Bootcamp - Section I Flashcards

(98 cards)

1
Q

If a processing activity is covered by a rule in both GDPR and the ePrivacy Directive, which applies?

A

ePrivacy Directive - Because it is more specific.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is another name for the
Treaty on European Union?

A

Maastricht Treaty
1992

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What did the European Court of Justice hold in Papasavvas v. O Fileleftheros Dimosia Etairia Ltd.?

A

As long as the company is receiving payment for services they provided, it is an information society service.

That the term “information society service” applies to all economic activities for which the service provider is remunerated, regardless of whether the user is the one that provides the remuneration.

Dienstleistungen der Informationsgesellschaft

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

True or False:
The Treaty on the Functioning of the European Union requires that the protection of personal data be incorporated into all aspects of member state law.

A

False.
This requirement does not apply to national measures that are not implementing some aspects of E.U. law.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What was the Article 29 Working Party (29WP)

A

An independent advisory panel that provided guidance on questions regarding the Directive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the “consultative” procedure of the legislative process in the E.U.?

A

Where the authority to enact law rests with the Council - not the Parliament.
But the Council is obligated to consult with the Parliament.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does FIPs stand for?

A

Fair Information Practices or
Fair Information Privacy Practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

T or F:
One of the primary shortcomings of the Data Protection Directive was that it only applied to private industry.

A

False:
The Data Protection Directive applied to both private and public sectors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What right is recognized in Article 8 of the
Charter of Fundamental Rights?

A

The right to the protection of personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What international organization drafted and signed the
European Convention on Human Rights?

A

Council of Europe
CoE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How many institutions are designated official institutions of the European Union?

A

7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What body did the European Data Protection Board replace?

A

Article 29 Working Party

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

In what way was the 2008 Framework Decision that regulated cooperating criminal authorities limited in scope?

A

It applied only to cross-border transfers of personal data and did not apply to internal processing within a member state.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Under the ePrivacy Directive, when is the interception of electronic communications permitted?

A

When the users of the system consent,
or where interception is
legally authorized to achieve important public purposes (e.g., national security or criminal prosecution).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How are members of the European Parliament elected?

A

Directly by citizens of the European Union.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does Article 19 of the Universal Declaration of Human Rights seek to protect?

A

Individual opinions and the communication of ideas.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the most recent data protection legislation enacted by the E.U.?

A

The NIS Directive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is the primary difference between a regulation and a directive?

A

Regulation: Applies upon its own force
Directive: Requires member states enable legislation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What treaty created a “single market” in Europe?

A

The Treaty on European Union
(aka The Maastricht Treaty)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are the two primary components of the Court of Justice of the European Union?

A

General Court &
European Court of Justice

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Is the European Court of Human Rights an EU institution.

A

No.
Its part of the Council of Europe.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which came first: the Universal Declaration of Human Rights or the European Convention on Human Rights?

A

The Universal Declaration of Human Rights

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What entity was created by the European Convention of Human Rights ECoHR?

A

The European Court of Human Rights.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What two interests was the Data Protection Directive designed to protect?

