GDPR - High level Flashcards

(30 cards)

1
Q

What is the scope/goals of GDPR?

A
  • Protect fundamental rights
  • Free movement of personal data

GDPR aims to safeguard individuals’ personal data and ensure its free flow within the EU.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does Art 2 of GDPR cover?

A
  • Processing of personal data
  • Wholly/partly automated systems
  • Non-automated filing systems

This article defines the material scope of GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When does GDPR apply according to Art 3?

A
  • EU establishments
  • Offering goods/services in the EU
  • Monitoring behavior of persons in the EU

This article outlines the territorial scope of GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Define the key terms in Art 4 of GDPR.

A
  • Personal data
  • Processing
  • Controller
  • Processor
  • Consent
  • Special categories
  • Pseudonymisation

These definitions are crucial for understanding GDPR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

List the principles relating to processing as per Art 5.

A
  • Lawfulness
  • Fairness
  • Transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity/confidentiality
  • Accountability

These principles guide the processing of personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the legal bases for processing under Art 6?

A
  • Consent
  • Contract
  • Legal obligation
  • Vital interests
  • Public task
  • Legitimate interests

These bases justify the lawful processing of personal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What conditions must be met for consent according to Art 7?

A
  • Freely given
  • Specific
  • Informed
  • Unambiguous
  • Recordkeeping
  • Easy withdrawal

Consent must be clear and easily revocable.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the age threshold for parental consent under Art 8?

A

Default 16, can be lowered to 13

This applies to information society services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Under what conditions can special categories of data be processed according to Art 9?

A
  • Explicit consent
  • Employment law
  • Vital interests
  • Public interest

Processing of special categories is generally prohibited except for specific exceptions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does Art 10 state about processing of criminal conviction data?

A
  • Only under official authority
  • Safeguards required
  • Member State law needed

This article regulates the handling of sensitive criminal data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

When is a controller not required to identify a data subject as per Art 11?

A

When identification is not possible

This limits the rights of data subjects in such cases.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What must a controller provide under Art 12?

A
  • Concise information
  • Transparent communications
  • No undue delay

This ensures data subjects are informed about their rights and processing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What information is required when data is collected from the data subject as per Art 13?

A
  • Identity
  • Purposes
  • Legal basis
  • Recipients
  • Retention
  • Rights
  • Transfers

This article mandates transparency at the point of data collection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What additional information must be provided when data is not collected from the data subject according to Art 14?

A
  • Source info
  • Categories of data
  • Lawful basis
  • Possible lack of access reasons

This ensures transparency even when data is sourced externally.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What rights does a data subject have under Art 15?

A
  • Confirm processing
  • Access copies
  • Purposes
  • Categories
  • Recipients
  • Retention
  • Rights
  • Source
  • Profiling info

This article outlines the right of access for data subjects.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the right to rectification as per Art 16?

A

Right to correct inaccurate or incomplete data without undue delay

This ensures data accuracy for individuals.

17
Q

What conditions apply to the right to erasure under Art 17?

A
  • Consent withdrawn
  • Unlawful processing
  • Compliance with legal obligation

This is also known as the right to be forgotten.

18
Q

What does Art 18 state about the right to restriction of processing?

A
  • Temporarily limit processing when accuracy contested
  • Unlawful processing
  • Pending legal basis dispute

This right allows individuals to restrict how their data is used.

19
Q

What is the notification obligation regarding rectification/erasure/restriction in Art 19?

A

Controller must inform recipients of changes unless impossible or disproportionate

This ensures accountability and transparency.

20
Q

What is the right to data portability as per Art 20?

A

Right to receive personal data in structured, commonly used, machine-readable format

This allows individuals to transmit their data to another controller.

21
Q

What does Art 21 state about the right to object?

A
  • Object to processing based on public interest
  • Object to direct marketing at any time

This right empowers individuals to control their data usage.

22
Q

What does Art 22 say about automated individual decision-making?

A

Right not to be subject to solely automated decisions with legal/effective significant effects

There are exceptions to this right.

23
Q

What are the restrictions mentioned in Art 23?

A

Member State or Union law may restrict certain GDPR rights for public interests

These restrictions must be under safeguards.

24
Q

What is the responsibility of the controller as per Art 24?

A

Implement appropriate technical/organizational measures for compliance

This ensures accountability in data processing.

25
What does **Art 25** state about **data protection by design and by default**?
Integrate data protection principles into processing and default minimisation ## Footnote This promotes proactive data protection measures.
26
What are the obligations of **joint controllers** according to **Art 26**?
Define respective responsibilities via arrangement * Inform data subjects about essence of agreement ## Footnote This ensures clarity in data processing responsibilities.
27
What must representatives of controllers/processors not established in the Union do as per **Art 27**?
Appoint EU representative unless exceptions apply ## Footnote This ensures accountability for non-EU entities.
28
What are the **processor obligations** under **Art 28**?
* Process only on documented instructions * Ensure security * Use subprocessors with contract * Assist controller * Keep records ## Footnote These obligations ensure processors act in compliance with GDPR.
29
What does **Art 29** state about processing under the authority of the controller/processor?
Persons authorized to process must follow instructions and confidentiality ## Footnote This ensures that data is handled securely and according to the controller's directives.
30
What must controllers/processors maintain according to **Art 30**?
Records of processing activities, including: * Purposes * Categories * Transfers * Security ## Footnote Small organizations with limited processing are exempt from this requirement.