article 6 and article 32 / II of the Data Protection Act for all contracts, - of article L.132-1 of the Consumer Code in
    392 KB (67,730 words) - 15:27, 17 March 2022
  • APD/GBA (Belgium) - 37/2020 (category Article 17 GDPR)
    provided for in Article 56(1), read in conjunction with Article 56(2), read in conjunction with Article 56(3), read in conjunction with Article 56(4), read in
    131 KB (22,429 words) - 16:57, 12 December 2023
  • appropriate security measures, in violation of Articles 5, 12, 13, 25, 28 and 32 GDPR. The GPDP held that Roma Capitale unlawfully carried out the the processing
    83 KB (13,648 words) - 11:30, 16 August 2022
  • HDPA (Greece) - 56/2021 (category Article 13 GDPR)
    and Article of 11Law No. 3471/2006, in accordance with Article 13(58i2) of the GDPR in conjunction with Article 83(1)(a) of the GDPR. 5 of the GDPR, and
    54 KB (8,916 words) - 15:22, 22 February 2022
  • Court of Appeal of Brussels - 2022/AR/292 (category Article 25 GDPR)
    companies that use the TC-string? (Article 4(1) GDPR) 2) a) Is IAB a (joint) controller (Article 4(7) GDPR and Article 24(1) GDPR)? b) Does it matter whether
    6 KB (675 words) - 09:55, 14 December 2023
  • AEPD (Spain) - PS/00474/2020 (category Article 21 GDPR)
    data subject has exercised their right to object under Article 21 GDPR. In the same way, Article 48(1)(b) of the Spanish General Telecommunications Act
    38 KB (5,945 words) - 12:14, 9 June 2021
  • HDPA (Greece) - 20/2021 (category Article 25 GDPR)
    unanimously considers that in accordance with Article 17 in in conjunction with Article 21 para. 3 of the GCP and Article 25 para. 1 of the GCP the conditions for
    20 KB (2,936 words) - 14:58, 22 November 2021
  • Protection Officer (DPO) under Section 4 of Chapter 4 of the GDPR (see in particular Article 37 GDPR to Article 39 GDPR). One of these audit proceedings concerned
    26 KB (3,862 words) - 17:41, 25 June 2022
  • basis under Article 6 GDPR to collect and process vehicle registration numbers. The legal basis is a statutory obligation prescribed by Article 229 of the
    16 KB (2,404 words) - 15:46, 30 October 2023
  • of this regulation and protect the rights of data subjects "(Article 25, paragraph 1, of GDPR). COMMENTS OF THE MISE In the note prot. n. XX of the XX century
    57 KB (9,144 words) - 15:55, 6 December 2023
  • UODO (Poland) - DKN.5130.1354.2020 (category Article 25(1) GDPR)
    expressed in Article 5 (1 ) (a)) f, and reflected in the obligations set out in Article 24 (1), Article 25 (1), Article 32 (1 ) (b ) and (d) and Article 32 (2)
    74 KB (11,513 words) - 09:58, 17 November 2023
  • "accept all" button be considered a breach of GDPR Article 4(11) and Article 7, read in conjunction with GDPR Article 5(3) -Privacy while the data controller
    120 KB (19,650 words) - 09:00, 6 April 2022
  • NAIH (Hungary) - NAIH/2020/193/8 (category Article 12(4) GDPR)
    been deleted by the employer upon request pursuant to Article 16, Article 17 and Article 5(1)(d) GDPR (inaccuracy of personal data). Therefore, the employer
    58 KB (9,413 words) - 10:11, 17 November 2023
  • administrative fines provided for by Article 83, paragraphs 4 and 5, of the Regulation and Article 166, paragraph 1 of the Code. 4.4. On the publication of the data
    129 KB (21,020 words) - 15:49, 6 December 2023
  • CJEU - C-311/18 - Schrems II (category Article 2(2) GDPR)
    under Article 57(1)(f) of the GDPR, each supervisory authority is required on its territory to handle complaints which, in accordance with Article 77(1)
    12 KB (1,780 words) - 17:22, 10 March 2022
  • Constitution, Article 19 TFEU and Article 47 CFR. As Mr A's mandate and termination had not been assessed in the light of the provisions of the GDPR, the Supreme
    46 KB (7,394 words) - 14:08, 21 March 2024
  • complied with the principle of data minimization as per Article 5 (1) (c) and Article 25 (2) GDPR? The Finnish DPA held that the controller has not complied
    17 KB (2,614 words) - 13:05, 3 March 2024
  • Persónuvernd (Island) - 2022020363 (category Article 25 GDPR)
    according to Article 8, Article 23. and paragraph 1 Article 25 Act no. 90/2018, cf. Article 5, paragraph 1 Article 24 and paragraph 1 Article 28 of regulation
    142 KB (22,881 words) - 12:42, 16 January 2024
  • DSB (Austria) - D122.844/0006-DSB/2018 (category Article 12(5) GDPR)
    coming into force of the GDPR on 25. 5. 2018. Can a controller charge for access to historic account data under Article 15 GDPR? Is GDPR applicable to a case
    19 KB (2,936 words) - 13:55, 12 May 2023
  • AEPD (Spain) - PS/00356/2020 (category Article 6(1) GDPR)
    sanctioning procedure against VODAFONE ESPAÑA S.A.U. for infringing Article 6(1) GDPR. Vodafone, recognising its responsibility, made an early payment of
    26 KB (3,848 words) - 14:31, 13 December 2023
  • OGH - 6Ob77/20x (category Article 25 GDPR)
    which contained clauses that are (accordning to the VKI) violating Article 25(2) GDPR. The decisions of the first and second court were appealed, the case
    7 KB (658 words) - 13:16, 8 July 2021
  • HDPA (Greece) - 51/2021 (category Article 22 GDPR)
    (definition) Article 4.1: Data subject (definition) Article 4.2: Processing (definition) Article 4.3: Restriction of processing (definition) Article 4.4: Profileing
    9 KB (1,168 words) - 15:30, 6 December 2023
  • provided for by Article 83, paragraphs 4 and 5, of the Regulation. 4. ORDER INJUNCTION FOR THE APPLICATION OF THE PECUNIARY ADMINISTRATIVE SANCTION 4.1. Information
    58 KB (9,448 words) - 15:50, 6 December 2023
  • AEPD (Spain) - PS/00417/2019 (category Article 83(4) GDPR)
    B66362906 , for a violation of thearticle 37 of the GDPR, typified in article 83.4 of the RGPD, a fine of € 25,000(twenty five thousand euros).SECOND: NOTIFY
    16 KB (2,298 words) - 14:36, 13 December 2023
  • APD/GBA (Belgium) - 141/2021 (category Article 38(6) GDPR)
    controller (Article 24 of the AVG) controller (Article 24 AVG), data protection by design and by default (Article 25 AVG), data default settings (section 25 AVG)
    90 KB (14,937 words) - 12:35, 3 August 2022
  • VG Wiesbaden - 6 K 788/20.WI (category Article 4(4) GDPR)
    conditions of Article 6 (1) of the GDPR. This follows both from Article 21(1)(1)(2) of the GDPR, which refers to Article 6(1)(1)(e) and (f) of the GDPR as a possible
    52 KB (8,534 words) - 12:58, 15 December 2021
  • BVwG - W214 2233132-1/13E (category Article 15(1)(c) GDPR)
    under Article 77 GDPR was very clear and limited in scope. However, the DSB went on to assert a violation of Article 12 GDPR and Article 15(1)(h) GDPR, acting
    47 KB (7,519 words) - 09:28, 13 February 2024
  • BVwG - W258 2227269-1/14E (category Article 4(7) GDPR)
    violating Article 5(1) GDPR Article 6 (1) GDPR Article 6(4) GDPR Article 9 GDPR Article 14 GDPR Article 30 GDPR Article 35 GDPR and Article 36 GDPR. The fine
    47 KB (7,345 words) - 09:41, 10 September 2021
  • RvS - 201901006/1/A2 (category Article 79 GDPR)
    did not acknowledge that with the introduction of Title 8.4 in the Awb on the basis of Article 8:4, paragraph 1, opening words and under f of the Awb, the
    34 KB (5,179 words) - 07:10, 7 April 2020
  • CNPD (Luxembourg) - Délibération n° 47FR/2021 (category Article 5(1)(c) GDPR)
    reception area. 25. 25. It nevertheless agrees with the finding of the head of the investigation that the non-compliance with Article 5.1(c) of the GDPR was established
    69 KB (11,315 words) - 13:30, 19 January 2022
  • accountability (Article 5 (2) and 24 (1), (2) GDPR), privacy by design (Article 25 (1) GDPR) and as controller towards its data processors (Article 28 GDPR). Consequently
    144 KB (23,155 words) - 15:46, 6 December 2023
  • CNPD (Luxembourg) - Délibération n° 18/FR/2022 (category Article 5(1)(b) GDPR)
    provided for in Article 12.3 of the GDPR, nor informed the claimants of a possible reason for its inaction as required by article 12.4 of the GDPR. It also considers
    76 KB (11,147 words) - 16:58, 6 December 2023
  • APD/GBA (Belgium) - 75/2023 (category Article 6(1)(f) GDPR)
    paying profiles. II.4. Article 12(1),(2) and (3), Article 17, Article 19, Article 24(1) and Article 25(1) AVG 63. Article 12 (1) GDPR stipulates that the
    77 KB (11,604 words) - 08:55, 29 June 2023
  • IMY (Sweden) - DI-2019-9457 (category Article 32(1) GDPR)
    inter alia, Article 32, the fee amounts to a maximum of SEK 5,000,000. It appears from ch. 6 Section 2 of the Data Protection Act and Article 83 (4) of the
    43 KB (4,600 words) - 17:08, 23 March 2022
  • BVwG - W176 2244407-1/18E (category Article 15(4) GDPR)
    in Article 23 GDPR. Restrictions on the right to information under Art. 15 GDPR result in particular from the express provision in Art. 15 (4) GDPR that
    48 KB (7,816 words) - 11:04, 29 July 2022
  • power conferred by Article 58(2)(d) and (f) and Article 83(3) and (5) GDPR, imposed to Fastweb multiple corrective measures and a fine of € 4.501.868. Share
