What is the scope/goals of GDPR?
GDPR aims to safeguard individuals’ personal data and ensure its free flow within the EU.
What does Art 2 of GDPR cover?
This article defines the material scope of GDPR.
When does GDPR apply according to Art 3?
This article outlines the territorial scope of GDPR.
Define the key terms in Art 4 of GDPR.
These definitions are crucial for understanding GDPR.
List the principles relating to processing as per Art 5.
These principles guide the processing of personal data.
What are the legal bases for processing under Art 6?
These bases justify the lawful processing of personal data.
What conditions must be met for consent according to Art 7?
Consent must be clear and easily revocable.
What is the age threshold for parental consent under Art 8?
Default 16, can be lowered to 13
This applies to information society services.
Under what conditions can special categories of data be processed according to Art 9?
Processing of special categories is generally prohibited except for specific exceptions.
What does Art 10 state about processing of criminal conviction data?
This article regulates the handling of sensitive criminal data.
When is a controller not required to identify a data subject as per Art 11?
When identification is not possible
This limits the rights of data subjects in such cases.
What must a controller provide under Art 12?
This ensures data subjects are informed about their rights and processing.
What information is required when data is collected from the data subject as per Art 13?
This article mandates transparency at the point of data collection.
What additional information must be provided when data is not collected from the data subject according to Art 14?
This ensures transparency even when data is sourced externally.
What rights does a data subject have under Art 15?
This article outlines the right of access for data subjects.
What is the right to rectification as per Art 16?
Right to correct inaccurate or incomplete data without undue delay
This ensures data accuracy for individuals.
What conditions apply to the right to erasure under Art 17?
This is also known as the right to be forgotten.
What does Art 18 state about the right to restriction of processing?
This right allows individuals to restrict how their data is used.
What is the notification obligation regarding rectification/erasure/restriction in Art 19?
Controller must inform recipients of changes unless impossible or disproportionate
This ensures accountability and transparency.
What is the right to data portability as per Art 20?
Right to receive personal data in structured, commonly used, machine-readable format
This allows individuals to transmit their data to another controller.
What does Art 21 state about the right to object?
This right empowers individuals to control their data usage.
What does Art 22 say about automated individual decision-making?
Right not to be subject to solely automated decisions with legal/effective significant effects
There are exceptions to this right.
What are the restrictions mentioned in Art 23?
Member State or Union law may restrict certain GDPR rights for public interests
These restrictions must be under safeguards.
What is the responsibility of the controller as per Art 24?
Implement appropriate technical/organizational measures for compliance
This ensures accountability in data processing.