Frequently Asked Questions

Filter on
Filter on topic

Hver er ábyrgðaraðili gagna og hver er gagnavinnsluaðili?

GDPR greinir á milli tveggja meginhlutverka: ábyrgðaraðila gagna og gagnavinnsluaðila. Þessi greinarmunur er mikilvægur þar sem ábyrgðaraðilinn ber meiri ábyrgð og þarf að uppfylla fleiri skyldur en vinnsluaðilinn.

Ábyrgðaraðilar og vinnsluaðilar geta verið einstaklingar eða lögaðilar, til dæmis: lítið eða meðalstórt fyrirtæki, opinbert yfirvald, félag, stofnun, ríkisstofnun, félag o.s.frv.

Ábyrgðaraðili ákvarðar tilgang og aðferðir við vinnsluaðgerð. Með öðrum orðum, stjórnandi ákveður hvernig og hvers vegna vinnslu aðgerð. Vinnsluaðilar vinna persónuupplýsingar fyrir hönd ábyrgðaraðila. Vinnsla vinnsluaðila verður að falla undir samning við ábyrgðaraðila gagna eða aðra réttargerð.

Dæmi um ábyrgðaraðila gagna:

  • fyrirtæki sem vinna persónuupplýsingar viðskiptavina sinna til að ljúka sölu;
  • fjármálastofnanir sem vinna persónuupplýsingar um viðskiptavini sína,
  • samtök sem vinna úr gögnum aðila sinna,
  • skólum eða háskólum sem vinna persónuupplýsingar um nemendur og kennara,
  • sjúkrahús sem vinna persónuupplýsingar um sjúklinga sína;
  • ríkisstofnanir sem vinna með persónuupplýsingar borgara.
     

Dæmi um gagnavinnsluaðila:

  • lítið eða meðalstórt fyrirtæki ræður bókhaldsþjónustu til að halda bókhald sitt og skrár, lítið eða meðalstórt fyrirtæki er ábyrgðaraðili gagna og bókhaldsþjónustan gagnavinnsluaðili,
  • launafyrirtæki vinnur persónuupplýsingar fyrir lítið eða meðalstórt fyrirtæki. Launafyrirtækið mun starfa sem vinnsluaðili ef það vinnur eingöngu persónuupplýsingar fyrir hönd lítilla og meðalstórra fyrirtækja. Lítil eða meðalstór fyrirtæki ákvarðar tilgang og aðferðir við gagnavinnsluna og er því ábyrgðaraðili gagna.
  • lítil og meðalstór fyrirtæki veitir markaðsfyrirtæki umboð til að safna netföngum á vefsíðum þriðja aðila.  Markaðsfyrirtækið gerir þetta í samræmi við skýr fyrirmæli lítilla og meðalstórra fyrirtækja og í eigin þágu lítilla og meðalstórra fyrirtækja. Markaðsfyrirtækið starfar sem örgjörva fyrir þetta safn.

Frekari upplýsingar:

Hvað eru viðkvæmar upplýsingar?

Sumar tegundir persónuupplýsinga tilheyra sérstökum flokkum persónuupplýsinga sem þýðir að þær eiga skilið meiri vernd, svokallaðar viðkvæmar upplýsingar. Viðkvæm gögn innihalda gögn sem sýna upplýsingar um:

  • heilbrigði einstaklings,
  • kynhneigð einstaklingsins;
  • kynþáttar eða þjóðernislegs uppruna einstaklings,
  • stjórnmálaskoðanir, trúar- eða heimspekilegar skoðanir einstaklings, aðild að stéttarfélagi einstaklings,
  • lífkenna og erfðafræðilegar upplýsingar einstaklings.

Vinnsla viðkvæmra gagna einstaklings er almennt bönnuð nema við sérstakar aðstæður réttlæti vinnslu þeirra.

Frekari upplýsingar:

Hver getur gegnt hlutverki persónuverndarfulltrúa (DPO)?

DPO getur verið núverandi starfsmaður með næga þekkingu á GDPR (ef fagleg verkefni starfsmanns eru í samræmi við verkefni gagnaverndarfulltrúa og það leiðir ekki til hagsmunaárekstra) eða utanaðkomandi aðila. Gagnaverndarfulltrúi ætti að geta sinnt verkefnum sjálfstætt og ætti að geta gefið skýrslu beint til æðstu stjórnenda.

Frekari upplýsingar:

Where can I find documents adopted by the Article 29 Working Party?

The archived documents adopted by the Article 29 Working Party (1997-2016) are available on the website of the European Commission here: WP29 archive.

Should you experience any difficulty accessing WP29 documents, we recommend contacting the European Commission's DG Justice. The European Commission provided the Secretariat for the Article 29 Working Party and was responsible for all its publications. 

You can contact them by filling out the following form

Does the GDPR apply to my organisation?

