Entrusting processing of personal data
Quite often it happens that an entrepreneur performing operations on personal data does not become their controller. Despite the fact that it processes data, someone else is their controller.
Quite often it happens that an entrepreneur performing operations on personal data does not become their controller. Despite the fact that it processes data, someone else is their controller.
GDPR provides for the function of a data protection officer, who should be appointed by the controller in certain situations. I explain when it is mandatory and who and how to appoint to this position, as well as what are his tasks.
GDPR imposes many requirements on the personal data controller. One of the first that the controller should perform is to provide information.
It is the best to avoid sensitive personal data. However, if you must process them, remember that this is only allowed in strictly defined cases.
Advertising triggers sales so every company processes personal data in connection with marketing.
The legitimate interest of the administrator is a convenient base for data processing. Therefore, it is sometimes abused by entrepreneurs.
It often happens that consent to the processing of personal data is not obtained in accordance with GDPR. I explain how to do it correctly.
Controller may not process personal data at his discretion. For this to be possible, there must be a legal basis. Determining this is one of the first steps an entrepreneur should take when dealing with personal data.
About personal data, processing and application of GDPR, I wrote in previous posts. Form today’s post you will learn who is a controller of personal data and what obligations does he have.
If data coming to your company are personal data, and what you do with them is processing, be aware that the President of the Personal Data Protection Office may get interested in you.