ENGLISH

The EU General Data Protection Regulation (GDPR): A Commentary

Book information

Publisher
Oxford University Press
Year
2020
ISBN
0198826494, 9780198826491, 0192561081, 9780192561084, 019884686X, 9780198846864
Language
english
Format
PDF
Filesize
13 MB (13940524 bytes)
Edition
1st Edition
Pages
1486\1486
Time added
2021-03-09 22:29:47

Description

This new book provides an article-by-article commentary on the new EU General Data Protection Regulation. Adopted in April 2016 and applicable from May 2018, the GDPR is the centrepiece of the recent reform of the EU regulatory framework for protection of personal data. It replaces the 1995 EU Data Protection Directive and has become the most significant piece of data protection legislation anywhere in the world. The book is edited by three leading authorities and written by a team of expert specialists in the field from around the EU and representing different sectors (including academia, the EU institutions, data protection authorities, and the private sector), thus providing a pan-European analysis of the GDPR. It examines each article of the GDPR in sequential order and explains how its provisions work, thus allowing the reader to easily and quickly elucidate the meaning of individual articles. An introductory chapter provides an overview of the background to the GDPR and its place in the greater structure of EU law and human rights law. Account is also taken of closely linked legal instruments, such as the Directive on Data Protection and Law Enforcement that was adopted concurrently with the GDPR, and of the ongoing work on the proposed new E-Privacy Regulation. Cover......Page 1 Title......Page 2 Title - Complete......Page 4 Copyright......Page 5 Foreword......Page 6 Editors’ Preface......Page 8 Contents......Page 12 Table of Cases......Page 18 Table of Instruments......Page 40 List of Abbreviations......Page 88 List of Contributors......Page 90 Background and Evolution of the EU General Data Protection Regulation (GDPR) (Christopher Kuner, Lee A. Bygrave and Christopher Docksey)......Page 94 Article 1 Subject-matter and objectives (Hielke Hijmans)......Page 141 Article 2 Material scope (Herke Kranenborg)......Page 153 Article 3 Territorial scope (Dan Jerker B. Svantesson)......Page 167 Article 4 Definitions (Luca Tosoni and Lee A. Bygrave)......Page 193 Article 4(1) Personal data (Lee A. Bygrave and Luca Tosoni)......Page 196 Article 4(2) Processing (Luca Tosoni and Lee A. Bygrave)......Page 209 Article 4(3) Restriction of processing (Luca Tosoni)......Page 216 Article 4(4) Profiling (Lee A. Bygrave)......Page 220 Article 4(5) Pseudonymisation (Luca Tosoni)......Page 225 Article 4(6) Filing system (Luca Tosoni)......Page 231 Article 4(7) Controller (Lee A. Bygrave and Luca Tosoni)......Page 238 Article 4(8) Processor (Lee A. Bygrave and Luca Tosoni)......Page 250 Article 4(9) Recipient (Luca Tosoni)......Page 256 Article 4(10) Third party (Luca Tosoni)......Page 263 Article 4(11) Consent (Lee A. Bygrave and Luca Tosoni)......Page 267 Article 4(12) Personal data breach (Luca Tosoni)......Page 281 Article 4(13) Genetic data (Lee A. Bygrave and Luca Tosoni)......Page 289 Article 4(14) Biometric data (Lee A. Bygrave and Luca Tosoni)......Page 300 Article 4(15) Data concerning health (Lee A. Bygrave and Luca Tosoni)......Page 310 Article 4(16) Main establishment (Luca Tosoni)......Page 318 Article 4(17) Representative (Luca Tosoni)......Page 331 Article 4(18) Enterprise (Lee A. Bygrave and Luca Tosoni)......Page 339 Article 4(19) Group of undertakings (Luca Tosoni)......Page 346 Article 4(20) Binding corporate rules (Luca Tosoni)......Page 350 Article 4(21) Supervisory authority (Lee A. Bygrave)......Page 358 Article 4(22) Supervisory authority concerned (Luca Tosoni)......Page 365 Article 4(23) Cross- border processing (Luca Tosoni)......Page 372 Article 4(24) Relevant and reasoned objection (Luca Tosoni)......Page 381 Article 4(25) Information society service (Luca Tosoni)......Page 385 Article 4(26) International organisation (Lee A. Bygrave and Luca Tosoni)......Page 396 Article 