Every organisation, regardless of the their size or sector, established in the European Economic Area (EEA) or offering products or services to individuals in the EEA, processing personal data whether or not by automated means needs to comply with the GDPR. The GDPR applies to the automated processing of personal data and to processing operations carried out manually from the moment the paper files are organised in a systematic manner, e.g. ordered alphabetically in a filing cabinet.

Examples of processing operations include collecting, recording, organising, using, modifying, storing, disclosing, altering and erasing individuals’ personal data.

Nevertheless, the application of the GDPR is modulated according to the nature, context, purposes and risks of the processing operations carried out. For SMEs whose core business is not the processing of personal data, the obligations can be less strict than for a large company.

What happens after a public consultation is closed?

Once a public consultation is closed, all contributions to the public consultation are reviewed and, where necessary, the guidelines may be adapted. Once this process has been completed, the guidelines will be up for final adoption at a subsequent EDPB plenary.

Hvað eru persónuupplýsingar?

Persónuupplýsingar eru allar upplýsingar sem tengjast persónugreindum eða persónugreinanlegum einstaklingi. Persónugreinanlegur einstaklingur er sá sem hægt er að bera kennsl á, beint eða óbeint. Mismunandi upplýsingar sem bætt er saman gætu leitt til þess að auðkenna tiltekinn einstakling eru einnig persónuupplýsingar.

Dæmi um persónuupplýsingar eru:

  • nafn og kenninafn,
  • heimilisfang,
  • tölvupóstfang,
  • kennivottorðsnúmer,
  • staðsetningargögn,
  • IP-vistfang (IP-vistfang),
  • auðkenni vafrakaka,
  • bankareikningar,
  • skattskýrslur,
  • lífkennaupplýsingar (eins og fingrafar),
  • almannatrygginganúmer,
  • vegabréfsnúmer,
  • niðurstöður úr prófunum,
  • einkunnir í skólanum;
  • vafrasaga;
  • ljósmynd af einstaklingi,
  • skráningarnúmer ökutækis o.s.frv.

 Frekari upplýsingar:

I submitted feedback to a public consultation, but I cannot see my comments on the public consultation page. How do I know that my feedback was received by the EDPB?

All comments submitted are screened and reviewed manually before being displayed on our website. There should have been a visual confirmation after submitting your comments on our website.

In any case, please allow for some time before your comments are published.

Do you think your data has been lost or stolen?

The GDPR puts in place clear procedures in case of a data breach. If a data breach poses a risk, companies and organisations holding your data have to inform the relevant data protection authority within 72 hours or without undue further delay. If the leak poses a high risk to you, then you must also be informed personally.

For more information on data breaches, please consult the EDPB Data Protection Guide for small business.

Are EDPB documents available in all EU languages?

We are constantly working on the translation of our documents into the official EU languages.
All static content, as well as press releases and documents officially adopted by the Board, such as Guidelines, will be made available in these languages.

This process takes time and various steps need to be completed in order to provide translations of the best quality.

Please note that documents undergoing public consultation are usually not translated. It is only after the public consultation has been concluded and a final version of the document has been adopted by the Board that these documents will be translated.

My organisation would like to become a certification body, how can we become accredited?

Certification bodies are accredited by the national data protection authorities (DPA) or by the national accreditation body (named in accordance with Regulation 17065/2012). For further information regarding certification bodies, we recommend contacting the national DPA in your country. You can find an overview of all EEA DPAs here.

You can find further information regarding accreditation of certification bodies here: Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679)

Are you asking tailored advice on how to interpret or apply data protection rules in your specific situation?

The EDPB does not provide tailored legal advice to citizens or private/public organisations on how to apply data protection law to specific cases. 

The EDPB’s main role is to issue general guidance and opinions. All adopted guidance and opinions can be consulted here: Guidelines, Recommendations, Best Practices and Opinions. We also recommend reading the Data Protection Guide for Small Business. This guide will help you understand key data protection concepts, the rights of individuals under the GDPR, compliance requirements, security measures, and how to handle data breaches.

Additional information on the EDPB's role and the application of the GDPR, can also be found here: Frequently Asked Questions.

We also invite you to consult the websites of the data protection authority in your country. The links to the websites of our Members can be found here: Our members.

Where can I find documents that were adopted during a recent/the latest EDPB plenary?

All documents adopted during the EDPB Plenary are subject to the necessary legal, linguistic and formatting checks and will be made available on the EDPB website once these have been completed.

Once published, recently adopted documents will be listed under “latest publications” on the main page of this website.

You can also find overviews of the documents adopted per plenary on the EDPB news page.

What is the EDPB?

The European Data Protection Board (EDPB) is an independent European body, which contributes to the consistent application of data protection rules throughout the European Union, and promotes cooperation between the EU’s data protection authorities (DPAs), as well as the DPAs of Iceland, Liechtenstein and Norway (the European Economic Area or EEA).

