eu-charter

Handvest van de grondrechten van de Europese Unie

Artikel 8 - De bescherming van persoonsgegevens

Artikel 8 - De bescherming van persoonsgegevens

1. Eenieder heeft recht op bescherming van zijn persoonsgegevens.

2. Deze gegevens moeten eerlijk worden verwerkt, voor bepaalde doeleinden en met toestemming van de betrokkene of op basis van een andere gerechtvaardigde grondslag waarin de wet voorziet. Eenieder heeft recht van inzage in de over hem verzamelde gegevens en op rectificatie daarvan.

3. Een onafhankelijke autoriteit ziet erop toe dat deze regels worden nageleefd.

Toelichtingen

  • Text:

    Dit artikel was gebaseerd op artikel 286 van het Verdrag tot oprichting van de Europese Gemeenschap en op Richtlijn 95/46/EG van het Europees Parlement en de Raad betreffende de bescherming van natuurlijke personen in verband met de verwerking van persoonsgegevens en betreffende het vrije verkeer van die gegevens (PB L 281 van 23.11.1995, blz. 31), alsmede op artikel 8 van het EVRM en op het Verdrag van de Raad van Europa van 28 januari 1981 tot bescherming van personen met betrekking tot de geautomatiseerde verwerking van persoonsgegevens, dat door alle lidstaten is bekrachtigd. Artikel 286 van het EG-Verdrag is nu vervangen door artikel 16 van het Verdrag betreffende de werking van de Europese Unie en artikel 39 van het Verdrag betreffende de Europese Unie. Voorts wordt verwezen naar Verordening (EG) nr. 45/2001 van het Europees Parlement en de Raad betreffende de bescherming van natuurlijke personen in verband met de verwerking van persoonsgegevens door de communautaire instellingen en organen en betreffende het vrije verkeer van die gegevens (PB L 8 van 12.1.2001, blz. 1). Bovengenoemde richtlijn en verordening bevatten voorwaarden en beperkingen voor de uitoefening van het recht op bescherming van persoonsgegevens.

    Source:
    Publicatieblad van de Europese Unie C 303/17 - 14.12.2007
    Preamble - Explanations relating to the Charter of Fundamental Rights:
    Deze toelichtingen werden oorspronkelijk opgesteld onder de verantwoordelijkheid van het praesidium van de Conventie die het Handvest van de grondrechten van de Europese Unie heeft opgesteld. Zij zijn bijgewerkt onder de verantwoordelijkheid van het praesidium van de Europese Conventie, in het licht van de wijzigingen die door laatstgenoemde Conventie in het Handvest zijn aangebracht (met name in artikel 51 en 52) en van verdere ontwikkelingen in het recht van de Unie. Hoewel zij op zich geen juridische waarde hebben, vormen zij een waardevol hulpmiddel voor de interpretatie, bedoeld om de bepalingen van het Handvest te verduidelijken.

Jurisprudentie

Nationaal constitutioneel recht

68 results found

  • Netherlands / Constitution of the Kingdom of the Netherlands
    Land:
    Netherlands

    Article 10 (...) 2. Rules to protect privacy shall be laid down by Act of Parliament in connection with the recording and dissemination of personal data. 3. Rules concerning the rights of persons to be informed of data recorded concerning them and of the use that is made thereof, and to have such data corrected shall be laid down by Act of Parliament.

  • Organic Law 15/1999 of 13 December on the Protection of Personal Data
    Land:
    Spain

    Article 1This Organic Law is intended to guarantee and protect the public liberties and fundamental rights of natural persons, and in particular their personal and family privacy, with regard to the processing of personal data

  • Personal Data Act (1998:204)
    Land:
    Sweden

    Article 1 The purpose of this Act is to protect people against the violation of their personal integrity by processing of personal data.

  • Personal Data Act (523/1999)
    Land:
    Finland

    Section 1The objectives of this Act are to implement, in the processing of personal data, the protection of private life and the other basic rights which safeguard the right to privacy, as well as to promote the development of and compliance with good processing practice.

  • Personal Data Protection Act 
    Land:
    Estonia

    § 1. Scope of application and purpose of Act.
    (1) The aim of this Act is to protect the fundamental rights and freedoms of natural persons upon processing of personal data, above all the right to inviolability of private life. (…)

  • Personal Data Protection Act 2001
    Land:
    Bulgaria

    Art. 1. (1) This Law shall govern the protection of rights of individuals with regard to the processing of their personal data.(2) The purpose of this law is to guarantee the inviolability of personality and privacy by ensuring protection of individuals in case of unauthorised personal data processing referred to them, in the process of free movement of data. (3) (new - SG 91/06) This Law shall apply to personal data processing:1. by automatic means; 2. by non-automatic means, where such data are, or are designed to become, part of a register.(...)

  • Personal Data Protection Act 2007
    Land:
    Slovenia
  • Personal Data Protection Law
    Land:
    Latvia

    Section 1. The purpose of this Law is to protect the fundamental human rights and freedoms of natural persons, in particular the inviolability of private life, regarding the processing of natural person data.

  • Personuppgiftslag (1998:204)
    Land:
    Sweden

    1 § Syftet med denna lag är att skydda människor mot att deras personliga integritet kränks genom behandling av personuppgifter.

  • Portugal / Constitution of the Portuguese Republic
    Land:
    Portugal

    Article 35 (Use of information technology) (1) All citizens have the right of access to any computerised data relating to them and the right to be informed of the use for which the data is intended, under the law; they are entitled to require that the contents of the files and records be corrected and brought up to date.(2) The law shall determine what is personal data as well as the conditions applicable to automatic processing, connection, transmission and use thereof, and shall guarantee its protection by means of an independent administrative body. (3) Computerised storage shall not be used for information concerning a person's ideological or political convictions, party or trade union affiliations, religious beliefs, private life or ethnic origin, except where there is express consent from the data subject, authorisation provided for under the law with guarantees of non-discrimination or, in the case of data, for statistical purposes, that does not identify individuals. (4) Access to personal data of third parties is prohibited, except in exceptional cases as prescribed by law. (5) Citizens shall not be given an all-purpose national identity number. (6) Everyone shall be guaranteed free access to public information networks and the law shall define the regulations applicable to the transnational data flows and the adequate norms of protection for personal data and for data that should be safeguarded in the national interest. (7) Personal data kept on manual files shall benefit from protection identical to that provided for in the above Articles, in accordance with the law.  

  • Sammenskrevet udgave af persondataloven
    Land:
    Denmark

    Lovens område § 1. Loven gælder for behandling af personoplysninger, som helt eller delvis foretages ved hjælp af elektronisk databehandling, og for ikke-elektronisk behandling af personoplysninger, der er eller vil blive indeholdt i et register. Stk. 2. Loven gælder tillige for anden ikke-elektronisk systematisk behandling, som udføres for private, og som omfatter oplysninger om personers private eller økonomiske forhold eller i øvrigt oplysninger om personlige forhold, som med rimelighed kan forlanges unddraget offentligheden. Dette gælder dog ikke reglerne i lovens kapitel 8 og 9. Stk. 3. Lovens § 5, stk. 1-3, §§ 6-8, § 10, § 11, stk. 1, § 38 og § 40 gælder også for manuel videregivelse af personoplysninger til en anden forvaltningsmyndighed. Datatilsynet fører i overensstemmelse med lovens kapitel 16 tilsyn med videregivelse som nævnt i 1. pkt. Stk. 4. Loven gælder endvidere for behandling af oplysninger om virksomheder m.v., jf. stk. 1 og 2, hvis denne behandling udføres for kreditoplysningsbureauer. Tilsvarende gælder for så vidt angår behandlinger, som er omfattet af § 50, stk. 1, nr. 2. Stk. 5. Kapitel 5 gælder også for behandling af oplysninger om virksomheder m.v. , jf. stk. 1. Stk. 6. Uden for de i stk. 4 nævnte tilfælde kan justitsministeren bestemme, at lovens regler helt eller delvis skal finde anvendelse på behandling af oplysninger om virksomheder m.v., som udføres for private. Stk. 7. Uden for de i stk. 5 nævnte tilfælde kan vedkommende minister bestemme, at lovens regler helt eller delvis skal finde anvendelse på behandling af oplysninger om virksomheder m.v., som udføres for den offentlige forvaltning.

