← į akto dosjė

GDPR — 30 straipsnis

Straipsnio tekstas

30 straipsnis Duomenų tvarkymo veiklos įrašai 1. Kiekvienas duomenų valdytojas ir, kai taikoma, duomenų valdytojo atstovas tvarko duomenų tvarkymo veiklos, už kurią jis atsako, įrašus. Tame įraše pateikiama visa toliau nurodyta informacija: a) duomenų valdytojo ir, jei taikoma, bendro duomenų valdytojo, duomenų valdytojo atstovo ir duomenų apsaugos pareigūno vardas bei pavardė (pavadinimas) ir kontaktiniai duomenys; b) duomenų tvarkymo tikslai; c) duomenų subjektų kategorijų ir asmens duomenų kategorijų aprašymas; d) duomenų gavėjų, kuriems buvo arba bus atskleisti asmens duomenys, įskaitant duomenų gavėjus trečiosiose valstybėse ar tarptautines organizacijas, kategorijos; e) kai taikoma, asmens duomenų perdavimai į trečiąją valstybę arba tarptautinei organizacijai, įskaitant tos trečiosios valstybės arba tarptautinės organizacijos pavadinimą, ir 49 straipsnio 1 dalies antroje pastraipoje nurodytais duomenų perdavimų atvejais tinkamų apsaugos priemonių dokumentai; f) kai įmanoma, numatomi įvairių kategorijų duomenų ištrynimo terminai; g) kai įmanoma, bendras 32 straipsnio 1 dalyje nurodytų techninių ir organizacinių saugumo priemonių aprašymas. kai įmanoma, bendras 32 straip
visas tekstas
snio 1 dalyje nurodytų techninių ir organizacinių saugumo priemonių aprašymas. 2. Kiekvienas duomenų tvarkytojas ir, jei taikoma, duomenų tvarkytojo atstovas tvarko su visų kategorijų su duomenų tvarkymo veikla, vykdoma duomenų valdytojo vardu, susijusius įrašus, kuriuose nurodoma: a) duomenų tvarkytojo ar duomenų tvarkytojų ir kiekvieno duomenų valdytojo, kurio vardu veikia duomenų tvarkytojas, taip pat, jei taikoma, duomenų valdytojo ar duomenų tvarkytojo atstovo ir duomenų apsaugos pareigūno vardas bei pavardė (pavadinimas) ir kontaktiniai duomenys; b) kiekvieno duomenų valdytojo vardu atliekamo duomenų tvarkymo kategorijos; c) kai taikoma, asmenų duomenų perdavimai į trečiąją valstybę arba tarptautinei organizacijai, be kita ko, nurodant tą trečiąją valstybę arba tarptautinę organizaciją, ir, 49 straipsnio 1 dalies antroje pastraipoje nurodytų duomenų perdavimų atveju, tinkamų apsaugos priemonių dokumentai; d) kai įmanoma, bendras 32 straipsnio 1 dalyje nurodytų techninių ir organizacinių saugumo priemonių aprašymas. kai įmanoma, bendras 32 straipsnio 1 dalyje nurodytų techninių ir organizacinių saugumo priemonių aprašymas. 3. 1 ir 2 dalyse nurodyti įrašai tvarkomi raštu, įskaitant elektronine forma. 4. Duomenų valdytojas ar duomenų tvarkytojas ir, jei taikoma, duomenų valdytojo arba duomenų tvarkytojo atstovas pateikia įrašą priežiūros institucijai, gavę prašymą. 5. 1 ir 2 dalyse nurodytos prievolės netaikomos įmonei arba organizacijai, kurioje dirba mažiau kaip 250 darbuotojų, išskyrus atvejus, kai dėl jos vykdomo duomenų tvarkymo gali kilti pavojus duomenų subjektų teisėms ir laisvėms, duomenų tvarkymas nėra nereguliarus arba duomenų tvarkymas apima specialių kategorijų asmens duomenis, kaip nurodyta 9 straipsnio 1 dalyje, arba tvarkomi asmens duomenys apie apkaltinamuosius nuosprendžius ir nusikalstamas veikas, kaip nurodyta 10 straipsnyje.

