GDPR and the Privacy Shield
Mark Prinsley Partner
+44 20 3130 3900 mprinsley@mayerbrown.com
Kendall Burman Counsel
+ 202 263 3210 kburman@mayerbrown.com
GDPR and the Privacy Shield Mark Prinsley Kendall Burman Partner - - PowerPoint PPT Presentation
GDPR and the Privacy Shield Mark Prinsley Kendall Burman Partner Counsel +44 20 3130 3900 + 202 263 3210 mprinsley@mayerbrown.com kburman@mayerbrown.com Speakers Mark Prinsley Kendall Burman Partner - London Counsel Washington DC
+44 20 3130 3900 mprinsley@mayerbrown.com
+ 202 263 3210 kburman@mayerbrown.com
Counsel – Washington DC
Partner - London
183
184
185
large scale?
186
187
188
– systematic and extensive evaluation of personal data – large-scale processing of special-category personal data – systematic monitoring of a publicly accessible area on a large scale
189
Evaluation or scoring/processing Automated decision-making with legal significant effect Systematic monitoring Use of sensitive data
190
Data processed on a large scale Datasets that are matched Data concerning vulnerable data subjects Innovative use or applying technological or organisational solutions Data transfers out of the EU Processing that prevents individuals from exercising a right or using a service or a contract
Examples of Processing Possible Relevant Criteria DPIA Required?
A hospital processing its patients’ genetic and health data (hospital information system).
The use of a camera system to monitor driving behaviour on
system to single out cars and automatically recognise licence plates.
Yes system to single out cars and automatically recognise licence plates.
A company monitoring its employees’ activities, including the monitoring of the employees’ work station, Internet activity, etc.
The gathering of public social media profile data to be used by private companies generating profiles for contact directories.
An online magazine using a mailing list to send a generic daily digest to its subscribers.
Not necessarily An e-commerce website displaying adverts for vintage car parts that involve limiting profiling based on past purchasing behaviour on certain parts of its website.
extensive 191
It should be underlined that the process depicted here is iterative: in practice, it is likely that each of the stages is revisited multiple
Description of the envisaged processing Assessment of the necessity and proportionality Monitoring and review 192
stages is revisited multiple times before the DPIA can be completed.
Measures envisaged to demonstrate compliance Assessment of the risks to the rights and freedoms Measures envisaged to address the risks Documentation
193
194
195
196
197
198
199
200
201
202
203
+44 20 3130 3900 mprinsley@mayerbrown.com
+ 202 263 3210 kburman@mayerbrown.com