Skip to main content

Questions tagged [gdpr]

Questions about the European Union General Data Protection Regulation (GDPR)

0 votes
0 answers
49 views

Could one's GDPR compliance affect the outcome of civil action relating to software failures?

Suppose a company provided a service, had a computer issue and as a result one of their customers suffered a loss. Are there circumstances that a failure in the documentation required by GDPR could ...
User65535's user avatar
  • 7,690
0 votes
0 answers
17 views

Is it GDPR compliant to require Digital Rights Management software to access a privacy policy?

Suppose a data controller provided a privacy policy, detailing the information that a data subject must have or be provided with under the various articles of the GDPR, including 13, 14, 15, 22 and 45....
User65535's user avatar
  • 7,690
1 vote
0 answers
61 views

Is it GDPR compliant to require registration to access a privacy policy?

There is currently an issue with Windows operating systems, reputed to be related to Falcon Sensor from CrowdStrike. From the description of their tool, the question of GDPR compliance can be asked ...
User65535's user avatar
  • 7,690
6 votes
1 answer
2k views

Is deciding to use google fonts the sort of decision that makes an entity a controller rather than a processor?

In ensuring GDPR compliance determining which entities are data controllers and which data processors is a critical step. The UK government says: The UK GDPR defines a controller as: the natural or ...
User65535's user avatar
  • 7,690
0 votes
0 answers
19 views

Does the transfer occurring under Article 45, 46 or 49 affect the Right of Access under Article 15.2?

Transfer of personal data from the UK to the US can, at least in theory, occur under Articles 45, 46 and 49. These all have different requirements. Article 15 of the GDPR the Right of access includes ...
User65535's user avatar
  • 7,690
0 votes
0 answers
22 views

What does being "informed of the appropriate safeguards pursuant to Article 46" mean?

Article 15 of the GDPR the Right of access includes section 2: Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be ...
User65535's user avatar
  • 7,690
0 votes
2 answers
177 views

Do patients have the right to foot moulds / models from chiropodists? [closed]

If a chiropodist produces a 3D model or mould from a patient's foot in order to produce orthotic insoles, is the chiropodist required to retain the model or mould for a particular period of time? Does ...
Griffin's user avatar
  • 97
1 vote
2 answers
151 views

Does a company have an obligation to attempt to answer a GDPR request if the requestor may not have provided sufficient identification information?

An individual has asked to provide information on his personal data which is stored by a company (GDPR). He has only provided his name and surname. He has signed the document electronically, i.e., we ...
ZygD's user avatar
  • 175
1 vote
0 answers
45 views

How specific does the information need to be relating to personal information transfer between data controllers?

When personal information is transferred between data controllers the GDPR imposses certain requirements. Among these are information that must be provided to the data subject. As I understand it ...
User65535's user avatar
  • 7,690
-1 votes
1 answer
72 views

How can I take legal action on a company who refused to send chat script on customer's request [closed]

I would like to know how can I take legal action on a company who refused to share the chat script with customers on request. The customer requested the chat script after chatting with the chat ...
Real Mi's user avatar
6 votes
3 answers
1k views

Locally stored PII: Are we a GDPR Data Processor?

We are a charity that uses software to keep names and addresses of it's members. Email addresses and Emergency Contacts. We use a piece of software that is NOT cloud based. It is installed on the ...
Andy C's user avatar
  • 63
1 vote
1 answer
139 views

Can computer performance metrics be personal data?

ScorecardResearch is a major data collection organisation that serves code onto some major UK web sites. Their privacy policy mentions a lot of tracking, including "hardware or device ...
User65535's user avatar
  • 7,690
3 votes
0 answers
43 views

Does there exist an example of meaningful information about an automated individual decision-making algorithm?

The GDPR Article 14 includes provisions for the data subject to have meaningful information about an automated individual decision-making algorithm that which produces legal effects concerning him or ...
User65535's user avatar
  • 7,690
0 votes
0 answers
58 views

Does the GDPR right to deletion in Art. 17 effectively include some "disproportionate effort" exception?

Some provisions of the GDPR have explicit exceptions about "disproportionate effort". Particularly relevant is the one in Article 19: The controller shall communicate any rectification or ...
User65535's user avatar
  • 7,690
1 vote
1 answer
89 views

What exactly is a decision wrt. GDPR Automated individual decision-making?

The GDPR Article 22 provides rights relating to automated individual decision-making, including profiling. It starts: The data subject shall have the right not to be subject to a decision based ...
User65535's user avatar
  • 7,690

15 30 50 per page
1
2 3 4 5
69