Podcast
Questions and Answers
What legal basis is usually required for processing data for marketing purposes?
What legal basis is usually required for processing data for marketing purposes?
- Legitimate interest or consent only
- Consent, performance of a contract, or legitimate interest (correct)
- Only consent
- Performance of a contract only
Which directive aims to protect the economic interests of consumers?
Which directive aims to protect the economic interests of consumers?
- EU Charter of Fundamental Rights
- Unfair Contract Terms Directive (UCTD)
- Unfair Commercial Practices Directive (UCPD) (correct)
- General Data Protection Regulation (GDPR)
What must a request for consent for direct marketing be?
What must a request for consent for direct marketing be?
- Lengthy and detailed
- Optional and vague
- Informal and conversational
- Clear, concise, and not unnecessarily disruptive (correct)
How can consent for marketing purposes be given?
How can consent for marketing purposes be given?
Which of the following statements about withdrawing consent is correct?
Which of the following statements about withdrawing consent is correct?
What is one requirement for consent to be considered valid under Art. 4(11)?
What is one requirement for consent to be considered valid under Art. 4(11)?
Which of the following is NOT an aspect of how consent should be given according to Art. 7(3)?
Which of the following is NOT an aspect of how consent should be given according to Art. 7(3)?
Under what circumstance is consent ineffective as a legal basis according to Article 7(4)?
Under what circumstance is consent ineffective as a legal basis according to Article 7(4)?
What is a characteristic of consent regarding the power dynamics between the data subject and controller?
What is a characteristic of consent regarding the power dynamics between the data subject and controller?
What does Art. 6(1) specifically provide regarding the bases for lawful processing?
What does Art. 6(1) specifically provide regarding the bases for lawful processing?
What is the main purpose of processing personal data in terms of compliance?
What is the main purpose of processing personal data in terms of compliance?
Which article of GDPR specifies the need for implementing security measures for processing personal data?
Which article of GDPR specifies the need for implementing security measures for processing personal data?
What responsibility does a data controller have under GDPR in the context of accountability?
What responsibility does a data controller have under GDPR in the context of accountability?
Which type of personal data is categorized under Article 9 of GDPR?
Which type of personal data is categorized under Article 9 of GDPR?
Which legitimate basis for processing personal data is linked to direct marketing?
Which legitimate basis for processing personal data is linked to direct marketing?
Under what condition can an individual invoke the right to erasure?
Under what condition can an individual invoke the right to erasure?
Which scenario does NOT allow for the right to erasure?
Which scenario does NOT allow for the right to erasure?
Which of the following is a valid ground for exercising the right to erasure?
Which of the following is a valid ground for exercising the right to erasure?
If personal data has been disclosed to others, what must the processor do if the right to erasure is invoked?
If personal data has been disclosed to others, what must the processor do if the right to erasure is invoked?
Which statement correctly identifies an exception to the right to erasure?
Which statement correctly identifies an exception to the right to erasure?
When can the right to erasure be invoked based on the individual's objection?
When can the right to erasure be invoked based on the individual's objection?
What is an example of a direct marketing purpose where the right to erasure can apply?
What is an example of a direct marketing purpose where the right to erasure can apply?
Which lawful basis under Article 6 is associated with the initiation of the right to erasure when consent is withdrawn?
Which lawful basis under Article 6 is associated with the initiation of the right to erasure when consent is withdrawn?
What is the primary function of the Court of Justice of the EU (CJEU)?
What is the primary function of the Court of Justice of the EU (CJEU)?
Which type of EU law is directly binding and applicable in all Member States?
Which type of EU law is directly binding and applicable in all Member States?
Which document is NOT considered primary law in the EU?
Which document is NOT considered primary law in the EU?
What is the role of a directive in EU legislation?
What is the role of a directive in EU legislation?
Which aspect is NOT considered when interpreting data protection law?
Which aspect is NOT considered when interpreting data protection law?
What does Article 7 of the Charter ensure for individuals?
What does Article 7 of the Charter ensure for individuals?
What procedure is used for proposing legislation in the EU?
What procedure is used for proposing legislation in the EU?
Why was GDPR implemented in the EU?
Why was GDPR implemented in the EU?
Which of the following must be included to ensure safe data transfers within a corporate group?
Which of the following must be included to ensure safe data transfers within a corporate group?
What is required for transferring personal data when there is a request from a third country's court or authority?
What is required for transferring personal data when there is a request from a third country's court or authority?
Which of these situations allows for the transfer of personal data in the absence of an adequacy decision?
Which of these situations allows for the transfer of personal data in the absence of an adequacy decision?
What must a data controller do if personal data is transferred based on compelling legitimate interests?
What must a data controller do if personal data is transferred based on compelling legitimate interests?
Which option represents a situation that does NOT allow personal data to be transferred without adequate safeguards?
Which option represents a situation that does NOT allow personal data to be transferred without adequate safeguards?
What must the rules for data transfer contain to be considered binding?
What must the rules for data transfer contain to be considered binding?
Which of these is NOT a tool of effectiveness for safe data transfers?
Which of these is NOT a tool of effectiveness for safe data transfers?
