Artikel 17
Boete bij onrechtmatige verwerking persoonsgegevens strafrechtelijke aard
Right to be forgotten and data erasure
Article 17 GDPR establishes the 'right to erasure' (also known as the 'right to be forgotten'). It obliges a controller to erase personal data without undue delay when one of six specific grounds applies. These grounds include: the data is no longer necessary for the collection purpose; the data subject withdraws consent (where consent was the lawful basis); the data subject objects to processing under Article 21(1) and there are no overriding legitimate grounds; the data has been unlawfully processed; erasure is required to comply with a legal obligation; or the data was collected in relation to an information society service offer to a child. As clarified by Recital 66, if the controller has made the data public, it must also take reasonable steps to inform other controllers processing that data to erase any copies or links.
The right is not absolute. Article 17(3) GDPR lists key exceptions where the right to erasure does not apply, including when processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest in the area of public health, for archiving purposes in the public interest, scientific or historical research, or for the establishment, exercise or defence of legal claims. The case law underscores a balancing test. For instance, in the Gerechtshof Arnhem-Leeuwarden ruling cited, the court had to weigh the right to data protection against the right to intellectual property. Furthermore, as seen in Digital Rights Ireland Ltd v. Ireland, even legally mandated data retention must be proportionate and for a strictly defined purpose like combating serious crime.
Boete bij onrechtmatige verwerking persoonsgegevens strafrechtelijke aard
Recht op gegevenswissing (ârecht op vergetelheidâ)
Right to erasure (âright to be forgottenâ)
Notification obligation regarding rectification or erasure of personal data or restriction of processing
Gerechtshof Arnhem-Leeuwarden - Civiel recht
Verzoek verwijdering zoekresultaten Google Search. AVG of Wbp?Belangenafweging
Gerechtshof Arnhem-Leeuwarden - Civiel recht
artikel 3:296 BW. artikel 4 sub 2 en 6 AVG. Preambule AVG overwegingen 47 en 50. Artikel 17 en 47 Handvest EU. Artikel 1 Eerste Protocol EVRM.Artikel 8 en 13 EVRM. Het hof moet beoordelen wiens belang in dit geval zwaarder weegt: het belang van DFW op bescherming van haar intellectueel eigendomsrecht of het belang van Ziggo c.s. op bescherming van persoonsgegevens van haar klanten. Het hof oordeelt dat op dit moment de belangen van de Ziggo-klanten na afgifte van de persoonsgegevens door DFW nog
Digital Rights Ireland
Data retention: Legally mandated communications meta-data retention can only be a justified interference with the right of privacy and the right to data protection under EU law if the retention is done for the purpose of fighting âserious crimeâ, on the basis of objective criteria and where there are clear substantial and procedural conditions laid down by law.
Worten
Security: Data protection law requires controllers (not Member States) to adopt technical and organizational measures which, having regard to the state of the art and cost of their implementation, are to ensure a level of security appropriate to the risks represented. Controller must ensure that only those persons duly authorized have access. (¶¶ 24â25, 28â29)
binding corporate rules voor verwerkingsverantwoordelijken
Guidelines on processing of personal data through video devices
Guidelines on the application of Article 60 GDPR
guidelines recht op inzage
Guidelines on the calculation of administrative fines under the GDPR
The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory authorities use when calculating of the amount of the fine. These Guidelines complement the previously adopted Guidelines on the application and setting of administrative fines for the purpose of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine. The calculation of the amount of the fine is at the discretion of the supervisory authority, ...
Guidelines on the concepts of controller and processor in the GDPR
The concepts of controller, joint controller and processor play a crucial role in the application of the General Data Protection Regulation 2016/679 (GDPR), since they determine who shall be responsible for compliance with different data protection rules, and how data subjects can exercise their rights in practice. The precise meaning of these concepts and the criteria for their correct interpretation must be sufficiently clear and consistent throughout the European Economic Area (EEA). The conc...
Guidelines on the targeting of social media users
Guidelines on the use of facial recognition technology in the area of law enforcement
More and more law enforcement authorities (LEAs) apply or intend to apply facial recognition technology (FRT). It may be used to authenticate or to identify a person and can be applied on videos (e.g. CCTV) or photographs. It may be used for various purposes, including to search for persons in police watch lists or to monitor a person's movements in the public space. FRT is built on the processing of biometric data , therefore, it encompasses the processing of special categories ...
