What is fair processing information?
Information controllers provide to data subjects about how their personal data is processed.
What legal effects can result from ADM?
Outcomes impacting rights or obligations.
Examples: credit scoring or benefits eligibility
When must notice be provided for secondary processing?
What are the controller’s obligations regarding notice?
What are the qualities of fair processing information?
What are acceptable mediums for providing notice?
What are examples of excessive requests?
What visual formats can be used in notices?
What are the requirements for visual notices?
They must simplify communication and be machine readable.
What must a user do before an organization stores or accesses data on their terminal equipment?
Provide consent
What does ‘similar technology’ include under the ePrivacy Directive?
What is a layered notice?
What is a just-in-time notice?
Provided at the point of collection.
What is a dashboard notice?
Web-based interface allowing users to toggle privacy options, e.g., social media settings.
What are key requirements for the Data Protection Officer (DPO)?
Who must the DPO report to?
The highest management level
What is the role of the DPO in relation to supervisory authorities?
What is considered a ‘third country’ under the GDPR?
Any country outside the EU/EEA
What is considered a ‘transfer’ under GDPR?
When personal data is intentionally sent or made accessible by a GDPR-subject organization to a third country or international organization.
Examples: using US-based cloud storage, outsourcing IT to Ukraine, using US email service for newsletters
What is considered ‘transit’ under GDPR?
Passage of personal data through an intermediary without access or processing ability.
Example: email routed through US infrastructure with no access by intermediary
What are the 3 factors to consider for adequacy?
What framework guides the Commission’s adequacy decision?
The WP29’s Adequacy Referential
What is the designation procedure for adequacy?
How often are adequacy decisions reviewed?
At least every 4 years.