Rina Steenkamp - Privacy and technology

My annotated General Data Protection Regulation

[Additional information]

[Directive 95/46/EC]

[Article 10]

Chapter II General rules on the lawfulness of the processing of personal data

Section IV Information to be given to the data subject

Article 10 Information in cases of collection of data from the data subject

Member States shall provide that the controller or his representative must provide a data subject from whom data relating to himself are collected with at least the following information, except where he already has it:

[Source: Directive 95/46/EC]

Cross-reference

Article 10

Article 10 Directive 95/46/ECArticle 14(5) point(a) GDPR

[...] except where he already has it: [...]

5. Paragraphs 1 to 4 shall not apply, where:

  • (a) the data subject has already the information referred to in paragraphs 1, 2 and 3;
 Artikel 33 lid 1 Wbp

[...] behalve indien de betrokkene daarvan reeds op de hoogte is: [...]

1. Indien persoonsgegevens worden verkregen bij de betrokkene, deelt de verantwoordelijke vóór het moment van de verkrijging de betrokkene de informatie mede, bedoeld in het tweede en derde lid, tenzij de betrokkene daarvan reeds op de hoogte is.

[Context: Article 14 GDPR, Artikel 33 Wbp]

Article 10 point (a)

Article 10 point (a) Directive 95/46/ECArticle 14(1) point (a) GDPR

(a) the identity of the controller and of his representative, if any;

(a) the identity and the contact details of the controller and, if any, of the controller's representative, of the data protection officer;

 Artikel 33 lid 2 Wbp

a) de identiteit van de voor de verwerking verantwoordelijke en, in voorkomend geval, van diens vertegenwoordiger,

2. De verantwoordelijke deelt de betrokkene zijn identiteit [...] mede.

[Context: Article 14 GDPR, Artikel 33 Wbp]

Article 10 point (b)

Article 10 point (b) Directive 95/46/ECArticle 14 point (b) GDPR

(b) the purposes of the processing for which the data are intended;

(b) the purposes of the processing for which the personal data are intended, as well as information regarding the security of the processing of personal data, including the contract terms and general conditions where the processing is based on point (b) of Article 6(1) and where applicable, information on how they implement and meet the requirements of point f of Article 6(1);

 Artikel 33 lid 2 Wbp

b) de doeleinden van de verwerking waarvoor de gegevens zijn bestemd,

2. De verantwoordelijke deelt de betrokkene [...] de doeleinden van de verwerking waarvoor de gegevens zijn bestemd, mede.

[Context: Article 14 GDPR, Artikel 33 Wbp]

Article 10 point (c)

Article 10 point (c) Directive 95/46/ECArticle 14(1) points (c) etc. GDPR

(c) any further information such as

  • - the recipients or categories of recipients of the data,
  • - whether replies to the questions are obligatory or voluntary, as well as the possible consequences of failure to reply,
  • - the existence of the right of access to and the right to rectify the data concerning him

in so far as such further information is necessary, having regard to the specific circumstances in which the data are collected, to guarantee fair processing in respect of the data subject.

1. Where personal data relating to a data subject are collected, the controller shall provide the data subject with at least the following information, after the particulars pursuant to Article 13a have been provided:

  • (c) the period for which the personal data will be stored, or if this is not possible, the criteria used to determine this period;
  • (d) the existence of the right to request from the controller access to and rectification or erasure of the personal data concerning the data subject to object to the processing of such personal data, or to obtain data;
  • (e) the right to lodge a complaint to the supervisory authority and the contact details of the supervisory authority;
  • (f) the recipients or categories of recipients of the personal data;
  • (g) where applicable, that the controller intends to transfer the data to a third country or international organisation and on the existence or absence of an adequacy decision by the Commission, or in case of transfers referred to in Article 42, Article 43, or point (h) of Article 44(1), reference to the appropriate safeguards and the means to obtain a copy of them;
  • (ga) where applicable, information about the existence of profiling, of measures based on profiling, and the envisaged effects of profiling on the data subject;
  • (gb) meaningful information about the logic involved in any automated processing;
  • (h) any further information which is necessary to guarantee fair processing in respect of the data subject, having regard to the specific circumstances in which the personal data are collected or processed, in particular the existence of certain processing activities and operations for which a personal data impact assessment has indicated that there may be a high risk;
  • (ha) where applicable, information whether personal data was provided to public authorities during the last consecutive 12-month period.
 Artikel 33 lid 3 Wbp

c) verdere informatie zoals

  • - de ontvangers of de categorieën ontvangers van de gegevens;
  • - antwoord op de vraag of men al dan niet verplicht is om te antwoorden en de eventuele gevolgen van niet-beantwoording,
  • - het bestaan van een recht op toegang tot zijn eigen persoonsgegevens en op rectificatie van deze gegevens,

voor zover die, met inachtneming van de specifieke omstandigheden waaronder de verdere informatie verkregen wordt, nodig is om tegenover de betrokkene een eerlijke verwerking te waarborgen.

3. De verantwoordelijke verstrekt nadere informatie voor zover dat gelet op de aard van de gegevens, de omstandigheden waaronder zij worden verkregen of het gebruik dat ervan wordt gemaakt, nodig is om tegenover de betrokkene een behoorlijke en zorgvuldige verwerking te waarborgen.

[Context: Article 14 GDPR, Artikel 33 Wbp]