interactive GDPR 2016/0679 EN
BG CS DA DE EL EN ES ET FI FR GA HR HU IT LV LT MT NL PL PT RO SK SL SV print pdf
- Article 1 Subject-matter and objectives
- Article 2 Material scope
- Article 3 Territorial scope
- Article 4 Definitions
- Article 5 Principles relating to processing of personal data
- Article 6 Lawfulness of processing
- Article 7 Conditions for consent
- Article 8 Conditions applicable to child's consent in relation to information society services
- Article 9 Processing of special categories of personal data
- Article 10 Processing of personal data relating to criminal convictions and offences
- Article 11 Processing which does not require identification
- Article 12 Transparent information, communication and modalities for the exercise of the rights of the data subject
- Article 13 Information to be provided where personal data are collected from the data subject
- Article 14 Information to be provided where personal data have not been obtained from the data subject
- Article 15 Right of access by the data subject
- Article 16 Right to rectification
- Article 17 Right to erasure (‘right to be forgotten’)
- Article 18 Right to restriction of processing
- Article 19 Notification obligation regarding rectification or erasure of personal data or restriction of processing
- Article 20 Right to data portability
- Article 21 Right to object
- Article 22 Automated individual decision-making, including profiling
- Article 23 Restrictions
- Article 24 Responsibility of the controller
- Article 25 Data protection by design and by default
- Article 26 Joint controllers
- Article 27 Representatives of controllers or processors not established in the Union
- Article 28 Processor
- Article 29 Processing under the authority of the controller or processor
- Article 30 Records of processing activities
- Article 31 Cooperation with the supervisory authority
- Article 32 Security of processing
- Article 33 Notification of a personal data breach to the supervisory authority
- Article 34 Communication of a personal data breach to the data subject
- Article 35 Data protection impact assessment
- Article 36 Prior consultation
- Article 37 Designation of the data protection officer
- Article 38 Position of the data protection officer
- Article 39 Tasks of the data protection officer
- Article 40 Codes of conduct
- Article 41 Monitoring of approved codes of conduct
- Article 42 Certification
- Article 43 Certification bodies
- Article 44 General principle for transfers
- Article 45 Transfers on the basis of an adequacy decision
- Article 46 Transfers subject to appropriate safeguards
- Article 47 Binding corporate rules
- Article 48 Transfers or disclosures not authorised by Union law
- Article 49 Derogations for specific situations
- Article 50 International cooperation for the protection of personal data
- Article 51 Supervisory authority
- Article 52 Independence
- Article 53 General conditions for the members of the supervisory authority
- Article 54 Rules on the establishment of the supervisory authority
- Article 55 Competence
- Article 56 Competence of the lead supervisory authority
- Article 57 Tasks
- Article 58 Powers
- Article 59 Activity reports
- Article 60 Cooperation between the lead supervisory authority and the other supervisory authorities concerned
- Article 61 Mutual assistance
- Article 62 Joint operations of supervisory authorities
- Article 63 Consistency mechanism
- Article 64 Opinion of the Board
- Article 65 Dispute resolution by the Board
- Article 66 Urgency procedure
- Article 67 Exchange of information
- Article 68 European Data Protection Board
- Article 69 Independence
- Article 70 Tasks of the Board
- Article 71 Reports
- Article 72 Procedure
- Article 73 Chair
- Article 74 Tasks of the Chair
- Article 75 Secretariat
- Article 76 Confidentiality
- Article 77 Right to lodge a complaint with a supervisory authority
- Article 78 Right to an effective judicial remedy against a supervisory authority
- Article 79 Right to an effective judicial remedy against a controller or processor
- Article 80 Representation of data subjects
- Article 81 Suspension of proceedings
- Article 82 Right to compensation and liability
- Article 83 General conditions for imposing administrative fines
- Article 84 Penalties
- Article 85 Processing and freedom of expression and information
- Article 86 Processing and public access to official documents
