{"id":776,"date":"2025-02-11T14:14:17","date_gmt":"2025-02-11T13:14:17","guid":{"rendered":"https:\/\/vraneseviclaw.com\/?p=776"},"modified":"2025-02-11T14:14:18","modified_gmt":"2025-02-11T13:14:18","slug":"data-protection-in-the-business-environment-qa","status":"publish","type":"post","link":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/","title":{"rendered":"Data protection in the business environment: Q&amp;A"},"content":{"rendered":"<h2><span class=\"TextRun SCXW158735140 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">Why <\/span><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">i<\/span><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">s <\/span><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">c<\/span><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">ompliance with <\/span><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">d<\/span><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">ata <\/span><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">p<\/span><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">rotection <\/span><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">r<\/span><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">egulations <\/span><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">i<\/span><span class=\"NormalTextRun SCXW158735140 BCX8\" data-ccp-parastyle=\"heading 3\">mportant?<\/span><\/span><span class=\"EOP SCXW158735140 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:281,&quot;335559739&quot;:281}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">A key aspect of data protection is the reduction of risks associated with non-compliance and security breaches. From a company\u2019s perspective, data protection fosters trust among customers and employees, safeguards reputation, and maintains financial stability.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Failure to comply with relevant regulations can lead to legal sanctions and a loss of market trust. In today&#8217;s world, investing in data protection has become essential for business sustainability.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">This article presents practical examples that companies may encounter in their daily operations.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h3><span class=\"TextRun SCXW53709759 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW53709759 BCX8\" data-ccp-parastyle=\"heading 3\">Key <\/span><span class=\"NormalTextRun SCXW53709759 BCX8\" data-ccp-parastyle=\"heading 3\">d<\/span><span class=\"NormalTextRun SCXW53709759 BCX8\" data-ccp-parastyle=\"heading 3\">efinitions<\/span><\/span><span class=\"EOP SCXW53709759 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:281,&quot;335559739&quot;:281}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">The Personal Data Protection Act defines personal data as any information relating to a natural person whose identity is determined or determinable, directly or indirectly, especially based on an identity marker such as a name, identification number, location data, an identifier in electronic communication networks, or one or more characteristics of their physical, physiological, genetic, mental, economic, cultural, or social identity.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The processing of personal data is defined as any action or set of actions performed, whether automated or non-automated, on personal data or data sets. These actions include, for example, collection, recording, classification, grouping, structuring, storage, adaptation or alteration, disclosure, access, use, transmission, duplication, dissemination, or otherwise making data available, as well as comparison, restriction, deletion, or destruction.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">As you can see, the definitions are extensive. This is precisely why understanding real-world examples helps in comprehending the legal regulations governing data protection, whether it is the domestic Personal Data Protection Act or the GDPR.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Furthermore, a data controller is defined as a natural or legal person, or a public authority, that alone or jointly with others determines the purpose and means of processing personal data.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Personal data must be processed lawfully, fairly, and transparently in relation to the individual concerned. Data processing must be necessary and limited to the purpose of processing, in line with the principle of data minimization.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Among the fundamental provisions, Article 12 of the Personal Data Protection Act specifies the conditions under which data processing is lawful. Processing is considered lawful if at least one of the six prescribed conditions is met.