Teikėjai, kurie savo tekste tiesiogiai nurodė būtent šį straipsnio numerį. Tai citata iš jų pačių teksto — ne mūsų vertinimas ir ne priežastinis ryšys.
| Kas | Šalis | Ką parašė |
|---|---|---|
| MyData-TRUST | BE | ty measures) could arguably be taken to cover assistance with the exporter's own Art.32 security obligations also, as required by Art.28(3)(f), but the only explicit reference in Clause 8.6(d) is to notification obligations. Requiring a Data Processor to imple ↗ |
| Shoosmiths LLP | GB | screening tool, complete a supplier due diligence questionnaire, ensure specific contractual provisions are in place in line with Article 28 GDPR, update its privacy information, put an international transfer mechanism in place, and carry out a transfer impact ↗ |
| Coalition for Online Accountability | US | Clarification that GDPR Article 6(1)e applies to the collection, maintenance and disclosure of the WHOIS databases required under Article 28 of NIS2, since they are necessary for the performance of a task carried out in the public interest, even where governme ↗ |
| German Insurance Association | DE | 2009/138/EC and Article 274 of Regulation (EU) 2015/35. If data processing within the group is not order processing according to Art. 28 GDPR, this legally constitutes a transfer of data to a third party. However, Art. 6 (1) (f) GDPR does not justify the proc ↗ |
| The Information Technology Industry Council (ITI) | US | e is the EU Cloud Code of Conduct, a legally operational transnational code of conduct that conforms to the legal requirements of Article 28 GDPR for all types of cloud computing services. It is a widely adopted tool that has received the approval of the compe ↗ |
| Gesellschaft für Datenschutz und Datensicherheit (GDD) e.V. | DE | elektronischer Form – wie in Art. 28. Abs. 9 DS-GVO – innerhalb der Begriffsbestimmun- gen in Art. 4 DS-GVO gelingen. 3. Datenschutzbeauftragte Nach Art. 37 Abs. 1 lit. a) DS-GVO muss jede öffentliche Stelle unabhängig von der personel- len Größe der Einrichtu ↗ |
| Selbstregulierung Informationswirtschaft e.V. (SRIW) | DE | e of SCC vs SDPC A more streamlined language and separation of intents will be appreciated. Standard Contractual Clauses refer to Art. 28.7 GDPR; Standard Data Protection Clauses refer to Art. 46.2 (e) GDPR. ■ Standard Contractual Clauses, per definition, addr ↗ |
| clever data gmbh | AT | tzliche Vorgaben hilfreich. Zudem werden sehr oft bei der Gestaltung von Auftragsverarbeitungsverträgen die Rahmenbedingungen des Art. 28 DSGVO nicht eingehalten. Das führt oftmals zu langwierigen und unnötigen Verhandlungen. Im Bereich der technischen und org ↗ |
| ICANN Business Constituency | US | t GDPR Article 6(1)e applies to the collection, maintenance and disclosure of the registration directory databases required under Article 28 of NIS2, since they are necessary for the performance of a task carried out in the public interest, even where governme ↗ |
| Deutscher Juristinnenbund e.V. | DE | (Art. 27 DSA). Auch wenn zusätzlich noch ein „Online-Schutz“ für Minderjährige eingezogen wurde (Art. 28 DSA) reichen die Regelungen aber nicht zur Beseitigung der oben aufgezeigten schädlichen Folgen aus. Die Empfehlungssysteme sind so komplex, dass Unternehm ↗ |
| Creativity Works! | BE | le 6(1)e of the GDPR applies to the collection, maintenance and disclosure of the registration directory databases required under Article 28 of NIS2, since they are necessary for the performance of a task carried out in the public interest, even where governme ↗ |
| Institut der Wirtschaftsprüfer in Deutschland e.V. (IDW) | DE | kt. Q1 General Comments Es bestehen Zweifel, ob die Auditrechte (insb. vor-Ort-Audits) in den Auftragsverarbeitungsverträgen nach Art. 28 DSGVO insbesondere aufgrund der nunmehr üblichen und regulierten Cloud-Nutzung noch zeitgemäß sind. Wir empfehlen eine stä ↗ |
| ZKI e.V. | DE | rantwortlichen gegenüber den Betroffenen. Anstelle des zwingenden Vertragsabschlusses sollte Art. 26 DSGVO analog zum derzeitigen Art. 28 Abs. 7 DSGVO ergänzt und die Möglichkeit für die Kommission geschaffen werden, (unverbindliche) Standardvertragsklauseln b ↗ |
| Sören Grünberg | DE | beeinträchtigen. Wünschenswert ist eine Vereinfachung für kleinere Unternehmen (z.B. bis 50 Mitarbeitende). 3. AV Verträge gemäß Art. 28 DSGVO: Um die Einhaltung der vereinbarten Schutzmaßnahmen kontrollieren zu können sind Prüfungen durch die Auftraggeber er ↗ |
| World Federation of Advertisers | BE | ns applicable to children’s (parental) consent to the processing of personal data with the requirements for the provisions in DSA Article 28(2) on not presenting advertising based on profiling using personal data of the service recipients where the provider is ↗ |