5 Principles relating to processing of personal data (Cécile de Terwangne)......Page 402 Article 6 Lawfulness of processing (Waltraut Kotschy)......Page 414 Article 7 Conditions for consent (Eleni Kosta)......Page 438 Article 8 Conditions applicable to child’s consent in relation to information society services (Eleni Kosta)......Page 448 Article 9 Processing of special categories of personal data (Ludmila Georgieva and Christopher Kuner)......Page 458 Article 10 Processing of personal data relating to criminal convictions and offences (Ludmila Georgieva)......Page 478 Article 11 Processing which does not require identification (Ludmila Georgieva)......Page 484 Article 12 Transparent information, communication and modalities for the exercise of the rights of the data subject (Radim Polčák)......Page 491 Article 13 Information to be provided where personal data are collected from the data subject (Gabriela Zanfir-Fortuna)......Page 506 Article 14 Information to be provided where personal data have not been obtained from the data subject (Gabriela Zanfir- Fortuna)......Page 527 Article 15 Right of access by the data subject (Gabriela Zanfir- Fortuna)......Page 542 Article 16 Right to rectification (Cécile de Terwangne)......Page 562 Article 17 Right to erasure (‘right to be forgotten’) (Herke Kranenborg)......Page 568 Article 18 Right to restriction of processing (Gloria González Fuster)......Page 578 Article 19 Notification obligation regarding rectification or erasure of personal data or restriction of processing (Gloria González Fuster)......Page 585 Article 20 Right to data portability (Orla Lynskey)......Page 590 Article 21 Right to object (Gabriela Zanfir-Fortuna)......Page 601 Article 22 Automated individual decision-making, including profiling (Lee A. Bygrave)......Page 615 Article 23 Restrictions (Dominique Moore)......Page 636 Article 24 Responsibility of the controller (Christopher Docksey)......Page 648 Article 25 Data protection by design and by default (Lee A. Bygrave)......Page 664 Article 26 Joint controllers (Christopher Millard and Dimitra Kamarinou)......Page 675 Article 27 Representatives of controllers or processors not established in the Union (Christopher Millard and Dimitra Kamarinou)......Page 682 Article 28 Processor (Christopher Millard and Dimitra Kamarinou)......Page 692 Article 29 Processing under the authority of the controller or processor (Christopher Millard and Dimitra Kamarinou)......Page 705 Article 30 Records of processing activities (Waltraut Kotschy)......Page 709 Article 31 Cooperation with the supervisory authority (Waltraut Kotschy)......Page 718 Article 32 Security of processing (Cédric Burton)......Page 723 Article 33 Notification of a personal data breach to the supervisoryauthority (Cédric Burton)......Page 733 Article 34 Communication of a personal data breach to the data subject (Cédric Burton)......Page 747 Article 35 Data protection impact assessment (Eleni Kosta)......Page 758 Article 36 Prior consultation (Cecilia Alvarez Rigaudias and Alessandro Spina)......Page 773 Article 37 Designation of the data protection officer (Cecilia Alvarez Rigaudias and Alessandro Spina)......Page 781 Article 38 Position of the data protection officer (Cecilia Alvarez Rigaudias and Alessandro Spina)......Page 793 Article 39 Tasks of the data protection officer (Cecilia Alvarez Rigaudias and Alessandro Spina)......Page 802 Article 40 Codes of conduct (Irene Kamara)......Page 809 Article 41 Monitoring of approved codes of conduct (Irene Kamara)......Page 818 Article 42 Certification (Ronald Leenes)......Page 825 Article 43 Certification bodies (Ronald Leenes)......Page 837 Article 44 General principle for transfers (Christopher Kuner)......Page 848 Article 45 Transfers on the basis of an adequacy decision (Christopher Kuner)......Page 864 Article 46 Transfers subject to appropriate safeguards (Christopher Kuner)......Page 890 Article 47 Binding corporate rules (Christopher Kuner)......Page 906 Article 48 Transfers or disclosures not authorised by Union law (Christopher Kuner)......Page 918 Article 49 Derogations