New European General Data Protection Regulation
A Practitioner's Guide- Authors:
- ,
- Publisher:
- 30.11.2017
Summary
The European General Data Protection Regulation introduces a uniform data protection legislation which will apply directly in all European Members States and which will also have to be observed by numerous companies outside the EU who have business in the EU. The new Regulation will essentially replace the national data protection legislation in the member states which has applied to date. Companies have two years to adapt their business models and processes to the new requirements.
The handbook “The European General Data Protection Regulation and its Impact on Corporate Practice”clearly and concisely addresses the key changes resulting from the General Data Protection Regulation in English. The data protection requirements the Regulation places on typical business processes and rapidly spreading new technologies are explained using practically relevant examples.
The handbook therefore provides the ideal basis for legal counsels and all international companies affected by the Regulation to review their existing business processes and ensure that new processes and business models are in line with these new data protection requirements.
This practical business handbook focuses on the following issues which are relevant for any company affected by the new Regulation:
- Scope and logic of the General Data Protection Regulation and remaining areas regulated at national level
- Mandatory data protection impact assessment
- Appointment of a data protection officer
- Transfer of personal data to third countries
- Cloud computing, outsourcing
- Advertising and data protection
- Profiling and big data analysis
- Requirements placed on IT security
- Information and reporting obligations
- Data breach notifications
- Rights of persons affected
- Liability and sanctions for data protection breaches
Keywords
Search publication
Bibliographic data
- Publication year
- 2017
- Publication date
- 30.11.2017
- ISBN-Print
- 978-3-8487-3262-3
- ISBN-Online
- 978-3-8452-7609-0
- Publisher
- Nomos, Baden-Baden
- Series
- Kooperationswerke Beck - Hart – Nomos
- Language
- German
- Pages
- 291
- Product type
- Comment
Table of contents
- Titelei/Inhaltsverzeichnis Pages I - XXVIII Download chapter (PDF)
- 1. Key steps within the legislative procedure No access
- a) Harmonisation of the level of protection No access
- b) Adaption to the technical progress No access
- c) Strengthening the rights of data subjects No access
- d) Free movement of personal data No access
- e) One-Stop-Shop-Principle No access
- aa) Legislative power and legal basis for adopting the GDPR No access
- bb) Fundamental rights in context with data protection No access
- b) Direct Applicability No access
- a) Need for a uniform European interpretation No access
- (1) Actual wording of the GDPR No access
- (2) Statements of supervisory authorities No access
- (3) Statements issued by the European Data Protection Board and the Art. 29 Working Party No access
- bb) Other suitable sources for interpreting the GDPR No access
- II. Importance of the GDPR for companies No access
- aa) Definition of “Processing” No access
- bb) Processing by manual means No access
- aa) Limits of applicability resulting from the technical way of processing No access
- bb) Household exemption No access
- a) “Any information” suitable for potentially being personal data No access
- b) Relationship required between the information and the data subject No access
- aa) Identified natural person No access
- (1) Direct or indirect identifiability No access
- (2) Criteria for determining indirect identifiability No access
- (3) Decision of the European Court of Justice on IP addresses No access
- d) Anonymous and anonymised data No access
- e) Pseudonymisation No access
- f) Encrypted data No access
- a) Dead persons No access
- aa) No protection under the GDPR No access
- bb) Indirect protection and protection under national law No access
- 4. Consequences of inapplicability of the GDPR No access
- a) Determination of the responsible body – natural person, legal person or any other body No access
- (1) Determination by law No access
- (2) Determination by way of factual influence No access
- bb) “Purposes and means” of data processing No access
- cc) Determination of the “purposes”/“why” of processing No access
- dd) Determination of the “means”/“how” of processing No access