  • Slovakia / Constitution of the Slovak Republic
    Land:
    Slovakia

    Article 19 (...) (3) Everyone has the right to protection against unauthorized collection, publication, or other misuse of personal data.

  • Slovenia / Constitution of the Republic of Slovenia
    Land:
    Slovenia

    Article 38 The protection of personal data shall be guaranteed. The use of personal data contrary to the purpose for which it was collected is prohibited. The collection, processing, designated use, supervision and protection of the confidentiality of personal data shall be provided by law. Everyone has the right of access to the collected personal data that relates to him and the right to judicial protection in the event of any abuse of such data.

  • Spain / Constitution of the Kingdom of Spain
    Land:
    Spain

    Article 18(...) 4. The law shall restrict the use of data processing in order to guarantee the honour and personal and family privacy of citizens and the full exercise of their rights.

  • Suomen perustuslaki
    Land:
    Finland

    10 § Yksityiselämän suoja Jokaisen yksityiselämä, kunnia ja kotirauha on turvattu. Henkilötietojen suojasta säädetään tarkemmin lailla. (...) 

  • The Act on Processing of Personal
    Land:
    Denmark

    Scope of the Act 1. - (1) This Act shall apply to the processing of personal data wholly or partly by automatic means, and to the processing otherwise than by automatic means of personal data which form part of a filing system or are intended to form part of a filing system. (2) This Act shall further apply to other non-automatic systematic processing of data which is performed for private persons or bodies and which includes data on individual persons' private or financial matters or other data on personal matters which can reasonably be claimed to be withheld from the public. However, this shall not apply to Chapters 8 and 9 of this Act. (3) This Act shall further apply to the processing of data concerning companies, etc., cf. subsections (1) and (2), if the processing is carried out for credit information agencies. The same shall apply in the case of processing of data covered by section 50 (1) 2. (4) Chapter 5 of the Act shall also apply to the processing of data concerning companies, etc., cf. subsection (1). (5) In other cases than those mentioned in subsection (3), the Minister of Justice may decide that the provisions of this Act shall apply, in full or in part, to the processing of data concerning companies, etc. which is performed for private persons or bodies. (6) In other cases than those mentioned in subsection(4), the competent Minister may decide that the provisions of this Act shall apply, in full or in part, to the processing of data concerning companies, etc., which is performed on behalf of public administrations. (7) This Act shall apply to any processing of personal data in connection with video surveillance. (...)

  • The Federal Act Concerning the Protection of Personal Data
    Land:
    Austria

    Sect. 1.(1) Everybody shall have the right to secrecy for the personal data concerning him, especially with regard to his private and family life, insofar as he has an interest deserving such protection. Such an interest is precluded when data cannot be subject to the right to secrecy due to their general availability or because they cannot be traced back to the data subject [Betroffener]. (2) Insofar personal data is not used in the vital interest of the data subject or with his consent, restrictions to the right to secrecy are only permitted to safeguard overriding legitimate interests of another, namely in case of an intervention by a public authority the restriction shall only be permitted based on laws [footnote 1] necessary for the reasons stated in Art. 8, para. 2 of the European Convention on Human Rights (Federal Law Gazette No. 210/1958). Such laws may provide for the use of data [Verwendung von Daten] that deserve special protection only in order to safeguard substantial public interests and shall provide suitable safeguards for the protection of the data subjects' interest in secrecy. Even in the case of permitted restrictions the intervention with the fundamental right shall be carried out using only the least intrusive of all effective methods. (3) Everybody shall have, insofar as personal data concerning him are destined for automated processing or manual processing, i.e. in filing systems [Dateien] without automated processing, as provided for by law, 1.the right to obtain information as to who processes what data concerning him, where the data originated, for which purpose they are used, as well as to whom the data are transmitted; 2.the right to rectification of incorrect data and the right to erasure of illegally processed data. (4) Restrictions of the rights according to para. 3 are only permitted under the conditions laid out in para. 2. (5) The fundamental right to data protection, except the right to information [Auskunftsrecht], shall be asserted before the civil courts against organisations that are established according to private law, as long as they do not act in execution of laws. In all other cases the Data Protection Commission [Datenschutzkommission] shall be competent to render the decision, unless an act of Parliament or a judicial decision is concerned.