Kas dėl šio straipsnio rašė konsultacijose

Teikėjai, kurie savo tekste tiesiogiai nurodė būtent šį straipsnio numerį. Tai citata iš jų pačių teksto — ne mūsų vertinimas ir ne priežastinis ryšys.

9
verslo asociacija
5
NVO
5
įmonė
3
kita
2
ACADEMIC_RESEARCH_INSTITTUTION
KasŠalisKą parašė
Confederation of Swedish EnterpriseSEwith the level of information required under Art. 30 GDPR, including the IMY's high standard for transparency? In Art. 30 (5) GDPR there is a limitation to the obligation to maintain a record of processing for an enterprise or an organisation with fewer than 2
Deutsche Industrie- und Handelskammer (DIHK) / German Chamber of Commerce and IndustryDE, wann für KMU die Pflicht entfällt, ein Verzeichnis über die Verarbeitungstätigkeit zu führen. Die für KMU geregelte Ausnahme in Art. 30 Absatz 5 DSGVO findet in der Praxis kaum Anwendung Die Vorgaben für Auftragsverarbeitungsverträge sollten dem Risiko entsp
Centre for European PolicyDEuced for sensible and necessary documentation and reporting obligations which the GDPR imposes on companies (using the example of Art. 30 and 33 of the GDPR), and, secondly, B. comment on the interaction between the GDPR and new initiatives (using the example
Selbstregulierung Informationswirtschaft e.V. (SRIW)DEGDPR. The record of processing requires in any case only categories of some information, Art. 30.1 lit c and lit d. Thus, information within external transparency information shall not exceed the required information for internal documentation. Acknowledging t
Shoosmiths LLPGBpresents an opportunity to better balance privacy protection with the operational realities of SMEs. The current exemption under Article 30(5) does not significantly reduce the compliance burden, as SMEs still need to document their data processing activities
Bundesvereinigung der Deutschen ArbeitgeberverbändeDEahrung des jeweiligen Auskunftsrechts muss eine Übersicht, die die verarbeiteten Daten in verständlicher Form auflistet, genügen. Art. 30 Gemäß Art. 30 DS-GVO muss ein Verzeichnis über Verarbeitungstätigkeiten lediglich in Unternehmen ab 250 Mitarbeitern gefüh
MyData-TRUSTBEcomplementing the requirements of the GDPR Art. 30, giving national flavour to the records of processing activities. These variations highlight the complexity of harmonizing data protection practices across the EU, as national DPAs may interpret and implement
Oplysningsforbundet May DayDKaa-overblikket-4-centrale-begreber-der-faar-det-offentlige-Ɵl-rime-paa-cloud 74 art. 5, stk. 1, litra f, jf. art. 5, stk. 2, og Ɵl art. 30, stk.
VNO-NCW / MKB NederlandNLlaw, because it has to prevent other controllers from reading too much leeway in its interpretations). We also recommend amending article 30 paragraph 5 as follows: to not restrict the derogation of keeping a record to occasional processing activities; and to
Xamit Bewertungsgesellschaft mbHDEwie sie in anderen Berufsfeldern selbstverständlich ist. Die Pflicht zum Führen eines "Verzeichnis von Verarbeitungstätigkeiten" (Art. 30 DS-GVO) bringt in der Praxis keinen Mehrwert. Die Verarbeitungen müssen im Wesentlichen in der (im Vergleich zum "Verzeich
Berufsverband der Datenschutzbeauftragten Deutschlands (BvD) e.V.DEsgrundlage nach Artt. 13, 14 DSGVO sowie der Pflicht zur Erfassung im Rahmen des Verzeichnisses von Verarbeitungstätigkeiten nach Art. 30 DSGVO. Damit löst selbst eine einfache Zulässigkeitsprüfung (z.B.
Alliance DigitaleFRrecords of processing activities and remove the term "occasional" from paragraph 5 of Article 30 of the GDPR. As specified in the same Article 30, this exemption would not apply if the processing they carry out is likely to result in a risk to the rights and f
AUSTRIAN FEDERAL ECONOMIC CHAMBERAT(e.g. from trade and craft, engineering offices) must be considered. A proper formulation of the SME exception in accordance with Article 30 Paragraph 5 GDPR for companies that also process data regularly (such as any company that looks after customers or empl