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h2><span class=\"TextRun SCXW127954652 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW127954652 BCX8\" data-ccp-parastyle=\"heading 3\">Video <\/span><span class=\"NormalTextRun SCXW127954652 BCX8\" data-ccp-parastyle=\"heading 3\">s<\/span><span class=\"NormalTextRun SCXW127954652 BCX8\" data-ccp-parastyle=\"heading 3\">urveillance and <\/span><span class=\"NormalTextRun SCXW127954652 BCX8\" data-ccp-parastyle=\"heading 3\">p<\/span><span class=\"NormalTextRun SCXW127954652 BCX8\" data-ccp-parastyle=\"heading 3\">ersonal <\/span><span class=\"NormalTextRun SCXW127954652 BCX8\" data-ccp-parastyle=\"heading 3\">d<\/span><span class=\"NormalTextRun SCXW127954652 BCX8\" data-ccp-parastyle=\"heading 3\">ata <\/span><span class=\"NormalTextRun SCXW127954652 BCX8\" data-ccp-parastyle=\"heading 3\">p<\/span><span class=\"NormalTextRun SCXW127954652 BCX8\" data-ccp-parastyle=\"heading 3\">rotection<\/span><\/span><span class=\"EOP SCXW127954652 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:281,&quot;335559739&quot;:281}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">The Commissioner for Personal Data Protection determined in one case that a data controller violated legal provisions while securing premises through video surveillance. The violation occurred because the surveillance cameras allowed real-time access to third parties via an application. This example is cited in Publication No. 9 \u2013 Personal Data Protection: Opinions and Views of the Commissioner, No. 072-04-2514\/2023-07.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In this case, the Commissioner issued a warning to the data controller, referencing provisions of the Personal Data Protection Act related to the principles of lawfulness, fairness, transparency, and data minimization. Additionally, Article 31 of the Private Security Act was cited, which stipulates that technical means used in private security must not infringe on others&#8217; privacy.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">If an objective can be achieved through less intrusive methods than continuous employee monitoring via video surveillance, then those less invasive methods should be used. Data must be collected for specific, explicit, justified, and lawful purposes. The principle of data minimization dictates that collected data should be adequate, relevant, and limited to what is necessary for processing.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In practice, the Commissioner determined that timely response by medical staff to emergency calls and dispatcher requests can be achieved through less intrusive methods than continuous monitoring of employees&#8217; actions and behavior via video surveillance (Publication No. 6 \u2013 Personal Data Protection: Opinions and Views of the Commissioner, No. 072-04-1409\/2020-07, dated 31.8.2020).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h3><span class=\"TextRun SCXW248394107 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW248394107 BCX8\" data-ccp-parastyle=\"heading 3\">European<\/span><span class=\"NormalTextRun SCXW248394107 BCX8\" data-ccp-parastyle=\"heading 3\"> case<\/span> <span class=\"NormalTextRun SCXW248394107 BCX8\" data-ccp-parastyle=\"heading 3\">l<\/span><span class=\"NormalTextRun SCXW248394107 BCX8\" data-ccp-parastyle=\"heading 3\">aw<\/span><\/span><span class=\"EOP SCXW248394107 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:281,&quot;335559739&quot;:281}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">In case No. 0603-47\/2023\/5, the Slovenian Commissioner for Personal Data Protection ruled on 24.10.2023 that the scope of workplace video surveillance by a data controller was excessive and could not be justified by legitimate interest.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In case Deliberation No. 47FR\/2021, dated 01.12.2021, the Luxembourg Data Protection Commissioner fined a transport company \u20ac6,800 for violating the data minimization principle. The company failed to limit the field of view of its video surveillance system and did not adequately inform employees and third parties about the system\u2019s presence.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">In case No. 2.1.-4\/22\/2585, dated 06.12.2022, the Estonian Commissioner for Personal Data Protection ruled that CCTV surveillance of employees cannot be based on consent but only on legitimate interest under Article 6(1)(f) of the GDPR, provided that a valid interest assessment is conducted.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h2><span class=\"TextRun SCXW196877767 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">Is it <\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">j<\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">ustified to <\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">c<\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">ollect <\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">b<\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">iometric <\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">d<\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">ata for <\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">e<\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">mployee <\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">a<\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">ttendance <\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">t<\/span><span class=\"NormalTextRun SCXW196877767 BCX8\" data-ccp-parastyle=\"heading 3\">racking?<\/span><\/span><span class=\"EOP SCXW196877767 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:281,&quot;335559739&quot;:281}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Article 17(1) of the Personal Data Protection Act prohibits the processing of data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the unique identification of an individual, health data, or data concerning a person&#8217;s sex life or sexual orientation.