Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

1)   The right to be informed

What this means (guidance for organisations):

The right to be informed encompasses your obligation to provide ‘fair processing information’, typically through a privacy notice. It emphasises the need for transparency over how you use personal data.

What this means (guidance for individuals):

The individual has the ability to ask the data controller, who is obligation to provide ‘fair processing information’ to them, typically through a simple to understand privacy notice. Emphasizing the requirement to be clear over how their personal data is used.


2) The right to access

What this means (guidance for organisations)

Under the GDPR, individuals will have the right to obtain:

    • confirmation that their data is being processed;
    • access to their personal data; and
    • other supplementary information – this largely corresponds to the information that should be provided in a privacy notice (see Article 15).

These are similar to existing subject access rights under the DPA.

What this means (guidance for individuals):

Individuals will have the right to obtain: personal data is being used, allow access to such data and other related information in the privacy notice.

These are similar to existing subject access rights under the DPA Data Protection Act).

Examples

3)   The right to rectification

What this means (guidance for organisations):

Individuals are entitled to have personal data rectified if it is inaccurate or incomplete.

...


What this means (guidance for individuals):

If personal dat is not correct or complete, indivduals have the ability to have it corrected

4)   The right of Erasure

What this means (guidance for organisations):

What this means (guidance for individuals):

...

Individuals are empowered to request personal data to be deleted and removed, it is also known as ‘the right to be forgotten’. This broad principle underpinning this right is to enable an individual to request the deletion or removal of personal data where there is no compelling reason for its continued processing, when not bound by a legal restriction.

5)   The right to restrict processing

What this means (guidance for organisations):

Under the DPA, individuals have a right to ‘block’ or suppress processing of personal data. The restriction of processing under the GDPR is similar.

When processing is restricted, you are permitted to store the personal data, but not further process it. You can retain just enough information about the individual to ensure that the restriction is respected in future.

What this means (guidance for individuals):

...


Individuals can stop the processing of personal data. The restriction of processing under the GDPR is similar.

Either the data controller or processor are permitted to store the personal data, but no longer use it. They may retain just enough information about the individual to ensure no further use is respected in future.

6)   The right to portability

What this means (guidance for organisations):

The right to data portability allows individuals to obtain and reuse their personal data for their own purposes across different services.

It allows them to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without hindrance to usability.

What this means (guidance for individuals):

...

Individuals are permitted to downlaod a copy of thier personal data and easily use it in another way, without hindrance to usability.

7)   The right to object

What this means (guidance for organisations):

Individuals have the right to object to:

      • processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling);
      • direct marketing (including profiling); and
      • processing for purposes of scientific/historical research and statistics.

What this means (guidance for individuals):

...

Individuals can stop the use of thier personal data via a request.

8) Rights related to automated decision making and profiling

What this means (guidance for organisations):

The GDPR provides safeguards for individuals against the risk that a potentially damaging decision is taken without human intervention. These rights work in a similar way to existing rights under the DPA.

Identify whether any of your processing operations constitute automated decision making and consider whether you need to update your procedures to deal with the requirements of the GDPR.

What this means (guidance for individuals):

Individuals are protected by safeguards against the risk of potentially damaged outcomes were taken without any human intervention in the process. The processing of personal information through automated decision should casue no harm.


Examples

Other Relevant Aspects of GDPR

...