Month: November 2018

Recital 119 – Organisation of several supervisory authorities of a Member State

Recital 119 Organisation of several supervisory authorities of a Member State Where a Member State establishes several supervisory authorities, it should establish by law mechanisms for ensuring the effective…

Read more 0 comments

Recital 120 – Features of supervisory authorities

Recital 120 Features of supervisory authorities Each supervisory authority should be provided with the financial and human resources, premises and infrastructure necessary for the effective performance of their tasks,…

Read more 0 comments

Recital 121 – Independence of the supervisory authorities

Recital 121 Independence of the supervisory authorities The general conditions for the member or members of the supervisory authority should be laid down by law in each Member State…

Read more 0 comments

Recital 102 – International agreements for an appropriate level of data protection

Recital 102 International agreements for an appropriate level of data protection This Regulation is without prejudice to international agreements concluded between the Union and third countries regulating the transfer…

Read more 0 comments

Recital 103 – Appropriate level of data protection based on an adequacy decision

Recital 103 Appropriate level of data protection based on an adequacy decision The Commission may decide with effect for the entire Union that a third country, a territory or…

Read more 0 comments

Recital 104 – Criteria for an adequacy decision

Recital 104 Criteria for an adequacy decision In line with the fundamental values on which the Union is founded, in particular the protection of human rights, the Commission should,…

Read more 0 comments

Recital 105 – Consideration of international agreements for an adequacy decision

Recital 105 Consideration of international agreements for an adequacy decision Apart from the international commitments the third country or international organisation has entered into, the Commission should take account…

Read more 0 comments

Recital 106 – Monitoring and periodic review of the level of data protection

Recital 106 Monitoring and periodic review of the level of data protection The Commission should monitor the functioning of decisions on the level of protection in a third country,…

Read more 0 comments

Recital 107 – Amendment, revocation and suspension of adequacy decisions

Recital 107 Amendment, revocation and suspension of adequacy decisions The Commission may recognise that a third country, a territory or a specified sector within a third country, or an…

Read more 0 comments

Recital 108 – Appropriate safeguards

Recital 108 Appropriate safeguards In the absence of an adequacy decision, the controller or processor should take measures to compensate for the lack of data protection in a third…

Read more 0 comments

Recital 109 – Standard data protection clauses

Recital 109Standard data protection clauses The possibility for the controller or processor to use standard data-protection clauses adopted by the Commission or by a supervisory authority should prevent controllers…

Read more 0 comments

Recital 110 – Binding corporate rules

Recital 110Binding corporate rules A group of undertakings, or a group of enterprises engaged in a joint economic activity, should be able to make use of approved binding corporate…

Read more 0 comments

Recital 111 – Exceptions for certain cases of international transfers

Recital 111 Exceptions for certain cases of international transfers Provisions should be made for the possibility for transfers in certain circumstances where the data subject has given his or…

Read more 0 comments

Recital 112 – Data transfers due to important reasons of public interest

Recital 112 Data transfers due to important reasons of public interest Those derogations should in particular apply to data transfers required and necessary for important reasons of public interest,…

Read more 0 comments

Recital 113 – Transfers qualified as not repetitive and that only concern a limited number of data subjects

Recital 113 Transfers qualified as not repetitive and that only concern a limited number of data subjects Transfers which can be qualified as not repetitive and that only concern…

Read more 0 comments

Recital 114 – Safeguarding of enforceability of rights and obligations in the absence of an adequacy decision

Recital 114Safeguarding of enforceability of rights and obligations in the absence of an adequacy decision In any case, where the Commission has taken no decision on the adequate level…

Read more 0 comments

Recital 115 – Rules in third countries contrary to the Regulation

Recital 115 Rules in third countries contrary to the Regulation Some third countries adopt laws, regulations and other legal acts which purport to directly regulate the processing activities of…

Read more 0 comments

Recital 116 – Cooperation among supervisory authorities

Recital 116 Cooperation among supervisory authorities When personal data moves across borders outside the Union it may put at increased risk the ability of natural persons to exercise data…

Read more 0 comments

Recital 85 – Notification obligation of breaches to the supervisory authority

Recital 85 Notification obligation of breaches to the supervisory authority A personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or…

Read more 0 comments

Recital 86 – Notification of data subjects in case of data breaches

Recital 86 Notification of data subjects in case of data breaches The controller should communicate to the data subject a personal data breach, without undue delay, where that personal…

Read more 0 comments

Recital 87 – Promptness of reporting / notification

Recital 87 Promptness of reporting / notification It should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data…

Read more 0 comments

Recital 88 – Format and procedures of the notification

Recital 88 Format and procedures of the notification In setting detailed rules concerning the format and procedures applicable to the notification of personal data breaches, due consideration should be…

Read more 0 comments

Recital 89 – Elimination of the general reporting requirement

Recital 89 Elimination of the general reporting requirement Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. While that obligation…

Read more 0 comments

Recital 90 – Data protection impact assessement

Recital 90 Data protection impact assessement In such cases, a data protection impact assessment should be carried out by the controller prior to the processing in order to assess…

Read more 0 comments

Recital 91 – Necessity of a data protection impact assessment

Recital 91 Necessity of a data protection impact assessment This should in particular apply to large-scale processing operations which aim to process a considerable amount of personal data at…

Read more 0 comments