eu-charter

EU's charter om grundlæggende rettigheder

Artikel 8 - Beskyttelse af personoplysninger

Artikel 8 - Beskyttelse af personoplysninger

  1. Enhver har ret til beskyttelse af personoplysninger, der vedrører den pågældende.
  2. Disse oplysninger skal behandles rimeligt, til udtrykkeligt angivne formål og på grundlag af de berørte personers samtykke eller på et andet berettiget ved lov fastsat grundlag. Enhver har ret til adgang til indsamlede oplysninger, der vedrører den pågældende, og til berigtigelse heraf.
  3. Overholdelsen af disse regler er underlagt en uafhængig myndigheds kontrol.

Forklaringer

  • Text:

    Denne artikel er baseret på EF-traktatens artikel 286 og Europa-Parlamentets og Rådets direktiv 95/46/EF om beskyttelse af fysiske personer i forbindelse med behandling af personoplysninger og om fri udveksling af sådanne oplysninger (EFT L 281 af 23.11.1995, s. 31) samt på EMK's artikel 8 og Europarådets konvention om beskyttelse af det enkelte menneske i forbindelse med elektronisk databehandling af personoplysninger af 28. januar 1981, som alle medlemsstaterne har ratificeret. EF-traktatens artikel 286 er nu erstattet af artikel 16 i traktaten om Den Europæiske Unions funktionsmåde og artikel 39 i traktaten om Den Europæiske Union. Der henvises endvidere til Europa-Parlamentets og Rådets forordning (EF) nr. 45/2001 om beskyttelse af fysiske personer i forbindelse med behandling af personoplysninger i Fællesskabets institutioner og organer og om fri udveksling af sådanne oplysninger (EFT L 8 af 12.1.2001, s. 1). Ovennævnte direktiv og forordning indeholder betingelser og begrænsninger for udøvelsen af retten til beskyttelse af personoplysninger.

    Source:
    Den Europæiske Unions Tidende C 303/17 - 14.12.2007
    Preamble - Explanations relating to the Charter of Fundamental Rights:
    Disse forklaringer blev oprindelig udarbejdet under præsidiet for den forsamling, der udarbejdede chartret om grundlæggende rettigheder. De er blevet ajourført under Det Europæiske Konvents præsidiums ansvar i lyset af de udkast til tilpasninger, som konventet har foretaget i charterteksten (især i artikel 51 og 52) og videreudviklingen af EU-retten. Selv om forklaringerne ikke i sig selv har retskraft, udgør de et værdifuldt fortolkningsinstrument beregnet til nærmere præcisering af chartrets bestemmelser.

Retspraksis

National Forfatningsret

68 results found

  • Ustawa z dnia 29 sierpnia 1997 r. o ochronie danych osobowych
    Land:
    Poland

    Rozdział 1 1. Każdy ma prawo do ochrony dotyczących go danych osobowych.2. Przetwarzanie danych osobowych może mieć miejsce ze względu na dobro publiczne, dobro osoby, której dane dotyczą, lub dobro osób trzecich w zakresie i trybie określonym ustawą.

  • Wet bescherming persoonsgegevens
    Land:
    Netherlands

    Artikel 4 1. Deze wet is van toepassing op de verwerking van persoonsgegevens in het kader van activiteiten van een vestiging van een verantwoordelijke in Nederland. 2. Deze wet is van toepassing op de verwerking van persoonsgegevens door of ten behoeve van een verantwoordelijke die geen vestiging heeft in de Europese Unie, waarbij gebruik wordt gemaakt van al dan niet geautomatiseerde middelen die zich in Nederland bevinden, tenzij deze middelen slechts worden gebruikt voor de doorvoer van persoonsgegevens. 3. Het is een verantwoordelijke als bedoeld in het tweede lid, verboden persoonsgegevens te verwerken, tenzij hij in Nederland een persoon of instantie aanwijst die namens hem handelt overeenkomstig de bepalingen van deze wet. Voor de toepassing van deze wet en de daarop berustende bepalingen, wordt hij aangemerkt als de verantwoordelijke.