    131 KB (21,014 words) - 15:55, 6 December 2023
  • AEPD (Spain) - EXP202201673 (category Article 15 GDPR)
    refused it with reasons. Therefore, the controller breached Article 18 GDPR as well as Article 12.4 LOPDGDD under which the controller must send a mandatory
    5 KB (622 words) - 10:49, 6 March 2024
  • BAG - 9 AZR 383/19 (category Article 38(3) GDPR)
    force of the GDPR, the controller also sent him a separate revocation letter referring to the operational reasons under Article 38(3) GDPR, second sentence
    40 KB (6,019 words) - 14:13, 28 November 2023
  • HDPA (Greece) - 47/2022 (category Article 28(3) GDPR)
    subject to the provision of Article 25(4) of Law 1756/88. Consequently, its provisions were not applicable in this case of Article 5 of the Civil Code and
    25 KB (3,943 words) - 14:32, 28 September 2022
  • Datatilsynet (Denmark) - 2019-423-0202 (category Article 12(3) GDPR)
    Datatilsynet hold that the Municipality of Odense infringed Article 12(3) GDPR and Article 15 GDPR due to delayed answers to access requests. The Datatilsynet
    20 KB (3,084 words) - 16:28, 6 December 2023
  • obligations under Article 5(1)(f) and Article 32 of GDPR. Article 5 (1) : Ticketmaster has failed to comply with the requirements of GDPR including to process
    130 KB (21,195 words) - 13:52, 25 April 2021
  • Protection Officer (DPO) under Section 4 of Chapter 4 of the GDPR (see in particular Article 37 GDPR to Article 39 GDPR). One of these audit proceedings concerned
    56 KB (8,326 words) - 16:57, 6 December 2023
  • AEPD (Spain) - PS/00189/2020 (category Article 58(2) GDPR)
    receiving a warning by the AEPD, and the consequent infringement of Article 58(2) GDPR. The decision is the consequence of a complaint submitted by a Spanish
    22 KB (3,343 words) - 14:08, 13 December 2023
  • CNIL (France) - SAN-2019-010 (category Article 5(1)(c) GDPR)
    investigations the CNIL found five breaches of the GDPR: -         Violation of the right to object, Article 21(2) GDPR: no procedure was implemented to ensure effectively
    62 KB (10,001 words) - 17:09, 6 December 2023
  • AEPD (Spain) - EXP202203969 (category Article 6(1) GDPR)
    hereinafter, LPACAP), for the alleged infringement of Article 6.1 of the GDPR, typified in Article 83.5 of the GDPR. SEVENTH: Notification of the aforementioned
    45 KB (7,135 words) - 13:08, 13 December 2023
  • AEPD (Spain) - PS/00070/2019 (category Article 4(11) GDPR)
    referred to Article 5(1)(a) (principle of lawfulness, fairness and transparency), Article 12(1), Article 7, Article 13 and Article 14 GDPR, the corresponding
    422 KB (70,184 words) - 13:56, 13 December 2023
  • IMY (Sweden) - DI-2020-11373 (category Article 44 GDPR)
    of Chapter V GDPR. The complaint was transferred to the Swedish DPA in its quality of lead supervisory authority pursuant to Article 56 GDPR. Following the
    113 KB (12,773 words) - 15:20, 6 December 2023
  • HDPA (Greece) - 61/2022 (category Article 25(1) GDPR)
    information provided to data subjects was less than that required by the GDPR, and the information was not provided in an intelligible and easily accessible
    6 KB (663 words) - 15:31, 6 December 2023
  • GHAL - 200.254.914 (category Article 6(1)(f) GDPR)
    Applicable GDPR Provisions 4.4 In this case, the first question that arises is whether the listing of the search results is lawful. In this case, Article 6(1)(f)
    20 KB (2,722 words) - 10:04, 14 December 2023
  • Datatilsynet (Norway) - 20/01790 (category Article 5(1)(a) GDPR)
    disclosing personal data from a surveillance footage, thus breaching Article 5(1)(a) GDPR and Article 6. The company appealed to the Norwegian Privacy Appeals Board
    49 KB (7,646 words) - 07:56, 7 March 2022
  • HDPA (Greece) - 20/2022 (category Article 12(3) GDPR)
    violation of article 17 in combination with article 21 par. 3 and article 12 paragraph 3 of the GDPR and article 25 paragraph 1 of the GDPR. For its judgment
    16 KB (2,374 words) - 11:46, 18 August 2022
  • the existing foreseeable risks, thereby acting contrary to Article 25 paragraph 1 and Article 32 paragraph 1 points b) and d) and paragraph 2 of the General
    7 KB (855 words) - 15:30, 30 October 2023
  • AEPD (Spain) - PS/00257/2020 (category Article 37 GDPR)
    handed down under this article." III Article 73 of the LOPDDG states Infringements considered serious: "In accordance with Article 83(4) of Regulation (EU)
    18 KB (2,737 words) - 14:23, 13 December 2023
  • CNIL (France) - SAN-2022-020 (category Article 25(2) GDPR)
    Failure to ensure data protection by default (Article 25(2) GDPR) The DPA also found a violation of Article 25(2) GDPR regarding the controllers “X” icon at the
    59 KB (9,566 words) - 17:03, 6 December 2023
  • Datatilsynet (Norway) - 20/02291 (category Article 5(1)(f) GDPR)
    patient data cf. Article 32 GDPR and Article 5(1)(f) GDPR and inadequate internal controls cf. Article 24 GDPR and Article 5(2) GDPR. Østfold Hospital
    45 KB (6,645 words) - 14:40, 28 March 2022
  • GHAL - 200.186.790/01 (category Article 6(1)(b) GDPR)
    terminated, must be assessed in the light of Article 6 GDPR and not Article 10 GDPR. Article 6(1)(f) GDPR provides a sufficient basis for processing. The
    50 KB (8,219 words) - 12:42, 4 March 2022
  • AEPD (Spain) - EXP202104917 (category Article 4(11) GDPR)
    valid consent under Article 4(11) GDPR and Article 6(1) LOPDGDD (National data protection law aimed at the implementation of the GDPR). In both articles
    27 KB (4,356 words) - 12:41, 13 December 2023
  • CE - 437808 (category Article 83 GDPR)
    Secondly, under Article 83 of the GDPR: "1. Each supervisory authority shall ensure that administrative fines imposed under this article for violations
    13 KB (1,928 words) - 09:51, 10 September 2021
  • CNIL (France) - SAN-2020-003 (category Article 5(1)(c) GDPR)
    disregarded the provisions of Article 5-1 e) of the GDPR. C. On the breach of the obligation to inform people 65. Article 13 of the GDPR requires the data controller
    61 KB (10,028 words) - 17:09, 6 December 2023
  • RvS - 201902417/1/A2 (category Article 6(1)(e) GDPR)
    time, which is a violation of the GDPR. As to the claim for damages, the CoS notes that though Article 82(1) of the GDPR states that full compensation for
    37 KB (5,721 words) - 12:41, 16 September 2021
  • not necessarily meet the requirements of Article 32 GDPR. To what extent are the provisions in Article 32 GDPR obligatory and thus, not subject to the preferences
    30 KB (4,562 words) - 15:27, 6 December 2023
  • Norges Høyesterett - 2021-2403-A (category Article 4(11) GDPR)
    case. (25) However, the other two conditions of Article 6 (1) (f) of the GDPR are not met. (26) The second condition of Article 6 (1) (f) of the GDPR is that
    46 KB (7,024 words) - 06:18, 6 March 2022
  • controller had violated Article 5(1)(f) GDPR, Article 17(1) GDPR, Article 25(1) GDPR, Article 32(1) GDPR and Article 32(2) GDPR. As a result, the DPA issued
    56 KB (8,980 words) - 08:47, 4 March 2024
  • 23Investigation report, page 34, point 4.4.8.1. 24Investigation report, page 34, point 4.4.8.2.1.1 25Investigation report, page 34, point 4.4.8.2.2.1 _______________
    82 KB (11,472 words) - 16:58, 6 December 2023
  • Protection Officer (DPO) under Section 4 of Chapter 4 of the GDPR (see in particular Article 37 GDPR to Article 39 GDPR). One of these audit proceedings concerned
    81 KB (11,895 words) - 16:58, 6 December 2023
  • HDPA (Greece) - 18/2020 (category Article 5(1)(a) GDPR)
    governed by the basic principle of GDPR, the principle of transparency (relevant Articles 12-14 of the GDPR). 4. The GDPR introduces the principle of accountability
    12 KB (1,733 words) - 15:34, 6 December 2023
  • AEPD (Spain) - PS/00326/2020 (category Article 37(1)(a) GDPR)
    under this article. " III Article 73 of the LOPDDG indicates: "Violations considered serious "Based on what is established in article 83.4 of Regulation
    14 KB (1,992 words) - 14:29, 13 December 2023
  • regarding Article 6(1) GDPR and consent requirements regulated previously to GDPR. The fact that the infringements related to Article 25 GDPR did not include
    440 KB (73,154 words) - 09:44, 12 May 2021
  • AEPD (Spain) - PS/00329/2020 (category Article 37 GDPR)
    issued under this article. " III Article 73 of the LOPDDG indicates: Violations considered serious "Based on what is established in article 83.4 of Regulation
    13 KB (2,002 words) - 14:29, 13 December 2023
  • AEPD (Spain) - EXP202104875 (category Article 5(1)(f) GDPR)
    SAW The violation of article 32 of the GDPR is typified in article 83.4.a) of the aforementioned GDPR in the following terms: "4. Violations of the following
    54 KB (8,451 words) - 13:35, 13 December 2023
  • AP (The Netherlands) - z2018-02009 (category Article 32 GDPR)
    (hereinafter: the GDPR) applies on 25 May 2018 become. The GDPR imposes the same obligation in Article 32, paragraph 1, as it applied under Article 13 6. The UWV