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">However, the processing of such data is exceptionally allowed in cases prescribed by law and when the individual concerned has given consent for one or more specific purposes of processing (except in cases where processing is legally required to be conducted without consent).<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">According to Publication No. 6 \u2013 Personal Data Protection: Opinions and Views of the Commissioner, No. 073-14-1929\/2019-02, dated 05.11.2019, when it comes to using biometric data for monitoring employees\u2019 compliance with work obligations, consent cannot be considered a voluntary declaration of will under the law due to the clear imbalance of power between employer and employee. Therefore, consent would not be a lawful legal basis for data processing in this context.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The Personal Data Protection Act defines consent as a voluntary, specific, informed, and unambiguous expression of will by an individual, given through a statement or a clear affirmative action, allowing the processing of their personal data.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">However, there is a major &#8220;but&#8221;\u2014a declaration of consent given without the possibility of modification or withdrawal cannot be considered valid consent.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h2><span class=\"TextRun SCXW87426431 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW87426431 BCX8\">Audit and <\/span><span class=\"NormalTextRun SCXW87426431 BCX8\">d<\/span><span class=\"NormalTextRun SCXW87426431 BCX8\">ata <\/span><span class=\"NormalTextRun SCXW87426431 BCX8\">p<\/span><span class=\"NormalTextRun SCXW87426431 BCX8\">rotection<\/span><\/span><span class=\"EOP SCXW87426431 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">The first issue we encountered in practice relates to statutory audits and the question of whether the audited entity, as the data controller, and the auditing firm, as the data processor, should enter into a data processing agreement or if the auditing firm acts as a third party when conducting the audit.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">To clarify definitions\u2014a controller is defined as a person who, alone or jointly with others, determines the purpose and manner of processing personal data, while a processor is a person who processes personal data on behalf of the controller. Whether an entity is classified as a controller or a processor is determined on a case-by-case basis, depending on the specific circumstances.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">According to the Commissioner\u2019s opinion (Publication No. 8 \u2013 Personal Data Protection: Opinions, Views, and Practice of the Commissioner, No. 073-14-233\/2022-02), a company performing a statutory audit of financial statements and processing personal data necessary for fulfilling legal obligations acts as a controller in accordance with Article 12(1)(3) of the Personal Data Protection Act. The Commissioner further noted that an auditing firm may, in some cases, be considered a joint controller or processor for other services it provides, but in the context of statutory audits, it is considered a controller.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The role of each participant in data processing must always be determined based on the specific circumstances of the case. This is particularly relevant when assessing whether companies providing audit and accounting services act as controllers or processors in their relationships with clients and whether they are required to conduct a data protection impact assessment when processing special categories of personal data.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">For statutory audits, the answer has already been provided. However, in this case, the Commissioner has taken a clear stance (Publication No. 6 \u2013 Personal Data Protection: Opinions and Views of the Commissioner, No. 073-14-2406\/2019-02), stating that If an audit and accounting firm operates independently in providing the services for which it has been engaged and determines the purpose or manner of processing (or if these are defined by law), then the firm should be considered a controller.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">On the other hand, if the audit and accounting firm follows the client&#8217;s instructions and processes data while providing services in accordance with a contract, thereby fulfilling its contractual or legal obligation, it is considered a processor for that specific processing activity.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559685&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Once again, the classification of roles must be determined individually for each case. If there is any doubt about the correct classification, it is always advisable to consult a law firm specializing in personal data protection.