Jeroen Terstegge πŸ‡ͺπŸ‡ΊπŸ‡³πŸ‡± Profile picture
Aug 22, 2019 β€’ 16 tweets β€’ 12 min read β€’ Read on X
Here is a little thread you need to know about the #GDPR and accountability πŸ‘‡πŸ‘‡
#eudatap #privacy
Chapters 2, 5 and 9 #GDPR contain the rules for processing personal data. However, 100% compliance with these rules is impossible in practice. #eudatap #privacy
So, during the #GDPR negotiations, the EU Council of Ministers pushed hard on the accountability principle enshired in Chapter 4. They called it "the risk-based approach". #eudatap #privacy
The risk-based approach means controllers (and to some extent also processors) must do their homework to limit risk and be compliant. #eudatap #privacy
'Homework' means a.o. carrying out a DPIA if risks are high (art.35 #GDPR), taking appropriate security measures taking into account costs and state of art (art.32) and appointing a DPO (art.37). #eudatap #privacy
However, there are limits to how much homework is required. DPIA's are only required when the risk is likely high. Most organization are not required to have a DPO, etc. #eudatap #privacy #GDPR
The only non risk-based article in Chapter 4 #GDPR is art. 30 (data registry), although a not very useful exception for SME's is included in there. #eudatap #privacy
So, #GDPR accountability means: doing your homework where appropriate and the best you can. But there is no obligation to stive to eleminate all risk and be 100% compliant with the material rules. #eudatap #privacy
Or as a high civil servant of the European Commission once put it: "the measures don't need to be perfect, only good enough".
#eudatap #privacy #GDPR
A good example of homework not required is a recent case in a Dutch court. A process server inquiring for information acts as a civil servant and is subject to disciplinary rules. The employer probably afraid of a data breach refused to disclose the personal data. #GDPR #privacy
The Court said that given the legal status of the process server, there was no #GDPR duty for the employer to verify the existence of the court order and he was required to disclose the data under procedural law. #eudatap #privacy
So basically the Court rightfully implied that any #GDPR liability aring from an unauthorized disclosure would in such case be the problem of the process server, not the disclosing employer. Same for fines. #eudatap #privacy
In contrast, another Dutch court recently prohibited an employer from implementing biometrics. The Court concluded that the employer had failed to do his #GDPR homework (necessity assessment, DPIA), so given art.9, the biometrics were disproportionate. #eudatap #privacy
The risk-based approach in Chapter 4 #GDPR means that a controller/processor cannot be fined nor held liable if he has done his homework and the extent if such homework was appropriate given the circumstamces. #eudatap #privacy
Not doing the #GDPR homework or doing it only half-baked given the circumstances may result in fines, liability and sometimes being barred from processing personal data. #eudatap #privacy
All you need to do is to find the level of appropriateness of the measures you implement or carry out to comply with the #GDPR in light of the risks involved, the costs and the state of art, best practices and the law (non-GDPR). There is no need to eliminate all risk. #privacy

β€’ β€’ β€’

Missing some Tweet in this thread? You can try to force a refresh
γ€€

Keep Current with Jeroen Terstegge πŸ‡ͺπŸ‡ΊπŸ‡³πŸ‡±

Jeroen Terstegge πŸ‡ͺπŸ‡ΊπŸ‡³πŸ‡± Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @PrivaSense

