← į akto dosjė

GDPR — 29 straipsnis

Straipsnio tekstas

29 straipsnis Duomenų valdytojui ar duomenų tvarkytojui pavaldžių asmenų atliekamas duomenų tvarkymas Duomenų tvarkytojas ir bet kuris duomenų valdytojui arba duomenų tvarkytojui pavaldus asmuo, galintis susipažinti su asmens duomenimis, negali tų duomenų tvarkyti, išskyrus atvejus, kai duomenų valdytojas duoda nurodymus juos tvarkyti, nebent tai daryti reikalaujama pagal Sąjungos ar valstybės narės teisę.

Kas dėl šio straipsnio rašė konsultacijose

Teikėjai, kurie savo tekste tiesiogiai nurodė būtent šį straipsnio numerį. Tai citata iš jų pačių teksto — ne mūsų vertinimas ir ne priežastinis ryšys.

18
verslo asociacija
8
įmonė
3
ACADEMIC_RESEARCH_INSTITTUTION
2
?
2
NVO
KasŠalisKą parašė
Van Bael & BellisBEy to result in a high risk" for the purposes of Regulation 2016/679, WP248 rev. 01, 4 October 2017, https://ec.europa.eu/newsroom/article29/items/611236 8 Cf. e.g., Agencia Española de Protección de Datos (AEPD), Gestión del riesgo y evaluación de impacto en t
German Insurance AssociationDE47 of the GDPR. The EDPB has thus significantly expanded the requirements for BCRs in the working papers WP 256 and WP 264 of the Art. 29 Working Party after only a short period of validity and - with the exception of the Schrems II case law - without any disc
BDI e.V. (Federation of German Industries)DEt with the encryption, anonymisation and deletion of data, would also facilitate GDPR-compliance. Updating the guidance from the „Article 29 working party“ on the BDI contribution on the GDPR evaluation 2024 www.bdi.eu Page 9 from 22 use of anonymous and pseud
ACCISBEts opinion 06/2014 on the notion of legitimate interests of the data controller under Article 7 of Directive 95/46/EC, the former Article 29 Working Party stated that “Credit reference checks prior to the grant of a loan are also not made at the request of the
MyData-TRUSTBE(or years) to complete. The BCRs must fulfil the conditions set out in Article 47 GDPR, and requirements set out in the relevant Article 29 Working Party guidelines as endorsed by the European Data Protection Board (EDPB). Organisations applying for BCRs must
eco - Association of the Internet IndustryDEta should be treated equally (especially affirming the importance of legitimate interest) and updating the 2014 guidance from the Article 29 working party on the use of anonymous and pseudonymous data. The requirements of the GDPR and their application should
Bitkom e.V.DEta should be treated equally (especially affirming the importance of legitimate interest) and updating the 2014 guidance from the Article 29 working party on the use of anonymous and pseudonymous data. The later would be particularly important in helping with
Insurance EuropeBE47 of the GDPR. The EDPB has thus significantly expanded the requirements for BCRs in the working papers WP 256 and WP 264 of the Art. 29 Working Party after only a short period of validity and — with the exception of the Schrems II case law — without any disc
Anonos Inc.USwhether processing for another purpose is compatible with the purpose for which the personal data are initially collected.” 3 See Article 29 Working Party 06/2014 at 42 and 67. 3 • Separate Processing Benefits from Identity Requirements [Articles 11(2) and 12(
Bitkom e.V.DEituation needs to be solved, and quickly. One promising approach could be the establishment of the European Data Innovation Bord (Art. 29 Data Governance Act), where a more diverse group of experts comes together to advise and assist the development of harmoni
Hans-Hermann SchildDEfalls nicht. 5 Fristen Neben der Monatsfrist in Art. 5 VO-E enthält der Entwurf noch eine Bestimmung über den Beginn der Fristen (Art. 29 Abs. 2 VO- E). Danach beginnt die Frist an dem Arbeitstag, der auf das Er- eignis folgt. Bezogen auf das deutsche Recht be
noybATllow identifying parties; and (b) redact other information that is legally protected under applicable law. Chapter VII – Remedies Article 29 - Remedies under Article 78 GDPR 1.
David BARNARD-WILLSGBmputers & Technology, Vol.30, No. 3, 2016, pp. 246-270. 102 Barnard-Wills & Papakonstantinou, op. cit., February 2016, p. 53. 103 Art 29 Working Party, Opinion 9/2011 on the revised Industry Proposal for a Privacy and Data Protection Impact Assessment Framewor
Multi-Regional Clinical Trials Center of Harvard University and Brigham and Women’s HospitalUSresearch purposes should be considered to be compatible lawful processing operations. 66 GDPR, recital 33 (emphasis added). 67 Article 29 Working Party, Guidelines on consent under Regulation 2016/679 (rev. Apr. 10, 2018). 68 EDPS, A Preliminary Opinion su
