SlideShare a Scribd company logo
Data Subject
Every person is considered
a Data Subject: citizens,
consumers, customers,
business partners,
employees, you and me.
Your company. You are
controlling, reviewing,
comparing and aggregating
data about your customers
(e.g. web analytics data).
Data Controller
Any information
relating to an identified or
identifiable natural person
(in other words: the Data
Subject).
Personal data
Right of access
Right to erasure
The purpose of processing.
Categories of personal data.
Recipients of the data.
A copy of the collected personal data.
Data Controllers have to provide Data Subjects:
Data Subjects can request correction of their data if they see
it is not accurate or truthful.
Data Controllers have to erase or rectify (fix / adjust)
inaccurate or incomplete data.
Why the Data Controller is processing the data.
What categories of data are being processed.
Whether the Data Controller is processing their data.
Will the Controller share their data and with who.
How long the data will be stored.
That they have the right to erasure, rectification, restriction
of processing, and to object to processing.
That they have the right to complain to the Data Protec-
tion Authority (DPA).
If there is automated processing that has a significant
effect on them.
Data Subjects have the right to know:
The data was collected unlawfully.
The time limit for the storage of the data has expired.
The Data Subject objects to their personal data being pro-
cessed.
The data was collected when the Data Subject was a child.
The purpose of collecting and processing data has
changed.
Erasure is necessary to comply with EU or Member State
law.
Personal data has to be removed within ONE MONTH when:
Right to restrict processing
They contest the accuracy of the data.
The processing is unlawful and they request
restriction.
The controller no longer needs the data for their
original purpose, but the data is still required by the
controller to establish, exercise or defend legal
rights.
There is an erasure request and the Data Controller is
verifying it.
Data Subjects can stop Data Controllers from performing specific actions
with their data (the Controller may only hold the data or use it for limited
purposes).
Data Subjects can restrict the processing of their personal data if:
IMPORTANT : The Data Controller has to ensure that all distributed personal data was removed.
Even the data that was processed by 3rd parties!
Right to rectification
The General Data Protection Regulation comes into effect on May 25th 2018 and introduces
a list of Data Subjects’ rights to protect internet users. Learn how Data Controllers can
ensure these rights and avoid severe fines, as high as €20m or 4% of your company’s yearly
turnover.
Resources:
The Final Text of the GDPR Including Recitals https://gdpr-info.eu/
5 GDPR Rights With Serious Technical Consequences https://goo.gl/Jvgz5L
How Will GDPR Affect Your Web Analytics Tracking? https://goo.gl/JCZkKs
Bird & Bird: Guide to the General Data Protection Regulation https://goo.gl/kwwNqH
Chapter 9: Rights of data subjects – Unlocking the EU General Data Protection Regulation https://goo.gl/ud2crx
Right to data portability
Provide the Data Subject’s personal data in a
usable, transferable format for further use.
Such information must be provided free of
charge.
BUT! The Data Controllers can protect
themselves from Data Subjects requesting data
over and over again with no real reason by
imposing an acceptable fee for each particular
request subject.
Right to object to processing
Compelling legitimate grounds for the processing
which override the interests, rights and freedoms
of the Data Subject.
That the processing requires the data for the
establishment, exercise or defense of legal rights.
The right to object to direct marketing is absolute
and the Data Controller must cease such processing.
In other cases the Controllers must cease such
processing unless they can demonstrate:
Processing based on legitimate interests (e.g. public interest).
Processing for purposes of scientific/historical research and statistics.
Direct marketing (including profiling).
Data subjects have the right to object to the processing of personal
data including:
NO

More Related Content

PDF
Data Privacy - Rights of the Data Subject
PPTX
Intellectual Property
PPTX
Presentation on GDPR
PPTX
Health care confidentiality and privacy
PDF
Privacy and Data Security
PPTX
Digital Evidences at the Crime Scene.pptx
PDF
What about GDPR?
PPTX
Die Betroffenenrechte im Datenschutz
Data Privacy - Rights of the Data Subject
Intellectual Property
Presentation on GDPR
Health care confidentiality and privacy
Privacy and Data Security
Digital Evidences at the Crime Scene.pptx
What about GDPR?
Die Betroffenenrechte im Datenschutz

What's hot (20)

