Entrusting processing of personal data
Quite often it happens that an entrepreneur performing operations on personal data does not become their controller. Despite the fact that it processes data, someone else is their controller.
Quite often it happens that an entrepreneur performing operations on personal data does not become their controller. Despite the fact that it processes data, someone else is their controller.
GDPR provides for the function of a data protection officer, who should be appointed by the controller in certain situations. I explain when it is mandatory and who and how to appoint to this position, as well as what are his tasks.
GDPR imposes many requirements on the personal data controller. One of the first that the controller should perform is to provide information.
It is the best to avoid sensitive personal data. However, if you must process them, remember that this is only allowed in strictly defined cases.
Advertising triggers sales so every company processes personal data in connection with marketing.
The legitimate interest of the administrator is a convenient base for data processing. Therefore, it is sometimes abused by entrepreneurs.
About personal data, processing and application of GDPR, I wrote in previous posts. Form today’s post you will learn who is a controller of personal data and what obligations does he have.
In the previous post I explained what data should be considered to be personal data. Now I would like to concentrate on the second definition from article 4 of GDPR explaining what personal data processing is.
In order to make personal data processing in your company, you should start from answering one very important question – what are personal data?
Article 28 sec. 3 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement…