← į akto dosjė

GDPR — 5 straipsnis

Straipsnio tekstas

5 straipsnis Su asmens duomenų tvarkymu susiję principai 1. Asmens duomenys turi būti: a) duomenų subjekto atžvilgiu tvarkomi teisėtu, sąžiningu ir skaidriu būdu (teisėtumo, sąžiningumo ir skaidrumo principas); b) renkami nustatytais, aiškiai apibrėžtais bei teisėtais tikslais ir toliau netvarkomi su tais tikslais nesuderinamu būdu; tolesnis duomenų tvarkymas archyvavimo tikslais viešojo intereso labui, mokslinių ar istorinių tyrimų tikslais arba statistiniais tikslais pagal 89 straipsnio 1 dalį nėra laikomas nesuderinamu su pirminiais tikslais (tikslo apribojimo principas); c) adekvatūs, tinkami ir tik tokie, kurių reikia siekiant tikslų, dėl kurių jie tvarkomi (duomenų kiekio mažinimo principas); d) tikslūs ir prireikus atnaujinami; turi būti imamasi visų pagrįstų priemonių užtikrinti, kad asmens duomenys, kurie nėra tikslūs, atsižvelgiant į jų tvarkymo tikslus, būtų nedelsiant ištrinami arba ištaisomi (tikslumo principas); e) laikomi tokia forma, kad duomenų subjektų tapatybę būtų galima nustatyti ne ilgiau, nei tai yra būtina tais tikslais, kuriais asmens duomenys yra tvarkomi; asmens duomenis galima saugoti ilgesnius laikotarpius, jeigu asmens duomenys bus tvarkomi tik ar
visas tekstas
chyvavimo tikslais viešojo intereso labui, mokslinių ar istorinių tyrimų tikslais arba statistiniais tikslais pagal 89 straipsnio 1 dalį, įgyvendinus atitinkamas technines ir organizacines priemones, kurių reikalaujama šiuo reglamentu siekiant apsaugoti duomenų subjekto teises ir laisves (saugojimo trukmės apribojimo principas); f) tvarkomi tokiu būdu, kad taikant atitinkamas technines ar organizacines priemones būtų užtikrintas tinkamas asmens duomenų saugumas, įskaitant apsaugą nuo duomenų tvarkymo be leidimo arba neteisėto duomenų tvarkymo ir nuo netyčinio praradimo, sunaikinimo ar sugadinimo (vientisumo ir konfidencialumo principas). duomenų tvarkymo ir nuo netyčinio praradimo, sunaikinimo ar sugadinimo (vientisumo ir konfidencialumo principas). 2. Duomenų valdytojas yra atsakingas už tai, kad būtų laikomasi 1 dalies, ir turi sugebėti įrodyti, kad jos laikomasi (atskaitomybės principas).

Kas dėl šio straipsnio rašė konsultacijose

Teikėjai, kurie savo tekste tiesiogiai nurodė būtent šį straipsnio numerį. Tai citata iš jų pačių teksto — ne mūsų vertinimas ir ne priežastinis ryšys.