| Xamit Bewertungsgesellschaft mbH | DE | ollte. Eine Analyse von 48 Verträgen zur Auftragsverarbeitung aus dem Zeitraum 01/2022-09/2023 ergab, dass 75% der Verträge gegen Art. 28 DS-GVO verstoßen. Die Folge ist, dass Auftraggeber nicht darauf vertrauen können, dass Auftragsverarbeiter gesetzeskonform ↗ |
| Délégué à la Protection des Données (ancien et formateur) | FR | les responsables de traitement à formaliser une convention avec leurs destinataires (hormis les sous- traitants, pour lesquels l’article 28 prévoit déjà l’obligation d’établir un contrat). Une telle convention pourrait, par exemple, aborder la question de l’e ↗ |
| Insurance Ireland | IE | or relationship7? Some II members noted that they haven’t made use of SCCs and already have standard contract templates that meet Article 28 requirements. Other members noted that they did make use of the Standard Contractual Clauses adopted by the Commission. ↗ |
| noyb | AT | (9) GDPR shall include a copy of the legally binding decision. Article 28 - Transparency of legally binding decisions 1. Supervisory authorities must publish all legally binding decisions without undue delay, but no later than three months after adoption,82 u ↗ |
| Gesamtverband der Deutschen Versicherungswirtschaft e.V. | DE | this context. For controller-to-processor relationships, uniform model clauses should be available for the processing pursuant to Article 28 Page 9 / 20 GDPR and for the transfer of data to third countries pursuant to Article 46(2)(c) and (d) GDPR. 3. Opening ↗ |
| David Erdos | GB | relations in article 28 and record keeping which is “not occasional” in article 30 are similarly acontextual. It is also concerning how many of these and indeed other provisions in the GDPR focus on mandating process rather ensuring concrete results which dire ↗ |
| BVPA Bundesverband professioneller Bildanbieter e.V. | DE | es der Vorlage von Original-RAW-Daten der gesamten Serie bedarf. Dies steht einer absoluten Weisungsbefugnis nach Art. 28 DSGVO entgegen, die auch einen Löschungsanspruch beinhalten könnte, ja regeln muss. Ein Fotograf wird deshalb beauRragt, weil man seine be ↗ |
| BSA | The Software Alliance | BE | PR and contractual obligations may be properly passed on by the controllers to processors onto sub-processors, as contemplated in Article 28 paragraph 4. Therefore, it would be helpful to clarify that the customer agrees to the use of sub-processors through a ↗ |
| SRIW & SCOPE Europe | DE | clauses (Art. 28 GDPR) as standardised processing agreements and standard data pro- tection clauses (Art. 46 GDPR) as safeguard for third country transfers would be appreciated. 2 The work of this industry consortium is available to the public to share perspec ↗ |
| Workday, Inc. | US | e Cloud Ecosystem As currently written, GDPR does not fully take into account the realities of the cloud ecosystem. For instance, Article 28 (2) of GDPR requires that controllers are given the opportunity to object to new subprocessors. On its face, Article 28 ↗ |
| American Express | US | and data processing agreements would be welcome as some of the provisions of the SCCs are in conflict with what is required under article 28 of the GDPR and create confusion (e.g. ↗ |
| Internet Corporation for Assigned Names and Numbers | US | tandard Contractual Clauses, the Clauses should be updated to reflect the requirements of the GDPR, including the requirements of Art. 28 GDPR in the EU Standard Contractual Clauses (Processors) (2010/87/EU). Furthermore, developing a set of Clauses applicable ↗ |
| Ecommerce Europe | BE | we would therefore consider that new SCCs should be developed for this relationship. However, if our reading of Art. 28(4) is correct and the obligation shifts unambiguously to the processor to ensure data privacy compliance by its sub-processors, we would wel ↗ |
| — | (Art. 23.1(e)), “important grounds of public interest” (Art. 28.3(a)), “important reasons of public interest” (Art. 49.1(d)/49.5) and “reasons of substantial public interest” (Art. 9.2(g)). - Transfer of personal data aimed in Chapter V of the GDPR. It is real ↗ | |
| French Association of Large Companies (AFEP) | FR | (article 28); - the analysis criteria used to consider and conclude adequacy decisions with third countries. • Updating the provisions relating to standard contractual clauses (“SCC”) - the reference to the 1995 directive must be deleted and must be accompanie ↗ |
Šaltinis: viešų konsultacijų atsiliepimai ir pozicijų dokumentai. n = 42 paminėjimų; skaičiuojama pažodinė nuoroda į straipsnio numerį.