- aa) Requirements for joint control under the GDPR No access
- (1) No privilege for transferring personal data between joint controllers No access
- (2) Transparent allocation of responsibilities No access
- (3) Joint liability No access
- aa) No factual influence of the processor on determining the purposes and means of processing No access
- bb) Processor subject to the instructions of the data controller No access
- cc) Factual compliance with the instructions of the data controller No access
- aa) Mandate of the processor No access
- bb) Choice of the right processor – provision of sufficient guarantees by the processor No access
- cc) Processing contract No access
- dd) Necessary content of a processing contract No access
- aa) Appropriate technical and organisational measures No access
- bb) Data protection officer No access
- cc) Records of processing activities No access
- d) Lawfulness of a data transfer to a data processor No access
- e) Consequenceach of the contractual relationship for the processor No access
- f) How to handle former mandates No access
- 3. Micro, small and medium-sized enterprises No access
- 1. Companies with an establishment in the EU (GDPR, art. 3, para 1) No access
- a) Offering of goods or services to data subjects in the EU No access
- b) Monitoring the behaviour of subjects in the EU No access
- 3. Application by virtue of public international law (GDPR, art. 3, para 3) No access
- 4. Summary assessment on changed scope of application No access
- 1. Basic principle: direct application of the Regulation irrespective of many opening clauses No access
- a) Data processing in employment contexts, GDPR, art. 88 No access
- b) Designation of a data protection officer in cases other than GDPR, art. 37, para 1 No access
- c) Processing carried out in the public interest or in compliance with a legal obligation No access
- d) Automated decisions and profiling No access
- e) Joint controllers No access
- f) Further examples No access
- 3. Data protection for online and electronic communication services No access
- 4. Data protection at public bodies No access
- aa) General prohibition of processing personal data No access
- bb) Legitimate basis for processing personal data as an exception No access
- b) Notion of fairness No access
- c) Notion of transparency No access
- d) No principle of collecting personal data directly from the data subject No access
- aa) “Specified” purpose No access
- bb) “Explicit” purpose No access
- cc) “Legitimate” purpose No access
- aa) (In)compatibility test requirement No access
- bb) Notion of “further processing” and scope of compatibility test No access
- (1) Assumed compatibility of further use for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes No access
- (2) Explicit legal exceptions from compatibility test No access
- (1) No change of purpose No access
- (2) Change of purpose No access
- (1) Link between the purposes No access
- (2) Context in which the personal data have been collected No access
- (3) Nature of the personal data No access
- (4) Possible consequences of the intended further processing No access
- (5) Existence of appropriate safeguards No access
- (1) Consequences of incompatibility No access
- (2) Consequences of compatibility No access
- gg) Documentation of compatibility test No access
- a) Notion of “necessity” No access
- b) Anonymisation and pseudonymisation No access
- c) Concept of data protection by design and by default No access
- a) Notion of “accurate data” No access
- b) Updating of inaccurate data No access
- c) Erasure and rectification of inaccurate data No access
- a) Notion of “necessity” No access
- b) Exception for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes No access
- c) Erasure, restriction and anonymisation of personal data no longer necessary No access
- d) Processing which does not require identification No access
- 6. Integrity and confidentiality No access
- a) Notion of accountability No access
- b) Possibilities to demonstrate compliance No access
- 1. Relevance and importance of the different legal grounds of the GDPR for processing of personal data from a business perspective No access
- aa) Performance of a contract to which the data subject is party No access
- bb) Steps at the request of the data subject prior to entering into a contract No access
- aa) Sources for legal obligations No access
- bb) Quality of legal basis and additional national provisions No access
- c) Vital interests No access