A

Individual rights to privacy and the internal European market.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
True or False: Unlike the original Convention 108, Convention 108+ is only available for signature to European nations.
False. Both are available to signature to all nations. There are currently 4 non-European signatories to Convention 108+.
26
What institution is charged with setting the political direction of the European Union?
European Council
27
In what year was the GDPR initially proposed?
The year 2012
28
What are the two exceptions permitting the use of web cookies without first obtaining user consent?
(1) When the use of cookies is **"strictly necessary"** for the provision of the service requested; and (2) When cookies are used for the sole purpose of carrying out the **transmission of a communication**.
29
True or False: One of the most important differences between the Data Protection Directive and the GDPR is that the GDPR has an expanded jurisdictional scope.
True
30
Does the **European Convention on Human Rights** consider the right to privacy to be an absolute right?
No. Article 8, which protects individual privacy, provides the right **can be limited** for certain public purposes.
31
What does the **ePrivacy Directive** regulate?
"The **processing** of personal data in connection with the provision of **publicly available electronic communications services** in public communications networks” within the E.U. *Privacy and confidentiality aspects of electronic communications, including rules for electronic marketing, the use of cookies and similar tracking technologies, and the confidentiality of communication data.*
32
What is an **"information society service"?** Dienst der Informationsgesellschaft
“[A]ny service normally provided for payment, at a distance, **by electronic means** and at the individual request of a recipient of services.” Online Dienstleistungen die Informationen über das Internet bereitstellen
33
True or False: Each member of the Council of the European Union is always entitled to one vote.
False. In some cases members get one vote each, but in others each member gets a number of votes proportionate to the number of citizens it represents.
34
How does the E.U. guarantee that member states enact legislation to enact a directive?
The European **Commission** may bring an **infraction** proceeding against a member state that fails to comply.
35
True or False: The ePrivacy Directive applies to electronic communication services that are publicly available and those that are not publicly available, such as internal intranet systems.
False. The ePrivacy Directive applies only to the processing of personal data over publicly available communication networks.
36
What does Article **10** of the **European Convention on Human Rights** seek to protect?
The right to **opinion** and **free expression**.
37
True or False: Like the UDHR and the ECHR, the Charter of Fundamental Rights recognizes that rights must be balanced against one another.
True
38
What two documents were amended by the Treaty of Lisbon?
(1) The Treaty Establishing the European Community; and (2) The Treaty on European Union.
39
In what year was the Universal Declaration of Human Rights **UDoHR** adopted?
1948
40
What is the primary reason that the European Court of Justice struck down the **Data Retention Directive** as invalid?
Because it violated the proportionality principle of the Charter of Fundamental Rights, as **no limits were placed on the obligation to retain data**.
41
Why is Article **94** of the GDPR important?
It clarified that prior references to the Data Protection **Directive** in other legislation **should be construed as a reference to the GDPR**.
42
What did the European Court of Human Rights hold in **Haralambie v. Romania**?
That placing obstacles in the way of an applicant seeking access to their secret personal file violated Article 8 of the ECHR.
43
What is another name for the Treaty Establishing the **European Economic Community** (EEC)?
Treaty of Rome
44
What is the primary responsibility of the **European Court of Human Rights**? **ECoHR**
To **enforce** the European **Convention on Human Rights**, along with Convention **108** and its amendments.
45
What are the primary goals of the **NIS** Directive?
(1) To promote **good risk management** systems; and (2) to facilitate **cooperation** among member states on **digital threats**.
46
Does the **E-Commerce** Directive apply if no remuneration is exchanged between a user and a service provider?
Yes, because an information society service includes all activities that may **“represent an economic activity”** regardless of whether they give rise to online contracting between the provider and recipient.
47
Why was the adoption of the **Data Protection Directive** an important inflection point for European data protection?
Many nations had **failed to ratify Convention 108**. The Directive therefore made each member state **legally obligated to pass data protection legislation.**
48
Was the **Data Protection Directive** designed more to target data controllers or data processors?
Data Controllers
49
In what year was the **Data Protection Directive** enacted?
1995
50
What are the common names of the three legislative procedures under the Treaty on European Union?
**Ordinary** Procedure **Consultative** Procedure **Consent** Procedure
51
What two primary factors led to the creation of data protection laws in Europe?
**Advances in technology**, and an increase in **transborder trade**.
52
What **entities** are subject to regulation under the **ePrivacy** Directive?
All **"electronic communication services,"** which includes telecommunication services and communications made over the internet, email, faxes, etc.
53
The **Digital Services Act** is proposed legislation that would **replace** what other law?
**E-Commerce** Directive
54
What treaty created the **European common market**?
The Treaty Establishing the **European Economic Community** (a/k/a The Treaty of **Rome**).
55
Other than traffic data, in what two instances may **location data be lawfully processed** under the **ePrivacy** directive?
When the user or subscriber has **consented** or when the data is **anonymized**.
56
True or False: Signing Convention 108+ makes it more likely that a non-member state will be found to provide an "adequate" level of privacy protection for purposes of international data transfers.
True
57
What did the **ECJ** hold in the **Tele2 and Watson** case?
That the **ePrivacy** Directive **prohibits the general and indiscriminate retention of data**, even if this is permitted under national legislation for the purposes of fighting crime.
58
On what two conditions does Convention **108 permit** member nations to place **limits** on **transborder data flows** between other member states?
When a country has **specific laws applicable to certain categories of personal information,** or when a member state is used as a **conduit through which to transfer data** from a non-member state.
