3 ms·
But Article 27(2) explicitly excludes the requirement of designating a representative according to 27(1), if the processing of personal data is limited within p
by cuspycode 8y ago
But Article 27(2) explicitly excludes the requirement of designating a representative according to 27(1), if the processing of personal data is limited within perfectly sound limits.
- tzs 8y agoArticle 27(2) excludes that requirement for "processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing". To be excluded, the processing has to satisfy three requirements: • "is occasional" • "does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10" • "is unlikely to result in a risk to the rights and freedoms of natural persons" Most businesses probably won't process any of the Article 9(1) special categories or the Article 10 criminal stuff, so that shouldn't my much of a hurdle for most. All kinds of data pose a risk to the rights and freedoms of natural persons. See Recital 75 for examples. Of particular note, if it can lead to identity theft, fraud, or financial loss it poses such a risk. This is going to snag a lot of businesses. Then there is that "is occasional" requirement for being excluded. I have no idea how that is going to be interpreted.