- aa) Relevance for the private sector No access
- bb) Legal basis for public interests or official authority No access
- cc) Quality of legal basis and additional national provisions No access
- aa) Legitimate interests pursued by the controller or by a third party No access
- bb) Interests or fundamental rights and freedoms of the data subject No access
- (1) Assessment of nature and source of the legitimate interest No access
- (2) Assessment of impact on data subjects No access
- (3) Provisional balance No access
- (4) Assessment of additional safeguards and final balance No access
- (5) Documentation of balance test No access
- (1) Statement or clear affirmative action No access
- (2) Written or oral consent No access
- (3) Consent by electronic means No access
- (4) Implied consent No access
- (5) Limitation to processing of personal data of the data subject No access
- (1) Clear imbalance between controller and data subject No access
- (2) Horizontal and vertical restriction of interconnection No access
- cc) Specific No access
- dd) Informed No access
- ee) Unambiguous No access
- b) Consent in the context of a written declaration which also concerns other matters No access
- (1) Information society services No access
- (2) Direct offer to a child No access
- (3) Age thresholds No access
- (4) Age and authorisation verification mechanisms No access
- bb) Other consent of children and other data subjects lacking full legal capacity No access
- d) Ability to demonstrate consent No access
- e) Right to withdraw consent No access
- f) Need for adaption and obtaining renewed consent No access
- a) Additional requirement of a legal ground No access
- b) Explicit consent No access
- c) Statutory exceptions No access
- d) Further conditions pursuant to Member State law No access
- 5. Processing of personal data relating to criminal convictions and offences No access
- 1. Company as controller No access
- a) Definition No access
- b) Forms No access
- aa) Fulfilment of data subject’s rights No access
- bb) Fulfilment of obligations to inform pursuant to GDPR, art. 13 and 14 No access
- d) Formal requirements, GDPR, art. 26, para 2, sentence 2 No access
- e) Joint and several responsibility and liability vis-a-vis data subject No access
- f) Administrative fine No access
- a) Principle: no group privilege No access
- b) Group privilege via concept of joint controllers No access
- c) Affiliation as a reasonable interest within GDPR, art. 6, para 1, subpara f) and Recital 48 No access
- 4. Responsibility for GDPR-compliance No access
- 5. Controllers/processors not established in the European Union, GDPR, art. 27 No access
- 6. Records of processing activities, GDPR, art. 30 No access
- a) Data protection by design No access
- b) Data protection by default No access
- c) Possible measures and scope No access
- d) Administrative fine No access
- a) Risk evaluation No access
- b) Appropriate measures No access
- c) Control of subordinate natural persons No access
- d) Administrative fine No access
- a) In which cases Data Protection Impact Assessments are to be carried out? No access
- b) Minimum content of Data Protection Impact Assessments No access
- c) Prior Consultation, GDPR, art. 36 No access
- d) Administrative fines No access
- 1. Drafting codes of conduct (GDPR, art. 40, para 2) No access
- 2. Approval procedure No access
- 3. Monitoring of approved codes of conduct No access
- 4. Relevance for business entities No access
- 1. Purpose of certifications and seals (GDPR, art. 42, paras 1 and 4) No access
- 2. Voluntariness (GDPR, art. 42, para 3) No access
- 3. Certification bodies (GDPR, art. 42, para 5 and GDPR, art. 43) No access
- 4. Certification Proceeding, GDPR, art. 42, para 6 No access
- 5. Maximum term of certificate/seal, GDPR, art. 42, para 7 No access
- 6. Register for certifications, data protection seals and marks No access
- 7. Relevance of certifications or seals for companies No access
- a) Deadline for fulfilment of data subject’s rights: One month pursuant to GDPR, art. 12, para 3 No access
- b) Form requirements No access
- c) Right to determine identity of individual wishing to enforce their rights pursuant to GDPR, art. 12, para 6: Controller’s right to request a copy of the claimant’s passport No access
- d) Processing which does not require identification, GDPR, art. 11, para 2 and no right to refuse (GDPR, recital 57) No access
- e) Free of charge, GDPR, art. 12, para 5 No access