28
verslo asociacija
12
NVO
8
įmonė
6
ACADEMIC_RESEARCH_INSTITTUTION
5
kita
KasŠalisKą parašė
Creativity Works!BEbases to invoke GDPR to notify controllers about and compel correction of inaccuracies would greatly improve the effectiveness of Article 5.
Bitkom e.V.DEe 6 (1) Data Act obliges a third party that has received the data from a user to delete the data made available to it pursuant to Article 5 Data Act when it is no longer necessary for the agreed purpose. If the third party has the agreement of the user, non-pe
Selbstregulierung Informationswirtschaft e.V. (SRIW)DEications, e.g., by extending Art. 40.2 GDPR, stating that Codes of Conduct may act as cross-regulatory harmonization. Furthermore Art. 5.1 (b) GDPR establishes the principle of limiting the purpose to protect data sub- jects, imposing restrictions on the use o
Asociación Española de Economía Digital (Adigital)ESil when submitting a notice & action, and if affirmative, how will this interplay with the principle of minimisation enshrined in Art. 5 GDPR.
The Information Technology Industry Council (ITI)USe important to ensure a consistent approach between the GDPR and AI Act, especially on the interplay between data minimization in Article 5 GDPR and data governance obligations in Article 10 AI Act, that seek to ensure that training, validation and testing of
German Insurance AssociationDE(1) of the text, a third party which has received the data from a costumer must delete the data made available to it pursuant to Article 5 when it is no longer necessary for the agreed purpose. If the third party has the consent of the individual, the data ca
AMICE - Association of Mutual Insurers and Insurance Cooperatives in EuropeBEresulting from the use of that vehicle; and 1 Article 3 of Directive 2009/103/CE states that “Each Member State shall, subject to Article 5, take all appropriate measures to ensure that civil liability in respect of the use of vehicles normally based in its te
University of PadovaITdi cura), in deroga ai principi di limitazione della finalità e della conservazione, evitando il complesso test di compatibilità (art. 5 lettere a) ed e) GDPR); d) deroghe all'obbligo di rendere l'informativa nel caso di raccolta indiretta dei dati personali,
Datenanfragen.de e. V.DEis not to happen in the definition of personal data, but at the level of lawful- ness of data processing, especially according to Art. 5 and 6 GDPR.²⁰ We share this view and argue that, especially concerning the severe dangers that we have already gone into, i
European Association of Public Banks and funding agencies (EAPB)BEncial means and organizational capacity to employ all necessary experts, including DPOs and CISOs. Areas for improvement include: Art. 5 GDPR: Administrative relief potential lies in addressing extensive accountability and documentation obligations, which have
DOT EuropeBEomic impact it can have on companies. For example, the recent EDPB public consultation on Guidelines 2/2023 on Technical Scope of Art 5(3) of the ePrivacy Directive proposed to extend cookie rules in a novel way to include technologies essential to the technic
ICANN Business ConstituencyUSe databases to invoke GDPR to notify controllers about and compel correction to inaccuracies would greatly improve the outcome of Article 5.
European Publishers Council - EPCBElication of the DMA during 2024, plenty of time remains for platforms to consolidate their data based position. Moreover, because article 5.2 of the DMA will continue to allow platforms to combine data from different services on the basis of consumer consent,
Gesellschaft für Datenschutz und Datensicherheit (GDD) e.V.DEnkretisierungsbedürftig und bedarf einer verständlichen Abgrenzung von der Informationspflicht i.S.d. Artt. 13 und 14 DS-GVO. Nach Art. 5 Abs. 1 lit. a) DS-GVO muss eine Verarbeitung personenbezogener Daten nicht nur rechtmäßig, sondern zudem auch transpa- rent
5Rights FoundationGBclearly defined on the basis of their age, according to the UNCRC account must be taken of the evolving capacities of the child (Article 5 UNCRC). When applying or implementing a rule it is possible that various ages must be taken into account, even if the la
FRntre les lignes directrices du CEPD et celle d’une APD : alors que le CEPD préparait ses lignes directrices sur le périmètre de l’article 5(3) de la directive ePrivacy (https://edpb.europa.eu/our-work-tools/documents/public- consultations/2023/guidelines-22023
Shoosmiths LLPGBAct or the GDPR (e.g., by disclosing data which constitutes personal data without a valid legal basis, which is prohibited under Article 5(7) of the Data Act and Article 6 of the GDPR).
Information Accountability FoundationUSntated research, see recital 12c and in Articles 5a and 5b (current text). Purpose limitation, anonymization and pseudonymization Article 5(1)(b) GDPR contains an important provision that further processing for the purposes scientific research, in accordance w
Spolek pro ohranu osobních údajůCZof the digital economy, both in the private and public spheres. An example of such guidelines is the extensive interpretation of Article 5(3) of the ePrivacy Directive in the current EDPB draft guidelines "Guidelines 2/2023 on Technical Scope of Art. 5(3) of
BSA | The Software AllianceBEwhen submitting a notice and action, and if affirmative, how will this interplay with the principle of minimization enshrined in Article 5 of the GDPR. Finally, BSA recognizes a particular role for privacy- and confidentiality-preserving technologies such as
Unipol GruppoITcessive extension of the time limit set for 1 Article 3 of Directive 2009/103/CE states that “Each Member State shall, subject to Article 5, take all appropriate measures to ensure that civil liability in respect of the use of vehicles normally based in its te
Oplysningsforbundet May DayDKTrustworthy PKI” 73 hƩps://www.version2.dk/arƟkel/faa-overblikket-4-centrale-begreber-der-faar-det-offentlige-Ɵl-rime-paa-cloud 74 art. 5, stk. 1, litra f, jf. art. 5, stk. 2, og Ɵl art. 30, stk.
World Federation of AdvertisersBEhas resulted in conflicting information. The public consultation on the EDPB’s draft Guidelines 02/2023 on the Technical Scope of Art. 5(3) of the ePrivacy Directive has recently closed. Although the consultation is welcome, a number of stakeholders consider t
European Blood Alliance (EBA)NLe 89(1). Using the legislation in this specific way facilitates overall compliance with Data Protection principles, in particular Article 5(1)(f). This should be encouraged throughout the EU. As big data processing becomes more prevalent across all member stat
ASNEFESing potential challenges in the application of the GDPR. The principle of accountability and the development of codes of conduct (art. 5 and 40) Our experience with the implementation of the principle of accountability has been challenging.
ZKI e.V.DEame Verantwortlichkeit ergänzt werden.  Anlagen mit Musterdokumenten zur DSGVO, bspw. betreffend die Dokumentationspflichten aus Art. 5, 12-14, 24, 25, 30 und 32 DSGVO, wobei zwischen einem öffentlichen und einem nicht öffentlichen Teil differenziert werden s
Die Deutsche KreditwirtschaftDEdetailed information upon request in the second stage. - The very general and abstractly formulated accountability obligation in Art. 5 (2) GDPR, in combination with the excessive sanction regime, has led to an enormous bureaucratisation of internal data prot
Berufsverband der Datenschutzbeauftragten Deutschlands (BvD) e.V.DEwird beispielsweise die Frage der Zulässigkeit einer Verarbeitung gemäß Art. 6 DSGVO flankiert von der Dokumentationspflicht nach Art. 5 Abs. 2 DSGVO (sog. Rechenschaftspflicht) und der Pflicht zur Angabe der Rechtsgrundlage gegenüber der betroffenen Person di
Hessischer LandtagDEtliche oder der Auftragsverarbeiter unterliegt, können die Pflichten und Rechte gemäß den Artikeln 12 bis 22 und Artikel 34 sowie Artikel 5, insofern dessen Bestimmungen den in den Artikeln 12 bis 22 vorgesehenen Rechten und Pflichten entsprechen, im Wege von
Europeans for Safe ConnectionsBEonsent. SOLUTION: Require each citizen’s explicit consent in order to subject their data to any automated procedure. According to Article 5-1 of the GDPR, personal data processed must be "relevant and limited to what is necessary for the purposes for which the

Šaltinis: viešų konsultacijų atsiliepimai ir pozicijų dokumentai. n = 73 paminėjimų; skaičiuojama pažodinė nuoroda į straipsnio numerį.

Klausti apie šį straipsnį →