Corrigendum to the General Data Protection Regulation changes, inter alia, the tasks of the European Data Protection Board concerning accreditation of certifying entities.
Although until the start of the legislation Regulation (EU) 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46 („GDPR, the “General Data Protection Regulation”) has little time left (the date of the amendment is 25 May 2018), It was the European Commission that prepared the correction, which changes both the content of the recitals and the normative content.
In addition to correcting minor stylistic errors, the document changes, inter alia, the scope of the catalogue covering specific categories of data, the concept of infringements and the definition of personal data itself.
The European Commission has also introduced changes to the issue of certification, accreditation and the European Data Protection Board. The amendments also concern the information obligation when personal data are made available to the State third.
The current version of the Act should provide information on the intention to transfer personal data to the State third or an international organisation and the fact that the Commission has established or failed to establish an adequate level of protection or, in the event of a communication (...), a reference to adequate or appropriate safeguards and the possibility of obtaining a copy of the data or the location of the data being made available.
It follows from the corrected act that it concerns information on how to obtain copies of these safeguards or where they are made available. Some of the major changes below are:
GDPR Recipe
Old wording
Corrigendum
Article 4(1)
Definition of ‘personal data’
„personal data’ means information about an identified or identifiable natural person (the data subject);
„personal data’ means any information about an identified or identifiable natural person (the data subject);
Article 6(4) point (c)
Legality of processing
„Nature of personal data, in particular whether specific categories of personal data are processed according to Article 9 or personal data relating to convictions and infringements in accordance with Article 10;”
„the nature of the personal data, in particular whether specific categories of personal data are processed in accordance with Article 9 or personal data concerning convictions and criminal offences in accordance with Article 10;”.
Article 10:
Conviction-related personal-data processing
„Processing of personal data on convictions and infringements
Processing of personal data concerning convictions and infringements of law or related security measures on the basis of Article 6(1) (...)”
„Processing of personal data on convictions and criminal offences
Processing of personal data concerning convictions and criminal offences or related security measures on the basis of Article 6(1) (...)”.
Article 41(3)
Monitoring of approved codes of conduct
„The competent supervisory authority shall submit the proposed accreditation criteria of the body referred to in section 1 This Article, the European Data Protection Board in accordance with the consistency mechanism referred to in Article 63.”
„The competent supervisory authority shall submit the proposed accreditation requirements of the body referred to in section 1 This Article, the European Data Protection Board in accordance with the consistency mechanism referred to in Article 63.”.
Article 41(5)
Monitoring of approved codes of conduct
„The competent supervisory authority shall withdraw the accreditation of the body referred to in section 1, where that body does not comply or no longer complies with the accreditation conditions, or where its actions do not comply with this Regulation.’
„The competent supervisory authority shall withdraw the accreditation of the body referred to in section 1, if that entity does not comply or no longer complies with the accreditation requirements or if its actions do not comply with this Regulation.’
Article 70(1) (o)
Tasks of the European Data Protection Board
„Accredits the certification bodies and periodically reviews the certification according to Article 43 and keep a public register of accredited entities in accordance with Article 43(6) and administrators and processors accredited in accordance with Article 42(7), established in countries third;”
„approve the certification criteria in accordance with Article 42(5) and maintains a public register of certification mechanisms and quality labels and indications in the field of data protection in accordance with Article 42(8), and administrators or processors certified in accordance with Article 42(7), established in countries third;”.
We invite you to train and audit the compliance of personal data security from GDPR to RB Academy
Author:
Emilia Pasławska
Legal advisor at the Legal Department Graduate of the Faculty of Law and Administration at the University of Gdańsk and Postgraduate Tax and Tax Law Studies at the University of Warsaw. In 2016 She completed an advisory application at the District Chamber of Legal Advisors in Warsaw, then passed the bar exam with a positive result.
She gained her professional experience in the Tricity and Warsaw law firms, conducting legal services for natural and legal persons. He also has professional experience in representing clients before general and administrative courts. Her interests focus on civil and economic law.