Nascleanúint
RGCS (GDPR) > Airteagal 17. An ceart go ndéanfaí léirscriosadh (“an ceart go ndéanfaí ligean i ndearmad”)
Íoslódáil PDF

Airteagal 17 RGCS (GDPR). An ceart go ndéanfaí léirscriosadh (“an ceart go ndéanfaí ligean i ndearmad”)

Article 17 GDPR. Right to erasure (‘right to be forgotten’)

1. Beidh sé de cheart ag an ábhar sonraí go léirscriosfaidh an rialaitheoir sonraí pearsanta a bhaineann leis nó léi gan mhoill mhíchuí agus beidh sé d’oibleagáid ar an rialaitheoir sonraí pearsanta a léirscriosadh gan mhoill mhíchuí i gcás go mbeidh feidhm ag ceann de na forais seo a leanas:

1. The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:

Tráchtaireacht
(EN) Author
(EN) Siarhei Varankevich CIPP/E, CIPM, CIPT, MBA, FIP
FIP_IAPP
(EN) Co-Founder & CEO of Data Privacy Office LLC. Data Protection Trainer and Principal Consultant

(a) níl na sonraí riachtanach a thuilleadh i ndáil leis na críocha ar chucu a bailíodh iad nó a próiseáladh iad;

(a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;

(b) tarraingíonn an t-ábhar sonraí siar a thoiliú a bhfuil an phróiseáil bunaithe air i gcomhréir le pointe (a) d’Airteagal 6(1) nó le pointe (a) d’Airteagal 9(2) agus i gcás nach bhfuil aon fhoras dlíthiúil eile leis an bpróiseáil;

(b) the data subject withdraws consent on which the processing is based according to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing;

Téacsanna gaolmhara

(c) déanann an t-ábhar sonraí agóid i gcoinne na próiseála de bhun Airteagal 21(1) agus ní ann d’fhorais dhlisteanacha sháraitheacha maidir leis an bpróiseáil, nó déanann an t-ábhar sonraí agóid i gcoinne na próiseála de bhun Airteagal 21(2);

(c) the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2);

Téacsanna gaolmhara

(d) rinneadh próiseáil mhídhleathach ar na sonraí pearsanta;

(d) the personal data have been unlawfully processed;

(e) is gá na sonraí pearsanta a léirscriosadh le go gcomhlíonfaí oibleagáid dhlíthiúil faoi dhlí an Aontais nó faoi dhlí Ballstáit a bhfuil an rialaitheoir faoina réir;

(e) the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;

(f) bailíodh na sonraí pearsanta i ndáil le seirbhísí na sochaí faisnéise dá dtagraítear in Airteagal 8(1) a thairiscint.

(f) the personal data have been collected in relation to the offer of information society services referred to in Article 8(1).

Téacsanna gaolmhara

2. I gcás inar chuir an rialaitheoir na sonraí pearsanta ar fáil don phobal agus ina bhfuil sé d’oibleagáid air de bhun mhír 1 na sonraí pearsanta a léirscriosadh, déanfaidh an rialaitheoir, agus an teicneolaíocht atá ar fáil agus costas an chur chun feidhme á gcur san áireamh, bearta réasúnta, lena n-áirítear bearta teicniúla, chun na rialaitheoirí a bhfuil próiseáil á déanamh acu a chur ar an eolas faoi go bhfuil sé iarrtha ag an ábhar sonraí go ndéanfadh rialaitheoirí den sórt sin aon nasc leis na sonraí pearsanta sin a léirscriosadh nó aon chóip nó aon mhacasamhlú de na sonraí pearsanta sin a léirscriosadh.

2. Where the controller has made the personal data public and is obliged pursuant to paragraph 1 to erase the personal data, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.

ISO 27701

(EN) ISO/IEC 27701, adopted in 2019, added additional ISO/IEC 27002 guidance for PII processors.

Here is the relevant paragraph to article 17(2) GDPR:

8.3.1 Obligations to PII principals

Control

The organization should provide the customer with the means to comply with its obligations related to PII principals.

Implementation guidance

A PII controller’s obligations can be defined by legislation, by regulation and/or by contract.