  • Wet van 8 december 1992 voor de bescherming van de persoonlijke levenssfeer ten opzichte van de verwerking van persoonsgegevens
    Land:
    Belgium

     

     

     

  • Zákon o ochraně osobních údajů
    Land:
    Czechia
  • Zakon o varstvu osebnih podatkov
    Land:
    Slovenia
  • Νόμοι 138(Ι) του 2001 και 37(Ι) του 2003
    Land:
    Cyprus

    Πεδίο εφαρμογής.3.-(1) Οι διατάξεις του παρόντος Νόμου εφαρμόζονται στην αυτοματοποιημένη εν όλω ή εν μέρει επεξεργασία, καθώς και στη μη αυτοματοποιημένη επεξεργασία δεδομένων προσωπικού χαρακτήρα, τα οποία περιλαμβάνονται (...).

  • Το Σύνταγμα της Ελλάδας
    Land:
    Greece

    Άρθρο 9A Καθένας έχει δικαίωμα προστασίας από τη συλλογή, επεξεργασία και χρήση, ιδίως με ηλεκτρονικά μέσα, των προσωπικών του δεδομένων, όπως νόμος ορίζει. Η προστασία των προσωπικών δεδομένων διασφαλίζεται από ανεξάρτητη αρχή, που συγκροτείται και λειτουργεί, όπως νόμος ορίζει.

  • Закон за защита на личните данни
    Land:
    Bulgaria

    Чл. 1. (Изм. - ДВ, бр. 103 от 2005 г.) (1) Този закон урежда защитата на правата на физическите лица при обработването на личните им данни. (2) Целта на закона е гарантиране на неприкосновеността на личността и личния живот чрез осигуряване на защита на физическите лица при неправомерно обработване на свързаните с тях лични данни в процеса на свободното движение на данните. (3) (Нова - ДВ, бр. 91 от 2006 г.) Този закон се прилага за обработването на лични данни със: 1. автоматични средства; 2. неавтоматични средства, когато тези данни съставляват или са предназначени да съставляват част от регистър. (...)

EU-ret

37 results found

  • Regulation (EU) No 524/2013 of the European Parliament and of the Council of 21 May 2013 on online dispute resolution for consumer disputes and amending Regulation (EC) No 2006/2004 and Directive 2009/22/EC

    Preamble:

    (1) Article 169(1) and point (a) of Article 169(2) of the Treaty on the Functioning of the European Union (TFEU) provide that the Union is to contribute to the attainment of a high level of consumer protection through measures adopted pursuant to Article 114 TFEU. Article 38 of the Charter of Fundamental Rights of the European Union provides that Union policies are to ensure a high level of consumer protection.

    (2) In accordance with Article 26(2) TFEU, the internal market is to comprise an area without internal frontiers in which the free movement of goods and services is ensured. In order for consumers to have confidence in and benefit from the digital dimension of the internal market, it is necessary that they have access to simple, efficient, fast and low-cost ways of resolving disputes which arise from the sale of goods or the supply of services online. This is particularly important when consumers shop cross-border.‘

    (4) Fragmentation of the internal market impedes efforts to boost competitiveness and growth. Furthermore, the uneven availability, quality and awareness of simple, efficient, fast and low-cost means of resolving disputes arising from the sale of goods or provision of services across the Union constitutes a barrier within the internal market which undermines consumers’ and traders’ confidence in shopping and selling across borders.‘

    (13) The definition of ‘consumer’ should cover natural persons who are acting outside their trade, business, craft or profession. However, if the contract is concluded for purposes partly within and partly outside the person’s trade (dual purpose contracts) and the trade purpose is so limited as not to be predominant in the overall context of the supply, that person should also be considered as a consumer.‘

    (14) The definition of ‘online sales or service contract’ should cover a sales or service contract where the trader, or the trader’s intermediary, has offered goods or services through a website or by other electronic means and the consumer has ordered those goods or services on that website or by other electronic means. This should also cover cases where the consumer has accessed the website or other information society service through a mobile electronic device such as a mobile telephone.