  • The Fundamental Law of Hungary
    Land:
    Hungary

    Article VI (Freedom and Responsibility) [...] (2) Everyone shall have the right to the protection of his or her personal data, as well as to access
    and disseminate data of public interest.
    (3) The application of the right to the protection of personal data and to access data of public
    interest shall be supervised by an independent authority established by a cardinal Act.

  • The Processing of Personal Data (Protection of the Individual) Law
    Land:
    Cyprus

    Scope of the law 3.(1) The provisions of this Law shall apply to the processing of personal data wholly or partly by automatic means, and to the processing otherwise than by automatic means of personal data which form part of a filing system or are intended to form part of a filing system.(…)

  • The Protection of Personal Data Act
    Land:
    Czechia

EU-recht

37 results found

  • Regulation (EU) No 524/2013 of the European Parliament and of the Council of 21 May 2013 on online dispute resolution for consumer disputes and amending Regulation (EC) No 2006/2004 and Directive 2009/22/EC

    Preamble:

    (1) Article 169(1) and point (a) of Article 169(2) of the Treaty on the Functioning of the European Union (TFEU) provide that the Union is to contribute to the attainment of a high level of consumer protection through measures adopted pursuant to Article 114 TFEU. Article 38 of the Charter of Fundamental Rights of the European Union provides that Union policies are to ensure a high level of consumer protection.

    (2) In accordance with Article 26(2) TFEU, the internal market is to comprise an area without internal frontiers in which the free movement of goods and services is ensured. In order for consumers to have confidence in and benefit from the digital dimension of the internal market, it is necessary that they have access to simple, efficient, fast and low-cost ways of resolving disputes which arise from the sale of goods or the supply of services online. This is particularly important when consumers shop cross-border.‘

    (4) Fragmentation of the internal market impedes efforts to boost competitiveness and growth. Furthermore, the uneven availability, quality and awareness of simple, efficient, fast and low-cost means of resolving disputes arising from the sale of goods or provision of services across the Union constitutes a barrier within the internal market which undermines consumers’ and traders’ confidence in shopping and selling across borders.‘

    (13) The definition of ‘consumer’ should cover natural persons who are acting outside their trade, business, craft or profession. However, if the contract is concluded for purposes partly within and partly outside the person’s trade (dual purpose contracts) and the trade purpose is so limited as not to be predominant in the overall context of the supply, that person should also be considered as a consumer.‘

    (14) The definition of ‘online sales or service contract’ should cover a sales or service contract where the trader, or the trader’s intermediary, has offered goods or services through a website or by other electronic means and the consumer has ordered those goods or services on that website or by other electronic means. This should also cover cases where the consumer has accessed the website or other information society service through a mobile electronic device such as a mobile telephone.

    (26) The right to an effective remedy and the right to a fair trial are fundamental rights laid down in Article 47 of the Charter of Fundamental Rights of the European Union. ODR is not intended to and cannot be designed to replace court procedures, nor should it deprive consumers or traders of their rights to seek redress before the courts. This Regulation should not, therefore, prevent parties from exercising their right of access to the judicial system.

    (35) This Regulation respects fundamental rights and observes the principles recognised in particular by the Charter of Fundamental Rights of the European Union and specifically Articles 7, 8, 38 and 47 thereof.

    Article 1: Subject matter
    The purpose of this Regulation is, through the achievement of a high level of consumer protection, to contribute to the proper functioning of the internal market, and in particular of its digital dimension by providing a European ODR platform (‘ODR platform’) facilitating the independent, impartial, transparent, effective, fast and fair out-of-court resolution of disputes between consumers and traders online.