    33 KB (5,112 words) - 17:10, 12 December 2023
  • Datatilsynet (Norway) - 21/03530 (category Article 6(1)(b) GDPR)
    it should have under Article 60 GDPR - Article 61(8) GDPR applied, which meant that the urgent need to act under Article 66(1) GDPR was presumed to be met
    99 KB (14,431 words) - 16:20, 6 December 2023
  • Personvernnemnda (Norway) - 2021-18 (20/02059) (category Article 5(1)(d) GDPR)
    around the processing of personal data subject to Article 10 GDPR. Pursuant to Article 6(1)(f) GDPR, the Privacy Appeals Board conducted a balancing test
    36 KB (5,859 words) - 06:40, 6 July 2022
  • BVerfG - 1 BvR 16/13 (category Article 17 GDPR)
    completely determined by it. This already follows from Article 1.3, Article 20.3 and Article 93.1 No. 4a of the Basic Law. According to these, the commitment
    133 KB (21,944 words) - 15:59, 22 March 2022
  • (2) and (4) of the General Data Protection Regulation. As such, the operator ING Bank NV Amsterdam was sanctioned with a fine in the amount of 4,874.40 lei
    4 KB (381 words) - 15:19, 13 December 2023
  • enshrined in Article 5(1)(c) GDPR. The Finish DPA further ordered the controller to bring its processing activities into compliance under Article 58(2)(d)
    13 KB (1,873 words) - 13:06, 3 March 2024
  • GHAL - 200.256.426 (category Article 4(2) GDPR)
    on legitimate interests according to Article 6(1)(f) GDPR and that Ziggo had to comply with Article 6(4)(d) GDPR. The Court found that DFW had a legitimate
    40 KB (6,777 words) - 16:28, 15 March 2022
  • AEPD (Spain) - PS/00009/2020 (category Article 6(1) GDPR)
    defendant) for the infringement of Article 6(1) of the GDPR, as the defendant agreed to an early voluntary payment of the corresponding part (48,000 €) of the
    27 KB (4,150 words) - 13:45, 13 December 2023
  • CJEU - C-601/20 - SOVIM (category Article 25(2) GDPR)
    guaranteed by Article 7 of the Charter and the right to protection of personal data guaranteed by Article 8 of the Charter? Question 3 1. Is Article 5(1)(a)
    9 KB (1,176 words) - 13:29, 5 January 2024
  • HDPA (Greece) - 30/2020 (category Article 4(1) GDPR)
    powers under Article 58(2) GDPR and impose on the respondent the responsibility to restore the fulfilment of Article 5(1)(a) GDPR and of Article 5(1)(b-f)
    20 KB (2,519 words) - 15:36, 6 December 2023
  • Protection Regulation) Article 5, paragraph 1, subparagraph c, Article 25, Article 58, paragraph 2, subparagraph d, and Article 87, Section 29, subsection
    45 KB (5,016 words) - 14:14, 21 March 2024
  • APD/GBA (Belgium) - 10/2019 (category Article 6(4) GDPR)
    of identified personal data as defined in Article 4(1) and (2) of the General Data Protection Regulations (GDPR). 1 Hof van beroep Brussel, sectie Marktenhof
    32 KB (5,190 words) - 16:51, 12 December 2023
  • AEPD (Spain) - PS/00179/2020 (category Article 32(1) GDPR)
    as established in article 5 of the GDPR. The security of personal data is regulated in articles 32, 33 and 34 of the GDPR. III The GDPR defines personal
    100 KB (16,401 words) - 14:07, 13 December 2023
  • Rb. Den Haag - C/09/581706 / HA RK 19-593 (category Article 12(5) GDPR)
    the same search results on the basis of Article 12 (4) GDPR has been rejected by Google . Article 21 (1) of the GDPR provides that a data subject has the
    34 KB (5,811 words) - 09:44, 8 December 2020
  • DSB (Austria) - D122.970/0004-DSB/2019 (category Article 17 GDPR)
    executed. Legal basis: Article 4 lines 1, 2 and 5, Article 11 paragraphs 1 and 2, Article 12 paragraph 2, Article 17 paragraph 1 and Article 58 paragraph 2 lit
    23 KB (3,622 words) - 13:57, 12 May 2023
  • AEPD (Spain) - EXP202100300 (category Article 16 GDPR)
    included within the framework of data protection. Therefore, Article 16 GDPR cannot be applied. Article 16 refers to inaccurate personal data, not to the rectification
    16 KB (2,362 words) - 13:37, 13 December 2023
  • APD/GBA (Belgium) - 72/2020 (category Article 5(1)(b) GDPR)
    until May 25, 2018, the treatment was subject to the HPPA. Applicable legislation has changed from the coming into force of the DMPP on May 25, 2018. 26
    34 KB (5,677 words) - 17:00, 12 December 2023
  • CNPD (Portugal) - Deliberação 2022/1072 (category Article 83(4)(a) GDPR)
    paragraph 3, all of article 35, and paragraph a) of paragraph 4 of article 83, all GDPR, with a fine of up to €20,000,000 or up to 4% of annual turnover
    163 KB (27,222 words) - 16:54, 6 December 2023
  • UODO (Poland) - DKN.5130.2024.2020 (category Article 25(1) GDPR)
    art. 24 sec. 1, art. 25 sec. 1, art. 28 sec. 1 and 3 and article. 32 sec. 1 and 2, as well as art. 83 sec. 1 - 3, art. 83 sec. 4 lit. a) and art. 83 sec
    75 KB (12,104 words) - 09:58, 17 November 2023
  • AEPD (Spain) - PS/00029/2020 (category Article 5(1)(f) GDPR)
    required by Article 35(3)(b). The AEPD also held that there had a been a violation of Article 32 because of a failure to comply with GDPR security measure
    44 KB (6,943 words) - 13:49, 13 December 2023
  • CNPD (Luxembourg) - Délibération n° 21FR/2021 (category Article 5(1)(c) GDPR)
    company was not compliant with Article 13 GDPR. The CNPD held that the controller infringed Article 5(1)(c) GDPR and Article 13 GDPR and decided to: - impose
    52 KB (7,520 words) - 13:13, 20 July 2021
  • AEPD (Spain) - PS/00262/2020 (category Article 5(2) GDPR)
    Spanish DPA (AEPD) fined XFERA MÓVILES, S.A. €40000 for violating Article 6(1) GDPR by illegally processing personal data of the claimants in a fraudulent
    22 KB (3,293 words) - 14:23, 13 December 2023
  • IP - 07126-1/2020/29 (category Article 4(7) GDPR)
    gave its non-binding opinion on the data protection roles under Article 4(7) and (8) GDPR of the entities involved in clinical trials in Slovenia , holding
    8 KB (1,029 words) - 11:07, 13 January 2021
  • CNPD (Luxembourg) - Délibération n° 13FR/2023 (category Article 5(1)(b) GDPR)
    their employees. The DPA found a violation of Article 5(1)(b) GDPR, Article 5(1)(c) GDPR and Article 13 GDPR. Following a visit to the premises of two public
    96 KB (13,984 words) - 16:57, 6 December 2023
  • AEPD (Spain) - PS/00054/2021 (category Article 32(1) GDPR)
    States ”. The violation of article 32 of the RGPD is typified in article 83.4.a) of the aforementioned RGPD in the following terms: "4. Violations of the following
    27 KB (3,993 words) - 13:52, 13 December 2023
  • regarding Article 6(1) GDPR and consent requirements regulated previously to GDPR. The fact that the infringements related to Article 25 GDPR did not include
    457 KB (75,575 words) - 09:36, 12 May 2021
  • NAIH (Hungary) - NAIH/2020/2000/5 (category Article 5(1)(a) GDPR)
    of a Commission decision on adequacy , or in Article 46, Article 47 or the second subparagraph of Article 49 (1) (a) the period for which the personal
    24 KB (3,815 words) - 10:11, 17 November 2023
  • Rb. Rotterdam - 9436020 \ CV EXPL 21-30289 (category Article 4(2) GDPR)
    data is a form of processing as referred to in the GDPR (article 4 sub 2 GDPR). Article 6 of the GDPR provides that the processing of personal data is only
    19 KB (2,828 words) - 10:09, 18 March 2022
  • AZOP (Croatia) - Decision 04-07-2022 (category Article 6(1) GDPR)
    space. The DPA found a violation of Article 6(1) GDPR and ordered the controller, pursuant to Article 58(2)(d) GDPR, to adjust the location of the cameras
    14 KB (2,038 words) - 15:20, 30 October 2023
  • APD/GBA (Belgium) - 105/2023 (category Article 5(1)(a) GDPR)
    therefore an infringement of Article 5 at the time of the facts. 1, a) GDPR, Article 6, Article 12.1 GDPR and Article 14.1 a) GDPR. 90. In addition, a controller
    102 KB (15,787 words) - 07:39, 6 September 2023
  • a violation of Article 5(1)(b) GDPR. As a result, the DPA issued a reprimand to the controller in accordance with Article 58(2)(b) GDPR. Generally, a controller
    20 KB (2,859 words) - 13:11, 13 March 2024
  • AEPD (Spain) - PS/00114/2019 (category Article 6(1) GDPR)
    the RGPD must be observed. In turn, pursuant to article 83. 2.k GDPR, the circumstances described in article 76 LOPDGDD may also be taken into consideration
    60 KB (10,197 words) - 14:01, 13 December 2023
  • CNIL (France) - SAN-2023-025 (category Article 6(1)(a) GDPR)
    the data subjects, therefore breaching Article 6 GDPR, as well as Article 5(1)(b) GDPR. Thirdly, Article 30 GDPR stipulates that the controller must keep
    53 KB (8,418 words) - 11:21, 6 February 2024
  • CNIL (France) - SAN-2019-001 (category Article 4(11) GDPR)
    comprehensible character, within the meaning of Article 12 of the GDPR, of the information provided for in Article 13 of the Regulation must be assessed. The
    90 KB (14,556 words) - 17:08, 6 December 2023
  • 2019, GDPR Art. 37, para. 1; Döpfler , EU-GDPR and BDSG, 2nd edition 2020, GDPR Art. 37, marginal 1; Paal / Pauly, DS-GVO BDSG, 2nd ed. 2018, GDPR Art.