U.S. Chamber of CommerceUSAPEC CBPRS, as many of the EU’s key trading partners, including the U.S., Japan, South Korea, and Singapore, are participants. 6 Article 29 Working Party, Opinion 02/2004. Consistency & Cooperation A major aim of the GDPR was to establish a unified data prote
International Society for Biological and Environmental Repositories (ISBER)USropean Commission collaborate with the EDPB and encourage it to issue guidance potentially in the planned 2020 EDPB update to the Article 29 Working Party’s 2010 guidance on controllers versus processors, setting forth a uniform standard on whether study sites
Global Alliance for Genomics and HealthCAance on identifying lead supervisory authorities for the purposes of applying the one-stop-shop mechanism (building from existing Article 29 Working Party guidance). The guidance should clarify the appropriate procedure for international entities wishing to en
Information Technology and Innovation Foundation (ITIF)USithout a decision over a decade later.12 Australia was considered for an adequacy decision in 2001, but after a report 4 from the Article 29 Working Party (the now European Data Protection Board (EDPB)) pointed out issues, Australia subsequently declined to re
EFPIAGBor example, both the standard contractual clauses and the Privacy Shield are subject to legal challenges in the EU. Moreover, the Article 29 Working Party has suggested that key-coded data is excluded from the scope of the Privacy Shield framework. Final 3 | P
ESOMARNL2 of 3 The guidance that has been published e.g. by the Dutch1, British2 regulators as well as the former Art. 29 Working Party3 and the European Commission4 underscore the reasons for ESOMAR’s position that the dichotomy of controller and processor in the con
eco - Verband der Internetwirtschaft e.V.DEDatenportabilität für Personen stellt auch zwei Jahre nach Verabschiedung der DSGVO eine Herausforderung dar. Auch wenn sich die Artikel 29-Datenschutzgruppe in einem Whitepaper bereits entsprechend positioniert hat, herrscht bei Unternehmen und Anwendern nac
RELXGBguidance (Ireland, UK) and that of the Article 29 Working Party on legitimate interest and commercial exploitation. Finally, the lack of a harmonised, clear approach to how the Supervisory Authority (SA) relates to a data- processing organisation still exists.
NLdigitalNLmple, the opinion on legitimate interest of the Dutch DPA is not aligned with the GDPR nor the interpretation of the ECJ (nor the Article 29 Working Party opinion on legitimate interest of 2014).
Workday, Inc.USresult in significant operational challenges for cloud service providers. Instead, C2P SCCs should be revised, in line with both Article 29 Working Party guidance and Article 28(2) of the GDPR, to clarify that processors may rely on the controller’s general c
EuroISPA - European Internet Services Providers AssociationBEadoption of the GDPR, the right to data portability for people is still a challenge. Even though the predecessor to the EDPB, the Article 29 Data Protection Group, has already set out its views on the topic in a white paper, companies and users still face unce
IAB EuropeBEbusinesses and is applicable across the EU. This is evident upon 15 See Opinion of A.G. Szpunar in case C-61/19, paras. 44-45. 16 Article 29 WP in Opinion WP217 on Legitimate interest insists on the fact that the legitimate interest legal basis should not be p
American ExpressUSly, to the ones already approved by some local data protection authorities or the ''Draft Model Clauses'' proposed by the extinct Article 29 Working Group). We believe that the updated version of the SCCs should also already address this situation.
and profit maximisation does not pass the ‘legitimacy’ test. The Dutch DPA's view differs in that respect from the opinion of the Article 29 Working Party on legitimate interests (Opinion 06/2014) and other DPAs where ‘the notion of legitimate interest could i
CNIL does not want to speak English, but they should. European Data Protection Board (EDPB). This body is not even close to the Article 29 Working Party. The Article 29 Working Party had great guidelines, they were of so much help. EDPB does not give any exp
Centre for Information Policy Leadership (CIPL)GB2016/679 (wp250rev.01). https://ec.europa.eu/newsroom/article29/document.cfm?action=display&doc_id=49827 page 17. “It should be clear that in the event of a breach involving cross-border processing, notification must be made to the lead supervisory authority,

Šaltinis: viešų konsultacijų atsiliepimai ir pozicijų dokumentai. n = 37 paminėjimų; skaičiuojama pažodinė nuoroda į straipsnio numerį.

Klausti apie šį straipsnį →