According to the E-Commerce Directive 2000/31/EC, where is the place of ''establishment'' for a company providing services via an Internet website confirmed by the GDPR?
According to the E-Commerce Directive 2000/31/EC, the place of establishment for a company providing services via an Internet website is the place where the service provider effectively pursues an economic activity through a fixed establishment for an indefinite period of time. The presence and use of the technical means and technologies required to provide the service do not, in themselves, constitute an establishment of the provider. The place of establishment is determined by the place where the decisions about processing are made, not by the place where the technology supporting the website is located, where the website is accessed, or where the customer's Internet service provider is located. This is confirmed by the GDPR, which applies to the processing of personal data in the context of the activities of an establishment of a controller or a processor in the EU, regardless of whether the processing takes place in the EU or not.Reference:
E-Commerce Directive 2000/31/EC, Article 2(a), Recital 191
GDPR, Article 3(1)2
Which of the following describes a mandatory requirement for a group of undertakings that wants to appoint a single data protection officer?
According to Article 37(2) of the GDPR, a group of undertakings may appoint a single data protection officer (DPO) provided that the DPO is easily accessible from each establishment12.This means that the DPO should be able to communicate effectively with the data subjects and the supervisory authorities in the relevant languages and jurisdictions, and to perform the tasks referred to in Article 39 of the GDPR34.The accessibility of the DPO does not necessarily depend on the physical location of the DPO, but rather on the availability of the DPO to the relevant stakeholders via various means of communication34. Therefore, the DPO does not have to be located in the country where the data controller has its main establishment, nor does the group of undertakings have to obtain approval from a supervisory authority or be comprised of organizations of similar sizes and functions to appoint a single DPO.Reference:CIPP/E Certification - International Association of Privacy Professionals,Free CIPP/E Study Guide - International Association of Privacy Professionals,GDPR - EUR-Lex,What's different about a group data protection officer?,Data Protection Officers: What US Companies Need to Know - Cooley
A company has collected personal data tor direct marketing purpose on the basis of consent. It is now considering using this data to develop new products through analytics. What is the company first required to do?
According to the GDPR, consent is one of the lawful bases for processing personal data1.Consent means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her2.Therefore, consent must be specific to each purpose of processing and cannot be bundled with other purposes3.If a company wants to use personal data for a new purpose that is not compatible with the original purpose for which consent was given, it must obtain a new consent from the data subjects for the new processing4. Simply informing the data subjects of the new purpose or updating the privacy notice is not sufficient, as it does not imply the data subject's agreement to the new processing.Proceeding with the new processing without obtaining a new consent would be unlawful and could result in fines and sanctions5.Reference:
Free CIPP/E Study Guide, page 23, section 4.1.1
GDPR, Article 4 (11)
GDPR, Recital 32
GDPR, Article 6 (4)
GDPR, Article 83 (5) (a)
A well-known video production company, based in Spain but specializing in documentaries filmed worldwide, has just finished recording several hours of footage featuring senior citizens in the streets of Madrid. Under what condition would the company NOT be required to obtain the consent of everyone whose image they use for their documentary?
According to the GDPR, consent is one of the six lawful bases for processing personal data, but not the only one. The other five are: contract, legal obligation, vital interests, public task and legitimate interests. Legitimate interests can be invoked by controllers who process personal data for their own benefit or for the benefit of third parties, as long as such processing does not override the rights and freedoms of the data subjects, especially if they are children. The GDPR also recognizes that processing personal data for journalistic purposes or the purposes of academic, artistic or literary expression may be necessary for the exercise of the right to freedom of expression and information, which is a legitimate interest. Therefore, the company may not need to obtain the consent of everyone whose image they use for their documentary, if they can demonstrate that their processing is necessary for the purposes of their journalistic, artistic or literary expression, and that they have taken into account the reasonable expectations of the data subjects and the potential impact on their privacy. The company should also comply with any relevant national laws or codes of conduct that may apply to such processing.Reference:
GDPR, Article 6(1)(a)-(f)
GDPR, Recital 47
GDPR, Article 85
What was the main failing of Convention 108 that led to the creation of the Data Protection Directive (Directive 95/46/EC)?
Convention 108 was the first legally binding international instrument in the data protection field, adopted by the Council of Europe in 19811.However, it had some limitations that led to the creation of the Data Protection Directive (Directive 95/46/EC) by the European Union in 19952.One of the main failings of Convention 108 was that it was implemented in a fragmented manner by a small number of states, resulting in divergent and inconsistent national laws and practices3.The Data Protection Directive aimed to harmonize the data protection rules within the EU and to ensure a high level of protection for individuals' rights and freedoms2. Therefore, option C is the correct answer.Option A is incorrect because Convention 108 did account for the rapid growth of the Internet by allowing for amendments and protocols to adapt to technological developments1.Option B is incorrect because Convention 108 did include protections for sensitive personal data, such as those revealing racial origin, political opinions, religious beliefs, health, or sexual life1.Option D is incorrect because Convention 108 did not prescribe specific penalties for violations of data protection rights, but left it to the Parties to adopt appropriate sanctions and remedies1.Reference:
Convention 108 and Protocols
CIPP/E Certification
Convention 108+ and the Data Protection Framework of the EU
Stephanie Collins
10 days agoPaul Bell
19 days agoDaniel Green
1 month agoNathan Turner
2 months agoSharon Baker
1 month agoSarah Wright
2 months agoRonald Moore
1 month agoSusan Johnson
1 month agoTimothy Walker
1 month agoGerman
2 months agoGeorgene
3 months agoLeonora
3 months agoXuan
3 months agoMaybelle
3 months agoChandra
4 months agoFrederic
4 months agoMarti
4 months agoBrandon
4 months agoDylan
5 months agoChaya
5 months agoRose
5 months agoValda
5 months agoMiesha
6 months agoTommy
6 months agoUla
6 months agoGary
6 months agoRoosevelt
7 months agoHyun
7 months agoRolf
7 months agoCyril
7 months agoBernardo
8 months agoAmmie
8 months agoAliza
8 months agoSylvia
8 months agoDarnell
9 months agoAdell
9 months agoYasuko
9 months agoRegenia
9 months agoBilly
9 months agoWhitney
9 months agoAvery
11 months agoIra
11 months agoJade
12 months agoDesiree
1 year agoVeda
1 year agoShawna
1 year agoLatrice
1 year agoKristian
1 year agoShawna
1 year agoTherese
1 year agoGwenn
1 year agoTerry
1 year agoRikki
1 year agoCatalina
1 year agoRemona
1 year agoGilberto
1 year agoTesha
1 year agoGolda
1 year agoCatarina
2 years agoRuthann
2 years agoLouisa
2 years agoEsteban
2 years agoAhmad
2 years agoFernanda
2 years agoClarence
2 years agoMerissa
2 years agoPhil
2 years agoLinsey
2 years agoAlida
2 years agoWillodean
2 years agoJosephine
2 years agoErinn
2 years agoVeronique
2 years agoWayne
2 years agoJill
2 years agoHector
2 years agoFlorencia
2 years agoRaelene
2 years agoJoesph
2 years agoFidelia
2 years agoHyun
2 years agoMireya
2 years ago