SlideShare ist ein Scribd-Unternehmen logo
1 von 18
22 January 2020
Dr Mistale Taylor, Trilateral Research
The SME hotline
experience of the
Hungarian DPA, 2020
SMEs? : staff headcount AND either turnover or balance sheet total
Small and medium-sized enterprises represent 99% of all
businesses in the EU!
2
What is an SME?
 Recital 13: ‘the Union institutions and bodies, and Member States and their
supervisory authorities, are encouraged to take account of the specific needs of
micro, small and medium-sized enterprises in the application of this Regulation’
 Article 30: ‘obligations to keep a record of processing activities shall not apply to
an enterprise or an organisation employing fewer than 250 persons, unless the
processing it carries out is likely to result in a risk to the rights and freedoms of
data subjects, the processing is not occasional, or the processing includes special
categories of data’
 Articles 40 & 42: ‘the specific needs of these companies should be taken into
account when developing of codes of conduct, data protection certification
mechanisms and of data protection seals and marks’
Recognising SME status in the GDPR
GDPR applies to all data controllers and processors  small businesses
Overarching obligations inc:
– Accountability (SMEs have to take the necessary organisational,
administrative and technical measures when processing personal data)
– Transparency (appropriate communication requirements)
• New data protection rights for individuals
• New responsibilities on data processors
• DPOs (compulsory appointment in some cases)
• Training employees
GDPR obligations for SMEs
Awareness-raising initiatives
SME expectations
March 2019 - March 2020
Scope: questions by SMEs throughout EU re interpretation +
application of GDPR
Further use: on the basis of SME questions + issues  handbook will
be compiled  usable throughout the EU
Country study: Hungary –
the SME Hotline
7
Statistics
• 14 March - 1 January 2020: 125 e-mails
• Sent out 113 responses, 4 in progress
• 8 requests outside scope
in progress; 4
responded;
113
outside the
scope of the
Hotline; 8
Hotline responses (state of processing up
to 1 January, 2020)
in progress responded outside the scope of the Hotline
18
178
8
The distribution of questions as per
type of question
general information (GDPR)
concrete question (GDPR
application in concret case)
other
9
35
32
25
25
17
16
14
15
14
11
Other
Compliance with GDPR
Video surveillance
Employees' data
Rights of the data subjects (Provision of
information to data subjects: 12)
Legal base of data processing (declaration
of consent: 10)
Need for data protection register
Scope of GDPR
Need for data protection rules
DPO
Topics of enquiries received via NAIH SME hotline*
Biggest GDPR myths SMEs
believed…• That data protection / the GDPR doesn’t apply to them
• That they will not be investigated or fined
• That you always need consent of the data subject to process
personal data
• They are not handling sensitive data because they’re not in
the health industry
• That the GDPR is a settled issue and this is all a done thing
• GDPR compliance as a tick-box exercise, not a process
• That “data protection” is about one singular issue (e.g.
CCTV, data access requests) and nothing else
Examples of enquiries
11
1. Are SMEs subject to the GDPR?
Yes. If they process personal data, they are subject to the GDPR rules.
The data protection reform took the special situation of SMEs into account:
• The majority of SMEs are not obliged to employ a data protection officer;
• The criteria for carrying out data protection impact assessments are significantly limited, and only small
portion of SMEs are subject to them.
• SMEs are also exempt from the obligation to document their data processing activities.
2. Does the processing of the telephone numbers of my clients for business purposes qualify as data
processing?
Yes, because it concerns business or professional activity, and does not belong among the exemptions of
so-called household data processing not subject to the GDPR.
3. Is it considered data processing when I publish my telephone number on my webpage or Facebook
profile, and I am thus called by my possible clients?
No, not until the processing of the personal data of other natural persons takes place (e.g. you are called
by natural persons).
12
4. Is a company subject to the GDPR when processing of a small number of personal data of
contractual partners or their contact persons for the purposes of fulfilling contracts of service?
Yes, because the frequency, quantity or purpose of data processing are irrelevant from the point
of view of scope, unless Article 2 mentions the as exemptions.
5. Is it subject to the GDPR when one contacts a company (a non-natural person) with a direct
marketing offer?
No. Article 4 point 1 of the GDPR defines the concept of personal data. The protection of the data
of non-natural persons does not fall within the scope of the GDPR.
6. Am I, or is my activity, subject to the GDPR even when I process no personal data as part of
my main activity, but I do have employees?
Yes. The processing of the data of employees is prescribed by several laws for various purposes,
whereby the enterprise is obliged to process the personal data of its employees.
Examples of enquiries
13
7. May consent be obtained from the data subject electronically?
Yes, because the GDPR has no provision on the form of consent; it only defines the requirements of
