|
What
Needs to be Done Prior to Collection
Contact the data subject
Contact the Information Commissioner
Informing the individual of the processing of personal data -
Article 19
(1)
If personal data
is collected directly from the individual to whom
it relates,
the data controller or his representative must communicate to the
individual the following information, if the individual is not yet
acquainted with them:
-
data on the data controller and his possible representative
(personal name, title or official name respectively and address or
seat respectively),
- the
purpose of the processing of personal data.
(2)
If in view of the special circumstances of collecting personal data
from the previous paragraph there is a need to ensure lawful and
fair processing of personal data of the individual, the person from
the previous paragraph must also communicate to the individual the
additional information, if the individual is not yet acquainted with
them, and in particular:
- a
declaration as to the data recipient or the type of data recipients
of his personal data,
- a
declaration of whether the collection of personal data is compulsory
or voluntary, and the possible consequences if the individual will
not provide data voluntarily,
-
information on the right to consult, transcribe, copy, supplement,
correct, block and erase personal data that relate to him.
(3)
If personal data
was not collected directly from the individual to whom
it relates,
the data controller or his representative must communicate to the
individual the following information no later than on the recording
or supply of personal data to the data recipient:
-
data on the data controller and his possible representative
(personal name, title or official name respectively and address or
seat respectively),
- the
purpose of the processing of personal data.
(4)
If in view of the special circumstances of collecting personal data
from the previous paragraph there is a need to ensure lawful and
fair processing of personal data of the individual, the person from
the previous paragraph must also communicate to the individual
additional information, and in particular:
-
information on the type of personal data collected,
- a
declaration as to the data recipient or the type of data recipients
of his personal data,
-
information on the right to consult, transcribe, copy, supplement,
correct, block and erase personal data that relate to him.
(5)
Information from the third and fourth paragraphs of this Article
shall not need to be ensured if in order to process personal data
for historical, statistical or scientific-research purposes it would
be impossible or would incur large costs or disproportionate effort
or would require a large amount of time, or if the recording or
supply of personal data is expressly provided by statute.
Contact the Information Commissioner
Notification of filing systems - Filing system catalogue - Article
26
(1)
Data controller shall establish for each filing system a filing
system catalogue containing:
1.
the title of the filing system;
2.
data on the data controller (for
a natural person: personal name, address where
activities are performed or address of permanent or temporary
residence, and for sole trader his official name, registered office,
seat and registration number; for
a legal person: title or registered office and address
or seat of the data controller and registration number);
3.
the legal basis for processing personal data;
4.
the category of individuals to whom the personal data relate;
5.
the type of personal data in the filing system;
6.
the purpose of processing;
7.
the duration of storage of personal data;
8.
restrictions on the rights of individuals with regard to personal
data in the filing system and the legal basis for such restrictions;
9.
data recipients or categories of data recipients of personal data
contained in the filing system;
10.
whether the personal data
is transferred to a third country, to where, to whom
and the legal grounds for such transfer;
11. a
general description of security of personal data;
12.
data on connected filing systems from official records and public
books.
13.
data on the representative from the third paragraph of Article 5 of
this Act (for natural person: personal name, address where
activities are performed or address of permanent or temporary
residence, and for sole trader his official name, registered office,
seat and registration number; for legal person: title or registered
office and address or seat of the data controller and registration
number).
(2)
Data controller must ensure that the contents of the catalogue are
accurate and up to date.
Notification of the supervisory body - Article 27
(1)
Data controller shall supply data from subparagraphs 1, 2, 4, 5, 6,
9, 10, 11, 12 and 13 of the first paragraph of Article 26 of this
Act to the National Supervisory Body for Personal Data Protection at
least 15 days prior to the establishing of a filing system or prior
to the entry of a new type of personal data.
(2)
Data controller shall supply to the National Supervisory Body for
Personal Data Protection modifications to the data from the previous
paragraph no later than eight days from the date of modification.
|