Guidelines on virtual voice assistants
A virtual voice assistant (VVA) is a service that understands voice commands and executes them or mediates with other IT systems if needed. VVAs are currently available on most smartphones and tablets, traditional computers, and, in the latest years, even standalone devices like smart speakers. VVAs act as interface between users and their computing devices and online services such as search engines or online shops. Due to their role, VVAs have access to a huge amount of personal...
guidelines beperkingen rechten van betrokkenen
guidelines berekenen administratieve boetes
Het Europees Comité voor gegevensbescherming (EDPB) heeft deze richtsnoeren vastgesteld met het oog op de harmonisatie van de methode die de toezichthoudende autoriteiten gebruiken om het bedrag van de geldboete te berekenen. Deze richtsnoeren vormen een aanvulling op de eerder vastgestelde Richtsnoeren voor de toepassing en vaststelling van administratieve geldboeten in de zin van Verordening (EU) 2016/679 (WP 253), die betrekking hebben op de omstandigheden waarin een geldboete moet worden opg...
guidelines cameratoezicht
guidelines certificering
guidelines connected vehicles
guidelines doorgifte van persoonsgegevens tussen overheidsinstanties en -organen binnen en buiten de EER
guidelines gebruik gezichtsherkenning bij rechtshandhaving
Steeds meer rechtshandhavingsinstanties passen gezichtsherkenningstechnologie toe of zijn voornemens deze toe te passen. De technologie kan worden gebruikt om een persoon te authenticeren of te identificeren en kan voor video's (bijv. CCTV) of foto's worden ingezet, maar ook voor andere doeleinden, waaronder het opzoeken van personen op signaleringslijsten van de politie of het volgen van de bewegingen van een persoon in de openbare ruimte. Gezichtsherkenningstechnologie is gebaseer...
guidelines meldplicht datalekken
guidelines misleidende ontwerppatronen
Deze richtsnoeren bieden praktische aanbevelingen aan aanbieders van sociale media als verwerkingsverantwoordelijken van sociale media, ontwerpers en gebruikers van socialemediaplatforms, over het beoordelen en vermijden van zogenaamde 'misleidende ontwerp patronen' in de interfaces van sociale media die inbreuk maken op de vereisten van de AVG. Daartoe beveelt de EDPB aan dat verwerkingsverantwoordelijken gebruikmaken van interdisciplinaire teams, bestaande uit onder meer ontwerpers, func...
guidelines over de begrippen 'verwerkingsverantwoordelijke'Â en 'verwerker'Â in de AVG
De begrippen 'verwerkingsverantwoordelijke', 'gezamenlijke verwerkingsverantwoordelijke' en 'verwerker' spelen een cruciale rol bij de toepassing van de algemene verordening gegevensbescherming (AVG, Verordening (EU) 2016/679), aangezien ermee wordt bepaald wie verantwoordelijk is voor de naleving van verschillende gegevensbeschermingsregels en op welke wijze betrokkenen hun rechten in de praktijk kunnen uitoefenen. De precieze betekenis van deze begrippen en de criteria voor de jui...
guidelines over virtuele spraakassistenten
Een virtuele spraakassistent ( virtual voice assistant , of VVA) betreft een dienst die spraakgestuurde opdrachten begrijpt en uitvoert, of indien nodig als tussenschakel optreedt naar andere IT-systemen. Tegenwoordig is een VVA als optie beschikbaar op de meeste smartphones, tablets en reguliere computers en sinds enkele jaren zelfs op losse apparaten zoals smartspeakers. Een VVA functioneert als schakel tussen de gebruiker en zijn apparaat of een online dienst zoals een zoekmachine...
DPC welcomes publication of EDPB CEF implementation report on right to be forgotten
Brussels, 18 February - The European Data Protection Board (EDPB) has adopted a report on its Coordinated Enforcement Framework (CEF) action on the right to be forgotten (Art.17 GDPR). The Board selected this topic as it is one of the most frequently exercised GDPR rights and one about which DPAs frequently receive complaints from individuals. The main objectives of this coordinated action are to ensure that the right to erasure is effectively exercised by individuals in Europe and understand ho
}}}} The DPA ordered a company to erase the data provided by potential tenants after not entering into a lease agreement with them.The DPA ordered a landlord to erase the data provided by potential tenants after not entering into a lease agreement with them. == English Summary ==== English Summary == In 2023 the data subjects intended to enter into a lease agreement with a company (the controller). The controller requested various information from the data subjects, including identity documents,
We, the undersigned organisations and individuals, urge you in the strongest possible terms to reject the deletion of the Article 49(2) transparency safeguard for high-risk AI systems that is proposed in the AI Omnibus. This transparency safeguard ensures that providers of AI systems cannot circumvent the core obligations of the AI Act. The post A call to EU legislators: protect rights and reject the call to delete transparency safeguard in AI Act appeared first on Access Now.