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h3><span class=\"TextRun SCXW250525937 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW250525937 BCX8\" data-ccp-parastyle=\"heading 3\">European <\/span><span class=\"NormalTextRun SCXW250525937 BCX8\" data-ccp-parastyle=\"heading 3\">c<\/span><span class=\"NormalTextRun SCXW250525937 BCX8\" data-ccp-parastyle=\"heading 3\">ase <\/span><span class=\"NormalTextRun SCXW250525937 BCX8\" data-ccp-parastyle=\"heading 3\">l<\/span><span class=\"NormalTextRun SCXW250525937 BCX8\" data-ccp-parastyle=\"heading 3\">aw<\/span><\/span><span class=\"EOP SCXW250525937 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:281,&quot;335559739&quot;:281}\">\u00a0<\/span><\/h3>\n<p><span class=\"TextRun SCXW79273149 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW79273149 BCX8\">The <\/span><span class=\"NormalTextRun SCXW79273149 BCX8\">Spanish Data Protection Authority<\/span><span class=\"NormalTextRun SCXW79273149 BCX8\"> fined an <\/span><span class=\"NormalTextRun SCXW79273149 BCX8\">audit firm \u20ac3,000<\/span><span class=\"NormalTextRun SCXW79273149 BCX8\"> for a <\/span><span class=\"NormalTextRun SCXW79273149 BCX8\">security incident<\/span><span class=\"NormalTextRun SCXW79273149 BCX8\">. The Commissioner found a <\/span><span class=\"NormalTextRun SCXW79273149 BCX8\">violation of Article 5(1)(f)<\/span><span class=\"NormalTextRun SCXW79273149 BCX8\"> because personal data had been leaked without the data subject&#8217;s consent. Additionally, the Commissioner found a <\/span><span class=\"NormalTextRun SCXW79273149 BCX8\">violation of Article 32(1)<\/span><span class=\"NormalTextRun SCXW79273149 BCX8\"> because the audit firm <\/span><span class=\"NormalTextRun SCXW79273149 BCX8\">lacked <\/span><span class=\"NormalTextRun SCXW79273149 BCX8\">appropriate technical<\/span><span class=\"NormalTextRun SCXW79273149 BCX8\"> and organizational measures<\/span><span class=\"NormalTextRun SCXW79273149 BCX8\"> to ensure adequate protection in such situations (<\/span><span class=\"NormalTextRun SCXW79273149 BCX8\">Case No. PS\/00483\/2020<\/span><span class=\"NormalTextRun SCXW79273149 BCX8\">).<\/span><\/span><span class=\"EOP SCXW79273149 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h2><span class=\"TextRun SCXW157529642 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW157529642 BCX8\">When should a Data Protection Impact Assessment be conducted?<\/span><\/span><\/h2>\n<p><span data-contrast=\"auto\">Article 54 of the Personal Data Protection Act states that if a type of processing\u2014particularly one involving new technologies\u2014is likely to pose a high risk to the rights and freedoms of individuals, the controller must conduct a Data Protection Impact Assessment before initiating the processing activities.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Furthermore, when carrying out a Data Protection Impact Assessment, the controller must seek the opinion of the Data Protection Officer (DPO), if one has been appointed.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The law specifies cases in which an Assessment is mandatory. These include:<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Systematic and extensive evaluation of personal aspects of an individual using automated processing (including profiling), where decisions are made that significantly affect the individual&#8217;s legal position or otherwise impact them in a similar manner.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/li>\n<li><span class=\"TextRun SCXW68598737 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW68598737 BCX8\">Systematic monitoring of publicly accessible areas on a large scale<\/span><span class=\"NormalTextRun SCXW68598737 BCX8\">.<\/span><\/span><span class=\"EOP SCXW68598737 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/li>\n<li><span class=\"TextRun SCXW98655442 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW98655442 BCX8\">Processing of special categories of personal data<\/span><span class=\"NormalTextRun SCXW98655442 BCX8\"> as defined in <\/span><span class=\"NormalTextRun SCXW98655442 BCX8\">Article 17(1)<\/span><span class=\"NormalTextRun SCXW98655442 BCX8\"> (e.g., <\/span><span class=\"NormalTextRun SCXW98655442 BCX8\">racial<\/span><span class=\"NormalTextRun SCXW98655442 BCX8\"> or ethnic origin, political opinions, genetic data, etc.), <\/span><span class=\"NormalTextRun SCXW98655442 BCX8\">Article 18(1)<\/span><span class=\"NormalTextRun SCXW98655442 BCX8\">, and <\/span><span class=\"NormalTextRun SCXW98655442 BCX8\">personal data related to criminal convictions and offenses<\/span><span class=\"NormalTextRun SCXW98655442 BCX8\"> under <\/span><span class=\"NormalTextRun SCXW98655442 BCX8\">Article 19<\/span><span class=\"NormalTextRun SCXW98655442 BCX8\">, provided that the processing is carried out on a <\/span><span class=\"NormalTextRun SCXW98655442 BCX8\">large scale<\/span><span class=\"NormalTextRun SCXW98655442 BCX8\">.<\/span><\/span><span class=\"EOP SCXW98655442 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span class=\"TextRun SCXW81053404 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW81053404 BCX8\">If a <\/span><span class=\"NormalTextRun SCXW81053404 BCX8\">D<\/span><span class=\"NormalTextRun SCXW81053404 BCX8\">ata Protection Impact Assessment<\/span><span class=\"NormalTextRun SCXW81053404 BCX8\"> conducted under Article 54 <\/span><span class=\"NormalTextRun SCXW81053404 BCX8\">indicates<\/span> <span class=\"NormalTextRun SCXW81053404 BCX8\">a high risk<\/span><span class=\"NormalTextRun SCXW81053404 BCX8\"> that cannot be mitigated through <\/span><span class=\"NormalTextRun SCXW81053404 BCX8\">additional<\/span><span class=\"NormalTextRun SCXW81053404 BCX8\"> measures, the controller must, under <\/span><span class=\"NormalTextRun SCXW81053404 BCX8\">Article 55<\/span><span class=\"NormalTextRun SCXW81053404 BCX8\">, <\/span><span class=\"NormalTextRun SCXW81053404 BCX8\">seek the Commissioner\u2019s opinion before starting the processing activities<\/span><span class=\"NormalTextRun SCXW81053404 BCX8\">. This requirement does <\/span><span class=\"NormalTextRun SCXW81053404 BCX8\">not<\/span><span class=\"NormalTextRun SCXW81053404 BCX8\"> apply to processing carried out by competent authorities for specific purposes.