- f) Information on legal remedies available, GDPR, art. 12, para 4 No access
- g) Administrative fines No access
- a) Information duties No access
- b) Point in time No access
- c) Exceptions of the information duties No access
- d) Administrative fines No access
- a) Obligation to provide information, GDPR, art. 15, para 1 No access
- b) Right of access, GDPR, art. 15, para 3 No access
- c) Exceptions, GDPR, art. 15, para 4 No access
- d) Administrative fines No access
- a) Correction No access
- b) Completion No access
- a) Prerequisites for right to erasure pursuant to GDPR, art. 17, para 1 No access
- b) Exceptions, GDPR, art. 17, para 3 No access
- c) Right to be forgotten, GDPR, art. 17, para 2 and GDPR, art. 19 No access
- d) Administrative fines No access
- 6. Right to restriction of processing, GDPR, art. 18 No access
- a) Prerequisites No access
- b) Performance of data portability No access
- c) What means “portability”? No access
- d) Receiving data controller No access
- e) Exceptions, GDPR, art. 20, paras 3 and 4 No access
- f) Administrative fines No access
- a) Right to object to processing for direct marketing purposes No access
- b) Obligation to inform the data subject about his right to object No access
- c) Modalities to exercise the right to object No access
- d) Deadline for the controller to respond to an objection No access
- e) Right to object to processing personal data for scientific or historical research purposes or statistical purposes pursuant to GDPR, art. 89, para 1 No access
- f) Administrative fines No access
- a) Legal or similar significant effects No access
- b) Exceptions and examples No access
- c) Right to review No access
- d) Special categories of personal data No access
- e) Administrative fines No access
- a) Obligation of the controller to notification No access
- b) Minimum content and form No access
- c) Exceptions No access
- d) Administrative fines No access
- a) Concept of lead and concerned authority No access
- b) Cooperation between authorities No access
- c) Consistency mechanism GDPR, art. 63 No access
- 2. Duty to cooperate (GDPR, art. 31) No access
- 3. Data breach notification to the supervisory authorities (GDPR, art. 33) No access
- a) Tasks of the supervisory authorities No access
- b) Enforcement empowerments No access
- c) Administrative fines, GDPR, art. 83 No access
- a) Risk based approach, GDPR, art. 37, para 1 No access
- b) Criteria to appoint a DPO in GDPR, art. 37, para 1, subparas b) and c) No access
- c) Processing on a large scale No access
- d) Regular and systematic monitoring of the data subjects No access
- e) Special categories of personal data No access
- f) Data relating to criminal convictions and offences No access
- a) Controllers No access
- b) Processors No access
- 3. Infringement to appoint a DPO No access
- 4. Group privilege, GDPR, art. 37, para 2 No access
- 5. Internal/external, GDPR, art. 37, para 6 No access
- 6. Full or part time No access
- 7. Qualification, GDPR, art. 37, para 5 No access
- 8. Publication/communication contact details, GDPR, art. 37, para 7 No access
- a) Secrecy obligation No access
- b) No instructions, privileged status No access
- c) Information obligation No access
- d) Necessary resources No access
- e) Direct reporting line, GDPR, art. 38, para 3, third sentence No access
- f) Contact for data subjects No access
- a) Inform No access
- b) Monitor No access
- c) Advice No access
- d) Cooperate with authorities/contact point No access
- aa) Level 1 infringements No access
- bb) Level 2 infringements No access
- cc) Concept of “undertaking” No access
- dd) Further criteria No access
- aa) Ex officio proceedings No access
- bb) Administrative complaints (GDPR, art. 77 and 78) No access
- cc) Proceedings against data controllers and data processors (GDPR, art. 79) No access
- dd) Capacity to sue for non-profit bodies, organisations or associations mandated by the data subject (GDPR, art. 80) No access
- a) Concept of damage No access
- b) Relevant infringements No access
- c) Exemption No access
- d) Joint processing No access
- 3. Liability based on national laws No access
- a) Procedure of implementing an adequacy decision No access
- b) Adequacy decisions under Directive 95/46 No access
- c) Special case: United States (Safe Harbour/EU-U.S. Privacy Shield) No access
- aa) Binding Corporate Rules under Directive 95/46 No access
- bb) Procedure to implement Binding Corporate Rules No access