(EN) […]


to read the full text

3. Ní bheidh feidhm ag mír 1 ná ag mír 2 a mhéid go bhfuil an phróiseáil sin riachtanach sna cásanna seo a leanas:

3. Paragraphs 1 and 2 shall not apply to the extent that processing is necessary:

ISO 27701

(EN) ISO/IEC 27701, adopted in 2019, added additional ISO/IEC 27002 guidance for PII controllers.

Here is the relevant paragraph to article 17(3) GDPR:

7.2.2 Identify lawful basis

Control

The organization should determine, document and comply with the relevant lawful basis for the processing of PII for the identified purposes.

Implementation guidance

Some jurisdictions require the organization to be able to demonstrate that the lawfulness of processing was duly established before the processing.

(EN) […]


to read the full text

(a) chun an ceart ar an tsaoirse chun tuairimí a nochtadh agus faisnéis a fháil a fheidhmiú;

(a) for exercising the right of freedom of expression and information;

(b) chun go gcomhlíonfar oibleagáid dhlíthiúil lena n-éilítear próiseáil le dlí an Aontais nó le dlí Ballstáit a bhfuil an rialaitheoir faoina réir nó chun cúram a chur i gcrích a dhéantar ar mhaithe le leas an phobail nó i bhfeidhmiú údaráis oifigiúil atá dílsithe don rialaitheoir;

(b) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

(c) ar chúiseanna a bhaineann le leas an phobail i réimse na sláinte poiblí i gcomhréir le pointe (h) agus le pointe (i) d’Airteagal 9(2) chomh maith le hAirteagal 9(3);

(c) for reasons of public interest in the area of public health in accordance with points (h) and (i) of Article 9(2) as well as Article 9(3);

Téacsanna gaolmhara

(d) chun críocha cartlannú a dhéanamh ar mhaithe le leas an phobail, chun críocha taighde eolaíoch nó stairiúil nó chun críocha staidrimh i gcomhréir le hAirteagal 89(1) a mhéid is dócha nach féidir cuspóirí na próiseala sin a ghnóthú nó go ndéanfaí dochar dá ngnóthú de bharr an chirt dá dtagraítear i mír 1; nó

(d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) in so far as the right referred to in paragraph 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing; or

Téacsanna gaolmhara

(e) chun éilimh dhlíthiúla a bhunú, a fheidhmiú nó a chosaint.

(e) for the establishment, exercise or defence of legal claims.

Tráchtaireacht ISO 27701 Recitals Dlí Treoirlínte & Cásanna Leave a comment
Tráchtaireacht

(EN) The so-called “right to be forgotten” was hailed as a breakthrough with the adoption of the General Data Protection Regulation, even though it existed in a limited form before. Article 17 provides for a broader “right to erasure”, to take into account the exact wording of the provision. European Union residents have a right to ask for the deletion of their personal data, and the organization that holds the data has a corresponding obligation to erase them “without undue delay” under a certain number of circumstances.

(EN) […]


to read the full text

(EN) Author
Louis-Philippe Gratton
(EN) Louis-Philippe Gratton PhD, LLM
(EN) Privacy Expert

(EN)

Data Subject Request Letter Sample

Concern: Request to erase my personal data

Dear Madam, Dear Sir,

You have data concerning me that I am asking you to delete…

(EN) […]


to read the full text

ISO 27701

(EN) ISO/IEC 27701, adopted in 2019, added additional ISO/IEC 27002 guidance for PII controllers.

Here is the relevant paragraph to article 17 GDPR:

7.3.6 Access, correction and/or erasure

Control

The organization should implement policies, procedures and/or mechanisms to meet their obligations to PII principals to access, correct and/or erase their PII.

Implementation guidance

The organization should implement policies, procedures and/or mechanisms for enabling PII principals to obtain access to, correct and erase of their PII, if requested and without undue delay.