    48 KB (7,320 words) - 12:44, 4 October 2021
  • AEPD (Spain) - PS/00315/2020 (category Article 28 GDPR)
    CIF A76539030, for a violation of article 28.3.g) of the RGPD, in accordance with article 83.4 b) of the RGPD, and article 74.k) of the LOPDGDD, with the
    62 KB (10,401 words) - 14:35, 21 November 2023
  • AEPD (Spain) - EXP202200471 (category Article 5(1)(f) GDPR)
    the violation of Article 5(1)(f) GDPR and €30,000 for the violation of Article 32 GDPR. According to the national legislation (Article 76(2)(b) LOPDGDDon
    40 KB (6,014 words) - 13:21, 13 December 2023
  • Commissioner (Cyprus) - 17.05.23 (category Article 5(1)(c) GDPR)
    perpetrator (Article 83(2) GDPR). Lastly, the amount of the fine shall not exceed the maximum amounts provided for in Articles 83(4) (5) and (6) GDPR. The quantification
    31 KB (4,973 words) - 16:50, 6 December 2023
  • AEPD (Spain) - PS/00188/2019 (category Article 5(1)(f) GDPR)
    infringement of Article 5.1.f) of the RGPD typified in Article 83.5.a) of the RGPD and considered very serious, for the purposes of prescription, in Article 72.1
    39 KB (6,623 words) - 14:08, 13 December 2023
  • OGH - 6Ob35/21x (category Article 4(1) GDPR)
    constitute personal data under Article 4(1) GDPR? If so, do they qualify as special categories of personal data under Article 9 GDPR? Is the defendant obliged
    27 KB (4,090 words) - 09:54, 10 September 2021
  • AEPD (Spain) - TD/00233/2020 (category Article 17 GDPR)
    December 13. " FIFTH: Article 25 of the RLOPD determines: "one. Except in the case referred to in paragraph 4 of the previous article, the exercise of the
    17 KB (2,670 words) - 14:46, 13 December 2023
  • RvS - 202100789/1/A3 (category Article 5(1)(b) GDPR)
    in accordance with Article 5, paragraph 1, preamble and under b, of the GDPR. 4.4. Article 6, paragraph 1, opening words, of the GDPR stipulates that processing
    20 KB (2,965 words) - 12:52, 28 June 2023
  • OLG Köln - 15 U 89/19 (category Article 17(3) GDPR)
    under Article 17(3) GDPR. Two doctors sued a platform for deletion of their basic profile set up on the platform without their consent under Article 17 GDPR
    143 KB (24,273 words) - 15:59, 10 March 2022
  • AEPD (Spain) - PS/00491/2020 (category Article 6(1) GDPR)
    violation of Article 13 GDPR and issued a warning to the controller. The AEPD took into account the following aggravating factors (Article 83 (2) GDPR) to determine
    19 KB (2,957 words) - 14:45, 13 December 2023
  • HDPA (Greece) - 44/2019 (category Article 5(1) GDPR)
    internal compliance and accountability according to Article 5(1) GDPR, Article 5(2) GDPR and Article 6(1) GDPR. Since the company had totally ignored the its
    127 KB (21,184 words) - 15:39, 6 December 2023
  • Rb. Rotterdam - ROT 19/1393 (category Article 17(1) GDPR)
    information to be retained by the defendant any longer. 4. Pursuant to Article 17 (1) of the GDPR , a data subject has the right to obtain erasure of personal
    9 KB (1,203 words) - 16:30, 10 March 2022
  • AZOP (Croatia) - Decision 05-10-2023 (category Article 5 GDPR)
    existence of a legal basis from Article 6, paragraph 1, and in connection with this, Article 9, paragraph 2 of the GDPR; 4. The data controller did not inform
    13 KB (1,934 words) - 20:55, 1 November 2023
  • OLG Frankfurt am Main - 13 U 206/20 (category Article 17(1) GDPR)
    by the plaintiff pursuant to Article 82(1) GDPR, since there have been violations of Article 6(1)(a) GDPR and Article 34 GDPR. The defendant also breached
    44 KB (7,334 words) - 09:02, 17 March 2022
  • APD/GBA (Belgium) - 02/2021 (category Article 6 GDPR)
    Compétence de la Chambre de Résolution des Litiges (Article 2 AVG ; Article 4 WOG) 55. Conformément à l'article 2, paragraphe 1, de l'AVG, le règlement s'applique
    96 KB (15,396 words) - 16:50, 12 December 2023
  • APD/GBA (Belgium) - 31/2022 (category Article 5(1)(a) GDPR)
    of his personal data would be based 5. 1, a) GDPR, Article 6, Article 12.1 GDPR and Article 14.1 a) GDPR. 67. Moreover, a controller, in this case defendant
    84 KB (12,933 words) - 16:46, 12 December 2023
  • OLG München - 3 U 2906/20 (category Article 4(1) GDPR)
    a claim under Article 15 GDPR entitles the data subject to be provided with copies of their personal data and whether Article 15(3) GDPR contains an independent
    21 KB (3,450 words) - 10:33, 8 February 2022
  • AEPD (Spain) - PS/00219/2019 (category Article 5(1)(d) GDPR)
    processing personal data without the accuracy required according to Article 5(1)(d) GDPR. BBVA sent the claimant's personal data to a collection agency. The
    37 KB (5,785 words) - 14:11, 13 December 2023
  • AP (The Netherlands) - 31.05.2021 (category Article 32 GDPR)
    other things, article 4 paragraph 1 SUWI and the ZBO register of the Dutch central government. See article 2 paragraph 2 SUWI and article 4 paragraph 1 SUWI
    106 KB (14,502 words) - 17:09, 12 December 2023
  • OLG Naumburg - 9 U 6/19 (category Article 9(1) GDPR)
    gross turnover per article sold. 35. On March 25, 2019, the plaintiff had his appeal substantiated by another attorney of record: 36. Article 9 of the DSGVO
    32 KB (5,236 words) - 16:00, 10 March 2022
  • accordance with Article 60(3) GDPR. Ten DPAs (AT, DE, FI, FR, IT, NL, NO, PL, PT, SE) raised objections, in accordance with Article 60(4) GDPR, to the Draft
    21 KB (3,005 words) - 14:16, 1 February 2023
  • EDPB - Binding Decision 1/2020 - 'Twitter' (category Article 4(24) GDPR)
    DE SA’s objection on Article 33(3) GDPR fails to meet the requirements set out in Article 4(24) GDPR Infringement of Article 34 GDPR on the communication
    183 KB (30,819 words) - 09:50, 20 January 2023
  • communication service. Therefore, TikTok had to obtain valid consent (Article 4(11) GDPR) from users before using the identifiers. The DPA stated that it should
    73 KB (11,864 words) - 17:03, 6 December 2023
  • AEPD (Spain) - PS/00483/2020 (category Article 5(1)(f) GDPR)
    confidentiality established by Article 5(1)(f) GDPR? Was there a personal data breach? The AEPD considered that there was an infringement of Article 5(1)(f), as there
    32 KB (4,834 words) - 14:43, 13 December 2023
  • DSB (Austria) - 2020-0.191.240 (category Article 4(1) GDPR)
    point b. of her applications, "by analogy pursuant to Article 25.1 in conjunction with Article 22.4 of the first case DSG". Arguments of the defendant: The
    66 KB (10,546 words) - 13:50, 12 May 2023
  • OLG Nürnberg - 8 U 2907/21 (category Article 12(5)(b) GDPR)
    right to access under Article 15 GDPR because the controller was entitled to reject the request pursuant to Article 12(5)(b) GDPR. The court reasoned that
    24 KB (3,847 words) - 15:19, 11 September 2022
  • Court of Appeal of Brussels - 2020/AR/813 (category Article 5(1)(c) GDPR)
    Therefore the controller violated Article 5(1)(a) and (2), Article 6(1), Article 12(1), Article 13(1)(b) and (c) GDPR. The DPA imposed a fine of €50.000
    85 KB (12,340 words) - 15:30, 19 August 2022
  • Datatilsynet (Denmark) - 2019-421-0028 (category Article 12(3) GDPR)
    data subject in the context of an access requests, to comply with Article 15(1)(h) GDPR. The Datatilsynet conducted some investigations at Udbetaling Danmark
    17 KB (2,639 words) - 16:27, 6 December 2023
  • AEPD (Spain) - EXP202209001 (category Article 5(1)(c) GDPR)
    te, LPACAP), for the alleged violation of Article 5.1.c) of the RGPD, typified in the Article 83.5 of the GDPR. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid
    22 KB (3,303 words) - 13:28, 13 December 2023
  • Hoge Raad - ECLI:NL:PHR:2023:935 (category Article 5(1)(c) GDPR)
    Hague October 4, 2022, ECLI:NL:GHDHA:2022:2100, para. 3.1-3.13. 4 Conclusion 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 Exhibit 4 to the introductory
    103 KB (17,620 words) - 10:13, 29 November 2023
  • AEPD (Spain) - EXP202209511 (category Article 6(1) GDPR)
    following the mandatory legal requirements to do so, violating Article 6(1) and Article 13 GDPR. A resident has installed, without the authorization of the
    22 KB (3,257 words) - 13:28, 13 December 2023
  • AEPD (Spain) - PS/00148/2019 (category Article 6 GDPR)
    manifestation of will. However, according to Article 31(1) of the Spanish Public Sector Act and to Article 25 of the Spanish Constitution, and the interpretation
    48 KB (7,550 words) - 14:05, 13 December 2023
  • AEPD (Spain) - PS/00247/2020 (category Article 7 GDPR)
    L. for the infringement of Article 13 GDPR (data privacy policy) and a warning penalty for the infringement of Article 7 GDPR regarding the collection of
    24 KB (3,893 words) - 14:22, 13 December 2023
  • AEPD (Spain) - EXP202202837 (category Article 6(1) GDPR)
    (Considering 40 GDPR), Article 6.1 of the GDPR is therefore applicable and not RD 1720/2007 used by the defendant. Thus, the aforementioned article 6.1 GDPR establishes
    58 KB (8,995 words) - 13:00, 13 December 2023
  • AEPD (Spain) - PS/00266/2019 (category Article 13 GDPR)
    refers to older national laws, instead of GDPR. Does an non-updated privacy policy infringe Article 13 GDPR? Shoud the AEPD calculate the fine by taking
