Artikolu 46 RĠPD (GDPR). Trasferimenti soġġetti għal salvagwardji xierqa
Article 46 GDPR. Transfers subject to appropriate safeguards
Artikolu 47 RĠPD (GDPR). Regoli korporattivi vinkolanti
Article 47 GDPR. Binding corporate rules
Artikolu 49 RĠPD (GDPR). Derogi għal sitwazzjonijiet speċifiċi
Article 49 GDPR. Derogations for specific situations
1. Fin-nuqqas ta’ deċiżjoni dwar l-adegwatezza skont l-Artikolu 45(3), jew salvagwardji xierqa skont l-Artikolu 46, inklużi regoli korporattivi vinkolanti, trasferiment jew sett ta’ trasferimenti ta’ data personali lejn pajjiż terz jew organizzazzjoni internazzjonali għandu jseħħ biss b’waħda mill-kondizzjonijiet li ġejjin:
1. In the absence of an adequacy decision pursuant to Article 45(3), or of appropriate safeguards pursuant to Article 46, including binding corporate rules, a transfer or a set of transfers of personal data to a third country or an international organisation shall take place only on one of the following conditions:
[…]
[…]
Fejn trasferiment ma setgħax ikun ibbażat fuq dispożizzjoni fl-Artikoli 45 jew 46, inklużi d-dispożizzjonijiet dwar regoli korporattivi vinkolanti, u l-ebda waħda mid-derogi għal sitwazzjoni speċifika msemmija fl-ewwel subparagrafu ta’ dan il-paragrafu ma tkun applikabbli, it-trasferiment ma jkunx ripetittiv, jikkonċerna biss għadd limitat ta’ suġġetti tad-data, ikun meħtieġ għall-għanijiet ta’ interessi leġittimi konvinċenti mfittxija mill-kontrollur li ma jingħelbux mill-interessi jew id-drittijiet u l-libertajiet tas-suġġett tad-data, u l-kontrollur ikun ivvaluta ċ-ċirkostanzi kollha madwar it-trasferiment tad-data u abbażi ta’ dik il-valutazzjoni pprovda salvagwardji xierqa fir-rigward tal-protezzjoni tad-data personali. Il-kontrollur għandu jinforma lill-awtorità superviżorja bit-trasferiment. Il-kontrollur għandu, barra milli jipprovdi l-informazzjoni msemmija fl-Artikolu 13 u 14, jinforma lis-suġġett tad-data dwar it-trasferiment u dwar l-interessi leġittimi konvinċenti segwiti.
Where a transfer could not be based on a provision in Article 45 or 46, including the provisions on binding corporate rules, and none of the derogations for a specific situation referred to in the first subparagraph of this paragraph is applicable, a transfer to a third country or an international organisation may take place only if the transfer is not repetitive, concerns only a limited number of data subjects, is necessary for the purposes of compelling legitimate interests pursued by the controller which are not overridden by the interests or rights and freedoms of the data subject, and the controller has assessed all the circumstances surrounding the data transfer and has on the basis of that assessment provided suitable safeguards with regard to the protection of personal data. The controller shall inform the supervisory authority of the transfer. The controller shall, in addition to providing the information referred to in Articles 13 and 14, inform the data subject of the transfer and on the compelling legitimate interests pursued.
[…]
[…]
(EN) ISO/IEC 27701, adopted in 2019, added additional ISO/IEC 27002 guidance for PII controllers.
Here is the relevant paragraph to article 14(2)(a) GDPR:
7.4.7 Retention
Control
The organization should not retain PII for longer than is necessary for the purposes for which the PII is processed.
Implementation guidance
The organization should develop and maintain retention schedules for information it retains, taking into account the requirement to retain PII for no longer than is necessary.
…
Iniciar sesión
para acceder al texto completo