validity. The data controller however is obliged to prove that the data subject had given consent.
8. Is consent provided by a minor valid?
In the case of the validity of consent by minors, the provisions on capacity, parental custody and
guardianship, as well as, in the case of the incapacity or limited capacity of adults, the provisions on
capacity and custodianship of Act V of 2013 on the Civil Code apply. As a consent to data processing
qualifies as a juridical act, the relevant provisions of the Civil Code apply.
9. What is the difference between the provision of information under Articles 13, 14 and 15 of
the GDPR?
While information under Articles 13 and 14 is meant ensure that the data subject receives a general
and comprehensive picture of the processing of his or her personal data, the right of access under
Article 15 has the express aim of ensuring that the data subject receives information on the processing
of his or her in order to establish and control the lawfulness of processing.
Examples of enquiries
10. When complying with the right to erasure under Article 17 of the GDPR, do personal data
have to be erased from backup files?
According to Article 17 (2), where the erasure of personal data is obligatory pursuant to Article 17 (1), all
PERSONAL DATA in backup copies (with either the controller or the processor, as well as third parties)
shall be erased, and, without undue delay, the ability to restore erased data shall be finally terminated by
all technically feasible means.
11. If a natural person requests my enterprise to erase his or her personal data, and I thus erase
all his or her data, including his or her name, from the records, how can I prove that I had
received such a request and fulfilled it?
The GDPR does not obligate data controllers to keep records of their measures taken in the course of
enforcing the rights of data subjects. Insofar as the data controller wishes to keep record of its fulfilling
data subject requests in order to comply with the principle of transparency and in the lack of a provision
thereto, it is expedient to define its contents so as not to include (or minimise) personal data.
Examples of enquiries
12. Must a data processor also maintain a data processing record?
Yes. Article 30 (2) of the GDPR defines the content of such a record. Accordingly, each
processor and, where applicable, the processor's representative shall maintain a record
of all categories of processing activities carried out on behalf of a controller.
13. In what form must such a record be maintained?
Pursuant to Article 30 (3) of the GDPR, such a record shall be in writing, including in
electronic form.
14. I intend to notify the data processing I carry out to the data protection register, but I
find no opportunity to do so on the website of the DPA.
The GDPR does not provide for a national data protection register to be maintained by
the authorities of Member States as the former regulation of the Privacy Act did. Article
30 of the GDPR obligates each data controller, and data processor, to maintain a record
of processing activities under its responsibility. This means that the data controllers, and
data processors, themselves must maintain records of their data processing activities
without having to notify the Authority thereof. The obligation to notify data processing to
the data protection register ceased as of 25 May 2018.
15. Does the GDPR provide for any exemption in view of SMEs?
Article 30 (5) of the GDPR exempts enterprises employing less than 250 persons from
the obligation to maintain a record unless the processing they carry out is likely to result
Examples of enquiries
16. Under what conditions may employees process the certificates of good conduct of
employees?
In the opinion of the Authority based on the relevant provisions of the GDPR and the Privacy
Act, employers may process the personal data of their employees concerning criminal actions,
the related security measures, and their having no criminal record, first, on the basis of
Article 6 (1) c) of the GDPR (processing is necessary for compliance with a legal obligation to
which the controller is subject) and, second, based on the authorisation of an Act detailing the
processing.
Note, however, employers may only require their employees to show them their certificates of
good conduct; they may not make copies of them.
17. May an enterprise use GPS in its company cars?
An indispensable condition of lawful data processing is that data processing has a legal basis
under Article 6 of the GDPR; according to Article 6 (1) f), data processing may be lawful when
it is necessary for the purposes of the legitimate interests pursued by the controller.
If the employer has also a legitimate interest in using tracking system, the first issue to be
examined is whether the data processing is by all means necessary for the purposes
designated by the employer, and whether its implementation by a GPS device is proportionate
to the limitation on rights.
It is particularly important that employers inform their employees of installing tracking
devices in the company cars their employees drive, and that while they use the vehicle, their
Examples of enquiries
What next?
Thank-you for your attention!
Any questions?
PhD Julia Sziklay
kkvhotline@naih.hu
www.naih.hu
mistale.taylor@trilateralresearch.com
http://www.project-star.eu/