    Article 12: Processing of personal data

    1. Access to information, including personal data, related to a dispute and stored in the database referred to in Article 11 shall be granted, for the purposes referred to in Article 10, only to the ADR entity to which the dispute was transmitted in accordance with Article 9. Access to the same information shall be granted also to ODR contact points, in so far as it is necessary, for the purposes referred to in Article 7(2) and (4).

    2. The Commission shall have access to information processed in accordance with Article 10 for the purposes of monitoring the use and functioning of the ODR platform and drawing up the reports referred to in Article 21. It shall process personal data of the users of the ODR platform in so far as it is necessary for the operation and maintenance of the ODR platform, including for the purposes of monitoring the use of the ODR platform by ADR entities and ODR contact points.

    3. Personal data related to a dispute shall be kept in the database referred to in paragraph 1 of this Article only for the time necessary to achieve the purposes for which they were collected and to ensure that data subjects are able to access their personal data in order to exercise their rights, and shall be automatically deleted, at the latest, six months after the date of conclusion of the dispute which has been transmitted to the ODR platform in accordance with point (iii) of point (c) of Article 10. That retention period shall also apply to personal data kept in national files by the ADR entity or the ODR contact point which dealt with the dispute concerned, except if the procedural rules applied by the ADR entity or any specific provisions of national law provide for a longer retention period.

    4. Each ODR advisor shall be regarded as a controller with respect to its data processing activities under this Regulation, in accordance with point (d) of Article 2 of Directive 95/46/EC, and shall ensure that those activities comply with national legislation adopted pursuant to Directive 95/46/EC in the Member State of the ODR contact point hosting the ODR advisor.

    5. Each ADR entity shall be regarded as a controller with respect to its data processing activities under this Regulation, in accordance with point (d) of Article 2 of Directive 95/46/EC, and shall ensure that those activities comply with national legislation adopted pursuant to Directive 95/46/EC in the Member State where the ADR entity is established.

    6. In relation to its responsibilities under this Regulation and the processing of personal data involved therein, the Commission shall be regarded as a controller in accordance with point (d) of Article 2 of Regulation (EC) No 45/2001.

    Article 13: Data confidentiality and security

    1. ODR contact points shall be subject to rules of professional secrecy or other equivalent duties of confidentiality laid down in the legislation of the Member State concerned.

    2. The Commission shall take the appropriate technical and organisational measures to ensure the security of information processed under this Regulation, including appropriate data access control, a security plan and a security incident management, in accordance with Article 22 of Regulation (EC) No 45/2001.

    Article 14: Consumer information

    1. Traders established within the Union engaging in online sales or service contracts, and online marketplaces established within the Union, shall provide on their websites an electronic link to the ODR platform. That link shall be easily accessible for consumers. Traders established within the Union engaging in online sales or service contracts shall also state their e-mail addresses.

    2. Traders established within the Union engaging in online sales or service contracts, which are committed or obliged to use one or more ADR entities to resolve disputes with consumers, shall inform consumers about the existence of the ODR platform and the possibility of using the ODR platform for resolving their disputes. They shall provide an electronic link to the ODR platform on their websites and, if the offer is made by e-mail, in that e-mail. The information shall also be provided, where applicable, in the general terms and conditions applicable to online sales and service contracts.

    3. Paragraphs 1 and 2 of this Article shall be without prejudice to Article 13 of Directive 2013/11/EU and the provisions on consumer information on out-of-court redress procedures contained in other Union legal acts, which shall apply in addition to this Article.

    4. The list of ADR entities referred to in Article 20(4) of Directive 2013/11/EU and its updates shall be published in the ODR platform.

    5. Member States shall ensure that ADR entities, the centres of the European Consumer Centres Network, the competent authorities defined in Article 18(1) of Directive 2013/11/EU, and, where appropriate, the bodies designated in accordance with Article 14(2) of Directive 2013/11/EU provide an electronic link to the ODR platform.

    6. Member States shall encourage consumer associations and business associations to provide an electronic link to the ODR platform.