PPTX
PPT on Trade mark act, 1999_(Rohan, Shweta, Soumya)
PDF
DPDP Act 2023.pdf
PPTX
Data protection ppt
PPTX
General data protection
PPT
Cyber Forensic - Policing the Digital Domain
PDF
24112015 icd10 tb_rr
PPTX
Protection for submission
PPTX
mobile forensic.pptx
PPTX
Data protection and privacy
PPTX
Data protection
PPTX
psychology-of-evidence-eyewitness-and-confession.pptx
PPTX
EU's General Data Protection Regulation (GDPR)
PPTX
Privacy in India: Legal issues
PDF
LGPD - LEI GERAL DE PROTEÇÃO DE DADOS - ESTRUTURA DA LEI
PPTX
Medical writing organisation
PPTX
Data Privacy and Security in Clinical Trials: Safeguarding Patient Information
PPT
Evidence
PDF
LGPD Apostila
PPT
Trade secrets vs. confidential information
PPTX
Patients’ privacy and confidentiality
PPT on Trade mark act, 1999_(Rohan, Shweta, Soumya)
DPDP Act 2023.pdf
Data protection ppt
General data protection
Cyber Forensic - Policing the Digital Domain
24112015 icd10 tb_rr
Protection for submission
mobile forensic.pptx
Data protection and privacy
Data protection
psychology-of-evidence-eyewitness-and-confession.pptx
EU's General Data Protection Regulation (GDPR)
Privacy in India: Legal issues
LGPD - LEI GERAL DE PROTEÇÃO DE DADOS - ESTRUTURA DA LEI
Medical writing organisation
Data Privacy and Security in Clinical Trials: Safeguarding Patient Information
Evidence
LGPD Apostila
Trade secrets vs. confidential information
Patients’ privacy and confidentiality
Ad

Similar to GDPR Data Subject Rights - What You Need to Know (20)

PPTX
Reddico GDPR Presentation
PDF
Protection des données et de la vie privée : nouvelles obligations pour les e...
PDF
Complete Guide to General Data Protection Regulation (GDPR)
PPTX
GDPR Practicalities - The Data Shed
PDF
Data Protection Subjects.pdf
PDF
GDPR Whitepaper
PDF
Data Protection Seminar_GDPR_ISOLAS_26-06-17
PDF
Gdpr in a nutshell
PPTX
DCH Data Protection Training Presentation
PDF
GDPR Overview
PPT
3e - Data Protection
PDF
Public sector breakfast club, October 2016, Exeter
PPTX
General Data Protection Regulation
PPTX
Cyber safe lambeth | GDPR taster
PPTX
Gdpr presentation
PDF
Data Protection and IDEA
PPTX
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
PPT
Dataprotectionactnew13 12-11-111213033116-phpapp02
PPTX
GDPR: Training Materials by Qualsys
PDF
How to Collect and Process Data Under GDPR?
Reddico GDPR Presentation
Protection des données et de la vie privée : nouvelles obligations pour les e...
Complete Guide to General Data Protection Regulation (GDPR)
GDPR Practicalities - The Data Shed
Data Protection Subjects.pdf
GDPR Whitepaper
Data Protection Seminar_GDPR_ISOLAS_26-06-17
Gdpr in a nutshell
DCH Data Protection Training Presentation
GDPR Overview
3e - Data Protection
Public sector breakfast club, October 2016, Exeter
General Data Protection Regulation
Cyber safe lambeth | GDPR taster
Gdpr presentation
Data Protection and IDEA
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
Dataprotectionactnew13 12-11-111213033116-phpapp02
GDPR: Training Materials by Qualsys
How to Collect and Process Data Under GDPR?
Ad

More from Piwik PRO (7)

PDF
DSGVO -Einwilligung? Was nun?
PDF
What Is Evercookie and Why You Should Avoid It for Privacy’s Sake
PDF
Piwik PRO The Real Cost of Data Privacy
PDF
Javascript Tracking or Web Log Analytics?
PDF
A Comparison of Analytics and Tag Management Suites by Piwik PRO and Google
PDF
Privacy Regulations and Your Digital Setup
PDF
Web Analytics and Privacy
DSGVO -Einwilligung? Was nun?
What Is Evercookie and Why You Should Avoid It for Privacy’s Sake
Piwik PRO The Real Cost of Data Privacy
Javascript Tracking or Web Log Analytics?
A Comparison of Analytics and Tag Management Suites by Piwik PRO and Google
Privacy Regulations and Your Digital Setup
Web Analytics and Privacy

Recently uploaded (20)

