Territorial and Material Scope & Accountability Flashcards

Define the GDPR's scope of application and examine how organizations demonstrate compliance through accountability measures. (56 cards)

1
Q

What is an establishment under the GDPR?

A

Any real and effective activity through stable arrangements by a controller or processor within the EU.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the Weltimmo case say about establishment?

A

Even minimal activity through stable arrangements in a member state can constitute establishment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What factors suggest an establishment exists?

A
  • Target audience
  • Presence of representatives
  • Bank accounts
  • Physical address for mail collection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does GDPR territorial scope cover?

A

Organizations established in the EU, or those selling goods/services to or monitoring individuals in the EU.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the focus of EDPB Guidelines 3/2018?

A

Whether the specific processing activity falls within GDPR’s territorial scope.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the main test concerning territorial scope under Article 3(1) of the GDPR?

A

Whether processing is in the context of the activities of an establishment in the Union.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the 2 parts of the Article 3(1) test?

A
  1. Is there an EU establishment involved?
  2. Is the data processing carried out in the context of that establishment’s activities?
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Does Article 3(1) depend on the location of processing?

A

No

It applies regardless of whether the processing occurs in the Union.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Does the GDPR apply based on the nationality or residence of the data subject?

A

No

Per Recital 14, GDPR applies regardless of nationality or residence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Is payment required for GDPR to apply under Article 3(2)?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is targeting according to EDPB?

A

Intentional direction of goods, services, or messages to individuals based on specific criteria

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are some EDPB targeting factors?

A
  • Use of EU domains
  • Marketing to EU
  • Translation for EU
  • Use of EU addresses
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is monitoring under GDPR?

A

The observation, tracking, or profiling of individuals’ behavior.

Examples: behavioral advertising, use of cookies, device fingerprinting, personalized recommendations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does Article 3(2)(b) require for monitoring to trigger GDPR?

A
  • Behavior must take place in the EU
  • Involve data subjects in the EU
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are examples of offline monitoring?

A
  • In-person health assessments
  • Surveys
  • Interviews
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How does the UK approach data protection post-Brexit?

A

The UK enforces legislation identical to the GDPR for non-UK organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is material scope under GDPR?

A

The types of data processing activities to which the GDPR applies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What types of processing fall within the GDPR’s material scope?

A

Processing of personal data, including both automated and manual processing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What activities fall outside the GDPR’s scope?

A

Activities outside Union law, including:

  • Public security
  • Defense
  • National security
  • EU foreign and security policy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are 3 exemptions to GDPR’s material scope?

A
  • Household use
  • Criminal law enforcement
  • Processing by EU institutions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the household exemption under the GDPR?

A

Processing by a natural person in the course of purely personal or household activities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What activities are covered by the crime-related exemption?

A

Processing for:

  • Prevention
  • Detection
  • Prosecution of crimes
  • Execution of criminal penalties
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Are EU institutions covered by the GDPR?

24
Q

What regulation applies to data processing by EU institutions?

A

Regulation 2018/1725

25
What is the **objective** of the **E-Commerce Directive**?
To **remove barriers to cross-border online services** and provide legal certainty for businesses and consumers.
26
What does the E-Commerce Directive establish **rules** for?
* Online intermediary liability * Transparency * Requirements for information society services
27
What is **accountability** under GDPR?
Obligation to comply with laws and **demonstrate compliance through evidence** and transparency.
28
What is CNIL’s '**the Standard**'?
A set of **25 requirements for privacy governance** used to grant a 'privacy seal'.
29
How can organizations demonstrate accountability?
* Through internal policies * Allocation of responsibilities * Training
30
What are examples of **high-risk processing**?
* Discrimination * Identity theft * Financial loss * Damage to reputation * Confidentiality breaches * Deprivation of rights * Processing sensitive or children’s data
31
What should be included in a **privacy policy scope**?
**Who** and **what** processing activities are covered.
32
What are **management responsibilities** in a privacy policy?
* Risk assessment * Procedure development * Control identification * DPO designation
33
What should be included in **incident reporting procedures**?
* Response team roles * Immediate reporting by employees * Internal and external reporting paths
34
What are compliance-related **consequences** of non-compliance?
* Disciplinary action * Termination * Civil and criminal penalties
35
What is the role of a **Privacy Governance Council**?
**Coordinate privacy efforts across an organization**, led by a Chief Privacy Officer.
36
What is the responsibility of **privacy leads/directors**?
**Implement privacy programs** within their specific business functions and maintain records.
37
What is **Privacy by Design**? | (PbD)
An approach where privacy is **embedded into the design, development, and maintenance** of systems and projects.
38
**Who** developed the concept of **Privacy by Design**?
Ann Cavoukian
39
What is **Privacy by Default**?
Processing only necessary data, with **strictest privacy settings active by default**.
40
What are the key **goals** of Privacy by Default?
* Limit data collection and retention * Ensure strong privacy settings * Implement necessary controls
41
What controls **demonstrate PbDD compliance**?
* Data minimization * Pseudonymization * User control * Data security
42
What is **RoPA** under GDPR?
Records of Processing Activities
43
What did the Data Protection Directive (DPD) require for documentation?
**Registration** and **notification** of processing activities with DPAs.
44
What does GDPR require regarding **documentation**?
Controllers and processors **must retain documentation** and provide it to the DPA upon request.
45
What must be included in a **controller's** RoPA?
* Controller/DPO contact details * Purpose of processing * Data subject and personal data categories * Recipient categories * Third-country transfers * Retention periods * Safeguards
46
What are the **exemptions to RoPA** under GDPR?
Organizations with fewer than 250 employees unless processing is: * Risky * Frequent, or * Involves special/criminal data
47
What is a **Data Protection Impact Assessment**? | (DPIA)
A tool and process to: * Identify * Assess, and * Mitigate privacy risk throughout a system or project development life cycle
48
When is a DPIA **required**?
When processing **involves high risk**. ## Footnote For example: profiling, large-scale special category data, or public monitoring
49
What **activities trigger** a DPIA?
* Systematic profiling with significant effects * Large-scale processing of sensitive data * Public area monitoring
50
What **must be included** in a DPIA?
* Processing activity explanation * Purpose * Legitimate interests * Necessity/proportionality assessment * Risk analysis * Mitigation controls
51
What should a controller do when risks **remain high after controls**?
Consult the supervisory authority (DPA).
52
What are '**core activities**' as defined by WP29?
Key **operations essential** to achieving the controller’s objectives. ## Footnote Examples: hospitals processing patient data, banks processing customer data, security companies conducting surveillance
53
What are **large-scale processing factors**?
* Number of data subjects * Volume of data * Range and geographic extent of collection * Duration of collection
54
What defines '**systematic**' processing?
Processing that follows a **system, is scheduled**, or **part of a general strategy**.
55
What defines '**regular**' processing?
**Ongoing** or **recurring** at set intervals.
56
What is the rule for **group-wide DPO designation**?
Organizations can share a DPO if the DPO is **easily accessible** to each entity.