The GDPR puts in place clear procedures in case of a data breach. If a data breach poses a risk, companies and organisations holding your data have to inform the relevant data protection authority within 72 hours or without undue further delay. If the leak poses a high risk to you, then you must also be informed personally.
Isikuandmete kaitse üldmääruse ehk IKÜM-ga kehtestatakse ühtlustatud eeskirjad, mida kohaldatakse Euroopa Majanduspiirkonnas (EMP) asutatud organisatsioonide (avalik-õiguslikud või eraõiguslikud organisatsioonid, olenemata nende suurusest) mis tahes isikuandmete töötlemise suhtes või mis on suunatud üksikisikutele EL-is. IKÜM-i esmane eesmärk on tagada, et isikuandmete kaitse tase on kõikjal EMP-s sama kõrge, suurendades nii andmeid töötlevate üksikisikute kui ka organisatsioonide õiguskindlust ning pakkudes üksikisikutele kõrgetasemelist kaitset.
Määrus jõustus 24. mail 2016 ja seda kohaldatakse alates 25. maist 2018.
Kuidas saan Euroopa Andmekaitsenõukogu tööga sammu pidada?
Euroopa Andmekaitsenõukogu avaldab korrapäraselt pressiteateid, uudiseid, blogisid ja muud sisu Euroopa Andmekaitsenõukogu veebisaidil ja enda sotsiaalmeediakanalites (X: @EU_EDPB; LinkedIn: Euroopa Andmekaitsenõukogu), et hoida andmekaitsekogukondi ja üldsust oma tööga kursis.
Euroopa Andmekaitsenõukogu veebisaidil on ka kaks RSS-kanalit, mida saate tellida Euroopa Andmekaitsenõukogu uudiste ja Euroopa Andmekaitsenõukogu viimaste väljaannete automaatseks teavituseks.
Does the GDPR apply to my organisation?
Every organisation, regardless of the their size or sector, established in the European Economic Area (EEA) or offering products or services to individuals in the EEA, processing personal data whether or not by automated means needs to comply with the GDPR. The GDPR applies to the automated processing of personal data and to processing operations carried out manually from the moment the paper files are organised in a systematic manner, e.g. ordered alphabetically in a filing cabinet.
Examples of processing operations include collecting, recording, organising, using, modifying, storing, disclosing, altering and erasing individuals’ personal data.
Nevertheless, the application of the GDPR is modulated according to the nature, context, purposes and risks of the processing operations carried out. For SMEs whose core business is not the processing of personal data, the obligations can be less strict than for a large company.
Are EDPB documents available in all EU languages?
We are constantly working on the translation of our documents into the official EU languages. All static content, as well as press releases and documents officially adopted by the Board, such as Guidelines, will be made available in these languages.
This process takes time and various steps need to be completed in order to provide translations of the best quality.
Please note that documents undergoing public consultation are usually not translated. It is only after the public consultation has been concluded and a final version of the document has been adopted by the Board that these documents will be translated.
The deadline for submitting comments to a public consultation has expired, can I still submit comments?
Unfortunately, the EDPB cannot consider late contributions as part of the public consultation.
The European Data Protection Supervisor (EDPS) is a Member of the European Data Protection Board. In addition, the EDPS provides the EDPB Secretariat. The Secretariat offers administrative and logistic support to the EDPB, performs analytical work and contributes to the EDPB’s tasks.
Although staff at the Secretariat is employed by the EDPS, staff members only work under the instructions of the Chair of the EDPB.
How can my processing operations or my organisation become GDPR certified?
Under the GDPR, certification is conducted by national certification bodies or by the competent national data protection authorities (Art. 42(5) GDPR).
For further information, we recommend contacting the relevant national DPA for your organisation. You can find a overview of all EEA DPAs here.
No. The EDPB does not handle complaints or conduct investigations. If you believe your data protection rights have been violated you can contact the organisation holding your data, contact your national data protection authority (DPA), or go to a national court.
Is the guidance adopted by the Article 29 Working Party (WP29) still relevant today?
The EDPB endorsed WP29 documents are available here.
As regards the other existing WP29 documents, they may remain relevant and helpful insofar as the EDPB has not adopted new documents on the topic and/or they are compatible with the GDPR. This amounts to a case-by-case assessment.