    (26) The right to an effective remedy and the right to a fair trial are fundamental rights laid down in Article 47 of the Charter of Fundamental Rights of the European Union. ODR is not intended to and cannot be designed to replace court procedures, nor should it deprive consumers or traders of their rights to seek redress before the courts. This Regulation should not, therefore, prevent parties from exercising their right of access to the judicial system.

    (35) This Regulation respects fundamental rights and observes the principles recognised in particular by the Charter of Fundamental Rights of the European Union and specifically Articles 7, 8, 38 and 47 thereof.

    Article 1: Subject matter
    The purpose of this Regulation is, through the achievement of a high level of consumer protection, to contribute to the proper functioning of the internal market, and in particular of its digital dimension by providing a European ODR platform (‘ODR platform’) facilitating the independent, impartial, transparent, effective, fast and fair out-of-court resolution of disputes between consumers and traders online.

    Article 12: Processing of personal data

    1. Access to information, including personal data, related to a dispute and stored in the database referred to in Article 11 shall be granted, for the purposes referred to in Article 10, only to the ADR entity to which the dispute was transmitted in accordance with Article 9. Access to the same information shall be granted also to ODR contact points, in so far as it is necessary, for the purposes referred to in Article 7(2) and (4).

    2. The Commission shall have access to information processed in accordance with Article 10 for the purposes of monitoring the use and functioning of the ODR platform and drawing up the reports referred to in Article 21. It shall process personal data of the users of the ODR platform in so far as it is necessary for the operation and maintenance of the ODR platform, including for the purposes of monitoring the use of the ODR platform by ADR entities and ODR contact points.

    3. Personal data related to a dispute shall be kept in the database referred to in paragraph 1 of this Article only for the time necessary to achieve the purposes for which they were collected and to ensure that data subjects are able to access their personal data in order to exercise their rights, and shall be automatically deleted, at the latest, six months after the date of conclusion of the dispute which has been transmitted to the ODR platform in accordance with point (iii) of point (c) of Article 10. That retention period shall also apply to personal data kept in national files by the ADR entity or the ODR contact point which dealt with the dispute concerned, except if the procedural rules applied by the ADR entity or any specific provisions of national law provide for a longer retention period.

    4. Each ODR advisor shall be regarded as a controller with respect to its data processing activities under this Regulation, in accordance with point (d) of Article 2 of Directive 95/46/EC, and shall ensure that those activities comply with national legislation adopted pursuant to Directive 95/46/EC in the Member State of the ODR contact point hosting the ODR advisor.

    5. Each ADR entity shall be regarded as a controller with respect to its data processing activities under this Regulation, in accordance with point (d) of Article 2 of Directive 95/46/EC, and shall ensure that those activities comply with national legislation adopted pursuant to Directive 95/46/EC in the Member State where the ADR entity is established.

    6. In relation to its responsibilities under this Regulation and the processing of personal data involved therein, the Commission shall be regarded as a controller in accordance with point (d) of Article 2 of Regulation (EC) No 45/2001.

    Article 13: Data confidentiality and security

    1. ODR contact points shall be subject to rules of professional secrecy or other equivalent duties of confidentiality laid down in the legislation of the Member State concerned.

    2. The Commission shall take the appropriate technical and organisational measures to ensure the security of information processed under this Regulation, including appropriate data access control, a security plan and a security incident management, in accordance with Article 22 of Regulation (EC) No 45/2001.

    Article 14: Consumer information

    1. Traders established within the Union engaging in online sales or service contracts, and online marketplaces established within the Union, shall provide on their websites an electronic link to the ODR platform. That link shall be easily accessible for consumers. Traders established within the Union engaging in online sales or service contracts shall also state their e-mail addresses.

