PodMaster.it, Social media non vi temo - Ascolti tra Marketing e AI
documento | 2023-01-30 · NEW: ![]() |
Record of processing activities | CNIL |
abstract:
Link: https://www.cnil.fr/en/record-processing-activitie
analisi:
index:
Indice
- to fulfil his missions
- By including in your record required det
- Archive of the data violations and make
testo:
E
estimated reading time: 8 min 19 August 2019 The recording obligation is stated by article 30 of the GDPR. It is a tool to help you to be compliant with the Regulation. The record is a document with inventory and analysis purposes, which must reflect the reality of your personal data processing and allow you to precisely identify, among others: Aside from being an obligation settled up by article 30 of the GDPR, the record is an intern control tool and, as mentioned above, a way to demonstrate your compliance with GDPR. It allows you to document your data processing and to know what questions you must ask yourself before and while processing the data: do I really need a certain data for this specific processing? Is it relevant to retain all this data for so long? Are the data sufficiently protected? Creating and updating the record are occasions to identify and to hierarchize the processing risks in light of the GDPR.This essential step will allow you to delineate an action plan of your processing complying with data protection rules. The Cnil introduces here the main elements related to the record and also proposes a record template meeting the conditions settled up by the GDPR. The duty to maintain a record of processing concerns, in principle, all entities, both private and public, regardless of their size, provided they process personal data. Companies with less than 250 employees are not obliged to keep a record. However, they must keep records from the moment that: In practice, this exemption is limited to certain data processing, which are rarely and unconventionally implemented. This can be the case, for instance, of an advertising campaign promoting the opening of a new branch of a company, under the condition that the processing does not present any risk for data subjects. If you are not sure if this exemption applies to you data processing, the Cnil advices you to include it in your records. The article 30 of GDPR provides specific requirements for the personal data controller’s record and for the processor’s record. If your organism acts both as a processor and controller, the record must clearly distinguish the two categories of activities. In practice, in this hypothesis, the Cnil recommends you to keep 2 records: The controller’s record must make an inventory of all the processing implemented by your organism. In practice, a record form must be introduced for each of these activities. This record must incorporate the name and the contact details of your organism, as well as, if necessary, details about your representative, if your organism is not established in the European Union, and finally, details about your Data Protection Officer if you have one. Furthermore, for each processing activity, the record’s note must include at least the following details: The record of the processor must make an inventory of all types of processing activities operated in place of your customers. In practice, a record note must be established for each type of activity (data hosting, IT maintenance, market research sending service, etc.). This record must include the name and contact details of your organism, as well as, if necessary, contact details of your representative, (if your organism is established out of the European Union), and details of your Data Protection Officer if you have one. For each type of activity operated in place of customers, it must include at least the following elements: The GDPR only requires a written form for the record. The record format can be chosen freely, and it can be created on paper or numerically. Document reference To make the holding of the record easier, the Cnil offers a record base model (format ODS), in order to answer to the most frequent needs in terms of data processing, in particular for small organizations (very small firms, small and average-size firms, societies, small communities, etc.) They allow to satisfy the requirements of the article 30 of GDPR. The Cnil recommends, insofar as possible, to complete the additional mentions record, in order to make it a more global complying tool. The record must be held by controllers or processors themselves. Thereby, they can have an overview on all activities of personal data processing they operate. Someone in the organism can be specifically charged with the record. If the organism has been designating a Data Protection Officer (DPO), internal or external, this one can be in charge of the record. The record can be one of the tools allowing the Data Protection Officer to fulfil his complying support mission to the GDPR and his task of informing and advising the controller and processor. Based on this record, identify and analyze the risks on data processing implemented. Develop an action plan of complying to GDPR. The record must be updated regularly, according to the functional and practical evolving of data processing. In practice, any change brought to the conditions of processing implementation for each processing subscribed to the record (new data collected, lengthen of the preservation time, new processing recipient, etc.) must be added to the record. By its nature, this record is an internal and progressive document, which must firstly fulfil the complying mission. Nevertheless, the record must be accessible and communicated to the Cnil when she ask for it. The Cnil will be able to use it for its mission of data processing control. By supplementing the record with complementary details, you can make the record a real control tool of compliance to the GDPR. Indeed, the duty of documentation provided by the GDPR are not restricted to the requirement for a record, provided by the article 30 of the GDPR. Gathering, in one document, all details related to the processing you operate and required by the GDPR will guaranty your compliance to the data protection rules or to identify the actions you need to lead to reach this goal. This record will also help your Data Protection Officer to fulfil his missions, even to be consulted by any collaborator of the organism being destined to implement data processing.
Who is concerned by the obligation?
Measures for entities with less than 250 employees
What does the record include?
What form must take the record?
Record model
Who must keep this record?
How to make a record?
Gather available details
Make a list of processing based on the news collected
Refine / Clarify
At what frequency do you have to update the record?
To whom should you communicate this record?
Good practices
Keywords associated to this article
Testo del 2023-01-30 Fonte: GPDP
Documento French Cnil Checklist Privacydb Registro dei trattamenti Wallabag
Link: https://www.cnil.fr/en/record-processing-activitie