for specific situations (Christopher Kuner)......Page 934 Article 50 International cooperation for the protection of personal data (Christopher Kuner)......Page 950 Article 51 Supervisory authority (Hielke Hijmans)......Page 956 Article 52 Independence (Thomas Zerdick)......Page 966 Article 53 General conditions for the members of the supervisory authority (Hielke Hijmans)......Page 977 Article 54 Rules on the establishment of the supervisory authority (Hielke Hijmans)......Page 986 Article 55 Competence (Hielke Hijmans)......Page 995 Article 56 Competence of the lead supervisory authority (Hielke Hijmans)......Page 1006 Article 57 Tasks (Hielke Hijmans)......Page 1020 Article 58 Powers (Ludmila Georgieva and Matthias Schmidl)......Page 1032 Article 59 Activity reports (Hielke Hijmans)......Page 1042 Article 60 Cooperation between the lead supervisory authority and the other supervisory authorities concerned (Luca Tosoni)......Page 1046 Article 61 Mutual assistance (Peter Blume)......Page 1066 Article 62 Joint operations of supervisory authorities (Peter Blume)......Page 1079 Article 63 Consistency mechanism (Patrick Van Eecke and Anrijs Šimkus)......Page 1088 Article 64 Opinion of the Board (Patrick Van Eecke and Anrijs Šimkus)......Page 1098 Article 65 Dispute resolution by the Board (Hielke Hijmans)......Page 1107 Article 66 Urgency procedure (Ludmila Georgieva)......Page 1120 Article 67 Exchange of information (Patrick Van Eecke and Anrijs Šimkus)......Page 1125 Article 68 European Data Protection Board (Christopher Docksey)......Page 1134 Article 69 Independence (Christopher Docksey)......Page 1148 Article 70 Tasks of the Board (Christopher Docksey)......Page 1162 Article 71 Reports (Christopher Docksey)......Page 1178 Article 72 Procedure (Christopher Docksey)......Page 1183 Article 73 Chair (Christopher Docksey)......Page 1188 Article 74 Tasks of the Chair (Christopher Docksey)......Page 1191 Article 75 Secretariat (Christopher Docksey)......Page 1195 Article 76 Confidentiality (Christopher Docksey)......Page 1204 Article 77 Right to lodge a complaint with a supervisory authority (Waltraut Kotschy)......Page 1210 Article 78 Right to an effective judicial remedy against a supervisory authority (Waltraut Kotschy)......Page 1218 Article 79 Right to an effective judicial remedy against a controller or processor (Waltraut Kotschy)......Page 1226 Article 80 Representation of data subjects (Gloria González Fuster)......Page 1235 Article 81 Suspension of proceedings (Waltraut Kotschy)......Page 1246 Article 82 Right to compensation and liability (Gabriela Zanfir- Fortuna)......Page 1253 Article 83 General conditions for imposing administrative fines (Waltraut Kotschy)......Page 1273 Article 84 Penalties (Orla Lynskey)......Page 1287 Article 85 Processing and freedom of expression and information (Herke Kranenborg)......Page 1295 Article 86 Processing and public access to official documents (Herke Kranenborg)......Page 1306 Article 87 Processing of the national identification number (Patrick Van Eecke and Anrijs Šimkus)......Page 1316 Article 88 Processing in the context of employment (Patrick Van Eecke and Anrijs Šimkus)......Page 1222 Article 89 Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes......Page 1333 Article 90 Obligations of secrecy (Christian Wiese Svanberg)......Page 1345 Article 91 Existing data protection rules of churches and religious associations (Luca Tosoni)......Page 1350 Article 92 Exercise of the delegation (Luca Tosoni)......Page 1361 Article 93 Committee procedure (Luca Tosoni)......Page 1371 Article 94 Repeal of Directive 95/ 46/ EC (Dominique Moore)......Page 1384 Article 95 Relationship with Directive 2002/58/EC (Piedade Costa de Oliveira)......Page 1387 Article 96 Relationship with previously concluded Agreements (Dominique Moore)......Page 1395 Article 97 Commission reports (Thomas Zerdick)......Page 1401 Article 98 Review of other Union legal acts on data protection (Luca Tosoni)......Page 1405 Article 99 Entry into force and application (Dominique Moore)......Page 1413 Index......Page 1416

Similar books