|
What Needs to be Done Prior to Collection
Contact the data subject
Contact the Data Protection Agency
28
(1)Where the personal data has been obtained from the data subject,
the controller or his representative shall provide the data subject
with the following information:
1.
the identity of the controller and of his representative;
2.the purposes of the processing for which the data is intended;
3.any further information which is necessary, having
regard to the specific circumstances in which the personal data is
obtained, to enable the data subject to safeguard his interests,
such as:
(a)the categories of recipients;
(b) whether replying to the questions is obligatory or voluntary, as
well as possible consequences of failure to reply;
(c)the rules on the right of access to and the right to rectify the
data relating to the data subject.
(2) The provisions
of subsection (1) shall not apply where the data subject already has
the information mentioned in paragraphs 1 to 3.
29
(1) Where the data has not been obtained from the data subject, the
controller or his representative shall at the time of undertaking
the recording of the data, or where disclosure to a third party is
envisaged, no later than the time when the data is disclosed,
provide the data subject with the following information:
1.the identity of the controller and of his representative;
2.the purposes of the processing for which the data is intended;
3.
any further information which is necessary, having
regard to the specific circumstances in which the data is obtained,
to enable the data subject to safeguard his interests, such as:
(a)the categories of data concerned;
(b) the categories of recipients;
(c)the rules on the right of access to and the right to rectify the
data relating to the data subject.
(2) The rules laid
down in subsection (1) shall not apply where the data subject
already has the information referred to in paragraphs 1 to 3 or if
recording or disclosure is expressly laid down by law or
regulations.
(3) The rules laid
down in subsection (1) shall not apply where the provision of such
information to the data subject proves impossible or would involve a
disproportionate effort.
Contact the Data Protection Agency
48
(1)
Prior to the commencement of any processing of data which is carried
out on behalf of a private controller, the controller or his
representative shall notify the Danish Data Protection Agency, cf.,
however, section 49.
(2) The
notification shall include the information mentioned in section 43
(2).
49
(1)Processing
of data shall, except in the cases mentioned in section 50 (2), be
exempt from the rules laid down in section 48 where:
-
the processing relates to data about employees, to the extent
that the processing does not relate to data as mentioned in
section 7 (1) and section 8 (4); or
-
the processing relates to data concerning the health of
employees, to the extent that the processing of health data is
necessary to comply with provisions laid down by law or
regulations; or
-
the processing relates to data concerning employees if
registration is necessary under collective agreements or other
agreements on the labour market; or
-
the processing relates to data concerning customers, suppliers
or other business relations, to the extent that the processing
does not relate to data as mentioned in section 7 (1) and
section 8 (4), or to the extent that it is not a matter of
processing operations as mentioned in section 50 (1) 4; or
-
the processing is carried out for the purpose of marketing, to
the extent that the processing does not relate to data as
mentioned in section 7 (1) and section 8 (4); or
-
the processing is carried out by an association or similar body,
to the extent that only data concerning the members of the
association are processed; or
-
the processing is carried out by lawyers or accountants in the
course of business, to the extent that only data concerning
their clients is processed; or
-
the processing is carried out by doctors, nurses, dentists,
dental technicians, chemists, therapists, chiropractors and
other persons authorised to exercise professional activities in
the health sector, to the extent that the data is used solely
for these activities and the processing of the data is not
carried out on behalf of a private hospital; or
-
the processing is carried out for the purpose of being used by
an occupational health service.
|