Datafication 10 Flashcards

1
Q

2 systems to ensure compliance

A

1) Authorities
2) Sanctions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Supervision through Authorities

A

1) European Data Protection Board (EDPB
2) National Supervisory / Data Protection Authority (DPA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

European Data Protection Board (EDPB)

A
  • independent EU body
  • contributes to consistent application of data protection rules
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

European Data Protection Board (EDPB) - composition

A

1) representatives of national DPAs &
2) European Data Protection Supervisor (EDPS)
3) Supervisory authorities of EFTA EEA States (but no right to vote & (deputy) chair)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

European Data Protection Board (EDPB) - Tasks / Responsibility (more in Art. 70):

A
  • Advice EU Commission
  • Issue legally binding decisions
  • Issue guidelines, recommendations & best practices (annual report including reviewing practical applications of those)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

National Supervisory / Data Protection Authority (DPA)

A

independent public authority(ies) which each Member State is required to provide

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

National Supervisory / Data Protection Authority (DPA) - task

A
  • Monitor, enforce & promote public awareness
  • annual report on its activities ( transparency)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

National Supervisory / Data Protection Authority (DPA) - requirements

A
  • Independency from external influence: law underlying it & organizational structure
  • no conflict of interests
  • sufficient resources & capabilities
  • choose own sfaff
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Lead Supervisory Authority

A
  • NSA of main establishment of dc or dp is competent to act as lead
  • for cross-border processing (when dc has establishments in several & processing affects ds in different member states)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Main establishment of dc or dp when establishments in > 1 Member State

A

= Place in EU
a) dc:
- where decisions on purposes & means of processing pd take place
- Otherwise: of its central administration
b) dp:
- of its central administration
- Otherwise: where main processing activities in context of activities of an establishment of the dp take place

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

e.g. main establishment Fb?

A

Ireland: established company in Ireland -> benefiting form GDPRs principles of free pd movement in EU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

e.g. main establishment Google?

A
  • established in California, sales offices in number of EU Member States
  • Google Spain case: CJEU found Google Inc. (dp established in US) along with its establishment in Spain (Google Spain) were processing pd “in context of activities of an establishment” in Spain
  • undisputed Google Spain was not (directly) involved in processing but promote & sell advertising space offered by the search -> used economically profitable
  • CJEU: directive applicable to processing done by Google to protect guaranteed protection by earlier Data Protection Directive & prevent excuse by having board territorial scope
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Relationship LSA & other DPAs

A
  • LSA can request assistant from other DPAs
  • DPAs can raise reasonable objects to draft decision, LSA can decide to follow or not
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

One stop shop (OSS) mechanism

A
  • if company conducts cross-border data processing
  • required to work primarily with the SA based in same Member State as companies main establishment (usually EU headquarters) to achieve compliance
  • aim: improve harmonization & consistency application in all Member States
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

e.g. Google Ireland Limited by French supervisory authority fine 53 mil. Euro

A
  • Frech DPA checked complains in other Member States if lead already appointed
  • as non-claimed lead (also not Irish) they took the case
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Ds (or non-profit entities on behalf of 1 or more ds) right to enforce

A
  • lodge complaint with SA in Member State of residence, place of work or place of alleged infringement if feels like pd not handled accordingly
  • effective judicial remedy against a SA (bring a decision from SA before court if Member State where SA established)
  • effective judicial remedy against a dc or dp (proceedings where dp or dc has establishment or in Member state of ds)
17
Q
  1. Sanctions
A
  1. Fines
  2. Art. 8: ds right to claim compensation from dc or dp for damage suffered
  3. Art. 58: Supervisory Authority corrective powers
18
Q

Sanctions - Fines

A
  • Requirement: effective, proportionate & dissuasive
  • levels: 1. up to 10 Mio Euro or 2% of total worldwide annual turnover of preceding financial year (what is higher), 2. Up to 20 Mio. Euro or up to 4%
  • Amount & Type depends on number of factors (e.g. nature of the breach, degree of fault, prior breaches, actions of dc & dp after mistake, cooperation with SA)
19
Q

Sanctions - Supervisory Authority corrective powers

A
  • Orders & warnings to dc or dp
  • Order to communicate pd breach to ds
  • Temporary or definitive limitation (including ban on processing)
  • Order rectification, restriction, or erasure of pd
  • Suspension of data flows to recipient in 3rd country or international organization