Data subject


Indirect obligations

Regulation name
Additional information claims from the controller


Rights

Regulation name
The right to withdraw his or her consent at any time
Right of the data subject to obtain a confirmation of the personal data processing from the controller
Right to be informed of appropriate safeguards pursuant to Article 46 relating to the transfer
Right to rectification
Reason for eligibility of the data subject to exercise the right to be forgotten
Restraining the personal data processing
Right of the data subject to personal data portability
Portability of the personal data from one controller to another controller
Right of the data subject to object the processing of personal data
Right of the data subject to object the personal data processing related to the marketing purposes
Application of the right to object using the automated services
Right to object the personal data processing for the purposes of the scientific, historical or statistical reasons
Right not to be subject to a decision based solely on the automated processing
Responsibilities of the controller relating to the personal data processing
Implementation of an appropriate data protection policies by the controller
Implementation of the appropriate technical and organisational measures
Processing of the personal data “by default”
Exercising the rights of the data subject against each of the controllers
Designation of the identical scope of the responsibilities for the other processor
Contacting the Data protection officer
The competency for submitting the request to the supervisory authority
The right to an effective judicial remedy
Right to an effective judicial remedy
Representation of data subjects


Indirect rights

Regulation name
Principle of lawfulness, fairness and transparency
Purpose limitation principle
Data minimization principle
Principle of accuracy
Storage limitation principle
Principle of integrity and confidentiality
Principle of accountability
Obligation to demonstrate the consent for processing the personal data
Prohibition of processing the special categories of personal data
Reasons for derogating the exercise of the Articles 15 – 20
Measures of the controller in terms of providing the information to data subjects
Facilitating the data subject rights
Providing the information on action taken on a request under Articles 15 to 22 to the data subject
Obligations of the controller in case when the data subject request is unadopted
Information provided to the data subject when personal data has been acquired from a data subject
Additional information provided to the data subject when personal data has been acquired from a data subject
Information provided to the data subject when controller intends to further process the personal data for a purpose other than that for which the personal data were collected
Information provided where personal data have not been obtained from the data subject
Some additional information provided where personal data have not been obtained from the data subject
Principles of providing the information in terms of the Article 14, paragraph 1 and 2 of the regulation
Providing the information where the controller intends to process the personal data for a purpose other than that for which the personal data were obtained
Obligation to provide a copy of the personal data which are being processed
Obligations of the controller after the right to be forgotten has been applied
Information duty of the controller in context of the personal data processing limitation
Information obligation of the controller towards the recipients
Prohibition of the personal data processing after the Article 21, paragraph 2 has been applied
Obligation of the controller to inform the data subject about the to object
Proceedings of the controller in case of the Article 22, paragraph 2, points a) – c) application
Respective roles and relationships of the joint controllers vis-à-vis the data subjects
Guaranties of the processor for implementing the adequate protective measurements
Implementation of the appropriate technical and organisational measures
Communication the personal data breach to the data subject
Personal data processing that require the DPIA – general provision
Situation where the DPIA might be necessary
Professional secrecy commitment of the supervisory authority members and employees
The free – of -charge principle of performing the supervisory authority tasks
Joint liability in context of the personal data processing
Appropriate safeguards related to the rights and freedoms of the data subject


Sanctions

Regulation name
Provisions concerning the administrative fines – up to 10 000 000,- EUR


Definitions

Regulation name
Personal data
Consent of a data subject
Performance of a contract
To protect the vital interests of the data subject or of another natural person
Purposes of the legitimate interests pursued by the controller or by a third party
Transparency of the consent for personal data processing
Exclusions from the prohibition of processing the special categories of personal data
Providing the information in terms of Articles 13 and 14
Exemptions from application the obligation of the controller to provide information in terms of the Article 14, paragraphs 1 – 4
Limitation of the negative implications in context of the other subjects' rights
Exemptions from the application of Article 17, paragraph 1 and 2
Processing the personal data after the right to restriction of processing has been applied
Limitation of the right to obtain the personal data
Restrictions in application of the Article 22, paragraph 1
Decisions according to the Article 22, paragraph 2
Minimal scope of the contract essentials between the Controller and Processor
Assessing the appropriate level of the security account
Notification method in context of the Article 34, paragraph 1 of the regulation
Accreditation conditions in relation to the certification subjects
Possibilities of setting the appropriate safeguards up
Minimal essential content of the binding corporate rules
Conditions for the personal data transfer in case of an appropriate safeguards decision absence
Proceedings in case of the urgent situations
The local competency of the judicial authorities for submitting the proceeding against the controller or processor