Finnish EnergyFIther a data breach should be reported or not. In addition, more clarification and detailed examples have been requested regarding Article 30 'Records of processing activities,' especially concerning the level at which the information mentioned in the article s
Délégué à la Protection des Données (ancien et formateur)FRles finalités du traitement et leur condition de licéité respective, conformément à l’article 6 du présent règlement ; 7) Article 30.2 RGPD : ajouter l’existence d’une sous-traitance de niveau inférieur dans un registre Sous-traitant Au titre de l’article 30.2
theinfosecvault.comITconsent art. 6 (only when other forms of consent could not be achieved by the Controller) 2) The Record of Processing Activities (art. 30) should be mandatory for every company and periodically archived with digital signature Thank you !
Border Violence Monitoring NetworkDE40 EURODAC Regulation, Article 30 39 Heinrich Böll Stiftung & BVMN. 2023. In defence of defenders: a practical guide to legal means and advocacy tools for criminalised Human Rights Defenders in Europe. Available at: https://gr.boell.org/sites/default/files/202
noybATlaw and Article 78(3) GDPR, any supervisory authority concerned may be joined to a national procedure in another Member State.87 Article 30 - Additional remedies before national courts Without prejudice to the rights under Article 78 GDPR and national laws,
David ErdosGBrelations in article 28 and record keeping which is “not occasional” in article 30 are similarly acontextual. It is also concerning how many of these and indeed other provisions in the GDPR focus on mandating process rather ensuring concrete results which dire
Ecommerce EuropeBEin the GDPR. For example, how detailed must the documentation be, in particular the record of processing activities according to Art. 30 GDPR? Which circumstances fall under Art. 28 GDPR (processing is carried out on behalf of a controller)? What is the corre
Internet Corporation for Assigned Names and NumbersUSbe important to specify under what conditions interested parties should be consulted (Art. 70 (4) of the GDPR). The provision of Art. 30 of the EDPB Rules of Procedure should therefore be supplemented in order to clarify this important issue. The provision sh
Digitale Gesellschaft e.V.DEn authorities. To promote transparency, the legislator must oblige controllers to publish their records of processing activities (Article 30) in a machine- readable form. To strengthen data protection in practice, the legislator must support the development an
BVPA Bundesverband professioneller Bildanbieter e.V.DEe sich aus Art. 28 DSGVO (AVV) i.V. m. Art. 32 DSGVO (TOM) und ggf. zusätzlich aus Art. 44ff DSGVO (Driostaatentransfer) sowie aus Art. 30 DSGVO (Verarbeitungsverzeichnis) und Art. 13 DSGVO (Infopflichten) ergebenden Pflichten für Verantwortliche und AuRraggeber
Deutsche Telekom AGDEe, if not directly accessible, at least retrievable without effort." 7) Record of categories of processing activities pursuant to Article 30 (2) GDPR Request: Where the same category of processing activities is performed on behalf of a large number of controll
Centre for Information Policy Leadership (CIPL)GBthe GDPR. For instance, some controllers are obliging processors contractually to keep 9 records of processing in accordance with Article 30 of the GDPR and requesting access to such records, or are trying contractually to position privacy by design and privac
Zentralverband der deutschen Werbewirtschaft ZAWDEchtspunkten orientieren und stärker an die Gegebenheiten in der Praxis angepasst werden. So ist der Auftragsverarbeiter z.B. nach Artikel 30 Abs. 2 DSGVO zur Führung von Verarbeitungsverzeichnissen verpflichtet, wobei kein Raum für eine Differenzierung zwische
GDPR Article 30(5) - clarifying the record keeping obligation Article 30(5) is clearly aimed at creating a general exception to the record-keeping obligation for smaller companies. What isn't clear, based on the current wording, is when such a small company

Šaltinis: viešų konsultacijų atsiliepimai ir pozicijų dokumentai. n = 27 paminėjimų; skaičiuojama pažodinė nuoroda į straipsnio numerį.

Klausti apie šį straipsnį →