- Article 87 Processing of the national identification number
- Article 88 Processing in the context of employment
- Article 89 Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes
- Article 90 Obligations of secrecy
- Article 91 Existing data protection rules of churches and religious associations
- Article 92 Exercise of the delegation
- Article 93 Committee procedure
- Article 94 Repeal of Directive 95/46/EC
- Article 95 Relationship with Directive 2002/58/EC
- Article 96 Relationship with previously concluded Agreements
- Article 97 Commission reports
- Article 98 Review of other Union legal acts on data protection
- Article 99 Entry into force and application
- whereas (1)
- whereas (2)
- whereas (3)
- whereas (4)
- whereas (5)
- whereas (6)
- whereas (7)
- whereas (8)
- whereas (9)
- whereas (10)
- whereas (11)
- whereas (12)
- whereas (13)
- whereas (14)
- whereas (15)
- whereas (16)
- whereas (17)
- whereas (18)
- whereas (19)
- whereas (20)
- whereas (21)
- whereas (22)
- whereas (23)
- whereas (24)
- whereas (25)
- whereas (26)
- whereas (27)
- whereas (28)
- whereas (29)
- whereas (30)
- whereas (31)
- whereas (32)
- whereas (33)
- whereas (34)
- whereas (35)
- whereas (36)
- whereas (37)
- whereas (38)
- whereas (39)
- whereas (40)
- whereas (41)
- whereas (42)
- whereas (43)
- whereas (44)
- whereas (45)
- whereas (46)
- whereas (47)
- whereas (48)
- whereas (49)
- whereas (50)
- whereas (51)
- whereas (52)
- whereas (53)
- whereas (54)
- whereas (55)
- whereas (56)
- whereas (57)
- whereas (58)
- whereas (59)
- whereas (60)
- whereas (61)
- whereas (62)
- whereas (63)
- whereas (64)
- whereas (65)
- whereas (66)
- whereas (67)
- whereas (68)
- whereas (69)
- whereas (70)
- whereas (71)
- whereas (72)
- whereas (73)
- whereas (74)
- whereas (75)
- whereas (76)
- whereas (77)
- whereas (78)
- whereas (79)
- whereas (80)
- whereas (81)
- whereas (82)
- whereas (83)
- whereas (84)
- whereas (85)
- whereas (86)
- whereas (87)
- whereas (88)
- whereas (89)
- whereas (90)
- whereas (91)
- whereas (92)
- whereas (93)
- whereas (94)
- whereas (95)
- whereas (96)
- whereas (97)
- whereas (98)
- whereas (99)
- whereas (100)
- whereas (101)
- whereas (102)
- whereas (103)
- whereas (104)
- whereas (105)
- whereas (106)
- whereas (107)
- whereas (108)
- whereas (109)
- whereas (110)
- whereas (111)
- whereas (112)
- whereas (113)
- whereas (114)
- whereas (115)
- whereas (116)
- whereas (117)
- whereas (118)
- whereas (119)
- whereas (120)
- whereas (121)
- whereas (122)
- whereas (123)
- whereas (124)
- whereas (125)
- whereas (126)
- whereas (127)
- whereas (128)
- whereas (129)
- whereas (130)
- whereas (131)
- whereas (132)
- whereas (133)
- whereas (134)
- whereas (135)
- whereas (136)
- whereas (137)
- whereas (138)
- whereas (139)
- whereas (140)
- whereas (141)
- whereas (142)
- whereas (143)
- whereas (144)
- whereas (145)
- whereas (146)
- whereas (147)
- whereas (148)
- whereas (149)
- whereas (150)
- whereas (151)
- whereas (152)
- whereas (153)
- whereas (154)
- whereas (155)
- whereas (156)
- whereas (157)
- whereas (158)
- whereas (159)
- whereas (160)
- whereas (161)
- whereas (162)
- whereas (163)
- whereas (164)
- whereas (165)
- whereas (166)
- whereas (167)
- whereas (168)
- whereas (169)
- whereas (170)
- whereas (171)
- whereas (172)
- whereas (173)
- personal data
- processing
- restriction of processing
- profiling
- pseudonymisation
- filing system
- controller
- processor
- recipient
- third party
- consent
- personal data breach
- genetic data
- biometric data
- data concerning health
- main establishment
- representative
- enterprise
- group of undertakings
- binding corporate rules
- supervisory authority
- supervisory authority concerned
- cross-border processing
- relevant and reasoned objection
- information society service
- international organisation
- personal_data 16
- subject 15
- data 15
- controller 12
- processing 12
- information 10
- referred 7
- which 7
- article 7
- shall 6
- from 5
- applicable 4
- purposes 4
- existence 4
- right 4
- provide 4
- well 3
- appropriate 3
- including 3
- further 3
- interests 3
- obligation 3
- have 3
- been 3
- obtained 3
- based 3
- latest 3
- such 3
- point 3
- period 3
- legitimate 3
- article 2
- first 2
- safeguards 2
- communication 2
- impossible 2
- paragraph 2
- used 2
- purpose 2
- consent 2
- available 2