<\/span><\/span><span class=\"EOP SCXW81053404 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h2><span class=\"EOP SCXW81053404 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\"><span class=\"TextRun SCXW169722856 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW169722856 BCX8\">When <\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">m<\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">ust a <\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">l<\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">egal <\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">e<\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">ntity with <\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">f<\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">ewer than 250 <\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">e<\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">mployees <\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">m<\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">aintain<\/span><span class=\"NormalTextRun SCXW169722856 BCX8\"> a <\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">r<\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">ecord of <\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">p<\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">rocessing <\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">a<\/span><span class=\"NormalTextRun SCXW169722856 BCX8\">ctivities?<\/span><\/span><span class=\"EOP SCXW169722856 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/span><\/h2>\n<p><span data-contrast=\"auto\">Article 47 of the Personal Data Protection Act establishes the obligation to maintain records of processing activities. However, it states that this requirement does not apply to businesses and organizations with fewer than 250 employees, unless the processing is likely to pose a high risk to the rights and freedoms of individuals and the processing is not occasional.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Publication No. 6 \u2013 Personal Data Protection: Opinions and Views of the Commissioner, No. 073-14-1788\/2019-02, clarifies that the number of employees is not the only criterion. Even if a business has fewer than 250 employees, it must maintain processing records if it carries out regular personal data processing activities.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Regardless of whether this obligation applies in a given case, maintaining records of processing activities is a valuable tool that allows controllers and processors to demonstrate compliance with legal requirements.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h2><span class=\"TextRun SCXW99038602 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW99038602 BCX8\">Transfer of <\/span><span class=\"NormalTextRun SCXW99038602 BCX8\">b<\/span><span class=\"NormalTextRun SCXW99038602 BCX8\">usiness <\/span><span class=\"NormalTextRun SCXW99038602 BCX8\">o<\/span><span class=\"NormalTextRun SCXW99038602 BCX8\">perations and <\/span><span class=\"NormalTextRun SCXW99038602 BCX8\">d<\/span><span class=\"NormalTextRun SCXW99038602 BCX8\">ata<\/span> <span class=\"NormalTextRun SCXW99038602 BCX8\">p<\/span><span class=\"NormalTextRun SCXW99038602 BCX8\">rotection<\/span><\/span><span class=\"EOP SCXW99038602 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">What happens when an entire business operation is transferred from one legal entity, which processes a large amount of personal data as a controller, to another legal entity? Specifically, does this raise questions about the validity of previously given consent for data processing? Should consent be obtained again, or is it sufficient to transparently notify individuals about the change in the controller?<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">According to the Commissioner\u2019s opinion (Publication No. 7 \u2013 <\/span><i><span data-contrast=\"auto\">Personal Data Protection: Opinions and Views of the Commissioner for Information of Public Importance and Personal Data Protection No. 073-14-2509\/2021-02<\/span><\/i><span data-contrast=\"auto\">), every controller must ensure a valid legal basis for processing personal data. This means that consent cannot be transferred or assigned to another controller. Before initiating any processing activity (including the transfer or any other form of making personal data available), an appropriate legal basis must be established.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">When assessing whether consent was specifically given for data processing, it is important to consider whether the execution of a contract, including the provision of services, was conditioned upon giving consent that was not necessary for the contract&#8217;s execution.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">If personal data is transferred to other countries or international organizations, the conditions outlined in Articles 63 to 72 of the Personal Data Protection Act must also be met.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The answer to this question is not straightforward and depends on the specific circumstances of each individual case.