Jul 25, 2022
1/ Tijd voor een cursus #AVG voor journalisten πŸ€”
@tweakers meldt: β€œβ€¦dat de klantendata naar China worden gestuurd, wat in strijd is met de AVG.” Is dat zo? Een draadje…
tweakers.net/nieuws/199310/…
2/ Als ik dit verhaal goed begrijp, is de verwerkingsverantwoordelijke een bedrijf in China, waar eigenaren van zonnepanelen in Nederland een account hebben. Hun apparatuur stuurt de gegevens rechtstreeks naar China.
3/ Er staat nergens in de #AVG dat Chinese bedrijven geen data in Nederland mogen verzamelen. Wat er wΓ©l in de AVG staat, is dat verwerkingsverantwoordelijken in China zich aan de AVG moeten houden als zij goederen of diensten aanbieden aan gebruikers in Nederland.
Read 10 tweets
Jul 4, 2022
πŸ”₯πŸ”₯ 1/ European Commission reprimands Dutch Data Protection Authority (AP) over its position on legitimate interest.
nrc.nl/nieuws/2022/07…
#GDPR #privacy
2/ In its letter to the AP, the Commission writes:
β€œThe strict interpretation by the Dutch regulator constitutes a serious obstacle for companies to process personal data for commercial reasons, because they would have to obtain consent from every data subject.” #GDPR #privacy
3/ According to Brussels, the Dutch supervisory authority does not strike the right balance between the right to data protection on the one hand and the freedom of undertaking on the other. #GDPR #privacy
Read 17 tweets
Sep 23, 2021
1/ Met 100 miljoen (lees: huidige budget x4) zou de klachtenafhandeling vermoedelijk maar van 0.04 naar 0.16 procent gaan. En het opvolgen van gemelde datalekken van 0.3 naar 1.2 procent. #AVG #privacy #rijksbegroting
2/ Het toezichtsmodel en eigenlijk de hele AVG is hopeloos achterhaald, want gebaseerd op principes die bedacht zijn in de jaren β€˜70, toen computers nog mainframes waren en gegevensverwerkingen nog overzichtelijk.
linkedin.com/pulse/do-we-ne…
#AVG #privacy
3/ De AP’s van deze wereld kunnen de oorlog sowieso niet winnen (lees: de informatiesamenleving in goede banen leiden). Die verantwoordelijkheid ligt bij de regeringen en de EU.
#AVG #privacy
Read 14 tweets
Jun 14, 2021
ICT is onveilig. Onze eerste reactie is nog steeds om regels te maken voor het gebruik daarvan. En dus doen we DPIA’s en audits, stellen we CISO’s, privacy officers en FG’s aan, en introduceren we documentatie- en rapportageverplichtingen. fd.nl/ondernemen/138…. @ZelYassini
2/ Maar laten we wel wezen: wie moet hier nu eigenlijk zijn leven beteren? De gebruiker, de IT-er, of de developer? Wie het ook is, laten we in ieder geval alsjeblieft ophouden met dit soort flauwekul als het voorstel van @ZelYassini.
3/ Ooit moest er voor elke auto een man met een rode vlag lopen (verantwoordelijkheid van de gebruiker), maar auto’s werden pas echt interessant toen de fabrikanten verplicht werden om er remmen en gordels in te bouwen.
Read 5 tweets
Apr 29, 2021
Time is a serious operational problem for #GDPR enforcement. Today, the Dutch DPA issued a fining report of 58 pages. Last week the Spanish AEPD needed 184 pages! It takes time to draft these reports, as each one is unique. Not counting the time spent on the investigation.
2/ Data Protection Authorities are not in the business of writing books. They are in the business of enforcing the #GDPR. But if GDPR enforcement requires decisions of the volume of books, such enforcement can never be systematic or high-volume (like traffic fines).
3/ Ergo, the DPA-model, which dates back from the β€˜70’s/80’s, when data processing operations were limited and easy to oversee/investigate, is not sustainable in our information society. Resources are limited by default, and selective enforcement violates the equality principle.
Read 9 tweets
Apr 9, 2021
De voorbeelden van de @Consumentenbond lijken eerder een overtreding van de #AVG. Bij kinderen legt de AVG de lat voor het gerechtvaardigd belang hoger. Hoe jonger het kind, hoe hoger de lat. En dus is gericht monitoren van het online klikgedrag van kinderen al snel uit den boze.
2/ Er is in Brussel uitgebreid gesproken over de bescherming van kinderen. Kinderen worden door de #AVG gezien als kwetsbare groep. En hoewel er maar weinig specifieke regels zijn voor kinderen, zijn er veel meer regels over verwerking van data over kwetsbare groepen, zoals ...
3/ Naast art. 6.1.f en 8, art. 12 (begrijpelijkheid van communicatie), art. 22 (profiling met significante effecten), art. 25 (privacy by design), en art. 35 (DPIAs). Je moet non-compliance niet verwarren met slechte bescherming.
Read 5 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(