In what situation can personal data be transferred if it does not involve repeated transfers and concerns a limited number of data subjects?
In what situation can personal data be transferred if it does not involve repeated transfers and concerns a limited number of data subjects?
Flashcards
EU Law
EU Law
The legal framework governing the European Union, ensuring the law is upheld across member states.
Primary EU Law
Primary EU Law
The foundational legal acts of the EU, including treaties and the Charter of Fundamental Rights.
Secondary EU Law
Secondary EU Law
EU legal acts derived from primary law, like regulations, directives, and decisions.
Regulation (EU Law)
Regulation (EU Law)
Signup and view all the flashcards
Directive (EU Law)
Directive (EU Law)
Signup and view all the flashcards
CJEU (Court of Justice of the EU)
CJEU (Court of Justice of the EU)
Signup and view all the flashcards
Preliminary Ruling (CJEU)
Preliminary Ruling (CJEU)
Signup and view all the flashcards
GDPR and fundamental rights
GDPR and fundamental rights
Signup and view all the flashcards
GDPR Data Security
GDPR Data Security
Signup and view all the flashcards
Legitimate Basis for Processing
Legitimate Basis for Processing
Signup and view all the flashcards
Data Controller Accountability
Data Controller Accountability
Signup and view all the flashcards
Marketing Data Storage
Marketing Data Storage
Signup and view all the flashcards
Security Measures for Data
Security Measures for Data
Signup and view all the flashcards
Data categories not in Art. 9
Data categories not in Art. 9
Signup and view all the flashcards
Legitimate basis of Consent
Legitimate basis of Consent
Signup and view all the flashcards
Freely given consent
Freely given consent
Signup and view all the flashcards
Informed consent
Informed consent
Signup and view all the flashcards
Consent and imbalanced power
Consent and imbalanced power
Signup and view all the flashcards
Right to Erasure
Right to Erasure
Signup and view all the flashcards
Personal Data Redundancy
Personal Data Redundancy
Signup and view all the flashcards
Consent-Based Data Holding
Consent-Based Data Holding
Signup and view all the flashcards
Legitimate Interest Exception
Legitimate Interest Exception
Signup and view all the flashcards
Unlawful Data Processing
Unlawful Data Processing
Signup and view all the flashcards
Legal Obligations
Legal Obligations
Signup and view all the flashcards
Data Disclosure and Erasure
Data Disclosure and Erasure
Signup and view all the flashcards
Reliance on Consent
Reliance on Consent
Signup and view all the flashcards
Data Transfers within Corporate Group
Data Transfers within Corporate Group
Signup and view all the flashcards
International Data Transfers (Art. 48)
International Data Transfers (Art. 48)
Signup and view all the flashcards
Safeguards for transfers
Safeguards for transfers
Signup and view all the flashcards
Exceptions to Transfer Rules
Exceptions to Transfer Rules
Signup and view all the flashcards
Adequacy Decisions (GDPR)
Adequacy Decisions (GDPR)
Signup and view all the flashcards
Appropriate Safeguards (GDPR)
Appropriate Safeguards (GDPR)
Signup and view all the flashcards
Compelling Legitimate Interest
Compelling Legitimate Interest
Signup and view all the flashcards
Supervisory Authority Notification
Supervisory Authority Notification
Signup and view all the flashcards
Article 6(1)(e) (public employer)
Article 6(1)(e) (public employer)
Signup and view all the flashcards
GDPR article 6(1)(f) (private employer)
GDPR article 6(1)(f) (private employer)
Signup and view all the flashcards
Marketing consent
Marketing consent
Signup and view all the flashcards
Legitimate interest
Legitimate interest
Signup and view all the flashcards
Performance of contract & marketing
Performance of contract & marketing
Signup and view all the flashcards
Study Notes
EU Law Summary
- The Court of Justice of the EU (CJEU) must ensure EU law is observed and remedies are available to guarantee effective legal protection.
- Ordinary legislative procedure involves the European Commission proposing regulations, directives, or decisions that are jointly adopted by the European Parliament and the European Council.
- Primary EU law consists of the Treaty on European Union, the Treaty on the Functioning of the EU, and the Charter of Fundamental Rights of the EU, with general principles of Union law reflected through case law.
- Secondary EU law includes international agreements and legislation, such as regulations (binding in all member states), directives (binding on the result, but national authorities choose the method), and decisions (binding and addressed to specific member states).
- Interpretation of data protection law considers the wording, objectives, legislative context, and the overall context of EU law, possibly including its origins.
- The CJEU provides preliminary rulings on the interpretation and validity of EU law, often requested by national courts in GDPR cases.
- The Internet is a place for exercising fundamental freedoms, such as freedom of expression, information, and association, and also respects private and family life, personal integrity, and non-discrimination.
GDPR Overview
- GDPR principles are derived from Article 8 of the Charter of Fundamental Rights of the EU.
- It replaced the 1995 Data Protection Directive.
- GDPR aims to protect fundamental rights and freedoms of natural persons with regard to the processing of personal data, and the free movement of personal data.
- GDPR principles are legitimacy (purpose limitations, fairness, processing must be limited to what's necessary), proportionality, transparency, and accountability, Security, and data minimization.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.