59
What is the **"ordinary"** procedure of the legislative process in the E.U.?
Where both the **Parliament and the Council agree** to the proposed legislation.
60
What does Article **12** of the Universal Declaration of Human Rights **UDoHR** seek to protect?
The **private life of individuals**, including - Privacy, - Family, - Home, and - Correspondence.
61
What does Article 8 of the European Convention on Human Rights seek to protect? **ECoHR**
The individual right to private life.
62
What institution plays the primary **executive role** in the **EU**.
European **Commission**
63
In what year was the **ePrivacy** Directive adopted?
2002
64
What are Fair Information Practices **FIP**?
A set of **principles and practices** that describe how best to approach the - collection, - storage, and - management of data to properly balance - fairness, - privacy, and - security with respect to that data.
65
What is the current status of the Data Protection **Directive**?
It was **repealed and replaced** by the GDPR in 2016.
66
True or False: The Council of the European Union must conduct all of its business in public.
False. When the Council **votes and debates on legislation**, it must do so in **public**. The treaties silence on other issues suggests the Council may conduct other business privately.
67
What was the primary goal of the E-Commerce Directive?
To **strengthen the internal market** of Europe by fostering a **healthy online economic environment**.
68
What aspect of the Charter of Fundamental Rights was incorporated into the underlying treaties establishing the European Union?
Article 8's right to the protection of personal information was incorporated into the Treaty on the Functioning of the European Union.
69
After the Treaty of Lisbon was signed, what is the new name given to the Treaty Establishing the European Economic Community?
The Treaty on the Functioning of the European Union.
70
Resolution 74/29 set forth principles governing the handling of personal information in automated data banks. Was it addressed toward the public of private sector?
Public sector
71
72
European Commission
Initiates legislative proposals. Represents the EU on the international stage. Consists of commissioners from each member state.
73
European Parliament
Represents the citizens of the EU. Participates in the legislative process by reviewing and amending proposals. Votes on proposed legislation.
74
Council of the European Union
Represents the member states' governments. Shares legislative power with the Parliament. Approves, amends, or rejects legilative proposals.
75
European Council
Comprises heads of state or government of member states. Sets the general political direction and priorities of the EU. Provides guidance on important issues.
76
Court of Justice of the European Union:
Ensures the uniform application of EU law. Interprets EU law and settles disputes between member states and institutions
77
European Central Bank:
Responsible for the euro currency and monetary policy within the Eurozone.
78
European Court of Auditors
Checks that the EU funds have been correctly spent, efficiently managed, and properly accounted for.
79
What does Article **67(3) of the Treaty on the Functioning of the European Union** call for?
Cooperation and coordination between **police and judicial authorities** across the E.U.
80
Under the E-Commerce Directive, information society services are subject to the local law of what member state?
The law of the member state in **which they are established**; not the laws of members states in which the service is accessible.
81
Other than changes related to the use of web cookies, what two other important amendments were made to the ePrivacy Directive in 2009?
(1) Service providers were required to provide certain **notice** in the event of a data breach; and (2) A **private cause of action** was provided to subscribers receiving unsolicited advertisements.
82
What other piece of legislation was proposed by the Commission at the same time it proposed the General Data Protection Regulation?
The Law Enforcement Data Protection Directive (LEDP Directive).
83
84
What was the primary reason that the Parliament and the Council expanded the scope of the ePrivacy Directive in comparison to its predecessor?
These bodies recognized that personal data should be protected in a consistent manner no matter what specific form of communication is utilized.
85
At what point must traffic data be erased or anonymized under the ePrivacy Directive?
When the traffic data is no longer needed for the purposes of the transmission, except as needed for billing, marketing, fraud detection, or similar services.
86
A clause in a regulation that permits member states to enact supplemental or more specific legislation is referred to as what?
An "opening clause."
87
What type of consent is required to engage in most digital marketing under the ePrivacy Directive?
Opt-in consent.
88
True or False: All data processed under the Data Governance Act must be done in compliance with the GDPR.
False. The Data Governance Act covers the processing of both personal and non-personal data; only processing of personal data is regulated by the GDPR.
89
In what case did the European Court of Justice hold that certain parts of the Data Protection Directive were "directly applicable" upon their own force and effect?
The Rechnungshof case.
90
Does the EDPB interpret the term "explicit consent" as used in the Payment Services Directive 2 as having the same meaning as that term under the GDPR?
No. The EDPB considers the term "explicit consent" in the PSD2 as imposing an additional requirement of "contractual consent."
91
Who does the E-Commerce Directive apply to?
"Information society services."
92
How many categories of risk-level are set forth in the AI Act?
There are four (4) levels of risk: - minimal risk, - limited risk, - high risk, and - unacceptable risk.
93
True or False: The LEDP Directive is intended to protect only the personal data of criminal victims.
False. The LEDP Directive calls for the protection of personal data of all individuals, regardless of his or her role in the criminal justice system.
94
Why was it necessary to include more than 50 different "opening clauses" into the GDPR?
In order for the Parliament and the Council to reach political agreement during the legislative process.
95
What are the two primary purposes of the LEDP Directive?
(1) It protects the natural rights and freedoms of natural persons; and ( 2) It facilitates the exchange of personal data by competent authorities.
96
True or False: The ePrivacy Directive requires a strict set of security controls be implemented by electronic communication services in all instances.
False. The ePrivacy Directive requires "appropriate technical and organisational" controls be adopted that are "appropriate to the risks presented."
97
What was the first legally binding agreement that addressed "how" privacy should be protected?
Convention 108
98