    7. When traders are obliged to provide information in accordance with paragraphs 1 and 2 and with the provisions referred to in paragraph 3, they shall, where possible, provide that information together.

  • Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union

    Article 2 - Processing of personal data
    ‘1. Processing of personal data pursuant to this Directive shall be carried out in accordance with Directive 95/46/EC.
    2. Processing of personal data by Union institutions and bodies pursuant to this Directive shall be carried out in accordance with Regulation (EC) No 45/2001.‘

  • Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detec...

    Article 1 - Subject-matter and objectives
    ‘1. This Directive lays down the rules relating to the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.
    2. In accordance with this Directive, Member States shall:
    (a) protect the fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data‘
    Article 4
    ‘Principles relating to processing of personal data
    1. Member States shall provide for personal data to be:
    (a) processed lawfully and fairly;
    (b) collected for specified, explicit and legitimate purposes and not processed in a manner that is incompatible with those purposes;
    (c) adequate, relevant and not excessive in relation to the purposes for which they are processed;
    (d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
    (e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed;
    (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
    2. Processing by the same or another controller for any of the purposes set out in Article 1(1) other than that for which the personal data are collected shall be permitted in so far as:
    (a) the controller is authorised to process such personal data for such a purpose in accordance with Union or Member State law; and
    (b) processing is necessary and proportionate to that other purpose in accordance with Union or Member State law.
    3. Processing by the same or another controller may include archiving in the public interest, scientific, statistical or historical use, for the purposes set out in Article 1(1), subject to appropriate safeguards for the rights and freedoms of data subjects.
    4. The controller shall be responsible for, and be able to demonstrate compliance with, paragraphs 1, 2 and 3.‘

    Article 57. Penalties:
    Member States shall lay down the rules on penalties applicable to infringements of the provisions adopted pursuant to this Directive and shall take all measures necessary to ensure that they are implemented. The penalties provided for shall be effective, proportionate and dissuasive.

  • Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime

    Article 13 - Protection of personal data
    ‘1. Each Member State shall provide that, in respect of all processing of personal data pursuant to this Directive, every passenger shall have the same right to protection of their personal data, rights of access, rectification, erasure and restriction and rights to compensation and judicial redress as laid down in Union and national law and in implementation of Articles 17, 18, 19 and 20 of Framework Decision 2008/977/JHA. Those Articles shall therefore apply.‘

  • Directive 2013/40/EU of the European Parliament and of the Council of 12 August 2013 on attacks against information systems and replacing Council Framework Decision 2005/222/JHA

    Preamble
    (30) The protection of personal data is a fundamental right in accordance with Article 16(1) TFEU and Article 8 of the Charter on Fundamental Rights of the European Union. Therefore, any processing of personal data in the context of the implementation of this Directive should fully comply with the relevant Union law on data protection

    Article 5 - Illegal data interference
    ‘Member States shall take the necessary measures to ensure that deleting, damaging, deteriorating, altering or suppressing computer data on an information system, or rendering such data inaccessible, intentionally and without right, is punishable as a criminal offence, at least for cases which are not minor.‘

    Article 6 - Illegal interception
    ‘Member States shall take the necessary measures to ensure that intercepting, by technical means, non-public transmissions of computer data to, from or within an information system, including electromagnetic emissions from an information system carrying such computer data, intentionally and without right, is punishable as a criminal offence, at least for cases which are not minor.‘

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General...

    Article 1 - Subject-matter and objectives
    ‘1. This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data.
    2. This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.
    3. The free movement of personal data within the Union shall be neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data.‘

  • Regulation (EU) 2016/794 of the European Parliament and of the Council of 11 May 2016 on the European Union Agency for Law Enforcement Cooperation (Europol) and replacing and repealing Council Decisions 2009/371/JHA, 2009/934/JHA, 2009/935/JHA, 2009/93...

