← į akto dosjė

GDPR — 27 straipsnis

Straipsnio tekstas

27 straipsnis Sąjungoje neįsisteigusių duomenų valdytojų ar duomenų tvarkytojų atstovai 1. Jeigu taikoma 3 straipsnio 2 dalis, duomenų valdytojas arba duomenų tvarkytojas raštu paskiria atstovą Sąjungoje. 2. Šio straipsnio 1 dalyje nustatyta prievolė netaikoma: a) jei duomenų tvarkymas yra nereguliarus, neapima specialių kategorijų duomenų tvarkymo, kaip nurodyta 9 straipsnio 1 dalyje, dideliu mastu ar 10 straipsnyje nurodyto asmens duomenų apie apkaltinamuosius nuosprendžius ir nusikalstamas veikas tvarkymo ir dėl jo neturėtų kilti pavojus fizinių asmenų teisėms ir laisvėms, atsižvelgiant į duomenų tvarkymo pobūdį, kontekstą, aprėptį ir tikslus; arba b) valdžios institucijai arba įstaigai. atsižvelgiant į duomenų tvarkymo pobūdį, kontekstą, aprėptį ir tikslus; arba b) valdžios institucijai arba įstaigai. 3. Atstovas turi būti įsisteigęs vienoje iš tų valstybių narių, kuriose yra duomenų subjektai ir kurių asmens duomenys yra tvarkomi prekių ar paslaugų siūlymo jiems tikslais arba kurių elgesys yra stebimas. 4. Duomenų valdytojas arba duomenų tvarkytojas įgalioja atstovą, kad visų pirma priežiūros institucijos ir duomenų subjektai galėtų kreiptis ne tik į duomenų valdytoją ar du
visas tekstas
omenų tvarkytoją, bet ir į atstovą, arba tik į atstovą visais klausimais, susijusiais su duomenų tvarkymu, siekiant užtikrinti, kad būtų laikomasi šio reglamento. 5. Tai, kad duomenų valdytojas arba duomenų tvarkytojas paskiria atstovą, nedaro poveikio teisiniams veiksmams, kurių galėtų būti imtasi prieš patį duomenų valdytoją arba duomenų tvarkytoją.

Kas dėl šio straipsnio rašė konsultacijose

Teikėjai, kurie savo tekste tiesiogiai nurodė būtent šį straipsnio numerį. Tai citata iš jų pačių teksto — ne mūsų vertinimas ir ne priežastinis ryšys.

4
verslo asociacija
3
įmonė
3
NVO
KasŠalisKą parašė
Deutscher Juristinnenbund e.V.DEhren AGBs die wichtigsten Parameter der Empfehlungssysteme nennen müssen, damit Nutzer*innen sie ändern oder beeinflussen können (Art. 27 DSA). Auch wenn zusätzlich noch ein „Online-Schutz“ für Minderjährige eingezogen wurde (Art.
ACCISBEnline platforms ensure that users of social media and search engines are aware of the data collected for targeted advertisements (Article 27). In the draft final text of the AI Act, AI systems involving any form of profiling are considered high-risk, irrespect
ACT | The App AssociationBEcers (DPO) functions to have access to clear guidelines and recommendations on this role. Certain provisions of the GDPR, such as Article 27, impose additional obligations on non-European firms, increasing the cost and risk associated with handling data of EU
MyData-TRUSTBEis a need for more flexibility in interpretation of localisation criteria for establishing DPRs. Current requirements outlined in Article 27(3) require appointing the DPRs in the country of data subjects. However, in practice, some organizations may conduct pr
Shoosmiths LLPGBe organisations with establishments outside the EU only and whose processing activities would give rise to the requirement for an Article 27 GDPR representative (EU Representative).  We find that the EU Representative mechanism is not well understood by non-E
Computer & Communications Industry Association's (CCIA Europe)BErequirement: https://edpb.europa.eu/our-work-tools/our-documents/letters/edpb-letter-enisa-regarding-european-cybersec urity_en; Article 27 of the Data Act also creates a separate regime for non-personal data transfers for cloud services providers subject to
noybATsupervisory authorities and the parties to the procedure; Chapter VI – Legally binding decisions Article 27 - Contents 1. Without prejudice to additional requirements under national law, any legally binding decision shall be issued in writing, using a concise
EU Business PartnersIEsier for the authorities in the EU to come after us by appointing a representative?” So, it would appear that if the objective of Article 27 is to provide the Union with an effective means of implementing and enforcing the GDPR globally, this will only be effe
Americans For Tax Reform FoundationUShe “reasonable” level of protection for personal data, allows regulators assessing fines with excessive flexibility. In addition, Article 27 requires firms outside the EU processing personal data to have a representative physically present in the EU.
ACT | The App AssociationBEto its extraterritorial reach) increase the cost and risk associated with handling data pertaining to EU citizens. For example, Article 27 of the law requires firms to physically place a representative in the EU.5 This 5 Commission Regulation 2016/679, art. 27

Šaltinis: viešų konsultacijų atsiliepimai ir pozicijų dokumentai. n = 10 paminėjimų; skaičiuojama pažodinė nuoroda į straipsnio numerį.

Klausti apie šį straipsnį →