When will the EDPB’s decision be published in those cases where it settles conflicting views on a draft decision or where it decides on the Lead Supervisory Authority (LSA)?

Once the Lead Supervisory Authority (LSA) or, in some cases the Concerned Supervisory Authority (CSA), with which the complaint was lodged has notified the EDPB of the date its final decision was communicated to the controller or processor and, where relevant, to the complainant, the EDPB will publish its own decision on its website.

What does the EDPB do?

The EDPB aims to ensure the consistent application of the General Data Protection Regulation and of the Law Enforcement Directive in the European Economic Area (EEA). The EDPB also looks into the application of certain aspects of the ePrivacy Directive.

Our main tasks and duties are:

  • providing general guidance (including guidelines, recommendations and best practices) to clarify the law and to promote a common understanding of EU data protection laws;
  • adopting opinions addressed to the European Commission or to the national Data Protection Authorities (DPAs):
    • to advise the European Commission on any issue related to the protection of personal data and newly proposed legislation in the European Union (Art. 70 GDPR). In some instances, we issue Joint Opinions together with the EDPS (Art.42 of Regulation 2018/1725);
    • to ensure consistency of the activities of national data protection authorities (DPAs) on cross-border matters (Art. 64 GDPR). If authorities fail to respect an opinion issued by the EDPB, we may adopt a binding decision;
  • adopting binding decisions addressed to the national DPAs and aiming to settle disputes between them when they cooperate in cross-border cases, with the purpose of ensuring the correct and consistent application of the GDPR in individual cases;
  • promoting and supporting the cooperation among national DPAs.

Sem ábyrgðaraðili hef ég safnað persónuupplýsingum einstaklinga frá þriðja aðila, hvað þarf ég að gera til að vera í samræmi við kröfur?

  1. Gakktu úr skugga um að gögnum sem þú fékkst hafi verið safnað með lögmætum hætti og að viðkomandi einstaklingar hafi verið upplýstir um vinnslu persónuupplýsinga þeirra.
  2. Ef þriðji aðili vinnur persónuupplýsingar fyrir þína hönd skaltu ganga úr skugga um að þú sért með ábyrgðaraðila-vinnslusamning, sem tilgreinir vinnsluaðgerðirnar og leiðir til að vinna úr persónuupplýsingum.

Og að sjálfsögðu, uppfylla allar skyldur ábyrgðaraðila.

Frekari upplýsingar:

Get ég birt nöfn sigurvegara keppninnar á vefsíðu stofnunarinnar?

Að birta nöfn sigurvegara samkeppni á vefsíðunni þinni gæti talist lögmætir hagsmunir, ef þú getur sannað þetta með því að framkvæma jafnvægispróf til að ákvarða hvort lögmætir hagsmunir þínir vega þyngra en rétt einstaklinga.

Góðar starfsvenjur eru að koma á fót innri málsmeðferð þar sem útskýrt er hvaða reglur um birtingu persónuupplýsinga vinningshafa eru útskýrðar.

Þar að auki ætti vinnsla persónuupplýsinga í þessum tilgangi að vera hluti af stefnu keppninnar um friðhelgi einkalífsins þannig að þátttakendur séu upplýstir fyrirfram um hvernig unnið verði með upplýsingar um þá.

Frekari upplýsingar:

Hvernig get ég vitað hvaða öryggisráðstafanir ég þarf að gera?

Nauðsynlegar öryggisráðstafanir geta verið mismunandi eftir eðli þeirra persónuupplýsinga sem þú vinnur með og tengdum áhættum fyrir einstaklinga. Í öllum tilvikum eru nokkrar lágmarksráðstafanir sem þú ættir að gera:

  • öruggan aðgang að athafnasvæðinu,
  • notaðu reglulega uppfærðan antivirus hugbúnað;
  • veldu lykilorðin þín vandlega;
  • gera notendur staðfesta sig áður en þeir nota tölvubúnað;
  • hafa yfir að ráða stefnu um öryggisafritun og endurheimt gagna ef um óhapp er að ræða.

Að auki eru nokkrar helstu ráðstafanir eins og að læsa skjánum á meðan þú ert í burtu og læsa upp skrifstofu í lok dags eru aldrei út af stað...

Frekari upplýsingar:

Get ég deilt lista yfir persónuupplýsingar einstaklinga með viðskiptafélögum mínum (þriðju aðila)?

Já, þú getur, en GDPR leggur ákveðnar skyldur á fyrirtæki sem deila persónuupplýsingum. Fyrirtækið þitt verður að upplýsa einstaklinga um að þú munir deila gögnum þeirra með þriðja aðila. Þú verður einnig að tilkynna þeim um tilgang þinn, öryggi, aðgang og varðveisluráðstafanir sem gilda.