    28 KB (4,459 words) - 14:23, 13 December 2023
  • APD/GBA (Belgium) - 15/2021 (category Article 5(2) GDPR)
    rectification.(article 16 of the GDPR), the right to be forgotten (article 17 of the GDPR), and the right to limit the use ofdata processed unlawfully (article 18
    85 KB (13,724 words) - 16:52, 12 December 2023
  • CNPD (Portugal) - Deliberação 2022/140 (category Article 5(1)(e) GDPR)
    violation of Article 5(1)(f) GDPR and a fine of €100,000 for the violation of Article 37 GDPR. The DPA issued a reprimand for the violations of Article 5(1)(e)
    75 KB (12,306 words) - 10:02, 21 December 2022
  • AEPD (Spain) - EXP202104530 (category Article 28 GDPR)
    Juan, 6 www.aepd.es 28001 – Madrid sedeagpd.gob.es 4/4 in accordance with the provisions of article 25 and paragraph 5 of the provision additional fourth
    12 KB (1,685 words) - 12:41, 13 December 2023
  • CNIL (France) - SAN-2022-011 (category Article 12 GDPR)
    breach of the obligation to inform pursuant to Article 14 of the GDPR 20. According to Article 14 of the GDPR: 1. Where personal data has not been collected
    48 KB (7,525 words) - 17:02, 6 December 2023
  • AKI (Estonia) - 18.02.2022 (category Article 5(1) GDPR)
    issues a reprimand under Article 58(2)(b) GDPR. After this, the DPA draws attention to the fact that pursuant of Article 5(1)(a) GDPR, data must be processed
    42 KB (5,838 words) - 10:27, 13 December 2023
  • Rb. Noord-Holland - C/15/311101 / HA RK 20-227 (category Article 17(1) GDPR)
    reluctant to minimize data. 4.4. The municipality takes the position that Article 17 paragraph 3 under b AVG in conjunction with Article 7.3.8 paragraph 3 Youth
    22 KB (3,333 words) - 13:22, 2 June 2021
  • informed of this provision. Pursuant to Article 78 of the Regulation, as well as to Article 152 of the Code and Article 10 of Legislative Decree no. 150 of
    9 KB (1,280 words) - 15:53, 6 December 2023
  • Gerechtshof Amsterdam - 200.258.736/01 (category Article 15 GDPR)
    the free movement of such data (OJEU L 119/1 of 4 May 2016) (hereinafter AVG) became applicable (cf. Article 99(1) and (3) AVG). As of that date, the AVG
    41 KB (7,150 words) - 12:30, 4 October 2021
  • APD/GBA (Belgium) - 36/2021 (category Article 5(1) GDPR)
    approved appeal of Article 5(1)(a), Article 12(1), Article 13(1) and Article 13(2). The appeal for Article 5(1)(c), Article 6(1) and Article 8 GDPR was not approved
    62 KB (9,417 words) - 16:57, 12 December 2023
  • CNIL (France) - MED-2020-015 (category Article 5(1)(a) GDPR)
    some of the provisions of the GDPR and the "loi informatique et libertés". Regarding, on one hand, the violation of the GDPR, the CNIL reminded the Ministry
    33 KB (5,322 words) - 17:08, 6 December 2023
  • DSB (Austria) - 2022-0.332.606 (category Article 2(2)(c) GDPR)
    case fell under the household exception found in Article 2(2)(c) GDPR. According to this provision, the GDPR does not apply to the processing of personal data
    21 KB (3,166 words) - 13:43, 12 May 2023
  • Autoriteit Persoonsgegevens disagrees: Article 78(2) GDPR defines the applicable time frame in line with Article 4:13(1) of the Dutch Administrative law
    25 KB (3,954 words) - 13:39, 16 November 2020
  • AEPD (Spain) - PS/00423/2019 (category Article 13 GDPR)
    information under Article 13 GDPR is illegal. Consequently, the APED decided to issue a fine of €1.500 for the violation of Article 13 GDPR. Share your comments
    23 KB (3,636 words) - 14:38, 13 December 2023
  • AEPD (Spain) - PS/00197/2020 (category Article 5(1)(b) GDPR)
    6(1)(b), 5(1)(b) and 5(1)(c) GDPR? The Spanish DPA (AEPD) deemed itself competent under Article 58(2) GDPR in conjunction with Article 47 of the Spanish Data
    129 KB (21,793 words) - 14:09, 13 December 2023
  • AEPD (Spain) - PS/00291/2019 (category Article 6(1)(a) GDPR)
    unlawful processing data from a public registry without a legal basis under Article 6 GDPR. A citizen filled a complaint with the AEPD regarding the unlawful processing
    33 KB (5,396 words) - 14:26, 13 December 2023
  • Rb. Amsterdam - C/13/696660/HA RK - 21-37 (category Article 79(2) GDPR)
    been stated nor has it been proven. 3.11. The GDPR also has a jurisdiction regulation. Article 79(2) of the GDPR provides that proceedings against a controller
    18 KB (2,617 words) - 08:23, 2 September 2021
  • AZOP (Croatia) - Decision 17-05-2022 (redirect from AZOP (Croatia) - Usž-27/22-4) (category Article 6 GDPR)
    consent, in line with Article 6(1)(a) GDPR. The Court recalled that Article 31 of the Croatian Law on the Implementation of the GDPR stipulates that the
    15 KB (2,261 words) - 15:55, 30 October 2023
  • AEPD (Spain) - EXP202301529 (category Article 17 GDPR)
    considering that it has violated the provisions of Article 17 of the GDPR and Article 21 of the GDPR and urge GLOBAL CAPITAL GROUP SPAIN, S.L. with NIF
    20 KB (3,078 words) - 13:05, 13 December 2023
  • CNPD (Portugal) - Deliberação 984/2018 (category Article 5(1)(f) GDPR)
    the combined provisions of article 32, paragraph 1, subparagraphs b) and d) and article 83, paragraph 4, al.a), of the GDPR, with a fine of € 0.00 to €
    40 KB (5,935 words) - 16:55, 6 December 2023
  • decision under Article 66 GDPR when the lead SA fails to respond to provide mutual assistance within a month as per Article 61(8) GDPR. The CJEU adopted
    10 KB (1,311 words) - 15:26, 13 June 2023
  • Supreme Court - C.20.0323.N (category Article 4(11) GDPR)
    minimisation under Article 5(1)(c) GDPR, and contrary to the obligation to obtain the freely given consent of the data subject under Article 6(1)(a) GDPR, when refusal
    43 KB (6,749 words) - 07:07, 28 October 2021
  • AEPD (Spain) - PS/00422/2018 (category Article 2 GDPR)
    RETAIL S.L. for alleged infringement of Article 5.1 f) of the GDPR, in accordance with Article 83.5.a) of the GDPR- Initiate sanctioning procedure against
    25 KB (3,933 words) - 14:37, 13 December 2023
  • AEPD (Spain) - TD/00183/2021 (category Article 15 GDPR)
    officer, article 39 of the RGPD attributes to him the function of cooperate with said authority. Similarly, the domestic legal system, in article 65.4 of the
    20 KB (3,087 words) - 13:30, 13 December 2023
  • DSB (Austria) - D123.921/0005-DSB/2019 (category Article 12(4) GDPR)
    referred to the provision of Art. 15 (4) GDPR. With regard to the respondent's reference to the provision of Art. 15 (4) GDPR, however, it should be noted that
    42 KB (6,592 words) - 13:58, 12 May 2023
  • AZOP (Croatia) - Decision 30-12-2021 (category Article 5(1)(a) GDPR)
    had a legal basis under Article 6(1) GDPR to publish the data subject’s personal data, and did not violate Article 5(1)(a) GDPR. In the decision, the Croatian
    16 KB (2,411 words) - 15:44, 30 October 2023
  • AEPD (Spain) - EXP202200439 (category Article 6(1) GDPR)
    constitutes sensitive data within the meaning of Article 9 GDPR. The DPA alluded to Article 9(1) GDPR which prohibits the processing of these special categories
    36 KB (5,608 words) - 13:01, 13 December 2023
  • AEPD (Spain) - E/00113/2019 (category Article 4(11) GDPR)
    unequivocal consent to the processing of his personal data according to Article 4(11) GDPR. The AEPD noted that to determine whether FEDA, having regard to the
    27 KB (4,497 words) - 13:38, 13 December 2023
  • IP - 0610-376/2020/35 (category Article 13(1) GDPR)
    should comply with the criteria set out in Article 6. (4) General Regulations. The application of Article 6 (4) of the General Regulation to a change in
    110 KB (17,995 words) - 11:15, 22 April 2021
  • DSB (Austria) - 2020-0.303.727 (category Article 17(1) GDPR)
    and Article 85 GDPR. In June 2019, the complainant requested erasure of her personal data from the respondent's website, claiming that an article on that
    21 KB (3,266 words) - 13:51, 12 May 2023
  • authority (cf. Article 36 (2) no. 7 lit. a DPA) for the purposes of military self-protection (cf. Article 36 (1) DPA in conjunction with Article 2 (1) no. 2
    28 KB (3,418 words) - 13:49, 12 May 2023
  • with Article 5 (1) (a) and Article 6 (1) (f) GDPR. Thus, the controller failed to comply with the accountability principle under Article 5 (2) GDPR. Second
    111 KB (17,604 words) - 13:08, 3 March 2024
  • APD/GBA (Belgium) - 42/2020 (category Article 4(7) GDPR)
    that regard on that article 2.1) GDPR read in conjunction with recital 15 of the GDPR, although an exclusion from the scope of the GDPR provides for files
    30 KB (4,871 words) - 16:58, 12 December 2023
  • AEPD (Spain) - PS/00060/2020 (category Article 58(1)(a) GDPR)
    personal data under Article 15 GDPR? The Spanish DPA held that the airline company had not complied with the right to access in Article 15 GDPR when it refused
    23 KB (3,695 words) - 13:53, 13 December 2023
  • BVwG - W274 2232028-1/3E (category Article 5 GDPR)
    is only determined by Article 5 et seqq. GDPR. A violation of Article 13 or 14 GDPR can be fined under Article 83(5) GDPR but it does not affect the lawfulness
    32 KB (5,232 words) - 09:40, 10 September 2021
  • AEPD (Spain) - PS/00028/2020 (category Article 6 GDPR)
