What are the OECD Guidelines on protection of privacy and trans-border flow of personal data?
What are the GDPR processing principles?
Defined by Article 5 of the GDPR
1. Lawfulness, fairness and transparency
2. Purpose limitation
3. Data Minimization
4. Accuracy
5. Storage Limitation
6. Integrity and Confidentiality
7. Accountability
What is data processing?
Defined by Article 4 (2)
- Any operation on data whether automated or manual
- Collecting, Storing, Using, Sharing, Deleting etc.
What is the territorial scope of the law?
GDPR applies when (Article 3):
1. Controller or Processer is established in the EU AND the context of the processing is related to that establishment.
2. Data subjects in the EU and the DC or DP is processing data in relation to offerings of goods/services or DS is in the EU and DC&DP are monitoring behavior in the EU - this applies even if the DC & DP are not in the EU.
3. Controller not in the Union but in a place where member law applies by virtue of public international law.
What is the material scope of the law?
GDPR applies when (Article 2):
- Personal data is processed by automated or manual means
Exclusions are:
* Activities outside scope of EU law - e.g. national security activities
* Law enforcement and public security
* Purely personal or household activities
What are the lawful grounds for processing personal data?
Six criteria defined by Article 6 of GDPR:
1. Consent
2. Performance of a contract - e.g. to complete a sale
3. Compliance with a legal obligation - e.g. an EU law.
4. Protect the vital interest of a data subject - e.g. to render critical medical assistance
5. Performance of a task in the public interest or exercise of authority - e.g. tax collection
6. Legitimate interests of the controller/3rd party balanced with the rights of the data subject -e.g. a company keeps an address book for its employees to reach each other.
What are the characteristics of consent that is a valid basis for processing personal data?
Best not to rely on consent as a basis.
Employer-employee relations are inherently unequal and employers will find it difficult to claim that consent was freely given. Same with children who may not have the capacity to give consent.
Controller must keep a record of the consent.
When is consent not an acceptable basis for processing personal data?
GDPR Principles - what is lawfulness, fairness and transparency mean?
GDPR Principles - what is Purpose Limitation?
Data Controllers must only collect and process personal data to accomplish specified, explicit and legitimate purpose.
Any secondary purpose requiring further processing must be compatible with the original stated purpose. Or else, new consent/legal basis is required to do so.
GDPR Principles - what is Data Minimization?
GDPR Principles - what is Data Accuracy?
Controllers must take reasonable measures to ensure the data is accurate and, where necessary, kept up to date.
GDPR Principles - what is Storage Limitation?
Personal data must not be kept for longer than necessary for the purposes for which the personal data is processed.
GDPR Principles - what is Integrity and Confidentiality?
Personal data must be ‘processed in a manner that ensures appropriate security of the personal data. Use of technical and organizational measures.
Requirement to implement a information security framework.