    Article 28 - General data protection principles
    ‘1. Personal data shall be:
    (a) processed fairly and lawfully;
    (b) collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes. Further processing of personal data for historical, statistical or scientific research purposes shall not be considered incompatible provided that Europol provides appropriate safeguards, in particular to ensure that data are not processed for any other purposes;
    (c) adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed;
    (d) accurate and kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;
    (e) kept in a form which permits identification of data subjects for no longer than necessary for the purposes for which the personal data are processed; and
    (f) processed in a manner that ensures appropriate security of personal data.‘
    Article 31 - Time-limits for the storage and erasure of personal data
    ‘1. Personal data processed by Europol shall be stored by Europol only for as long as is necessary and proportionate for the purposes for which the data are processed.‘
    Article 36 - Right of access for the data subject
    ‘1. Any data subject shall have the right, at reasonable intervals, to obtain information on whether personal data relating to him or her are processed by Europol.‘

Internationaal recht

3 results found

  • European Convention on Human Rights - Article 8

    Article 8 – Right to respect for private and family life

    1. Everyone has the right to respect for his private and family life, his home and his correspondence.

    2. There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others.

  • Council of Europe, Guidelines on the protection of individuals with regard to the processing of personal data in a world of big data

    ‘The present Guidelines recommend measures that Parties, controllers and processors should take to prevent the potential negative impact of the use of Big Data on human dignity, human rights, and fundamental individual and collective freedoms, in particular with regard to personal data protection.
    Given the nature of Big Data and its uses, the application of some of the traditional principles of data processing (e.g. the principle of data minimisation, purpose limitation, fairness and transparency, and free, specific and informed consent) may be challenging in this technological scenario. These Guidelines therefore suggest a specific application of the principles of Convention 108, to make them more effective in practice in the Big Data context.‘

  • OECD, Guidelines governing the Protection of Privacy and Transborder Flows of Personal Data

    ‘2. These Guidelines apply to personal data, whether in the public or private sectors, which, because of the manner in which they are processed, or because of their nature or the context in which they are used, pose a risk to privacy and individual liberties.‘
    ‘3. The principles in these Guidelines are complementary and should be read as a whole. They should not be interpreted:
    a) as preventing the application of different protective measures to different categories of personal data, depending upon their nature and the context in which they are collected, stored, processed or disseminated; or
    b) in a manner which unduly limits the freedom of expression‘
    ‘7. There should be limits to the collection of personal data and any such data should be obtained by lawful and fair means and, where appropriate, with the knowledge or consent of the data subject.‘
    ‘9. The purposes for which personal data are collected should be specified not later than at the time of data collection and the subsequent use limited to the fulfilment of those purposes or such others as are not incompatible with those purposes and as are specified on each occasion of change of purpose.‘

