- ホーム
- > 洋書
- > 英文書
- > Politics / International Relations
Full Description
From May 2018, the General Data Protection Regulation 2016/679 (GDPR) replaces the Data Protection Directive 95/46/EC, representing a significant overhaul of data protection law in the European Union. Applicable to all EU Member States, the GDPR's relevance spans not only organisations operating within the EU, but also those operating outside the EU.This commentary, published in association with German Law Publishers, provides a detailed look at the individual articles of the GDPR and is an essential resource aimed at helping legal practitioners prepare for compliance. Content includes:*full text of the GDPR's articles and recitals;*article-by-article commentary explaining the individual provisions and elements of each article;*a general introduction to data protection law with a focus on issues such as:* how to adapt a compliance management program*whether or not to appoint a data protection officer*'privacy by design' and 'privacy by default'* the consequences of non-compliance with the GDPR*data portability* the need for data protection impact assessments*a detailed index.In addition to lawyers and in-house counsel, this book is also suitable for law professors and students, and offers comprehensive coverage of this increasingly important area of data protection legislation.
Contents
List of abbreviationsList of Recitals of the General Data Protection RegulationIntroduction to the General Data Protection Regulation1. Introduction2. The most important compliance steps until the GDPR applies from May 25, 20183. Basic terms of the GDPR4. The scope of the GDPR4.1 Material scope - What processing activities are covered?4.2 Personal scope - Who does the GDPR apply to?4.3 Territorial scope - Where does the GDPR apply?5. The relationship with national data protection laws6. The principles relating to the processing of personal data7. Legal basis requirement for any data processing activity7.1 Available legal bases7.2 Requirements for valid consent8. Information obligations and privacy notices9. Rights of the data subject10. Profiling and automated individual decision-making11. Data protection compliance program11.1 Organizational measures including data protection strategies11.2 Technical measures including privacy by design and by default12. Maintaining a record of processing activities13. Data protection impact assessment and consultation obligation with supervisory authority14. Data protection officer15. Data security15.1 Mandatory data security measures15.2 Obligation to notify personal data breaches16. Mandatory arrangements between joint controllers17. Obligations in case of outsourcing18. International data transfers18.1 Transfers not subject to notification or approval18.2 Transfers subject to notification18.3 Transfers subject to approval19. International jurisdiction of supervisory authorities20. Administrative fines and other sanctions21. Civil liability and private enforcementText of the General Data Protection Regulation and commentaryChapter I - General ProvisionsArticle 1 Subject-matter and objectivesArticle 2 Material scopeArticle 3 Territorial scopeArticle 4 DefinitionsChapter II - PrinciplesArticle 5 Principles relating to processing of personal dataArticle 6 Lawfulness of processingArticle 7 Conditions for consentArticle 8 Conditions applicable to child's consent in relation to information society servicesArticle 9 Processing of special categories of personal dataArticle 10 Processing of personal data relating to criminal convictions and offencesArticle 11 Processing which does not require identificationChapter III - Rights of the data subjectSection 1 - Transparency and modalitiesArticle 12 Transparent information, communication and modalities for the exercise of the rights of the data subjectSection 2 - Information and access to personal dataArticle 13 Information to be provided where personal data are collected from the data subjectArticle 14 Information to be provided where personal data have not been obtained from the data subjectArticle 15 Right of access by the data subjectSection 3 - Rectification and erasureArticle 16 Right to rectificationArticle 17 Right to erasure ('right to be forgotten')Article 18 Right to restriction of processingArticle 19 Notification obligation regarding rectification or erasure of personal data or restriction of processingArticle 20 Right to data portabilitySection 4 - Right to object and automated individual decision-makingArticle 21 Right to objectArticle 22 Automated individual decision-making, including profilingSection 5 - RestrictionsArticle 23 RestrictionsChapter IV - Controller and processorSection 1 - General obligationsArticle 24 Responsibility of the controllerArticle 25 Data protection by design and by defaultArticle 26 Joint controllersArticle 27 Representatives of controllers or processors not established in the UnionArticle 28 ProcessorArticle 29 Processing under the authority of the controller or processorArticle 30 Records of processing activitiesArticle 31 Cooperation with the supervisory authoritySection 2 - Security of personaldataArticle 32 Security of processingArticle 33 Notification of a personal data breach to the supervisory authorityArticle 34 Communication of a personal data breach to the data subjectSection 3 - Data protection impact assessment and prior consultationArticle 35 Data protection impact assessmentArticle 36 Prior consultationSection 4 - Data protection officerArticle 37 Designation of the data protection officerArticle 38 Position of the data protection officerArticle 39 Tasks of the data protection officerSection 5 - Codes of conduct and certificationArticle 40 Codes of conductArticle 41 Monitoring of approved codes of conductArticle 42 CertificationArticle 43 Certification bodiesChapter V - Transfers of personal data to third countries or international organisationsArticle 44 General principle for transfersArticle 45 Transfers on the basis of an adequacy decisionArticle 46 Transfers subject to appropriate safeguardsArticle 47 Binding corporate rulesArticle 48 Transfers or disclosures not authorised by Union lawArticle 49 Derogations for specific situationsArticle 50 International cooperation for the protection of personal dataChapter VI - Independent supervisory authoritiesSection 1 - Independent statusArticle 51 Supervisory authorityArticle 52 IndependenceArticle 53 General conditions for the members of the supervisory authorityArticle 54 Rules on the establishment of the supervisory authoritySection 2 - Competence, tasks and powersArticle 55 CompetenceArticle 56 Competence of the lead supervisory authorityArticle 57 TasksArticle 58 PowersArticle 59 Activity reportsChapter VII - Cooperation and consistencySection 1 - CooperationArticle 60 Cooperation between the lead supervisory authority and the other supervisory authorities concernedArticle 61 Mutual assistanceArticle 62 Joint operations of supervisory authoritiesSection 2 - ConsistencyArticle 63 Consistency mechanismArticle 64 Opinion of the BoardArticle 65 Dispute resolution by the BoardArticle 66 Urgency procedureArticle 67 Exchange of informationSection 3 - European data protectionboardArticle 68 European Data Protection BoardArticle 69 IndependenceArticle 70 Tasks of the BoardArticle 71 ReportsArticle 72 ProcedureArticle 73 ChairArticle 74 Tasks of the ChairArticle 75 SecretariatArticle 76 ConfidentialityChapter VIII - Remedies, liability and penaltiesArticle 77 Right to lodge a complaint with a supervisory authorityArticle 78 Right to an effective judicial remedy against a supervisory authorityArticle 79 Right to an effective judicial remedy against a controller or processorArticle 80 Representation of data subjectsArticle 81 Suspension of proceedingsArticle 82 Right to compensation and liabilityArticle 83 General conditions for imposing administrative finesArticle 84 PenaltiesChapter IX - Provisions relating to specific processing situationsArticle 85 Processing and freedom of expression and informationArticle 86 Processing and public access to official documentsArticle 87 Processing of the national identification numberArticle 88 Processing in the context of employmentArticle 89 Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposesArticle 90 Obligations of secrecyArticle 91 Existing data protection rules of churches and religious associationsChapter X - Delegated acts and implemented actsArticle 92 Exercise of the delegationArticle 93 Committee procedureChapter XI - Final provisionsArticle 94 Repeal of Directive 95/46/ECArticle 95 Relationship with Directive 2002/58/ECArticle 96 Relationship with previously concluded AgreementsArticle 97 Commission reportsArticle 98 Review of other Union legal acts on data protectionArticle 99 Entry into force and applicationKeyword Index