Teikėjai, kurie savo tekste tiesiogiai nurodė būtent šį straipsnio numerį. Tai citata iš jų pačių teksto — ne mūsų vertinimas ir ne priežastinis ryšys.
| Kas | Šalis | Ką parašė |
|---|---|---|
| Deutscher Juristinnenbund e.V. | DE | rden müssen. Dazu gehört, betroffene Personen vor Schaden und Diskriminierung zu bewahren (Erw. 85). Bereits nach der Wertung von Art. 35 Abs. 3 lit a) DSGVO hat Profiling grundsätzlich ein hohes Risiko für die Rechte und Freiheiten natürlicher Personen zur Fo ↗ |
| ACCIS | BE | red for high-risk data processing, is not inherently mandated for profiling, except in cases covered by Article 22 GDPR (refer to Article 35.3.a GDPR). Details of relevant GDPR provisions for the AI Act: ↗ |
| Information Accountability Foundation | US | ue. GDPR, AI and risk assessment Considering the two-step concept outlined above the IAF proposes that there is merit in amending Article 35 of the GDPR. It should be amended to apply to the application of insights stage (use of data) more clearly, where there ↗ |
| BSA | The Software Alliance | BE | tection impact assessments (DPIAs) for high-risk activities, which can be a helpful tool for businesses, the powers granted under Article 35(5) of the GDPR to DPAs to create their own list of processing operations subject to DPIAs has caused irregular approach ↗ |
| Van Bael & Bellis | BE | t pertinent issues. For example, the guidance on DPIA7 does not address key points such as the exact methods for risk assessment (Article 35(7)(c) GDPR), for proportionality and necessity assessment (Article 35(7)(b) GDPR) or for consultation with data subject ↗ |
| Avvocato | IT | l'emersione di numerose incertezze/difficoltà di ordine teorico e pratico), la valutazione di impatto sulla protezione dei dati (art. 35) e soprattutto la designazione del DPO (art. 37); 2) la razionalizzazione delle basi giuridiche, constatata la non sempre ↗ |
| ZKI e.V. | DE | Ein weiteres offizielles Musterdokument könnte für die Durchführung einer Datenschutzfolgenabschätzung gemäß Art. 35 DSGVO sowie für die Durchführung eines Transfer Impact Assessment (TIA) im Rahmen der Art. 44 ff. DSGVO erstellt und veröffentlicht werden. All ↗ |
| Oplysningsforbundet May Day | DK | ligheder skal vælges den mindst bebyrdende foranstaltning, jf. fx GDPRs artikel 25, stk. 1 state-of-the-art vedr. design og GDPRs artikel 35, stk. 1 om konsekvensanalyse. Desto hårdere en retsakt rammer private interesser, desto mere må forvaltningen sikre sig ↗ |
| Europeans for Safe Connections | BE | tion laws We call for such assessment to be conducted regularly, every year, and for each EU member state. This requires amending Article 35 of the GDPR on the basis of Article 16 of the TFEU, so that this type of impact assessment can be initiated at the leve ↗ |
| Délégué à la Protection des Données (ancien et formateur) | FR | à la personne physique concernée pour que celle-ci puisse atténuer les effets négatifs potentiels de la violation. 12) Article 35 RGPD : les risques résiduels identifiés dans le cadre d’une analyse d’impact doivent peser explicitement sur le responsable de tra ↗ |
| Privacy Company | NL | s We recommend introducing a requirement for large organisations or smaller organisations with high risk processing as defined in Art. 35 GDPR to include a paragraph in their annual report about their progress with privacy compliance, similar to obligations ab ↗ |
| Anonos Inc. | US | itimate interests are in place.” • Improve Scalability of Data Protection Impact Assessments a. Pseudonymization helps to satisfy Article 35(3)(b) obligations when “processing on a large scale of special categories of data referred to in Article 9(1).” b. ↗ |
| noyb | AT | nd the Board. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2). Article 35 - Statistics ↗ |
| Border Violence Monitoring Network | DE | toring to ensure new technology that circumvents EU law cannot be used freely. While there are supposed provisions for this under Article 35 and 36 of the GDPR, BVMN asserts that these do not go far enough in preventing the use of these technologies, which can ↗ |
| David BARNARD-WILLS | GB | ining when DPIAs are required in certain contexts, and for consulting with data processors following impact assessment exercises (Article 35). DPAs should determine collectively what they consider to be data processing that is likely to result in a high risk t ↗ |
| Federation of Austrian Industries (Industriellenvereinigung) | AT | btain. - a specification what should be part of the information about the joint controller arrangement given to data subjects. h. Art 35 – Data Protection Impact Assessment (DPIA) In practice there are some uncertainties how comprehensive a DPIA should be. ↗ |
| Digitale Gesellschaft e.V. | DE | data protection impact assessment according to Article 35(4) and prior consultation pursuant to Article 36 of the GDPR. 3. Specifying the Rules for Profiling Profiling addresses a broad number of different cases. From simple customer data bases containing name ↗ |
| Ecommerce Europe | BE | rations which are subject to the requirement for a data protection impact assessment” established by the German DPAs according to Art. 35 (4) GDPR. The “blacklist” according to Art. 35 (5) GDPR is not established yet by the German DPAs. In the end, the control ↗ |
| BSA | The Software Alliance | BE | benefit from uniformity and guidance on DPIA thresholds and triggers. Local differences created by the opt-in and opt-out lists (Article 35 (4) and (5)) bring harmonization risks. More guidance pertaining to cloud-based examples or multi-party contracting exa ↗ |
| Federation of German Consumer Associations (Verbraucherzentrale Bundesverband e.V. - vzbv) | DE | o children in the normative text and thereby ensuring that controllers respect their specific rights and freedoms. The changes to Art. 35 GDPR go further than mere clarification and establish specific obligations to pay par- ticular attention to children when ↗ |
| Centre for Information Policy Leadership (CIPL) | GB | s and society of not going forward with a specific project due to potential risks?) should be part of risk assessments and DPIAs. Article 35(1) GDPR uses the notion of “impact”, which can include both negative and positive factors and does not prevent the incl ↗ |
Šaltinis: viešų konsultacijų atsiliepimai ir pozicijų dokumentai. n = 21 paminėjimų; skaičiuojama pažodinė nuoroda į straipsnio numerį.