Producten

  • Handbook / Guide / Manual
    19
    August
    2022
    Het Handvest van de grondrechten van de Europese Unie is de bill of rights van de EU. Voor de EU-instellingen en lidstaten is het Handvest altijd bindend wanneer zij binnen de werkingssfeer van het Unierecht handelen. De beoordeling of een concreet geval binnen de werkingssfeer van het Unierecht valt, is echter verre van eenvoudig. Daarom is het nodig beoefenaars van juridische beroepen opleidingen en opleidingsmateriaal aan te bieden over het toepassingsgebied van het Handvest, zoals omschreven in artikel 51 daarvan. In het handboek wordt gebruikgemaakt van een reeks casestudy’s, die in de toekomst verder zullen worden uitgebreid.
  • Handbook / Guide / Manual
    25
    May
    2018
    New language version - Estonian
    04 November 2020
    De snelle ontwikkeling van de informatietechnologie heeft de noodzaak voor een degelijke bescherming
    van persoonsgegevens weer versterkt, het recht dat wordt gewaarborgd door zowel de Europese Unie
    (EU) als de Raad van Europa (RvE). De bescherming van dit belangrijke recht brengt nieuwe en belangrijke
    uitdagingen met zich mee, aangezien technologische ontwikkelingen de grenzen van domeinen zoals
    toezicht, onderschepping van communicatie en gegevensopslag, verlegt. Deze handleiding is bedoeld voor
    beoefenaars van juridische beroepen die niet gespecialiseerd zijn in gegevensbescherming, om vertrouwd
    te raken met dit opkomende domein van de wet.
  • Fundamental Rights Report
    8
    June
    2022
    Het jaar 2021 kende zowel vooruitgang als tegenslagen bij de bescherming van de grondrechten. Het Verslag over de grondrechten 2022 van FRA evalueert de belangrijkste ontwikkelingen op het gebied van de grondrechten, waarbij niet alleen wordt ingegaan op de successen die zijn behaald, maar ook wordt gewezen op de resterende punten van zorg. Deze publicatie zet de adviezen van FRA op een rij over de belangrijkste ontwikkelingen binnen deze thematische gebieden en geeft in het kort de feitelijke gegevens weer waarop deze adviezen berusten.
  • Leaflet / Flyer
    16
    January
    2020
    Deze folder is bedoeld om ambtenaren en autoriteiten te helpen om asielzoekers en migranten op een begrijpelijke manier uit te leggen hoe hun vingerafdrukken in Eurodac worden verwerkt.
  • Report / Paper / Summary
    21
    January
    2021
    German language version now available
    26 January 2021
    Nationale mensenrechteninstituten (National Human Rights Institutions — NHRI’s) maken een wezenlijk onderdeel uit van het nationale systeem ter bescherming van de mensenrechten. Zij vervullen een centrale rol in de aanpak van de grote uitdagingen van onze tijd op het gebied van de mensenrechten — aanhoudende zorgen, zoals discriminatie en ongelijkheid, en nieuwe problemen, zoals de gevolgen van kunstmatige intelligentie en de COVID-19-pandemie voor de mensenrechten — door het bewustzijn van mensenrechten te vergroten, advies aan te reiken, een monitoringfunctie te vervullen en instanties op hun verantwoordelijkheid te wijzen.
  • Handbook / Guide / Manual
    11
    March
    2021
    In deze gids wordt uitgelegd wat profilering is, welke wettelijke kaders van toepassing zijn en waarom een rechtmatige toepassing van profilering niet alleen nodig is om aan de grondrechten te voldoen, maar ook van cruciaal belang is voor een doeltreffende ordehandhaving en grensbeheer.
  • Report / Paper / Summary
    3
    September
    2020
    Summary version now available
    21 January 2021
    National Human Rights Institutions (NHRIs) are a vital part of the country-level human rights protection system. This report, published 10 years after FRA’s first in-depth study on NHRIs, looks at such bodies in the EU, as well as the Republic of North Macedonia, the Republic of Serbia, and the United Kingdom of Great Britain and Northern Ireland. It explores relevant developments, challenges to their effectiveness and ways to maximise their impact.
  • Fundamental Rights Report
    11
    June
    2026
    The Fundamental Rights Report: Challenges and Achievements in 2025 is FRA’s flagship annual publication. It provides an overview of the state of fundamental rights in the EU and highlights selected critical developments from 2025. This year, it focuses on four areas: rights protection in a rapidly changing digital environment; the housing crisis and rising homelessness rates; employment challenges for people from non-EU countries; and the implementation of the EU Charter of Fundamental Rights. The publication is a valuable resource for those seeking to stay informed about the EU’s shifting landscape of fundamental rights.
  • In brief / Factsheet
    22
    May
    2026
    This factsheet examines the "right to be forgotten" within the context of EU law and the European Convention on Human Rights. It emphasizes the intersections of these legal frameworks, with particular attention to case law from the Court of Justice of the European Union (CJEU) and the European Court of Human Rights (ECtHR).
  • Report / Paper / Summary
    11
    May
    2026
    The ability to communicate freely and privately online is protected under Article 7 of the EU Charter; it is a crucial enabler of other fundamental rights, particularly as the world becomes increasingly digital. This paper presents results from an EU-wide survey about people’s views on encryption of their private online communication. It looks, for example, at concern regarding access by outside actors to information shared when using private messaging applications. The results indicate that people highly value encryption and at the same time have concerns about online communications being accessed without their knowledge or permission. It provides a timely evidence base to shape policy discussions on internal security and digital privacy.
    FRA, 2026