Weitere ähnliche Inhalte

Was ist angesagt?

Personal Data Protection Bill 2018
Personal Data Protection Bill 2018Personal Data Protection Bill 2018
Personal Data Protection Bill 2018Nanda Mohan Shenoy
 
Personal data protection bill
Personal data protection bill Personal data protection bill
Personal data protection bill Mathew Chacko
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanEquiGov Institute
 
Impact of ict on privacy and personal data
Impact of ict on privacy and personal dataImpact of ict on privacy and personal data
Impact of ict on privacy and personal datamohd kamal
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacylegalPadmin
 
Feedback on Draft Personal Data Protection Bill 2018 submitted to MEITY
Feedback  on Draft Personal Data Protection Bill 2018 submitted to MEITYFeedback  on Draft Personal Data Protection Bill 2018 submitted to MEITY
Feedback on Draft Personal Data Protection Bill 2018 submitted to MEITYNanda Mohan Shenoy
 
Ch 17 data protections act
Ch 17 data protections actCh 17 data protections act
Ch 17 data protections actKhan Yousafzai
 
Professional issues in IT
Professional issues in IT Professional issues in IT
Professional issues in IT Savithri Nandadasa
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?VILT
 
GDPR and Analytics
GDPR and AnalyticsGDPR and Analytics
GDPR and Analyticsbrunomase
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationOlivier Vandeputte
 
Information technology law
Information technology lawInformation technology law
Information technology lawAssignment Prime
 
Biometric Personal Data, Legal and Technological Utilization Issues
Biometric Personal Data, Legal and Technological Utilization IssuesBiometric Personal Data, Legal and Technological Utilization Issues
Biometric Personal Data, Legal and Technological Utilization IssuesGiannisBasa
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochureJean Luc Creppy
 
RIGit Privacy Policy
RIGit Privacy PolicyRIGit Privacy Policy
RIGit Privacy PolicyApril Mellas
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessMark Baker
 
Flash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPRFlash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPRPrecisely
 

Was ist angesagt? (20)

Personal Data Protection Bill 2018
Personal Data Protection Bill 2018Personal Data Protection Bill 2018
Personal Data Protection Bill 2018
 
Personal data protection bill
Personal data protection bill Personal data protection bill
Personal data protection bill
 
Operational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbeanOperational impact of gdpr finance industries in the caribbean
Operational impact of gdpr finance industries in the caribbean
 
Impact of ict on privacy and personal data
Impact of ict on privacy and personal dataImpact of ict on privacy and personal data
Impact of ict on privacy and personal data
 
Are you GDPRed yet?
Are you GDPRed yet?Are you GDPRed yet?
Are you GDPRed yet?
 
Personal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data PrivacyPersonal Data Protection Act - Employee Data Privacy
Personal Data Protection Act - Employee Data Privacy
 
Feedback on Draft Personal Data Protection Bill 2018 submitted to MEITY
Feedback  on Draft Personal Data Protection Bill 2018 submitted to MEITYFeedback  on Draft Personal Data Protection Bill 2018 submitted to MEITY
Feedback on Draft Personal Data Protection Bill 2018 submitted to MEITY
 
Pdpa(kewal)
Pdpa(kewal)Pdpa(kewal)
Pdpa(kewal)
 
Ch 17 data protections act
Ch 17 data protections actCh 17 data protections act
Ch 17 data protections act
 
Professional issues in IT
Professional issues in IT Professional issues in IT
Professional issues in IT
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?
 
GDPR and Analytics
GDPR and AnalyticsGDPR and Analytics
GDPR and Analytics
 
Key Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection RegulationKey Issues on the new General Data Protection Regulation
Key Issues on the new General Data Protection Regulation
 
Information technology law
Information technology lawInformation technology law
Information technology law
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
Biometric Personal Data, Legal and Technological Utilization Issues
Biometric Personal Data, Legal and Technological Utilization IssuesBiometric Personal Data, Legal and Technological Utilization Issues
Biometric Personal Data, Legal and Technological Utilization Issues
 
Personal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochurePersonal Data Protection Singapore - Pdpc corporate-brochure
Personal Data Protection Singapore - Pdpc corporate-brochure
 
RIGit Privacy Policy
RIGit Privacy PolicyRIGit Privacy Policy
RIGit Privacy Policy
 
GDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your businessGDPR- Get the facts and prepare your business
GDPR- Get the facts and prepare your business
 
Flash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPRFlash Friday: Data Quality & GDPR
Flash Friday: Data Quality & GDPR
 

Ähnlich wie Star II sme hotline 21.01.20

Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfDaviesParker
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. dan hyde
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationN N
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Happiest Minds Technologies
 
GDPR
GDPRGDPR
GDPRGopi PD
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018Shane Gray
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill Komal Gadia
 
UAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfUAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfDaviesParker
 
General data protection regulation GDPR
General data protection regulation GDPRGeneral data protection regulation GDPR
General data protection regulation GDPRAfraAlZadjali
 
GDPR for Marketers - teaser
GDPR for Marketers - teaserGDPR for Marketers - teaser
GDPR for Marketers - teaserLava Consult BVBA
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)BenjaminShalevSalovi
 
GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands legalandgeneral
 
General data protection regulation - European union
General data protection regulation  - European unionGeneral data protection regulation  - European union
General data protection regulation - European unionRohana K Amarakoon
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
Managing Data Protection guide powerpoint presentation
Managing Data Protection guide powerpoint presentationManaging Data Protection guide powerpoint presentation
Managing Data Protection guide powerpoint presentationsilvereyez11
 

Ähnlich wie Star II sme hotline 21.01.20 (20)

Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
 
Guide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulationGuide to-the-general-data-protection-regulation
Guide to-the-general-data-protection-regulation
 
Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)Complete Guide to General Data Protection Regulation (GDPR)
Complete Guide to General Data Protection Regulation (GDPR)
 
GDPR
GDPRGDPR
GDPR
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
GDPR Overview
GDPR OverviewGDPR Overview
GDPR Overview
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018The implications of gdpr for the solutions industry tatech 2018
The implications of gdpr for the solutions industry tatech 2018
 
An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill An overview of the Indian Data Privacy Bill
An overview of the Indian Data Privacy Bill
 
UAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdfUAE-Personal-Data-Protection-Law.pdf
UAE-Personal-Data-Protection-Law.pdf
 
General data protection regulation GDPR
General data protection regulation GDPRGeneral data protection regulation GDPR
General data protection regulation GDPR
 
GDPR for Marketers - teaser
GDPR for Marketers - teaserGDPR for Marketers - teaser
GDPR for Marketers - teaser
 
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR)
 
GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands GDPR: data needs to be in safe hands
GDPR: data needs to be in safe hands
 
General data protection regulation - European union
General data protection regulation  - European unionGeneral data protection regulation  - European union
General data protection regulation - European union
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
Managing Data Protection guide powerpoint presentation
Managing Data Protection guide powerpoint presentationManaging Data Protection guide powerpoint presentation
Managing Data Protection guide powerpoint presentation
 

Mehr von Trilateral Research

Designing Security Across Boundaries: mapping disperse data to collaborative...
Designing Security Across Boundaries:  mapping disperse data to collaborative...Designing Security Across Boundaries:  mapping disperse data to collaborative...
Designing Security Across Boundaries: mapping disperse data to collaborative...Trilateral Research
 
Privacy and Data Protection: Limits and Opportunities for Unmanned Aerial Pla...
Privacy and Data Protection: Limits and Opportunities for Unmanned Aerial Pla...Privacy and Data Protection: Limits and Opportunities for Unmanned Aerial Pla...
Privacy and Data Protection: Limits and Opportunities for Unmanned Aerial Pla...Trilateral Research
 
Risky Borders: Designing togetherness using information technology for intero...
Risky Borders: Designing togetherness using information technology for intero...Risky Borders: Designing togetherness using information technology for intero...
Risky Borders: Designing togetherness using information technology for intero...Trilateral Research
 
DroneRules Pro: Supporting GDPR compliance through privacy culture among dron...
DroneRules Pro: Supporting GDPR compliance through privacy culture among dron...DroneRules Pro: Supporting GDPR compliance through privacy culture among dron...
DroneRules Pro: Supporting GDPR compliance through privacy culture among dron...Trilateral Research
 
Ethics and technology in humanitarian setting
Ethics and technology in humanitarian settingEthics and technology in humanitarian setting
Ethics and technology in humanitarian settingTrilateral Research
 
Privacy & Ethical Impact Assessment Workshop_RAMSES Project
Privacy & Ethical Impact Assessment Workshop_RAMSES ProjectPrivacy & Ethical Impact Assessment Workshop_RAMSES Project
Privacy & Ethical Impact Assessment Workshop_RAMSES ProjectTrilateral Research
 
Workshop on Ethical, Legal, social Issues in Networked Information Exchange f...
Workshop on Ethical, Legal, social Issues in Networked Information Exchange f...Workshop on Ethical, Legal, social Issues in Networked Information Exchange f...
Workshop on Ethical, Legal, social Issues in Networked Information Exchange f...Trilateral Research
 
Technology for Human Trafficking and sexual exploitation - Trace Projects Fin...
Technology for Human Trafficking and sexual exploitation - Trace Projects Fin...Technology for Human Trafficking and sexual exploitation - Trace Projects Fin...
Technology for Human Trafficking and sexual exploitation - Trace Projects Fin...Trilateral Research
 
Overview of CLARITY project
Overview of CLARITY projectOverview of CLARITY project
Overview of CLARITY projectTrilateral Research
 
CRISP project: overview of findings and lessons learned.
CRISP project: overview of findings and lessons learned.CRISP project: overview of findings and lessons learned.
CRISP project: overview of findings and lessons learned.Trilateral Research
 
Legal and ethical issues in social capital analysis
Legal and ethical issues in social capital analysis Legal and ethical issues in social capital analysis
Legal and ethical issues in social capital analysis Trilateral Research
 
Examining End-User Standardisation Needs for Disaster Resilience
Examining End-User Standardisation Needs for Disaster ResilienceExamining End-User Standardisation Needs for Disaster Resilience
Examining End-User Standardisation Needs for Disaster ResilienceTrilateral Research
 
A stakeholder based approach to standardisation for disaster resilience
A stakeholder based approach to standardisation for disaster resilienceA stakeholder based approach to standardisation for disaster resilience
A stakeholder based approach to standardisation for disaster resilienceTrilateral Research
 
