Skip to main content

The day has come...

when the new GDPR entered into force. If not else, you noticed it by receiving e-mails from all quarters, partially confirming that the sender complies with the new rules or that changed its privacy policies in line with the new rules or asking for your consent to use your data.
Did those who did not write you, miss something? Did you miss something when you did not write to all people whose data you store? Well, it depends.

Those who complied with the old directive (and the national laws transposing it), do not necessarily have to do something. There are, however, three changes behind for them:
- instead of relying on a notification to their data protection authority, they themselves have to keep documentation demonstrating that they comply with the new regulation
- there are more strict and also more precise rules when someone can ask "to be forgotten" i.e. his/her data erased
- non-compliance can result in hefty fines.
Some organisations may have to nominate a data protection officer which they didn't have before.

So for whom do things change?
Those who had vague or non-comprehensive privacy statements, have to adjust them to contain all information required by the regulation.
The scope of the regulation being wider than that of the directive, overseas organisations who process personal data of EU residents clearly have to comply now. One sign of that are the notices we receive about new privacy policies - they may have indeed changed but  it is also possible that only the content of the privacy statements was made comprehensive.

Finally, the biggest change can be for those, who based their personal data processing on implicit consent. The requirement for an express and informed consent was reinforced in the new regulation, leaving a pre-ticked box ticked or simply continuing to browse or to use a service does not constitute consent any more. So therefore do we get e-mails where organisations ask us to consent for the use (processing in the jargon of the regulation) of our personal data in order to be able to continue using the service.

Now this is an interesting setup as unless the data are necessary for the use of the service, the consent cannot be the condition of using it. Of course we cannot use Facebook without giving some basic data as it does not make sense and an e-mail address for contact may also be necessary. No one can be expected to deliver goods to us without knowing our address. There are, however, some questions ahead: a payment provider needs our payment card data, but a merchant (the seller) may simply redirect us to the sit of the payment provider, they do not need our card data. A convenience service can be offered to remember the card data so that we do not have to enter them again at the next purchase, but this is typically the case where this cannot be a precondition for buying. There are a number of similar cases so look forward for some disputes in the future, and not just the high-profile crusade of Mr Schrems against Facebook and now, Google and others). This crusade, however, will be subject of an article soon.

Comments

Popular posts from this blog

A Hungarian case about processing data based on law - what are the requirements?

This question can be interesting in respect of the latest change in Hungarian health data processing: doctors performing health on the workplace tests are obliged to upload the entire files to the common health space where access is not as limited as it should be. The concrete case adjudicated by the European Court of Justice concerns the processing of COVID vaccination data, also based on national law. For processing based on a legal obligation to which the controller is subject, Member Statesmay maintan and introduce specific provisions determining more specific requirements and can also describe features of the processing, including measures to ensure fair and lawful processing. Processing of special categories of data (including health data) for reasons of substantial public interest (in any area) or of public interest in the area of public health requires that the élaw should provide for suitable and specific measures to safeguard the fundamental rights and interests of the data ...

Doubts around data transfer - use of derogations

 A lot happened since Schrems-II , among others the European Data Protection Board published a FAQ document , a guidance on essential guarantees for surveillance measures      and submitted another guidance , on measures that supplement transfer tools. Transfer tools are either safeguards which ensure that data subjects enjoy adequate protection of their privacy at the place and in the organisation to where their data are transferred or derogations which enable transfer essentially without adequate protection. I used the term adequate protection and previously the view was that the protection ensured need not be identical with that in the EU. The Schrems II judgment, however, speaks about equivalent protection and this is stronger. In case the derogations (according to article 49 GDPR) are used, the EDPB is of the view that the last sentence of Article 44 GDPR (All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural...

The right to information and data subject access requests

The European Court of Justice dealt with some cases concerning data subject access requests and clarified the scope of certain information to be provided. 1. The right to informationThe data subjects have the right to be informed about how their personal data are processed by the controller. This information has to be provided using a privacy statement which is also called data protection notice. The privacy statement has a set content which serves not only to inform data subjects about which of their personal data are processed and how but also to assure them that their personal data are processed in compliance with EU rules. Some information in the privacy statements is nevertheless general and therefore data subjects can request further information and access to the personal data the controller processes about them. Privacy statements can be displayed on the webpages of the controller. Some controllers publish one comprehensive privacy statement which contains information about vari...