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h3><span data-ccp-props=\"{&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><span class=\"TextRun SCXW113885472 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW113885472 BCX8\">From European <\/span><span class=\"NormalTextRun SCXW113885472 BCX8\">p<\/span><span class=\"NormalTextRun SCXW113885472 BCX8\">ractice<\/span><\/span><span class=\"EOP SCXW113885472 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/h3>\n<p><span data-contrast=\"auto\">In case no. 9860553, the Italian Data Protection Commissioner fined AssitecaSpa, an insurance company, \u20ac120,000 on December 15, 2022, for unlawful data processing due to lack of consent and prolonged data retention. The violations stemmed from issues related to IT system integration following a company merger and business transfer.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">When issuing this decision, the Italian Commissioner identified four key issues:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Post-merger data retention \u2013 AssitecaSpa retained data from nearly 9,700 users of the previous company without their knowledge, exposing them to potential unauthorized processing for promotional purposes, even without proper consent. The Commissioner found that system errors led to incorrect implementation of users\u2019 preferences, as consent was unintentionally registered after users accessed promotional emails for car insurance offers. The company argued that this was due to technical issues.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Lack of clear and transparent information \u2013 The information provided to users was unclear, especially regarding third-party transfers and profiling. The company later updated its privacy notice to offer a clearer explanation of processing activities and legal bases.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Failure to define data retention periods \u2013 The company did not have pre\u2013defined retention periods for specific purposes, violating Article 5(1)(e) of the GDPR.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Inadequate technical measures \u2013 Although the Commissioner noted the absence of sufficient technical measures, no fine was issued in this regard due to the recent integration of two corporate systems and the company\u2019s efforts to remediate the situation.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-ccp-props=\"{&quot;335551550&quot;:6,&quot;335551620&quot;:6}\">\u00a0<\/span><\/p>\n<p><em>Note: This text does not constitute legal advice but represents the personal opinion of the author.\u00a0<\/em><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p>\n<h2><span class=\"EOP SCXW81053404 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/h2>\n<h2><span class=\"EOP SCXW157529642 BCX8\" data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/h2>\n","protected":false},"excerpt":{"rendered":"<p>Why is compliance with data protection regulations important?\u00a0 A key aspect of data protection is the reduction of risks associated with non-compliance and security breaches. From a company\u2019s perspective, data protection fosters trust among customers and employees, safeguards reputation, and maintains financial stability.\u00a0 Failure to comply with relevant regulations can<\/p>\n","protected":false},"author":2,"featured_media":774,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5],"tags":[376,544,613,377,22,299,239,614,615,616,541,185,170,617],"class_list":["post-776","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attorney-belgrade","tag-attorney-for-data-protection","tag-attorney-for-gdpr","tag-attorney-serbia","tag-corporate-law","tag-data-privacy","tag-data-protection","tag-data-protection-impact-assessment","tag-data-protection-officer","tag-dpo","tag-gdpr-2","tag-it-law","tag-legal-tech","tag-personal-data-protection"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection in the business environment: Q&amp;A - Law firm Vranesevic Grbic Belgrade<\/title>\n<meta name=\"description\" content=\"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd -pravne usluge iz: krivi\u010dnog, imigracionog, ugovornog, IT, korporativnog i privrednog prava.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection in the business environment: Q&amp;A - Law firm Vranesevic Grbic Belgrade\" \/>\n<meta property=\"og:description\" content=\"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd -pravne usluge iz: krivi\u010dnog, imigracionog, ugovornog, IT, korporativnog i privrednog prava.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/\" \/>\n<meta property=\"og:site_name\" content=\"Law firm Vranesevic Grbic Belgrade\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-11T13:14:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-02-11T13:14:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/vraneseviclaw.com\/wp-content\/uploads\/2025\/02\/data-protection-slika-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"848\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Lucija Vrane\u0161evi\u0107 Grbi\u0107\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lucija Vrane\u0161evi\u0107 Grbi\u0107\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/data-protection-in-the-business-environment-qa\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/data-protection-in-the-business-environment-qa\\\/\"},\"author\":{\"name\":\"Lucija Vrane\u0161evi\u0107 Grbi\u0107\",\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/#\\\/schema\\\/person\\\/9f46bf860a5a48a8578a19e0a92346af\"},\"headline\":\"Data protection in the business environment: Q&amp;A\",\"datePublished\":\"2025-02-11T13:14:17+00:00\",\"dateModified\":\"2025-02-11T13:14:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/data-protection-in-the-business-environment-qa\\\/\"},\"wordCount\":2336,\"publisher\":{\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/data-protection-in-the-business-environment-qa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/vraneseviclaw.