Evolving Technology - Delivering Neighbourhood Policing with a smaller workforce
Evolving Technology - Delivering Neighbourhood Policing with a smaller workforceEvolving Technology - Delivering Neighbourhood Policing with a smaller workforce
Evolving Technology - Delivering Neighbourhood Policing with a smaller workforceTrilateral Research
 
Social Media and ICT in Neighbourhood Policing - Opportunities and Challanges
Social Media and ICT in Neighbourhood Policing - Opportunities and ChallangesSocial Media and ICT in Neighbourhood Policing - Opportunities and Challanges
Social Media and ICT in Neighbourhood Policing - Opportunities and ChallangesTrilateral Research
 
Social Media Analysis Tools for Preparedness and Disaster Risk Reduction
Social Media Analysis Tools for Preparedness and Disaster Risk Reduction Social Media Analysis Tools for Preparedness and Disaster Risk Reduction
Social Media Analysis Tools for Preparedness and Disaster Risk Reduction Trilateral Research
 
ENERGIC-OD @ GEO Business 2017 presentation
ENERGIC-OD @ GEO Business 2017 presentationENERGIC-OD @ GEO Business 2017 presentation
ENERGIC-OD @ GEO Business 2017 presentationTrilateral Research
 
Esports in the UK - privacy risks
Esports in the UK - privacy risksEsports in the UK - privacy risks
Esports in the UK - privacy risksTrilateral Research
 
Enhancing ethics assessment in R&I at the national level
Enhancing ethics assessment in R&I at the national levelEnhancing ethics assessment in R&I at the national level
Enhancing ethics assessment in R&I at the national levelTrilateral Research
 
Methodologies for Addressing Privacy and Social Issues in Health Data: A Case...
Methodologies for Addressing Privacy and Social Issues in Health Data: A Case...Methodologies for Addressing Privacy and Social Issues in Health Data: A Case...
Methodologies for Addressing Privacy and Social Issues in Health Data: A Case...Trilateral Research
 

Mehr von Trilateral Research (20)

Designing Security Across Boundaries: mapping disperse data to collaborative...
Designing Security Across Boundaries:  mapping disperse data to collaborative...Designing Security Across Boundaries:  mapping disperse data to collaborative...
Designing Security Across Boundaries: mapping disperse data to collaborative...
 
Privacy and Data Protection: Limits and Opportunities for Unmanned Aerial Pla...
Privacy and Data Protection: Limits and Opportunities for Unmanned Aerial Pla...Privacy and Data Protection: Limits and Opportunities for Unmanned Aerial Pla...
Privacy and Data Protection: Limits and Opportunities for Unmanned Aerial Pla...
 
Risky Borders: Designing togetherness using information technology for intero...
Risky Borders: Designing togetherness using information technology for intero...Risky Borders: Designing togetherness using information technology for intero...
Risky Borders: Designing togetherness using information technology for intero...
 
DroneRules Pro: Supporting GDPR compliance through privacy culture among dron...
DroneRules Pro: Supporting GDPR compliance through privacy culture among dron...DroneRules Pro: Supporting GDPR compliance through privacy culture among dron...
DroneRules Pro: Supporting GDPR compliance through privacy culture among dron...
 
Ethics and technology in humanitarian setting
Ethics and technology in humanitarian settingEthics and technology in humanitarian setting
Ethics and technology in humanitarian setting
 
Privacy & Ethical Impact Assessment Workshop_RAMSES Project
Privacy & Ethical Impact Assessment Workshop_RAMSES ProjectPrivacy & Ethical Impact Assessment Workshop_RAMSES Project
Privacy & Ethical Impact Assessment Workshop_RAMSES Project
 
Workshop on Ethical, Legal, social Issues in Networked Information Exchange f...
Workshop on Ethical, Legal, social Issues in Networked Information Exchange f...Workshop on Ethical, Legal, social Issues in Networked Information Exchange f...
Workshop on Ethical, Legal, social Issues in Networked Information Exchange f...
 
Technology for Human Trafficking and sexual exploitation - Trace Projects Fin...
Technology for Human Trafficking and sexual exploitation - Trace Projects Fin...Technology for Human Trafficking and sexual exploitation - Trace Projects Fin...
Technology for Human Trafficking and sexual exploitation - Trace Projects Fin...
 
Overview of CLARITY project
Overview of CLARITY projectOverview of CLARITY project
Overview of CLARITY project
 
CRISP project: overview of findings and lessons learned.
CRISP project: overview of findings and lessons learned.CRISP project: overview of findings and lessons learned.
CRISP project: overview of findings and lessons learned.
 