PDF
Votre score augmente si vous choisissez une catégorie et que vous rédigez une...
PPTX
Acceptance and paychological effects of mandatory extra coach I classes.pptx
PPTX
SAP 2 completion done . PRESENTATION.pptx
PDF
Business Analytics and business intelligence.pdf
PDF
168300704-gasification-ppt.pdfhghhhsjsjhsuxush
PPTX
STERILIZATION AND DISINFECTION-1.ppthhhbx
PPTX
(Ali Hamza) Roll No: (F24-BSCS-1103).pptx
PPTX
Pilar Kemerdekaan dan Identi Bangsa.pptx
PPTX
Qualitative Qantitative and Mixed Methods.pptx
PDF
REAL ILLUMINATI AGENT IN KAMPALA UGANDA CALL ON+256765750853/0705037305
PPTX
01_intro xxxxxxxxxxfffffffffffaaaaaaaaaaafg
PPTX
Microsoft-Fabric-Unifying-Analytics-for-the-Modern-Enterprise Solution.pptx
PDF
How to run a consulting project- client discovery
PDF
Introduction to Data Science and Data Analysis
PPT
ISS -ESG Data flows What is ESG and HowHow
PPTX
Database Infoormation System (DBIS).pptx
PPTX
retention in jsjsksksksnbsndjddjdnFPD.pptx
PDF
[EN] Industrial Machine Downtime Prediction
PPTX
modul_python (1).pptx for professional and student
PPTX
Topic 5 Presentation 5 Lesson 5 Corporate Fin
Votre score augmente si vous choisissez une catégorie et que vous rédigez une...
Acceptance and paychological effects of mandatory extra coach I classes.pptx
SAP 2 completion done . PRESENTATION.pptx
Business Analytics and business intelligence.pdf
168300704-gasification-ppt.pdfhghhhsjsjhsuxush
STERILIZATION AND DISINFECTION-1.ppthhhbx
(Ali Hamza) Roll No: (F24-BSCS-1103).pptx
Pilar Kemerdekaan dan Identi Bangsa.pptx
Qualitative Qantitative and Mixed Methods.pptx
REAL ILLUMINATI AGENT IN KAMPALA UGANDA CALL ON+256765750853/0705037305
01_intro xxxxxxxxxxfffffffffffaaaaaaaaaaafg
Microsoft-Fabric-Unifying-Analytics-for-the-Modern-Enterprise Solution.pptx
How to run a consulting project- client discovery
Introduction to Data Science and Data Analysis
ISS -ESG Data flows What is ESG and HowHow
Database Infoormation System (DBIS).pptx
retention in jsjsksksksnbsndjddjdnFPD.pptx
[EN] Industrial Machine Downtime Prediction
modul_python (1).pptx for professional and student
Topic 5 Presentation 5 Lesson 5 Corporate Fin

GDPR Data Subject Rights - What You Need to Know

  • 1. Data Subject Every person is considered a Data Subject: citizens, consumers, customers, business partners, employees, you and me. Your company. You are controlling, reviewing, comparing and aggregating data about your customers (e.g. web analytics data). Data Controller Any information relating to an identified or identifiable natural person (in other words: the Data Subject). Personal data Right of access Right to erasure The purpose of processing. Categories of personal data. Recipients of the data. A copy of the collected personal data. Data Controllers have to provide Data Subjects: Data Subjects can request correction of their data if they see it is not accurate or truthful. Data Controllers have to erase or rectify (fix / adjust) inaccurate or incomplete data. Why the Data Controller is processing the data. What categories of data are being processed. Whether the Data Controller is processing their data. Will the Controller share their data and with who. How long the data will be stored. That they have the right to erasure, rectification, restriction of processing, and to object to processing. That they have the right to complain to the Data Protec- tion Authority (DPA). If there is automated processing that has a significant effect on them. Data Subjects have the right to know: The data was collected unlawfully. The time limit for the storage of the data has expired. The Data Subject objects to their personal data being pro- cessed. The data was collected when the Data Subject was a child. The purpose of collecting and processing data has changed. Erasure is necessary to comply with EU or Member State law. Personal data has to be removed within ONE MONTH when: Right to restrict processing They contest the accuracy of the data. The processing is unlawful and they request restriction. The controller no longer needs the data for their original purpose, but the data is still required by the controller to establish, exercise or defend legal rights. There is an erasure request and the Data Controller is verifying it. Data Subjects can stop Data Controllers from performing specific actions with their data (the Controller may only hold the data or use it for limited purposes). Data Subjects can restrict the processing of their personal data if: IMPORTANT : The Data Controller has to ensure that all distributed personal data was removed. Even the data that was processed by 3rd parties! Right to rectification The General Data Protection Regulation comes into effect on May 25th 2018 and introduces a list of Data Subjects’ rights to protect internet users. Learn how Data Controllers can ensure these rights and avoid severe fines, as high as €20m or 4% of your company’s yearly turnover. Resources: The Final Text of the GDPR Including Recitals https://gdpr-info.eu/ 5 GDPR Rights With Serious Technical Consequences https://goo.gl/Jvgz5L How Will GDPR Affect Your Web Analytics Tracking? https://goo.gl/JCZkKs Bird & Bird: Guide to the General Data Protection Regulation https://goo.gl/kwwNqH Chapter 9: Rights of data subjects – Unlocking the EU General Data Protection Regulation https://goo.gl/ud2crx Right to data portability Provide the Data Subject’s personal data in a usable, transferable format for further use. Such information must be provided free of charge. BUT! The Data Controllers can protect themselves from Data Subjects requesting data over and over again with no real reason by imposing an acceptable fee for each particular request subject. Right to object to processing Compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject. That the processing requires the data for the establishment, exercise or defense of legal rights. The right to object to direct marketing is absolute and the Data Controller must cease such processing. In other cases the Controllers must cease such processing unless they can demonstrate: Processing based on legitimate interests (e.g. public interest). Processing for purposes of scientific/historical research and statistics. Direct marketing (including profiling). Data subjects have the right to object to the processing of personal data including: NO