Fixed Link He latter further claimed during the lawsuit against AZOP's decision that the authority had incorrectly and incompletely established the facts, misapplied substantive law, and breached procedural rules. He emphasized that the published personal data was unrelated to transparency in public administration, that he was neither a public figure nor a political actor, and that any public interest ended once he left office on 31 March 2023. He invoked his right to erasure under [[Articl
Facts }}}} A court held that a television broadcaster lawfully published a video containing personal data about a public company board member as the information served the public interest thus complying with [[Article 6 GDPR|Article 6 GDPR]] and outweighting the right to erasure.A court held that a television broadcaster lawfully published a video containing personal data about a public company board member as the information served the public interest thus complying with [[Article 6 GDPR]] and
}}}} An Austrian media company was fined âŹ6,820 by the Data Protection Authority for negligently failing to implement a binding order to modify its websiteâs cookie banner, delaying user consent options despite all appeals being rejected.The DPA fined a media company âŹ6,820 for failing to bring its cookie banner into compliance by implementing a visually equivalent option to reject cookies. The DPA previously ordered the controller to do so in accordance with Article 58(2)(d) GDPR. == English Su
A media company in Austria (the controller), which was publishing local news, operated a website which collected personal data from visitors using cookies and a cookie consent banner. Cookies included unique identifiers for tracking visitors. A media company in Austria (the controller), which was publishing local news, operated a website which collected personal data from visitors using cookies and a cookie consent banner. Cookies included unique identifiers for tracking visitors. In August 2021
Facts }}}} A court held that a television broadcaster lawfully published a video containing personal data about a public company board member as the information served the public interest thus complying with [[Article 6 GDPR]] and outweighting the right to erasure.A court held that a television broadcaster lawfully published a video concerning the resignation of a public companyâs board member as well as their personal data. According to the court, the information served the public interest and
Facts }}}} The Court ruled that the storage period for settled payment default data by private credit agencies is not automatically limited by debtor register deletion rules, and that GDPR codes of conduct may guide the balancing of interests under [[Article 6 GDPR#1f|Article 6(1)(f) GDPR]].The Federal Court of Justice held that a credit information agency's maximum storage period for data about an already settled payment default is not limited by national deletion rules for a public debtor
A media company in Austria (the controller), which was publishing local news, operated a website which collected personal data from visitors using cookies and a cookie consent banner. Cookies included unique identifiers for tracking visitors. A media company in Austria (the controller), which was publishing local news, operated a website which collected personal data from visitors using cookies and a cookie consent banner. Cookies included unique identifiers for tracking visitors. In August 2021
Hague Court of Appeal February 3, 2023, IT 4226; ECLI:NL:GHDHA:2023:306 (Veilig Thuis v. the respondent) In this case, a man requested the deletion of his personal data processed by Veilig Thuis. The court ruled that Veilig Thuis's processing of the man's data was lawful under the Social Support Act (Wmo) and that the request for data deletion was therefore denied. Safe Home is not obliged to erase the man's personal data in order to comply with the legal obligation under Article 17(1)(e) AVG, b
Request for destruction of Safe Home files; admissibility; right to erasure of personal data under the AVG and Wmo
Personal data protection. Request for removal of search results from the Google Search search engine: the right to be forgotten. Articles 17 and 21 General Data Protection Regulation (AVG) and Article 35 AVG Implementation Act.
> Privacybescherming is niet absoluut. Dat staat zelfs letterlijk zo in de privacywetgeving. De AVG bevat daarom ook allerlei uitzonderingen. Een van de uitzonderingen die enkele keren terugkomt in de AVG ziet op de verwerking van persoonsgegevens in het kader van "de instelling, uitoefening of onderbouwing van een rechtsvordering". Tot op heden was echter niet heel erg duidelijk wat die woorden nu precies betekenen. Een recente uitspraak van de Afdeling bestuursrechtspraak van de Raad van State
The Danish Data Protection Agency has looked into the tool Google Analytics and its settings, and the terms under which the tool is provided. On the basis of this review, the Danish Data Protection Agency concludes that the tool cannot, without more, be used lawfully. Lawful use requires the implementation of supplementary measures in addition to the settings provided by Google.
The European Data Protection Supervisor ordered Europol to hand over personal data to Dutch activist Frank van der Linde. The decision is the result of a two-year investigation into Europol's possession and storage of van der Linde's personal data.
> The fine is the result of an investigation that began in 2020 and focused on the companyâs processing of childrenâs personal data. Based on press reports, the investigation focused on children between the ages of 13 and 17 who were allowed to operate business or creator Instagram accounts. As a result, childrenâs phone numbers and email addresses were publicly accessible.
> The proposed fine follows complaints filed by privacy NGO âPrivacy Internationalâ against Criteo. [âŠ] Under the CNILâs sanction procedure, Criteo has the right to respond to the report, both with respect to the alleged infringements and the proposed sanction.
Lawfully collected and stored personal data may be retained in an additional internal database, to the extent that it pursues the same data processing purposes as the original data collection. That is the opinion of Advocate General PikamÀe to the EU Court in response to questions from a Hungarian judge.