- aa) Standard Contractual-Clauses under Directive 95/46 No access
- bb) Implementation and use of Standard Data Protection Clauses No access
- c) Codes of conduct No access
- d) Certification No access
- e) Individual authorisation of contractual clauses No access
- a) Consent of the data subject No access
- b) Performance of a contract No access
- c) Interest of the data subject No access
- d) Public interest No access
- aa) Interpretation of derogation Directive 95/46, art. 26, para 1, subpara d) No access
- bb) Uniform Interpretation and framework under the GDPR No access
- cc) Transfers or disclosures not authorised by Union law No access
- f) Vital interests No access
- g) Public register No access
- h) Special justification No access
- 1. Controller or processor No access
- a) Selection of service provider and commissioning as processor No access
- aa) Standard data protection clauses No access
- bb) Binding Corporate Rules No access
- cc) Approved codes of conduct and approved certifications No access
- dd) Other measures No access
- ee) Derogations No access
- aa) Prior authorisation No access
- bb) Contract between processor and sub-processor No access
- cc) Liability No access
- aa) Processor and sub-processor in third countries No access
- bb) Processor in the EU and sub-processor in a third country No access
- a) Cloud computing rollout and service models No access
- aa) Roles and responsibilities of parties involved No access
- bb) Commissioning as data processing and sub-processing No access
- cc) Documentation and information obligations No access
- a) Genetic data No access
- b) Biometric data No access
- c) Data concerning health No access
- a) Explicit Consent No access
- aa) Employment, social security and social protection law No access
- bb) Vital interests No access
- cc) Foundation, association or any other not-for-profit body No access
- dd) Personal data manifestly made public No access
- ee) Legal claims No access
- ff) Substantial public interest No access
- gg) Processing for medical purposes No access
- hh) Public interest in the area of public health No access
- ii) Archiving purposes in the public interest, scientific or historical research purposes or statistical purposes No access
- jj) Limitations in Member State law No access
- 3. Additional protective measures No access
- 1. Definition of direct marketing No access
- 2. Direct Marketing in Directive 95/46 and the GDPR No access
- a) Directive 2002/58/EC (ePrivacy-Directive) No access
- b) Directive 2005/29/EC (Unfair Commercial Practices Directive) No access
- aa) GDPR No access
- bb) Directive 2002/58/EC (ePrivacy-Directive) No access
- b) Right to obtain erasure No access
- c) Principle of transparency No access
- d) Principle of purpose limitation No access
- aa) Freely given No access
- bb) Pre-formulated declaration of consent No access
- cc) Time limit No access
- b) Right to withdraw consent No access
- a) Contract or pre-contractual relations No access
- b) Advertising based on legitimate interests No access
- aa) Obligatory prior consent (opt-in) No access
- bb) Exceptions No access
- cc) Transparency and information No access
- aa) Automated calling No access
- bb) Direct marketing voice-to-voice calls No access
- cc) ePrivacy Regulation No access
- c) Postal advertising No access
- d) Sweepstake No access
- e) Tell-a-friend No access
- f) Address trading No access
- 1. Definition of profiling No access
- a) Data protection impact assessment No access
- b) Purpose limitation No access
- c) Data minimisation No access
- d) Obligation to inform No access
- e) Right to object No access
- f) Privacy by design and by default No access
- a) ePrivacy-Directive No access
- b) Consent to the use of cookies No access
- a) Statistical and aggregate data No access
- aa) Roles and responsibilities No access
- bb) Legal basis No access
- cc) Obligation to inform No access
- dd) Further obligations No access
- c) Customer Relationship Management No access
- 1. Web analytics No access
- a) Social media page No access
- b) Social plugins No access
- 3. Privacy policy No access
- 4. Right to be forgotten No access
- a) App developers No access
- b) App store operators No access
- c) OS and device manufactures No access
- a) Consent No access
- b) Processing necessary for performance of a contract No access
- c) Legitimate interests No access
- 3. Geolocation No access
- 4. Privacy Policy No access
- Index No access Pages 287 - 291