    2. Traders established within the Union engaging in online sales or service contracts, which are committed or obliged to use one or more ADR entities to resolve disputes with consumers, shall inform consumers about the existence of the ODR platform and the possibility of using the ODR platform for resolving their disputes. They shall provide an electronic link to the ODR platform on their websites and, if the offer is made by e-mail, in that e-mail. The information shall also be provided, where applicable, in the general terms and conditions applicable to online sales and service contracts.

    3. Paragraphs 1 and 2 of this Article shall be without prejudice to Article 13 of Directive 2013/11/EU and the provisions on consumer information on out-of-court redress procedures contained in other Union legal acts, which shall apply in addition to this Article.

    4. The list of ADR entities referred to in Article 20(4) of Directive 2013/11/EU and its updates shall be published in the ODR platform.

    5. Member States shall ensure that ADR entities, the centres of the European Consumer Centres Network, the competent authorities defined in Article 18(1) of Directive 2013/11/EU, and, where appropriate, the bodies designated in accordance with Article 14(2) of Directive 2013/11/EU provide an electronic link to the ODR platform.

    6. Member States shall encourage consumer associations and business associations to provide an electronic link to the ODR platform.

    7. When traders are obliged to provide information in accordance with paragraphs 1 and 2 and with the provisions referred to in paragraph 3, they shall, where possible, provide that information together.

  • Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union

    Article 2 - Processing of personal data
    ‘1. Processing of personal data pursuant to this Directive shall be carried out in accordance with Directive 95/46/EC.
    2. Processing of personal data by Union institutions and bodies pursuant to this Directive shall be carried out in accordance with Regulation (EC) No 45/2001.‘

  • Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detec...

    Article 1 - Subject-matter and objectives
    ‘1. This Directive lays down the rules relating to the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.
    2. In accordance with this Directive, Member States shall:
    (a) protect the fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data‘
    Article 4
    ‘Principles relating to processing of personal data
    1. Member States shall provide for personal data to be:
    (a) processed lawfully and fairly;
    (b) collected for specified, explicit and legitimate purposes and not processed in a manner that is incompatible with those purposes;
    (c) adequate, relevant and not excessive in relation to the purposes for which they are processed;
    (d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
    (e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed;
    (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
    2. Processing by the same or another controller for any of the purposes set out in Article 1(1) other than that for which the personal data are collected shall be permitted in so far as:
    (a) the controller is authorised to process such personal data for such a purpose in accordance with Union or Member State law; and
    (b) processing is necessary and proportionate to that other purpose in accordance with Union or Member State law.
    3. Processing by the same or another controller may include archiving in the public interest, scientific, statistical or historical use, for the purposes set out in Article 1(1), subject to appropriate safeguards for the rights and freedoms of data subjects.
    4. The controller shall be responsible for, and be able to demonstrate compliance with, paragraphs 1, 2 and 3.‘

    Article 57. Penalties:
    Member States shall lay down the rules on penalties applicable to infringements of the provisions adopted pursuant to this Directive and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive.

  • Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime

    Article 13 - Protection of personal data
    ‘1. Each Member State shall provide that, in respect of all processing of personal data pursuant to this Directive, every passenger shall have the same right to protection of their personal data, rights of access, rectification, erasure and restriction and rights to compensation and judicial redress as laid down in Union and national law and in implementation of Articles 17, 18, 19 and 20 of Framework Decision 2008/977/JHA. Those Articles shall therefore apply.‘

  • Directive 2013/40/EU of the European Parliament and of the Council of 12 August 2013 on attacks against information systems and replacing Council Framework Decision 2005/222/JHA

    Preamble
    (30) The protection of personal data is a fundamental right in accordance with Article 16(1) TFEU and Article 8 of the Charter on Fundamental Rights of the European Union. Therefore, any processing of personal data in the context of the implementation of this Directive should fully comply with the relevant Union law on data protection

