CIPP/E · Domain 2
European Data Protection Regulation
About 40% of the exam
Obligations at a glance
- Article 24
- measures proportionate to the risk
- Article 25
- protection by design and default
- Article 26
- joint controller arrangements
- Article 28
- processor contracts and sub processors
- Article 30
- records of processing activities
- Article 32
- security appropriate to the risk
- Article 35
- assessments for high risk processing
- Article 37
- when an officer is mandatory
The rights and their limits
- Information
- at collection or within a month
- Access
- confirmation, a copy and context
- Rectification
- correct and complete the record
- Erasure
- six grounds, five exceptions
- Restriction
- hold the data, stop using it
- Portability
- consent or contract, automated only
- Objection
- absolute only for direct marketing
- Automated decisions
- human review, view and challenge
One month to respond, extendable by two for complex cases, and any refusal must point the person toward the authority and the courts
Cookies and the ePrivacy Directive
- Consent before storing or reading anything
- Strictly necessary cookies are exempt
- Analytics usually needs consent
- Legitimate interests cannot replace this consent
- Rejecting must be as easy as accepting
- Fingerprinting counts as terminal equipment access
- Transposed nationally, so rules vary
ePrivacy beyond cookies
- Confidentiality of communications and traffic data
- Location data needs consent or anonymity
- Unsolicited marketing rules for electronic mail
- A soft opt in for existing customers
- Business contacts treated differently by state
- Providers report breaches to their regulator
- It prevails over the general regulation
Employment processing
- Consent rarely free in employment
- Contract covers pay and benefits
- Legal obligation covers tax and payroll
- Legitimate interests cover network security
- Works councils may need consulting
- National law varies most here
Monitoring at work
- The least intrusive method that works
- Tell staff before monitoring starts
- An assessment for systematic monitoring
- Covert monitoring only in extreme cases
- Private areas remain off limits
- Retention of footage kept short
Transfers in outline
Mechanisms
- Adequacy decisions from the Commission
- Standard clauses in four modules
- Binding corporate rules inside groups
- Codes and certification with commitments
Conditions
- Assess the destination legal regime
- Add supplementary measures where needed
- Derogations stay occasional and narrow
- Onward transfers need their own cover
Access from a third country counts as a transfer, so remote support desks and global administration teams belong on the transfer map
Roles in practice
- Purposes and means decide the role
- Analytics providers are often joint controllers
- Cloud vendors normally act as processors
- Exceeding instructions creates a new controller
- One firm can hold both roles
Impact assessments
- Required before high risk processing
- Description, necessity, risks and measures
- The officer advises, the controller decides
- Authority blacklists list national triggers
- Consult when residual risk stays high
- Review when the processing changes
Security and breaches
- Measures appropriate to the assessed risk
- Seventy two hours to the authority
- High risk means telling individuals too
- Encryption can excuse the individual notice
- Every breach recorded, notified or not
- Processors tell controllers without undue delay
Marketing rules together
- Electronic mail generally needs prior consent
- A soft opt in for similar products
- Every message carries an unsubscribe route
- Objection to marketing is absolute
- Profiling for advertising needs its own basis
- Consent records kept as evidence
Operational traps
- Cookies set before consent is given
- Records of processing frozen at launch
- Employee consent used for monitoring
- Vendor list never matched to contracts
- An assessment written after deployment
- Transfers mapped without remote access
Running a compliance review
- Inventory processing and update records
- Confirm the basis for each purpose
- Check notices match reality
- Test the rights process end to end
- Review contracts and sub processors
- Map and assess transfers
- Rehearse the breach response
- Records drive everything else you check
- Notices are the easiest gap to find
- Rights handling reveals process maturity
- Transfers change quietly through vendors
Deadlines in one place
- Rights response
- one month, extendable by two
- Breach to authority
- seventy two hours from awareness
- Article 14 notice
- within a month of obtaining
- Prior consultation
- eight weeks, plus six if extended
- Mutual assistance
- one month between authorities
- Certification validity
- three years, then renewal
Consent, compared
- Regulation consent
- freely given, specific, informed, unambiguous
- Explicit consent
- a clear express statement required
- Cookie consent
- before anything is stored
- Marketing consent
- prior, with an easy withdrawal
- Transfer consent
- informed of the specific risks
Reference strip: obligations, rights, ePrivacy, employment, transfers
Obligations
- Design, records, security, assessments
- Contracts with every processor
- An officer where triggers apply
Rights
- One month to answer
- Erasure and objection have limits
- Automated decisions need human review
ePrivacy
- Consent before terminal access
- Strictly necessary is exempt
- National variation is real
Employment
- Consent rarely free here
- Tell staff before monitoring
- National rules dominate
Transfers
- Adequacy, clauses, rules, derogations
- Assess the destination law
- Remote access counts
Quick exam traps
- Trap: Cookie consent is governed by the regulation rather than the ePrivacy Directive
- Trap: Analytics cookies are always strictly necessary
- Trap: Employee consent is a reliable basis for workplace monitoring
- Trap: A cloud provider becomes a joint controller because it holds the data
- Trap: Data portability covers the profiles a controller inferred
- Trap: An impact assessment is only needed when the authority asks
- Trap: A banner that only offers accept satisfies the consent requirement
cybercertprep.com · original revision sheet written from the public body of knowledge