- time 2
- disclosure 2
- publicly 2
- member state 2
- cases 2
- union 2
- recipients 2
- intends 2
- details 2
Article 14
Information to be provided where personal_data have not been obtained from the data subject
1. Where personal_data have not been obtained from the data subject, the controller shall provide the data subject with the following information:
(a) | the identity and the contact details of the controller and, where applicable, of the controller's representative; |
(b) | the contact details of the data protection officer, where applicable; |
(c) | the purposes of the processing for which the personal_data are intended as well as the legal basis for the processing; |
(d) | the categories of personal_data concerned; |
(e) | the recipients or categories of recipients of the personal_data, if any; |
(f) | where applicable, that the controller intends to transfer personal_data to a recipient in a third country or international_organisation and the existence or absence of an adequacy decision by the Commission, or in the case of transfers referred to in Article 46 or 47, or the second subparagraph of Article 49(1), reference to the appropriate or suitable safeguards and the means to obtain a copy of them or where they have been made available. |
2. In addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following information necessary to ensure fair and transparent processing in respect of the data subject:
(a) | the period for which the personal_data will be stored, or if that is not possible, the criteria used to determine that period; |
(b) | where the processing is based on point (f) of Article 6(1), the legitimate interests pursued by the controller or by a third_party; |
(c) | the existence of the right to request from the controller access to and rectification or erasure of personal_data or restriction of processing concerning the data subject and to object to processing as well as the right to data portability; |
(d) | where processing is based on point (a) of Article 6(1) or point (a) of Article 9(2), the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal; |
(e) | the right to lodge a complaint with a supervisory_authority; |
(f) | from which source the personal_data originate, and if applicable, whether it came from publicly accessible sources; |
(g) | the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. |
3. The controller shall provide the information referred to in paragraphs 1 and 2:
(a) | within a reasonable period after obtaining the personal_data, but at the latest within one month, having regard to the specific circumstances in which the personal_data are processed; |
(b) | if the personal_data are to be used for communication with the data subject, at the latest at the time of the first communication to that data subject; or |
(c) | if a disclosure to another recipient is envisaged, at the latest when the personal_data are first disclosed. |
4. Where the controller intends to further process the personal_data for a purpose other than that for which the personal_data were obtained, the controller shall provide the data subject prior to that further processing with information on that other purpose and with any relevant further information as referred to in paragraph 2.
5. Paragraphs 1 to 4 shall not apply where and insofar as:
(a) | the data subject already has the information; |
(b) | the provision of such information proves impossible or would involve a disproportionate effort, in particular for processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, subject to the conditions and safeguards referred to in Article 89(1) or in so far as the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously impair the achievement of the objectives of that processing. In such cases the controller shall take appropriate measures to protect the data subject's rights and freedoms and legitimate interests, including making the information publicly available; |
(c) | obtaining or disclosure is expressly laid down by Union or Member State law to which the controller is subject and which provides appropriate measures to protect the data subject's legitimate interests; or |
(d) | where the personal_data must remain confidential subject to an obligation of professional secrecy regulated by Union or Member State law, including a statutory obligation of secrecy. |
whereas
dal 2004 diritto e informatica