Legal and ethical issues in social capital analysis
Legal and ethical issues in social capital analysis Legal and ethical issues in social capital analysis
Legal and ethical issues in social capital analysis
 
Examining End-User Standardisation Needs for Disaster Resilience
Examining End-User Standardisation Needs for Disaster ResilienceExamining End-User Standardisation Needs for Disaster Resilience
Examining End-User Standardisation Needs for Disaster Resilience
 
A stakeholder based approach to standardisation for disaster resilience
A stakeholder based approach to standardisation for disaster resilienceA stakeholder based approach to standardisation for disaster resilience
A stakeholder based approach to standardisation for disaster resilience
 
Evolving Technology - Delivering Neighbourhood Policing with a smaller workforce
Evolving Technology - Delivering Neighbourhood Policing with a smaller workforceEvolving Technology - Delivering Neighbourhood Policing with a smaller workforce
Evolving Technology - Delivering Neighbourhood Policing with a smaller workforce
 
Social Media and ICT in Neighbourhood Policing - Opportunities and Challanges
Social Media and ICT in Neighbourhood Policing - Opportunities and ChallangesSocial Media and ICT in Neighbourhood Policing - Opportunities and Challanges
Social Media and ICT in Neighbourhood Policing - Opportunities and Challanges
 
Social Media Analysis Tools for Preparedness and Disaster Risk Reduction
Social Media Analysis Tools for Preparedness and Disaster Risk Reduction Social Media Analysis Tools for Preparedness and Disaster Risk Reduction
Social Media Analysis Tools for Preparedness and Disaster Risk Reduction
 
ENERGIC-OD @ GEO Business 2017 presentation
ENERGIC-OD @ GEO Business 2017 presentationENERGIC-OD @ GEO Business 2017 presentation
ENERGIC-OD @ GEO Business 2017 presentation
 
Esports in the UK - privacy risks
Esports in the UK - privacy risksEsports in the UK - privacy risks
Esports in the UK - privacy risks
 
Enhancing ethics assessment in R&I at the national level
Enhancing ethics assessment in R&I at the national levelEnhancing ethics assessment in R&I at the national level
Enhancing ethics assessment in R&I at the national level
 
Methodologies for Addressing Privacy and Social Issues in Health Data: A Case...
Methodologies for Addressing Privacy and Social Issues in Health Data: A Case...Methodologies for Addressing Privacy and Social Issues in Health Data: A Case...
Methodologies for Addressing Privacy and Social Issues in Health Data: A Case...
 

KĂźrzlich hochgeladen

COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxRRR Chambers
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxRRR Chambers
 
Essentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmmEssentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmm2020000445musaib
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书Fs Las
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdfSUSHMITAPOTHAL
 
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxAudience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxMollyBrown86
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxRRR Chambers
 
一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书E LSS
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书SS A
 
FULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | Delhi
FULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | DelhiFULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | Delhi
FULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | Delhisoniya singh
 
Divorce Procedure in India (Info) (1).pdf
Divorce Procedure in India (Info) (1).pdfDivorce Procedure in India (Info) (1).pdf
Divorce Procedure in India (Info) (1).pdfdigitalnikesh24
 
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)Delhi Call girls
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueSkyLaw Professional Corporation
 
一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书E LSS
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptjudeplata
 
Legal Risks and Compliance Considerations for Cryptocurrency Exchanges in India
Legal Risks and Compliance Considerations for Cryptocurrency Exchanges in IndiaLegal Risks and Compliance Considerations for Cryptocurrency Exchanges in India
Legal Risks and Compliance Considerations for Cryptocurrency Exchanges in IndiaFinlaw Consultancy Pvt Ltd
 
Old Income Tax Regime Vs New Income Tax Regime
Old  Income Tax Regime Vs  New Income Tax   RegimeOld  Income Tax Regime Vs  New Income Tax   Regime
Old Income Tax Regime Vs New Income Tax RegimeCA Dr. Prithvi Ranjan Parhi
 

KĂźrzlich hochgeladen (20)

COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
 
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 6 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
 
Essentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmmEssentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmm
 
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
如何办理(USF文凭证书)美国旧金山大学毕业证学位证书
 
589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf589308994-interpretation-of-statutes-notes-law-college.pdf
589308994-interpretation-of-statutes-notes-law-college.pdf
 
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxAudience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
 
PPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptxPPT- Voluntary Liquidation (Under section 59).pptx
PPT- Voluntary Liquidation (Under section 59).pptx
 
一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书一比一原版利兹大学毕业证学位证书
一比一原版利兹大学毕业证学位证书
 
一比一原版旧金山州立大学毕业证学位证书
 一比一原版旧金山州立大学毕业证学位证书 一比一原版旧金山州立大学毕业证学位证书
一比一原版旧金山州立大学毕业证学位证书
 
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
Sensual Moments: +91 9999965857 Independent Call Girls Vasundhara Delhi {{ Mo...
 
FULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | Delhi
FULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | DelhiFULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | Delhi
FULL ENJOY - 8264348440 Call Girls in Netaji Subhash Place | Delhi
 
Divorce Procedure in India (Info) (1).pdf
Divorce Procedure in India (Info) (1).pdfDivorce Procedure in India (Info) (1).pdf
Divorce Procedure in India (Info) (1).pdf
 
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
 
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top BoutiqueAndrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
Andrea Hill Featured in Canadian Lawyer as SkyLaw Recognized as a Top Boutique
 
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书一比一原版牛津布鲁克斯大学毕业证学位证书
一比一原版牛津布鲁克斯大学毕业证学位证书
 
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.pptFINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
FINALTRUEENFORCEMENT OF BARANGAY SETTLEMENT.ppt
 
Legal Risks and Compliance Considerations for Cryptocurrency Exchanges in India
Legal Risks and Compliance Considerations for Cryptocurrency Exchanges in IndiaLegal Risks and Compliance Considerations for Cryptocurrency Exchanges in India
Legal Risks and Compliance Considerations for Cryptocurrency Exchanges in India
 
Old Income Tax Regime Vs New Income Tax Regime
Old  Income Tax Regime Vs  New Income Tax   RegimeOld  Income Tax Regime Vs  New Income Tax   Regime
Old Income Tax Regime Vs New Income Tax Regime
 