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/data-protection-slika-1.jpg\",\"keywords\":[\"attorney belgrade\",\"attorney for data protection\",\"attorney for gdpr\",\"attorney serbia\",\"corporate law\",\"data privacy\",\"data protection\",\"data protection impact assessment\",\"data protection officer\",\"dpo\",\"GDPR\",\"IT law\",\"legal tech\",\"personal data protection\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/data-protection-in-the-business-environment-qa\\\/\",\"url\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/data-protection-in-the-business-environment-qa\\\/\",\"name\":\"Data protection in the business environment: Q&amp;A - Law firm Vranesevic Grbic Belgrade\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/data-protection-in-the-business-environment-qa\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/data-protection-in-the-business-environment-qa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/vraneseviclaw.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/data-protection-slika-1.jpg\",\"datePublished\":\"2025-02-11T13:14:17+00:00\",\"dateModified\":\"2025-02-11T13:14:18+00:00\",\"description\":\"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd -pravne usluge iz: krivi\u010dnog, imigracionog, ugovornog, IT, korporativnog i privrednog prava.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/data-protection-in-the-business-environment-qa\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/data-protection-in-the-business-environment-qa\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/data-protection-in-the-business-environment-qa\\\/#primaryimage\",\"url\":\"https:\\\/\\\/vraneseviclaw.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/data-protection-slika-1.jpg\",\"contentUrl\":\"https:\\\/\\\/vraneseviclaw.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/data-protection-slika-1.jpg\",\"width\":1280,\"height\":848},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/data-protection-in-the-business-environment-qa\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Po\u010detna\",\"item\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection in the business environment: Q&amp;A\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/#website\",\"url\":\"https:\\\/\\\/vraneseviclaw.com\\\/\",\"name\":\"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd\",\"description\":\"Law firm Vranesevic Grbic Belgrade\",\"publisher\":{\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/#organization\"},\"alternateName\":\"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/vraneseviclaw.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/#organization\",\"name\":\"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd\",\"alternateName\":\"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd\",\"url\":\"https:\\\/\\\/vraneseviclaw.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/vraneseviclaw.com\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/advokat-beograd-lucija-vranesevic.jpg\",\"contentUrl\":\"https:\\\/\\\/vraneseviclaw.com\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/advokat-beograd-lucija-vranesevic.jpg\",\"width\":696,\"height\":696,\"caption\":\"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd\"},\"image\":{\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/vraneevi-law\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/vraneseviclaw.com\\\/#\\\/schema\\\/person\\\/9f46bf860a5a48a8578a19e0a92346af\",\"name\":\"Lucija Vrane\u0161evi\u0107 Grbi\u0107\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e86792d8ec8b429caf69e278d2d9b8960a040c86245e26f520ef84e0bf3526ec?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e86792d8ec8b429caf69e278d2d9b8960a040c86245e26f520ef84e0bf3526ec?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e86792d8ec8b429caf69e278d2d9b8960a040c86245e26f520ef84e0bf3526ec?s=96&d=mm&r=g\",\"caption\":\"Lucija Vrane\u0161evi\u0107 Grbi\u0107\"},\"sameAs\":[\"https:\\\/\\\/vraneseviclaw.com\"],\"url\":\"https:\\\/\\\/vraneseviclaw.com\\\/en\\\/author\\\/lucijavranesevicgrbic\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection in the business environment: Q&amp;A - Law firm Vranesevic Grbic Belgrade","description":"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd -pravne usluge iz: krivi\u010dnog, imigracionog, ugovornog, IT, korporativnog i privrednog prava.