(EN) […]


to read the full text

Recitals

(65) Ba cheart an ceart a bheith ag ábhar sonraí go ndéanfaí sonraí pearsanta a bhaineann leis nó léi a cheartú agus ba cheart “ceart go ndéanfaí ligean i ndearmad” a bheith aige nó aici i gcás ina sáraíonn coinneáil sonra pearsanta í den sórt sin an Rialachán seo nó dlí an Aontais nó dlí Ballstáit a bhfuil an rialaitheoir faoina réir. Ba cheart, go háirithe, é a bheith de cheart ag s ábhar sonraí go léirscriosfaí a shonraí pearsanta nó a sonraí pearsanta agus nach ndéanfaí iad a phróiseáil a thuilleadh, mura bhfuil na sonraí pearsanta riachtanach a thuilleadh i ndáil leis na críocha ar chucu a bailíodh iad nó ar chucu a próiseáladh iad ar bhealach eile, i gcás ina dtarraingíonn ábhar sonraí siar a thoiliú nó a toiliú nó ina ndéanann sé nó sí agóid i gcoinne phróiseáil na sonraí pearsanta a bhaineann leis nó léi nó i gcás nach gcomhlíonann próiseáil a shonraí pearsanta nó a sonraí pearsanta an Rialachán seo ar bhealach eile. Tá an ceart sin ábhartha go háirithe nuair atá toiliú tugtha ag an ábhar sonraí agus é nó í ina leanbh nach bhfuil láneolach ar na rioscaí a bhaineann leis an bpróiseáil, agus go bhfuil sé nó sí ag iarraidh sonraí pearsanta den sórt sin a bhaint níos moille, go háirithe ón idirlíon. Ba cheart don ábhar sonraí a bheith in ann an ceart sin a fheidhmiú d'ainneoin nach leanbh é nó í a thuilleadh. Ba cheart, áfach, é a bheith dleathach na sonraí pearsanta a choinneáil tuilleadh i gcás gur gá sin le haghaidh fheidhmiú an chirt chun tuairimí a nochtadh agus faisnéis a fháil, le haghaidh oibleagáid dhlíthiúil a chomhlíonadh, le haghaidh cúram a chur i gcrích a dhéantar ar mhaithe le leas an phobail nó i bhfeidhmiú údaráis oifigiúil atá dílsithe don rialaitheoir, ar fhorais a bhaineann le leas an phobail i réimse na sláinte poiblí, chun críocha cartlannú a dhéanamh ar mhaithe le leas an phobail, chun críocha taighde eolaíoch nó stairiúil nó chun críocha staidrimh, nó chun éilimh dhlíthiúla a bhunú, a fheidhmiú nó a chosaint.

(65) A data subject should have the right to have personal data concerning him or her rectified and a ‘right to be forgotten’ where the retention of such data infringes this Regulation or Union or Member State law to which the controller is subject. In particular, a data subject should have the right to have his or her personal data erased and no longer processed where the personal data are no longer necessary in relation to the purposes for which they are collected or otherwise processed, where a data subject has withdrawn his or her consent or objects to the processing of personal data concerning him or her, or where the processing of his or her personal data does not otherwise comply with this Regulation. That right is relevant in particular where the data subject has given his or her consent as a child and is not fully aware of the risks involved by the processing, and later wants to remove such personal data, especially on the internet. The data subject should be able to exercise that right notwithstanding the fact that he or she is no longer a child. However, the further retention of the personal data should be lawful where it is necessary, for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, on the grounds of public interest in the area of public health, for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, or for the establishment, exercise or defence of legal claims.

(66) Chun neart a chur leis an gceart go ndéanfaí ligean i ndearmad sa timpeallacht ar líne, ba cheart an ceart go ndéanfaí léirscriosadh a leathnú amach freisin chun go mbeadh oibleagáíd ar rialaitheoir a bhfuil na sonraí pearsanta curtha ar fáil go poiblí aige aon naisc chuig na sonraí pearsanta sin, aon chóipeanna díobh agus aon mhacasamhlú orthu a léirscriosadh. Agus é ag déanamh amhlaidh, ba cheart don rialaitheoir sin bearta réasúnta a dhéanamh, agus an teicneolaíocht atá ar fáil dón rialaitheoir agus na modhanna atá ar fail dó, lena n-áirítear bearta teicniúla, á gcur san áireamh chun rialaitheoirí a phróiseálann sonraí pearsanta den sórt sin a chur ar an eolas faoi iarraidh an ábair sonraí.

(66) To strengthen the right to be forgotten in the online environment, the right to erasure should also be extended in such a way that a controller who has made the personal data public should be obliged to inform the controllers which are processing such personal data to erase any links to, or copies or replications of those personal data. In doing so, that controller should take reasonable steps, taking into account available technology and the means available to the controller, including technical measures, to inform the controllers which are processing the personal data of the data subject's request.

Dlí Treoirlínte & Cásanna Leave a comment
[js-disqus]