    aviolation of article 6 of the RGPD, typified in article 83.5 of the RGPD, in relation towith article 72.1 b) of the LOPDGDD, a fine of € 4,000 (four thousand
    14 KB (2,075 words) - 13:48, 13 December 2023
  • AEPD (Spain) - PS/00430/2018 (category Article 4(7) GDPR)
    ( *** POSITION 1) for an infraction of Article 6.1.f) of the GDPR, in accordance with Article 83.5 of the GDPR ”. In the face of it, no allegations have
    40 KB (6,508 words) - 14:39, 13 December 2023
  • AEPD (Spain) - PS/00408/2020 (category Article 6(1) GDPR)
    according to article 4.1 of the RGPD, is data personal protection and their protection, therefore, is the object of said Regulation. Article 4.2 of the RGPD
    47 KB (7,616 words) - 14:35, 13 December 2023
  • AEPD (Spain) - PS/00464/2020 (category Article 32(1) GDPR)
    Member States ”. The violation of article 32 is classified in article 83.4.a) of the cited GDPR in the following terms: "4. Violations of the following provisions
    29 KB (4,300 words) - 14:41, 13 December 2023
  • AEPD (Spain) - PS/00043/2020 (category Article 13 GDPR)
    specified period - article 58. 2 d) -. According to the provisions of article 83.2 of the RGPD, the measure provided for in article 58.2 d) of the aforementioned
    24 KB (3,838 words) - 13:51, 13 December 2023
  • HDPA (Greece) - 20/2020 (category Article 4(15) GDPR)
    explanatory statement of the law, Article 10 defines the Authority’s competence in compliance with Article 55 GDPR.Article 55 GDPR provides for a restriction
    29 KB (4,578 words) - 15:35, 6 December 2023
  • AEPD (Spain) - EXP202201247 (category Article 4(11) GDPR)
    hereinafter, LPACAP), for the alleged violation of article 6.1 of the RGPD, typified in Article 83.5 of the GDPR. C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid
    17 KB (2,350 words) - 13:17, 13 December 2023
  • AEPD (Spain) - EXP202203617 (category Article 5(1)(c) GDPR)
    according to article 4.1 of the GDPR, are a Personal data and its protection, therefore, is the subject of said Regulation. In the article 4.2 of the GDPR defines
    74 KB (11,726 words) - 13:02, 13 December 2023
  • AEPD (Spain) - PS/00235/2020 (category Article 6(1) GDPR)
    Telefónica Móviles España, S.A.U. with a fine of €75,000 for violating Article 6(1) GDPR. The complainant had five telephone lines contracted with Telefónica
    24 KB (3,766 words) - 14:21, 13 December 2023
  • AEPD (Spain) - PS/00251/2020 (category Article 37(1)(b) GDPR)
    company result in a breach of Article 37 GDPR? The Spanish DPA (AEPD) found that Conseguridad SL had violated Article 37(1)(b) GDPR by not having designated
    15 KB (2,245 words) - 14:22, 13 December 2023
  • Datatilsynet (Norway) - 21/00480 (category Article 5(1)(f) GDPR)
    fined a municipality €409,768 (NOK 4,000,000) for breaches of Article 5(1)(f) GDPR, Article 24 GDPR and Article 32 GDPR after a serious ransomware attack
    31 KB (4,380 words) - 06:12, 14 March 2023
  • AEPD (Spain) - PS/00269/2019 (category Article 5(1)(f) GDPR)
    infringement of article 5.1.f), in relation to article 6.1, of the RGPD. The infringement of article 5.1.f) of the RGPD is typified in article 83.5.a) of the
    30 KB (4,761 words) - 14:24, 13 December 2023
  • [The equivalent GDPR Article to Article 48(3)(a) EU GDPR is Article 46(3)(a) GDPR, and Article 50(1)(d) EU GDPR is Article 49(1)(d) GDPR.] Share blogs or
    73 KB (9,347 words) - 13:28, 26 July 2023
  • HDPA (Greece) - Opinion 2/2020 (category Article 35(1) GDPR)
    of Article 6(1)(e) GDPR -public interest and exercise of official authority vested in it, which falls within the exception of Article 9(2)(j) GDPR. It
    33 KB (5,266 words) - 15:32, 6 December 2023
  • AEPD (Spain) - PS/00452/2019 (category Article 6(1)(a) GDPR)
    pursuant to Article 47(1) and 48.1 of Law 39/2015 of 1 October, on the limitation of the infringement of article 6.1 of the RGPD typified in article 83.5 a)
    25 KB (4,037 words) - 14:55, 13 December 2023
  • AEPD (Spain) - PS/00173/2020 (category Article 5(1)(d) GDPR)
    defendant) for the infringement of the accuracy principle, as per Article 5(1)(d) of the GDPR. The decision is the consequence of a complaint submitted by another
    22 KB (3,424 words) - 14:06, 13 December 2023
  • IMY (Sweden) - DI-2021-5595 (category Article 5(1)(f) GDPR)
    other GDPR provisions, such as those related to the transfer of personal data to third countries. The IMY took into account Recital 75 and 76 GDPR in order
    47 KB (5,207 words) - 18:51, 21 March 2022
  • OLG Innsbruck - 1 R 182/19b (category Article 82 GDPR)
    had fulfilled its obligation to provide information pursuant to Article 12(3) and Article 4(7) of the Basic Law (Voriger SuchbegriffDSGVONächster Suchbegriff)
    54 KB (7,916 words) - 12:06, 9 May 2022
  • UODO (Poland) - DKN.5130.2815.2020 (category Article 25(1) GDPR)
    57(1)(a) and Article 58(2)(b) in connection with Article 5(1)(f), Article 24(1), Article 25(1), Article 32(1) and (2) of 2 of Regulation EU 2016/679 of the European
    37 KB (5,819 words) - 09:58, 17 November 2023
  • AEPD (Spain) - PS/00273/2020 (category Article 17 GDPR)
    (thousand euros) for the violation of article 21 of the LSSI, typified in article 38.4.d) of the LSSI. SEVENTH: On November 25, 2020, the respondent presented
    15 KB (2,337 words) - 14:24, 13 December 2023
  • AEPD (Spain) - EXP202208230 (category Article 28(2) GDPR)
    violation of article 28.2 typified in Article 83.4 a) GDPR. SIXTY THOUSAND EUROS (€60,000) for alleged violation of article 28.3 typified in Article 83.4 a) GDPR
    45 KB (6,904 words) - 13:12, 13 December 2023
  • APD/GBA (Belgium) - 38/2021 (category Article 5 GDPR)
    consent of the 10 complainant (article 6.1 a) of the GDPR combined with article 7 of the GDPR), (2) article 6.1 c) of the GDPR in that the publication results
    73 KB (11,604 words) - 16:57, 12 December 2023
  • Datatilsynet (Norway) - 20/01879 (category Article 24 GDPR)
    highly sensitive personal data exposed, thus breaching Article 32(1)(b) GDPR and Article 32(2), cf. Article 24. An employee in a municipal health care center
    30 KB (4,302 words) - 18:53, 5 March 2022
  • AEPD (Spain) - PS/00287/2020 (category Article 5(1)(f) GDPR)
    States ”. The violation of article 32 of the RGPD is typified in article 83.4.a) of the aforementioned RGPD in the following terms: "4. Violations of the following
    32 KB (4,837 words) - 14:26, 13 December 2023
  • AEPD (Spain) - PS/00062/2020 (category Article 13 GDPR)
    breach Article 13 GDPR even if the contact form is not operational? The Spanish DPA (AEPD) held that the defendant, PSI, violated Article 13 GDPR by failing
    44 KB (7,162 words) - 13:53, 13 December 2023
  • AEPD (Spain) - PS/00058/2020 (category Article 5(1)(f) GDPR)
    for the alleged violation of article 5.1f) of the RGPD in relation to the Article 5 of the LOPDGDD, typified in article 83.5 a) of the RGPD. C / Jorge
    28 KB (4,619 words) - 13:53, 13 December 2023
  • APD/GBA (Belgium) - 73/2020 (category Article 5 GDPR)
    plain. The word "concise" in Article 12(1) GDPR, however, does not mean incomplete, all mandatory information from Article 13 GDPR must still be included. The
    93 KB (14,040 words) - 17:00, 12 December 2023
  • AEPD (Spain) - EXP202204631 (category Article 5(1)(f) GDPR)
    comes regulated in article 32 of the GDPR. II Article 5.1.f) of the GDPR Article 5.1.f) of the GDPR establishes the following: "Article 5 Principles relating
    36 KB (5,485 words) - 13:19, 13 December 2023
  • personal data and information under Article 15 GDPR in his Google account, Google has not violated Article 15 GDPR concerning this data/information. As
    107 KB (17,615 words) - 09:42, 10 September 2021
  • controller for the purposes of Article 4(7) GDPR, and Company A was the processor for the purposes of Article 4(8) GDPR. The DPA found that both Companies
    55 KB (9,079 words) - 16:57, 6 December 2023
  • AEPD (Spain) - EXP202202164 (category Article 5(1) GDPR)
    AEPD fined in €2,000 a website for non-GDPR compliant privacy policy, violating Article 13 GDPR. On January 16, 2022 the data subject complaint against
    29 KB (4,482 words) - 14:06, 5 March 2024
  • Persónuvernd (Iceland) - 2020061954 (category Article 14(1) GDPR)
    Point 6 of Article 3 Act no. 90/2018 and item 7 of Article 4. of Regulation (EU) 2016/679, cf. and the first and second paragraphs. Article 4 Epidemiology
    88 KB (14,189 words) - 09:58, 7 December 2021
  • APD/GBA (Belgium) - 19/2020 (category Article 5(1)(b) GDPR)
    1 f) GDPR) (and the obligations arising from it – Article 32 GDPR) and the principle of purpose (Article 5 § 1 b) GDPR) which the principle of security
    39 KB (6,246 words) - 16:55, 12 December 2023
  • AEPD (Spain) - PS/00268/2019 (category Article 13 GDPR)
    specific enough and did not comply with Article 13 GDPR. Does the lack of precision enough to infrige Article 13 GDPR? The AEPD found that the information
    28 KB (4,435 words) - 14:23, 13 December 2023
  • controller within the meaning of Article 4(7) of the AVG. 3.4 Violation regarding the reporting of a violation 3.4.1 Introduction Article 33(1) of the AVG stipulates
    77 KB (12,915 words) - 17:15, 12 December 2023
  • AEPD (Spain) - PS/00341/2019 (category Article 21 GDPR)