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/","og_locale":"en_US","og_type":"article","og_title":"Data protection in the business environment: Q&amp;A - Law firm Vranesevic Grbic Belgrade","og_description":"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd -pravne usluge iz: krivi\u010dnog, imigracionog, ugovornog, IT, korporativnog i privrednog prava.","og_url":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/","og_site_name":"Law firm Vranesevic Grbic Belgrade","article_published_time":"2025-02-11T13:14:17+00:00","article_modified_time":"2025-02-11T13:14:18+00:00","og_image":[{"width":1280,"height":848,"url":"https:\/\/vraneseviclaw.com\/wp-content\/uploads\/2025\/02\/data-protection-slika-1.jpg","type":"image\/jpeg"}],"author":"Lucija Vrane\u0161evi\u0107 Grbi\u0107","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Lucija Vrane\u0161evi\u0107 Grbi\u0107","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/#article","isPartOf":{"@id":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/"},"author":{"name":"Lucija Vrane\u0161evi\u0107 Grbi\u0107","@id":"https:\/\/vraneseviclaw.com\/#\/schema\/person\/9f46bf860a5a48a8578a19e0a92346af"},"headline":"Data protection in the business environment: Q&amp;A","datePublished":"2025-02-11T13:14:17+00:00","dateModified":"2025-02-11T13:14:18+00:00","mainEntityOfPage":{"@id":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/"},"wordCount":2336,"publisher":{"@id":"https:\/\/vraneseviclaw.com\/#organization"},"image":{"@id":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/#primaryimage"},"thumbnailUrl":"https:\/\/vraneseviclaw.com\/wp-content\/uploads\/2025\/02\/data-protection-slika-1.jpg","keywords":["attorney belgrade","attorney for data protection","attorney for gdpr","attorney serbia","corporate law","data privacy","data protection","data protection impact assessment","data protection officer","dpo","GDPR","IT law","legal tech","personal data protection"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/","url":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/","name":"Data protection in the business environment: Q&amp;A - Law firm Vranesevic Grbic Belgrade","isPartOf":{"@id":"https:\/\/vraneseviclaw.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/#primaryimage"},"image":{"@id":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/#primaryimage"},"thumbnailUrl":"https:\/\/vraneseviclaw.com\/wp-content\/uploads\/2025\/02\/data-protection-slika-1.jpg","datePublished":"2025-02-11T13:14:17+00:00","dateModified":"2025-02-11T13:14:18+00:00","description":"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd -pravne usluge iz: krivi\u010dnog, imigracionog, ugovornog, IT, korporativnog i privrednog prava.","breadcrumb":{"@id":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/#primaryimage","url":"https:\/\/vraneseviclaw.com\/wp-content\/uploads\/2025\/02\/data-protection-slika-1.jpg","contentUrl":"https:\/\/vraneseviclaw.com\/wp-content\/uploads\/2025\/02\/data-protection-slika-1.jpg","width":1280,"height":848},{"@type":"BreadcrumbList","@id":"https:\/\/vraneseviclaw.com\/en\/data-protection-in-the-business-environment-qa\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Po\u010detna","item":"https:\/\/vraneseviclaw.com\/en\/"},{"@type":"ListItem","position":2,"name":"Data protection in the business environment: Q&amp;A"}]},{"@type":"WebSite","@id":"https:\/\/vraneseviclaw.com\/#website","url":"https:\/\/vraneseviclaw.com\/","name":"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd","description":"Law firm Vranesevic Grbic Belgrade","publisher":{"@id":"https:\/\/vraneseviclaw.com\/#organization"},"alternateName":"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/vraneseviclaw.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/vraneseviclaw.com\/#organization","name":"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd","alternateName":"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd","url":"https:\/\/vraneseviclaw.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vraneseviclaw.com\/#\/schema\/logo\/image\/","url":"https:\/\/vraneseviclaw.com\/wp-content\/uploads\/2023\/12\/advokat-beograd-lucija-vranesevic.jpg","contentUrl":"https:\/\/vraneseviclaw.com\/wp-content\/uploads\/2023\/12\/advokat-beograd-lucija-vranesevic.jpg","width":696,"height":696,"caption":"Advokatska kancelarija Vrane\u0161evi\u0107 Grbi\u0107 Beograd"},"image":{"@id":"https:\/\/vraneseviclaw.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/vraneevi-law\/"]},{"@type":"Person","@id":"https:\/\/vraneseviclaw.com\/#\/schema\/person\/9f46bf860a5a48a8578a19e0a92346af","name":"Lucija Vrane\u0161evi\u0107 Grbi\u0107","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/e86792d8ec8b429caf69e278d2d9b8960a040c86245e26f520ef84e0bf3526ec?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/e86792d8ec8b429caf69e278d2d9b8960a040c86245e26f520ef84e0bf3526ec?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e86792d8ec8b429caf69e278d2d9b8960a040c86245e26f520ef84e0bf3526ec?s=96&d=mm&r=g","caption":"Lucija Vrane\u0161evi\u0107 Grbi\u0107"},"sameAs":["https:\/\/vraneseviclaw.com"],"url":"https:\/\/vraneseviclaw.com\/en\/author\/lucijavranesevicgrbic\/"}]}},"_links":{"self":[{"href":"https:\/\/vraneseviclaw.com\/en\/wp-json\/wp\/v2\/posts\/776","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vraneseviclaw.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vraneseviclaw.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vraneseviclaw.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vraneseviclaw.com\/en\/wp-json\/wp\/v2\/comments?post=776"}],"version-history":[{"count":1,"href":"https:\/\/vraneseviclaw.com\/en\/wp-json\/wp\/v2\/posts\/776\/revisions"}],"predecessor-version":[{"id":777,"href":"https:\/\/vraneseviclaw.com\/en\/wp-json\/wp\/v2\/posts\/776\/revisions\/777"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vraneseviclaw.com\/en\/wp-json\/wp\/v2\/media\/774"}],"wp:attachment":[{"href":"https:\/\/vraneseviclaw.com\/en\/wp-json\/wp\/v2\/media?parent=776"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vraneseviclaw.com\/en\/wp-json\/wp\/v2\/categories?post=776"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vraneseviclaw.com\/en\/wp-json\/wp\/v2\/tags?post=776"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}