Which failing of Privacy Shield, cited by the CJEU as a reason for its invalidation, is the Trans-Atlantic Data Privacy Framework intended to address?
According to the GDPR, the material scope of the regulation covers the processing of personal data wholly or partly by automated means, or by non-automated means if the data forms part of a filing system or is intended to form part of a filing system (Article 2(1)). Personal data is defined as any information relating to an identified or identifiable natural person (data subject) (Article 4(1)). An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (Article 4(1)). Therefore, pseudonymous data, such as blockchain transactions that use public keys or other identifiers, may still fall within the definition of personal data if the data subject can be identified or re-identified by using additional information or means (Recital 26).
The GDPR also applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the European Union, regardless of whether the processing takes place in the European Union or not (Article 3(1)). The GDPR also applies to the processing of personal data of data subjects who are in the European Union by a controller or processor not established in the European Union, where the processing activities are related to the offering of goods or services to such data subjects in the European Union or the monitoring of their behaviour as far as their behaviour takes place within the European Union (Article 3(2)). Therefore, the territorial scope of the GDPR covers both controllers and processors established in the European Union, and controllers and processors not established in the European Union but targeting or monitoring data subjects in the European Union.
In this scenario, blockchain transactions are classified as pseudonymous data, which may still be considered as personal data under the GDPR if the data subjects can be identified or re-identified. Therefore, such transactions are within the material scope of the GDPR, as they involve the processing of personal data by automated means. However, the GDPR only applies to such transactions to the extent that they include data subjects in the European Union, either by having a controller or processor established in the European Union, or by offering goods or services to or monitoring the behaviour of such data subjects. Therefore, the answer is C.
Laurel
5 months agoSkye
5 months agoAlita
6 months agoFrancis
6 months agoEulah
6 months agoHyun
6 months agoLazaro
6 months agoCyndy
7 months agoTarra
7 months agoGlynda
7 months agoReiko
7 months agoLouisa
7 months agoColene
7 months agoBuck
7 months agoMargart
7 months agoElenor
7 months agoGerry
7 months agoTaryn
7 months agoEvette
11 months agoMozell
12 months agoCarma
10 months agoNida
11 months agoSilva
11 months agoMichal
11 months agoMila
12 months agoUlysses
10 months agoJoni
10 months agoQuinn
11 months agoGene
1 year agoEzekiel
11 months agoIlona
11 months agoEzekiel
11 months agoVirgilio
1 year agoKayleigh
11 months agoDeja
12 months agoCeleste
12 months agoMerissa
1 year agoHarrison
12 months agoFrederick
12 months agoDoretha
1 year agoNovella
1 year agoShawnda
1 year agoLaquita
1 year agoJacob
1 year ago