Nascleanúint
RGCS (GDPR) > Airteagal 19. An oibleagáid fógra a thabhairt go ndearnadh sonraí pearsanta a cheartú nó a léirscriosadh nó próiseáil a shrianadh
Íoslódáil PDF

Airteagal 19 RGCS (GDPR). An oibleagáid fógra a thabhairt go ndearnadh sonraí pearsanta a cheartú nó a léirscriosadh nó próiseáil a shrianadh

Article 19 GDPR. Notification obligation regarding rectification or erasure of personal data or restriction of processing

Tabharfaidh an rialaitheoir fógra do gach faighteoir ar nochtadh na sonraí pearsanta dóibh má ceartaíodh nó má léirscriosadh nó má srianadh próiseáil a rinneadh i gcomhréir le hAirteagal 16, Airteagal 17(1) agus Airteagal 18, ach amháin má tá sé dodhéanta é sin a dhéanamh nó má tá iarracht dhíréireach ag baint leis. Déanfaidh an rialaitheoir an t-ábhar sonraí a chur ar an eolas faoi na faighteoirí sin má iarrann an t-ábhar sonraí go ndéanfar amhlaidh.

The controller shall communicate any rectification or erasure of personal data or restriction of processing carried out in accordance with Article 16, Article 17(1) and Article 18 to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.

Téacsanna gaolmhara
Tráchtaireacht ISO 27701 Dlí Treoirlínte & Cásanna Leave a comment
Tráchtaireacht

(EN) Article 19 includes a notification obligation, which should not be confused with the specific personal data breach notification obligation (article 33). It is a mechanism that gives full effect to other provisions of the General Data Protection Regulation, ensuring that third parties are informed about actions taken by the controller regarding personal data (recital 66).

(EN) […]


to read the full text

(EN) Author
Louis-Philippe Gratton
(EN) Louis-Philippe Gratton PhD, LLM
(EN) Privacy Expert
ISO 27701

(EN) ISO/IEC 27701, adopted in 2019, added additional ISO/IEC 27002 guidance for PII controllers.

Here is the relevant paragraph to article 19 GDPR:

7.3.7 PII controllers’ obligations to inform third parties

Control

The organization should inform third parties with whom PII has been shared of any modification, withdrawal or objections pertaining to the shared PII, and implement appropriate policies, procedures and/or mechanisms to do so.

Implementation guidance

The organization should take appropriate steps, bearing in mind the available technology, to inform third parties of any modification or withdrawal of consent, or objections pertaining to the shared PII.

(EN) […]


to read the full text

Dlí Treoirlínte & Cásanna Leave a comment
[js-disqus]