Star II sme hotline 21.01.20

  • 1. 22 January 2020 Dr Mistale Taylor, Trilateral Research The SME hotline experience of the Hungarian DPA, 2020
  • 2. SMEs? : staff headcount AND either turnover or balance sheet total Small and medium-sized enterprises represent 99% of all businesses in the EU! 2 What is an SME?
  • 3.  Recital 13: ‘the Union institutions and bodies, and Member States and their supervisory authorities, are encouraged to take account of the specific needs of micro, small and medium-sized enterprises in the application of this Regulation’  Article 30: ‘obligations to keep a record of processing activities shall not apply to an enterprise or an organisation employing fewer than 250 persons, unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data’  Articles 40 & 42: ‘the specific needs of these companies should be taken into account when developing of codes of conduct, data protection certification mechanisms and of data protection seals and marks’ Recognising SME status in the GDPR
  • 4. GDPR applies to all data controllers and processors  small businesses Overarching obligations inc: – Accountability (SMEs have to take the necessary organisational, administrative and technical measures when processing personal data) – Transparency (appropriate communication requirements) • New data protection rights for individuals • New responsibilities on data processors • DPOs (compulsory appointment in some cases) • Training employees GDPR obligations for SMEs
  • 7. March 2019 - March 2020 Scope: questions by SMEs throughout EU re interpretation + application of GDPR Further use: on the basis of SME questions + issues  handbook will be compiled  usable throughout the EU Country study: Hungary – the SME Hotline 7
  • 8. Statistics • 14 March - 1 January 2020: 125 e-mails • Sent out 113 responses, 4 in progress • 8 requests outside scope in progress; 4 responded; 113 outside the scope of the Hotline; 8 Hotline responses (state of processing up to 1 January, 2020) in progress responded outside the scope of the Hotline 18 178 8 The distribution of questions as per type of question general information (GDPR) concrete question (GDPR application in concret case) other
  • 9. 9 35 32 25 25 17 16 14 15 14 11 Other Compliance with GDPR Video surveillance Employees' data Rights of the data subjects (Provision of information to data subjects: 12) Legal base of data processing (declaration of consent: 10) Need for data protection register Scope of GDPR Need for data protection rules DPO Topics of enquiries received via NAIH SME hotline*
  • 10. Biggest GDPR myths SMEs believed…• That data protection / the GDPR doesn’t apply to them • That they will not be investigated or fined • That you always need consent of the data subject to process personal data • They are not handling sensitive data because they’re not in the health industry • That the GDPR is a settled issue and this is all a done thing • GDPR compliance as a tick-box exercise, not a process • That “data protection” is about one singular issue (e.g. CCTV, data access requests) and nothing else
  • 11. Examples of enquiries 11 1. Are SMEs subject to the GDPR? Yes. If they process personal data, they are subject to the GDPR rules. The data protection reform took the special situation of SMEs into account: • The majority of SMEs are not obliged to employ a data protection officer; • The criteria for carrying out data protection impact assessments are significantly limited, and only small portion of SMEs are subject to them. • SMEs are also exempt from the obligation to document their data processing activities. 2. Does the processing of the telephone numbers of my clients for business purposes qualify as data processing? Yes, because it concerns business or professional activity, and does not belong among the exemptions of so-called household data processing not subject to the GDPR. 3. Is it considered data processing when I publish my telephone number on my webpage or Facebook profile, and I am thus called by my possible clients? No, not until the processing of the personal data of other natural persons takes place (e.g. you are called by natural persons).
  • 12. 12 4. Is a company subject to the GDPR when processing of a small number of personal data of contractual partners or their contact persons for the purposes of fulfilling contracts of service? Yes, because the frequency, quantity or purpose of data processing are irrelevant from the point of view of scope, unless Article 2 mentions the as exemptions. 5. Is it subject to the GDPR when one contacts a company (a non-natural person) with a direct marketing offer? No. Article 4 point 1 of the GDPR defines the concept of personal data. The protection of the data of non-natural persons does not fall within the scope of the GDPR. 6. Am I, or is my activity, subject to the GDPR even when I process no personal data as part of my main activity, but I do have employees? Yes. The processing of the data of employees is prescribed by several laws for various purposes, whereby the enterprise is obliged to process the personal data of its employees. Examples of enquiries
  • 13. 13 7. May consent be obtained from the data subject electronically? Yes, because the GDPR has no provision on the form of consent; it only defines the requirements of validity. The data controller however is obliged to prove that the data subject had given consent. 8. Is consent provided by a minor valid? In the case of the validity of consent by minors, the provisions on capacity, parental custody and guardianship, as well as, in the case of the incapacity or limited capacity of adults, the provisions on capacity and custodianship of Act V of 2013 on the Civil Code apply. As a consent to data processing qualifies as a juridical act, the relevant provisions of the Civil Code apply. 9. What is the difference between the provision of information under Articles 13, 14 and 15 of the GDPR? While information under Articles 13 and 14 is meant ensure that the data subject receives a general and comprehensive picture of the processing of his or her personal data, the right of access under Article 15 has the express aim of ensuring that the data subject receives information on the processing of his or her in order to establish and control the lawfulness of processing. Examples of enquiries
  • 14. 10. When complying with the right to erasure under Article 17 of the GDPR, do personal data have to be erased from backup files? According to Article 17 (2), where the erasure of personal data is obligatory pursuant to Article 17 (1), all PERSONAL DATA in backup copies (with either the controller or the processor, as well as third parties) shall be erased, and, without undue delay, the ability to restore erased data shall be finally terminated by all technically feasible means. 11. If a natural person requests my enterprise to erase his or her personal data, and I thus erase all his or her data, including his or her name, from the records, how can I prove that I had received such a request and fulfilled it? The GDPR does not obligate data controllers to keep records of their measures taken in the course of enforcing the rights of data subjects. Insofar as the data controller wishes to keep record of its fulfilling data subject requests in order to comply with the principle of transparency and in the lack of a provision thereto, it is expedient to define its contents so as not to include (or minimise) personal data. Examples of enquiries
  • 15. 12. Must a data processor also maintain a data processing record? Yes. Article 30 (2) of the GDPR defines the content of such a record. Accordingly, each processor and, where applicable, the processor's representative shall maintain a record of all categories of processing activities carried out on behalf of a controller. 13. In what form must such a record be maintained? Pursuant to Article 30 (3) of the GDPR, such a record shall be in writing, including in electronic form. 14. I intend to notify the data processing I carry out to the data protection register, but I find no opportunity to do so on the website of the DPA. The GDPR does not provide for a national data protection register to be maintained by the authorities of Member States as the former regulation of the Privacy Act did. Article 30 of the GDPR obligates each data controller, and data processor, to maintain a record of processing activities under its responsibility. This means that the data controllers, and data processors, themselves must maintain records of their data processing activities without having to notify the Authority thereof. The obligation to notify data processing to the data protection register ceased as of 25 May 2018. 15. Does the GDPR provide for any exemption in view of SMEs? Article 30 (5) of the GDPR exempts enterprises employing less than 250 persons from the obligation to maintain a record unless the processing they carry out is likely to result Examples of enquiries
  • 16. 16. Under what conditions may employees process the certificates of good conduct of employees? In the opinion of the Authority based on the relevant provisions of the GDPR and the Privacy Act, employers may process the personal data of their employees concerning criminal actions, the related security measures, and their having no criminal record, first, on the basis of Article 6 (1) c) of the GDPR (processing is necessary for compliance with a legal obligation to which the controller is subject) and, second, based on the authorisation of an Act detailing the processing. Note, however, employers may only require their employees to show them their certificates of good conduct; they may not make copies of them. 17. May an enterprise use GPS in its company cars? An indispensable condition of lawful data processing is that data processing has a legal basis under Article 6 of the GDPR; according to Article 6 (1) f), data processing may be lawful when it is necessary for the purposes of the legitimate interests pursued by the controller. If the employer has also a legitimate interest in using tracking system, the first issue to be examined is whether the data processing is by all means necessary for the purposes designated by the employer, and whether its implementation by a GPS device is proportionate to the limitation on rights. It is particularly important that employers inform their employees of installing tracking devices in the company cars their employees drive, and that while they use the vehicle, their Examples of enquiries
  • 18. Thank-you for your attention! Any questions? PhD Julia Sziklay kkvhotline@naih.hu www.naih.hu mistale.taylor@trilateralresearch.com http://www.project-star.eu/