Proposed EU General Data Protection Regulation
Robert L. Rothman
June 5, 2014
6/5/2014 1
Proposed EU General Data Protection Regulation Robert L. Rothman - - PowerPoint PPT Presentation
Proposed EU General Data Protection Regulation Robert L. Rothman June 5, 2014 6/5/2014 1 Purpose At last Privacy Committee Meeting there was a request to review the proposed EU General Data Protection Regulation and the associated
June 5, 2014
6/5/2014 1
6/5/2014 2
3 6/5/2014
4 6/5/2014
5 6/5/2014
6
7 6/5/2014
8 6/5/2014
6/5/2014 9
6/5/2014 10 6/5/2014
6/5/2014 11
6/5/2014 12
– Definition of “Personal Data” also changed (Art 4(2))
– “Without undue delay” (presumed 72 hours) – Art 31(3) contains a list of information that must be in the notification, most of which the controller will be unlikely to know – Required regardless whether the data was encrypted
– If breach "likely to adversely affect the protection of personal data or privacy of the data subject“ or, under EP version, the data subjects “the rights or the legitimate interests “
6/5/2014 13
14 6/5/2014
15 6/5/2014
16 6/5/2014
6/5/2014 17
6/5/2014 18
6/5/2014 19
6/5/2014 20
6/5/2014 21
6/5/2014 22
6/5/2014 23
– Consent (Art 20(2)(c)) – Performance of a contract (Art 20(2)(a)) – Allowed by law (Art 20(2)(b))
6/5/2014 24
6/5/2014 25
6/5/2014 26
6/5/2014 27
6/5/2014 28
6/5/2014 29
6/5/2014 30
6/5/2014 31
6/5/2014 32
33 6/5/2014
6/5/2014 34