    Article 5 - Illegal data interference
    ‘Member States shall take the necessary measures to ensure that deleting, damaging, deteriorating, altering or suppressing computer data on an information system, or rendering such data inaccessible, intentionally and without right, is punishable as a criminal offence, at least for cases which are not minor.‘

    Article 6 - Illegal interception
    ‘Member States shall take the necessary measures to ensure that intercepting, by technical means, non-public transmissions of computer data to, from or within an information system, including electromagnetic emissions from an information system carrying such computer data, intentionally and without right, is punishable as a criminal offence, at least for cases which are not minor.‘

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General...

    Article 1 - Subject-matter and objectives
    ‘1. This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data.
    2. This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.
    3. The free movement of personal data within the Union shall be neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data.‘

  • Regulation (EU) 2016/794 of the European Parliament and of the Council of 11 May 2016 on the European Union Agency for Law Enforcement Cooperation (Europol) and replacing and repealing Council Decisions 2009/371/JHA, 2009/934/JHA, 2009/935/JHA, 2009/93...

    Article 28 - General data protection principles
    ‘1. Personal data shall be:
    (a) processed fairly and lawfully;
    (b) collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes. Further processing of personal data for historical, statistical or scientific research purposes shall not be considered incompatible provided that Europol provides appropriate safeguards, in particular to ensure that data are not processed for any other purposes;
    (c) adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed;
    (d) accurate and kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
    (e) kept in a form which permits identification of data subjects for no longer than necessary for the purposes for which the personal data are processed; and
    (f) processed in a manner that ensures appropriate security of personal data.‘
    Article 31 - Time-limits for the storage and erasure of personal data
    ‘1. Personal data processed by Europol shall be stored by Europol only for as long as is necessary and proportionate for the purposes for which the data are processed.‘
    Article 36 - Right of access for the data subject
    ‘1. Any data subject shall have the right, at reasonable intervals, to obtain information on whether personal data relating to him or her are processed by Europol.‘

International ret

3 results found

  • European Convention on Human Rights - Article 8

    Article 8 – Right to respect for private and family life

    1. Everyone has the right to respect for his private and family life, his home and his correspondence.

    2. There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others.

  • Council of Europe, Guidelines on the protection of individuals with regard to the processing of personal data in a world of big data

    ‘The present Guidelines recommend measures that Parties, controllers and processors should take to prevent the potential negative impact of the use of Big Data on human dignity, human rights, and fundamental individual and collective freedoms, in particular with regard to personal data protection.
    Given the nature of Big Data and its uses, the application of some of the traditional principles of data processing (e.g. the principle of data minimisation, purpose limitation, fairness and transparency, and free, specific and informed consent) may be challenging in this technological scenario. These Guidelines therefore suggest a specific application of the principles of Convention 108, to make them more effective in practice in the Big Data context.‘

  • OECD, Guidelines governing the Protection of Privacy and Transborder Flows of Personal Data

    ‘2. These Guidelines apply to personal data, whether in the public or private sectors, which, because of the manner in which they are processed, or because of their nature or the context in which they are used, pose a risk to privacy and individual liberties.‘
    ‘3. The principles in these Guidelines are complementary and should be read as a whole. They should not be interpreted:
    a) as preventing the application of different protective measures to different categories of personal data, depending upon their nature and the context in which they are collected, stored, processed or disseminated; or
    b) in a manner which unduly limits the freedom of expression‘
    ‘7. There should be limits to the collection of personal data and any such data should be obtained by lawful and fair means and, where appropriate, with the knowledge or consent of the data subject.‘
    ‘9. The purposes for which personal data are collected should be specified not later than at the time of data collection and the subsequent use limited to the fulfilment of those purposes or such others as are not incompatible with those purposes and as are specified on each occasion of change of purpose.‘

Produkter