What is joint controllership?
When two or more entities jointly determine the purposes and means of processing.
What is a converging decision in joint controllership?
Independent but complementary decisions that are inextricably linked and necessary for the processing.
What is the significance of the Fashion ID case?
It demonstrated joint controllership.
Concerned the integration of a social media plug-in where both retailer and platform influenced data processing.
What factors determine joint controllership?
What is a best practice for identifying joint controllership?
What is the definition of personal data under the GDPR?
Any information relating to an identified or identifiable natural person.
What are the 4 parts of the definition of personal data according to WP29 Opinion 4/2007?
What are the 3 features used to determine if information is personal data?
What types of statements fall under ‘Nature’ in personal data analysis?
Objective: e.g., education, experience
Subjective: e.g., work quality, collegiality
What types of information constitute ‘Content’ in the context of personal data?
Private life and public/professional activities
What does ‘Format’ include under the definition of personal data?
Any form, whether processed by automated means or manually in a filing system.
What qualifies as ‘automated means’ in data processing?
Systems that operate automatically without human intervention.
What is a ‘filing system’ under GDPR?
A structured set of personal data accessible by specific criteria, such as alphabetical or numeric order.
Examples: employee files, medical records, customer orders, student records
What does ‘relating to’ mean in the context of personal data?
It involves linkability between the data and the individual based on context.
According to WP29 Opinion 4/2007, what are the 3 ways data can relate to a person?
What does the ‘Content’ criterion mean?
Data is inherently about or describes an individual.
E.g., medical report or passport
What does the ‘Purpose’ criterion mean?
Data is used or intended to evaluate, treat, or affect a person, even if not inherently about them.
What does the ‘Result’ criterion mean?
Processing affects a person’s rights, interests, or status.
E.g., through fleet tracking or surveillance
Does the GDPR apply to anonymized data?
No, as long as all personal identifiers have been removed.
Does the GDPR apply to pseudonymized data?
Yes, even though direct identifiers are removed.
What is pseudonymization?
A process that removes direct identifiers and keeps them separate to prevent re-identification.
What is aggregation in the context of data?
Combining and summarizing data from multiple sources into a high-level format.
Does the GDPR define the term ‘natural person’?
No, the definition is left to member states.
According to Recital 27, does the GDPR apply to deceased persons?
No