    AEPD found that the Socialist Party of Catalonia (PSC-PSOE) violated Article 21 GDPR due to unsolicited political propaganda sent after the data subject
    26 KB (4,032 words) - 14:31, 13 December 2023
  • AEPD (Spain) - PS/00408/2019 (category Article 58(2) GDPR)
    es Page 4 4/5IIIThis infraction is typified in article 83.5.e) of the RGPD, which considers as such: “ nofacilitate access in breach of article 58, paragraph
    12 KB (1,812 words) - 14:35, 13 December 2023
  • LG Essen - 6 O 190/21 (category Article 33 GDPR)
    the controller's premises, constituting a violation of Article 24, Article 25(1), or Article 32 GDPR. The alleged loss of the data did not occur at the controller's
    28 KB (4,596 words) - 18:30, 18 November 2021
  • CE - N° 430810 (category Article 6(1)(a) GDPR)
    to in Article 9 of the GDMPR in order to infer that such consent would not be necessary for data not referred to in that Article, since Article 4 of the
    42 KB (6,800 words) - 09:50, 10 September 2021
  • processing of personal data within the meaning of Article 4 GDPR and is it justified on the basis of Article 6 GDPR? Can the controller raise the argument that
    73 KB (11,238 words) - 16:59, 12 December 2023
  • the GDPR was allegedly breached. The Court did not specify the article of the GDPR on which the processing could have been based. However they stated that
    16 KB (2,099 words) - 12:30, 4 October 2021
  • APD/GBA (Belgium) - 12/2019 (category Article 4(11) GDPR)
    the ePrivacy Directive and Articles 6(1)(a) and 7 GDPR, in the lights of Article 4(11) and Recital 32 GDPR. Following this report, the GBA issued a decision
    107 KB (17,697 words) - 16:52, 12 December 2023
  • AEPD (Spain) - PS/00059/2020 (category Article 28 GDPR)
    the definitions of the legal concepts that the RGPD indicates in article 4: Article 4 GDPR. Definitions For the purposes of this Regulation, the following
    287 KB (48,336 words) - 13:53, 13 December 2023
  • AEPD (Spain) - PS/00416/2019 (category Article 6 GDPR)
    provisions of article 6 of the LOPDGDD:"Article 6. Treatment based on the consent of the affected party1. In accordance with the provisions of article 4.11 of
    206 KB (32,869 words) - 14:36, 13 December 2023
  • APD/GBA (Belgium) - 51/2023 (category Article 5(1)(b) GDPR)
    obligation under Article 37(7) GDPR. The DPA ordered the controller to comply with his obligations under Article 13(1)(b) GDPR and Article 37(7) GDPR and to publish
    18 KB (2,611 words) - 12:45, 16 June 2023
  • Commissioner (Cyprus) - 11.17.001.009.232 (category Article 12(3) GDPR)
    breaching Article 12(3) GDPR, since it failed to notify the data subject that her erasure request was satisfied, as well as Article 24(1) GDPR, given that
    17 KB (2,515 words) - 11:17, 6 February 2024
  • APD/GBA (Belgium) - 63/2020 (category Article 12(4) GDPR)
    en hij deze zaak niet wenst verder te zetten. 2. Rechtsgrond Artikel 12.4 AVG 4. Wanneer de verwerkingsverantwoordelijke geen gevolg geeft aan het verzoek
    20 KB (2,982 words) - 17:00, 12 December 2023
  • AEPD (Spain) - PS/00025/2019 (category Article 6(1) GDPR)
    infringement of article 6.1 of the RGPD, typified in article 83.5 of the RGPD, afine of 75,000 euros (seventy-five thousand euros).SECOND: Under article 58.2.d)
    88 KB (14,301 words) - 13:48, 13 December 2023
  • AEPD (Spain) - PS/00026/2021 (category Article 21 GDPR)
    processor, Vamavi Phone SL, had violated Article 48(1) LGT, Article 21 GDPR in link with Article 23 LOPDGDD and Article 28 GDPR by making a commercial call on behalf
    33 KB (5,185 words) - 13:48, 13 December 2023
  • AEPD (Spain) - PS/00379/2019 (category Article 6 GDPR)
    an alleged violation of article 6 of the GDPR typified as an infringement of basic principles for processing in article 83.5 GDPR. In determining the amount
    26 KB (4,235 words) - 14:33, 13 December 2023
  • Gerechtshof Amsterdam - 200.258.200/01 (category Article 6(1)(f) GDPR)
    based are contested by [the appellant]. 3.4 The Court of Appeal will first jointly discuss grievances 1, 2 and 4 with which [the appellant] challenges the
    16 KB (2,462 words) - 12:29, 4 October 2021
  • right to erasure (“right to be forgotten”) of Article 17 GDPR and Article 19 of Regulation 2018/1725. Under GDPR, such prolonged and unrestricted data retention
    61 KB (9,971 words) - 14:28, 4 January 2024
  • AEPD (Spain) - PS/00135/2021 (category Article 6(1) GDPR)
    violated Article 6(1)GDPR, for processing personal data without a legal basis. Hence, the AEPD decided to fine Telefónica for the violation of Article 6(1)GDPR
    30 KB (4,631 words) - 13:00, 13 December 2023
  • accordance with Article 60(3) GDPR. Ten DPAs (AT, DE, ES, FI, FR, HU, IT, NL, NO, SE) raised objections, in accordance with Article 60(4) GDPR, to the Draft
    468 KB (51,340 words) - 14:10, 30 January 2023
  • LG Bonn - 29 OWi 1/20 (category Article 83(4) GDPR)
    states that the party concerned violated Article 83(4)(a) GDPR in conjunction with [Article 32(1) GDPR. Article 32 (1) GDPRby failing, at least with gross
    58 KB (9,577 words) - 08:06, 16 September 2021
  • States" (Article 288 of the Treaty on functioning of the European Union) starting from the date of 25/5/2018 in which the became applicable (Article 99, paragraph
    27 KB (4,339 words) - 15:50, 6 December 2023
  • RvS - 201905319/1/A3 (category Article 12(6) GDPR)
    Act and, subsequently, the GDPR. Request for compensation in case his data is processed unlawfully is also in line with the GDPR. The facts that this may
    21 KB (3,337 words) - 10:08, 16 December 2020
  • CNPD (Portugal) - Deliberação 2021/533 (category Article 9 GDPR)
    April 2016 (General Data Protection Regulation - GDPR), in conjunction with Article 3, Article 4(2) and Article 6(1)(b), all of which are applicable to the
    30 KB (4,708 words) - 16:56, 6 December 2023
  • AEPD (Spain) - EXP202309109 (category Article 5(1)(c) GDPR)
    purposes and means of such activity, by virtue of article 4.7 of the GDPR. For its part, article 5.1.c) of the GDPR regulates the “principles relating to processing”
    18 KB (2,733 words) - 13:18, 13 December 2023
  • reviewe the security of the data processed by the processor under Article 28(3)(a) and (h) GDPR. For these reasons, the responsibility of the security incident
    50 KB (8,001 words) - 15:52, 6 December 2023
  • AEPD (Spain) - PS/00008/2020 (category Article 6(1) GDPR)
    signed by C / Jorge Juan, 6 www.aepd.es 28001 - Madrid sedeagpd.gob.es Page 4 4/14 the customer and send this copy to "Docout" for custody. Docout reviews
    27 KB (4,408 words) - 13:45, 13 December 2023
  • HDPA (Greece) - 3/2020 (category Article 15 GDPR)
    coverage of the image of the third party shall not be required.” 4. As follows from Article 12 (4) of Law 2472/1997, the controller was required to respond to
    19 KB (3,034 words) - 15:33, 6 December 2023
  • reprimand to the controller in accordance with Article 58(2)(b) GDPR. Pursuant to Article 58(2)(d) GDPR, the DPA also ordered the controller to erase the
    15 KB (2,137 words) - 20:18, 27 March 2024
  • AEPD (Spain) - PS/00335/2020 (category Article 5(1)(f) GDPR)
    protocols. This therefore breached Article 5(1)(f) GDPR and Article 32 GDPR. The initial sanction for infringing Article 5(1)(f) was a fine of €5000 and the
    34 KB (5,427 words) - 14:30, 13 December 2023
  • AEPD (Spain) - PS/00348/2020 (category Article 5(1)(a) GDPR)
    claimant’s signature constitute a breach under the GDPR? The AEPD held that Vodafone violated Article 6(1) GDPR, as they had processed the claimant’s data without
    38 KB (5,648 words) - 14:31, 13 December 2023
  • AEPD (Spain) - PS/00128/2020 (category Article 4(13) GDPR)
    with article 4.1 of the RGPD. As for the fingerprint, it is also data that must be qualified. two as biometric data and in accordance with article 4.14 of
    39 KB (5,912 words) - 14:02, 13 December 2023
  • AEPD (Spain) - EXP202208091 (category Article 5(1)(f) GDPR)
    for the alleged violation of Article 5.1.f) of the GDPR and Article 32 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Notified of the aforementioned
    40 KB (6,014 words) - 13:24, 13 December 2023
  • LfDI (Baden-Württemberg) - O 1018/115 (category Article 32(1)(a) GDPR)
    for indirect determinability: BeckOK Datenschutzrecht Wolff/Brink, DSGVO Article 4 marginal no. 17). Contrary to its obligation as the responsible body, Knuddels
    13 KB (1,926 words) - 10:22, 17 November 2023
  • AEPD (Spain) - PS/00227/2020 (category Article 6(1) GDPR)
    Articles 6 and 13 GDPR? The AEPD decided to impose, for infringement of Article 6 GDPR, a fine of € 10000 and, for infringement of Article 13 GDPR, a fine of
    46 KB (7,230 words) - 14:20, 13 December 2023
  • AEPD (Spain) - PS/00386/2019 (category Article 7 GDPR)
    Juan, 6www.aepd.es28001 - Madridsedeagpd.gob.es Page 4 4/5In accordance with the provisions of article 39.1. c) of the LSSI, minor infractions canwill be
    16 KB (2,335 words) - 14:33, 13 December 2023
  • Art. 4 No. 1 GDPR, is processed and stored here by the defendant as the person responsible in accordance with Art. 4 No. 7 GDPR. According to Art. 4 No.
    28 KB (4,215 words) - 15:09, 6 December 2023
  • AEPD (Spain) - EXP202203956 (category Article 6(1) GDPR)
    hereinafter, LPACAP), for the alleged infringement of Article 6.1 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Notified of the aforementioned start-up
    52 KB (8,323 words) - 13:17, 13 December 2023
  • AEPD (Spain) - PS/00092/2020 (category Article 13 GDPR)
    reprimand to the company for not complying with Article 13 GDPR, since it failed to even mention the GDPR in its Privacy Policy. Share your comments here
    22 KB (3,514 words) - 13:58, 13 December 2023
  • AZOP (Croatia) - Decision 18-12-2020 (category Article 5(1)(c) GDPR)
    information. Article 7 of said act, however, states that public figures cannot expect the same level of protection as other citizens. Article 8 also states
    21 KB (3,345 words) - 15:24, 30 October 2023
  • AEPD (Spain) - PS/00339/2019 (category Article 5(1)(f) GDPR)
    against the respondent, for the alleged infringement of Article 6 of the RGPD, typified in Article 83.5 of the RGPD. In view of the foregoing, the following
    18 KB (2,781 words) - 14:30, 13 December 2023
  • publication of the press release of 17 June 2020 infringed Article 54(2) GDPR and Article 48(1) and Article 64(3) WOG. This press release described that the DPA
    206 KB (30,485 words) - 09:54, 14 December 2023
  • Court of Appeal of Brussels - 2021/AR/163 (category Article 83 GDPR)
    (articles 12 and 14 of the GDPR); A breach of his right of access (article 15 of the GDPR); A breach of Article 28 of the GDPR with regard to its status
    72 KB (11,389 words) - 08:59, 20 August 2021
  • AP (The Netherlands) - 09.04.2021 (category Article 12(1) GDPR)
    of Article 12(1) GDPR. The AP outlined that, in the event of an infringement of Article 12(1) of the GDPR, pursuant to Article 58(2)(i) and Article 83(5)
    12 KB (1,616 words) - 17:08, 12 December 2023
  • AEPD (Spain) - PS/00279/2020 (category Article 6 GDPR)
    for the violation of Article 6 GDPR and € 4 000 for the violation of article 13, under the power conferred by Article 83(5) GDPR. Share your comments here
    21 KB (3,123 words) - 14:25, 13 December 2023
  • AEPD (Spain) - PS/00357/2020 (category Article 13 GDPR)
    accordance with provided for in article 58.2.b) of the RGPD, for an infringement of article 13 of the RGPD, typified in article 83.5 of the RGPD, a warning
    20 KB (3,075 words) - 14:32, 13 December 2023
  • Datatilsynet (Norway) - 20/01626 (category Article 5(1)(a) GDPR)
    processing as per Article 5(1)(b), nor legal grounds as per Article 6. In sum, the DPA found that NIF had breached Article 5(1)(a), (c) and (f), Article 6, and Article
    50 KB (8,081 words) - 18:52, 5 March 2022
  • AEPD (Spain) - PS/00070/2020 (category Article 5(1)(a) GDPR)
    publication of the judgment breach the GDPR? The AEPD held that the respondent’s actions violated the GDPR Article 5(1)(a) requirement that processing must
    43 KB (7,001 words) - 13:56, 13 December 2023
  • HDPA (Greece) - 31/2023 (category Article 5(1)(c) GDPR)
    with the principles of article 5 par. 1 GDPR. It is no coincidence that the GDPR includes accountability (see Article 5 para. 2 GDPR) in the regulation of
    61 KB (10,257 words) - 10:15, 1 November 2023
  • BVwG - W256 2240235-1 (category Article 6(1)(e) GDPR)
    interests under Article 6(1)(f) GDPR. The data subject was heard on this statement and filed a submission, arguing that Article 6(1)(f) GDPR does not apply
    33 KB (5,154 words) - 11:08, 21 January 2022
  • APD/GBA (Belgium) - 06/2019 (category Article 5(1)(c) GDPR)
    (e) and 13(2)(a) GDPR. Thus, it ordered the controller to comply with the GDPR. In addition it fined € 10,000 under Article 58(2)(i) GDPR for the violation
    20 KB (3,137 words) - 16:51, 12 December 2023
  • Commissioner (Cyprus) - 11.17.001.008.222 (category Article 12(3) GDPR)
    Moreover, following an infringement of Article 12(3) GDPR, as explained above, under the provisions of Article 83 of the GDPR, I take into account the following
    16 KB (2,438 words) - 09:07, 9 June 2023
  • VGH München – 5 CS 19.2087 (category Article 4(1) GDPR)
    paragraph 1a Basic Law Article 5(1), first sentence VIG § 1, § 2, § 3, § 4 para. 4, § 5 para. 1, para. 4 p. 1, § 6 para. 1, para. 3, para. 4 Regulation (EU) 2017/625
    40 KB (6,397 words) - 08:03, 21 March 2022
  • AEPD (Spain) - EXP202104873 (category Article 5(1)(f) GDPR)
    for the alleged violation of Article 5.1.f) of the GDPR and Article 32 of the GDPR, typified in Article 83.5 of the GDPR. FIFTH: Notified of the aforementioned
    24 KB (3,512 words) - 10:43, 13 December 2023
  • HDPA (Greece) - 6/2020 (category Article 5 GDPR)
    compliance with the principles of Article 5 (1) GDPR. 4. As, in accordance with the provisions of Article 4 (c) (d).1 GDPR is personal data “any information
    29 KB (4,557 words) - 15:33, 6 December 2023
  • AEPD (Spain) - EXP202201681 (category Article 13 GDPR)
    infringement of article 32.1 of the GDPR (LCEur 2016, 605), typified in the Article 83.4.a) of the GDPR, a warning sanction, in accordance with article 77 of the
    195 KB (30,495 words) - 12:40, 13 December 2023
  • RvS - 201905347/1/A3 (category Article 6(4) GDPR)
    decision of the Minister is no longer based on Article 17(3) GDPR. Instead the decision is based on Article 6(4) GDPR. However the Minister did not explain well
    25 KB (3,824 words) - 22:46, 10 October 2020
  • AEPD (Spain) - PS/00315/2019 (category Article 13 GDPR)
    information provided was in breach of Article 13 GDPR. Therefore, the authority warned the controller (Article 83(5) GDPR) and requested to complete the notice
    17 KB (2,633 words) - 14:28, 13 December 2023
  • Commissioner (Cyprus) - 11.17.001.007.251 (category Article 32(4) GDPR)
    reason, claimed that she shall receive the medical report under the veil of GDPR. The Cypriot Office of the Commissioner for Personal Data Protection disagreed
    4 KB (448 words) - 16:52, 6 December 2023
  • AEPD (Spain) - PS/00036/2020 (category Article 13 GDPR)
    based comply with Article 13 of the GDPR? The Spanish DPA found that the facts constituted an infringement for violation of Article 13 of the RGPD, and
    16 KB (2,587 words) - 13:50, 13 December 2023
  • AEPD (Spain) - PS/00351/2019 (category Article 58(2)(c) GDPR)
    regard to Article 83 (2) (k) of the GDPR, Article 76 of the GDPR, ‘Sanctions and remedial measures’, provides: ‘2. In accordance with Article 83 (2) (k)
    17 KB (2,739 words) - 14:31, 13 December 2023
  • AEPD (Spain) - PS/00254/2019 (category Article 4(12) GDPR)
    infringement of Article 32.1 of the GDPR typified as a serious infringement in Article 73 f) of the LOPDGDD and in Article 83.4 of the GDPR. For its part
    39 KB (6,341 words) - 14:23, 13 December 2023
  • AEPD (Spain) - PS/00274/2020 (category Article 21 GDPR)
    Raise Marketing violated the data subject's right to object (Article 21 GDPR and Article 23 LOPDGDD). The DPA fined Raise Marketing €1500 for this violation
    16 KB (2,544 words) - 14:25, 13 December 2023
  • AEPD (Spain) - PS/00212/2019 (category Article 32 GDPR)
    typified in article 83.4 of the RGPD and is qualified as serious in article 73.1 g) of the LOPDPGDD for prescription purposes.III Article 58.Article 58.2 of
    17 KB (2,518 words) - 14:11, 13 December 2023
  • amount of the fine under Article 83(2) GDPR. The data subjects complains about the violation of its right of access (Article 15 GDPR) by the Istituto Nazionale
    22 KB (3,478 words) - 15:51, 6 December 2023
  • AEPD (Spain) - PS/00322/2020 (category Article 83(4)(a) GDPR)
    States ”. The violation of article 32 of the RGPD is typified in article 83.4.a) of the aforementioned RGPD in the following terms: "4. Violations of the following
    26 KB (3,840 words) - 14:28, 13 December 2023
  • AEPD (Spain) - PS/00268/2020 (category Article 13 GDPR)
    Policy on their website (Article 13 GDPR) and for the absence of a reject button on the second layer of their Cookie Policy (Article 22(2) LSSI). The claimant
    17 KB (2,700 words) - 14:23, 13 December 2023
  • NAIH (Hungary) - NAIH/2020/5553 (category Article 12(3) GDPR)
    request under Article 15 and with the one month deadline under Article 12(3). Was Google Ireland Ltd in breach of its obligations under GDPR Article 15(1) and
    27 KB (4,279 words) - 10:12, 17 November 2023
  • OLG Dresden - 4 U 1905/21 (category Article 12(5)(b) GDPR)
    that a controller is allowed to reject a request to access under Article 12(5)(b) GDPR as "excessive" if the request's sole purpose is to verify the validity
    40 KB (6,325 words) - 16:12, 18 May 2022
  • AEPD (Spain) - PS/00129/2022 (category Article 83(5) GDPR)
    RGPD, and for the violation of article 32 of the RGPD, classified in the article 83.4 of the GDPR. The aforementioned initiation agreement was notified
    22 KB (3,420 words) - 12:59, 13 December 2023
View (previous 500 | ) (20 | 50 | 100 | 250 | 500)