Lets say that a basketball academy for kids wants to monitor their athletes skills, so they decide to install a CCTV system that records all the games when the team is playing against other team.
GDPR Data Controller or Data Processor
My company provides billing feature to different companies. The list of processing activities for which DPIA needs to be conducted does not talk about Card holder data. As my company stores card holder data, Do I require to conduct DPIA in my company? Is DPIA mandatory for SAAS (B2B) based company?
GDPR and Transparency
We are a Sports Association which consists of 7 Board committee members and 13 club representatives. I have been elected as a Treasurer of the board committee recently. Whenever there are committee meetings, the Board secretory sends out meeting invitations to all committee members and 13 Club representatives. The email recipients are always kept on "BCC" field so one can not independently verify if the the email invitations have gone out to all members? Many times we make important decisions during the meeting such as playing matters, budget/spending matters, election of representatives etc. which require members to caste their vote prior to taking a final decision by the board committee but many times I see most of the members are absent / do not attend the meetings which makes me to ask questions such as if e-mail invitations have been sent out to all members?. So when I raised this matter during our committee meeting "why the e-mail receipients are not kept on the "To" filed ? "; the Secretory brings up GDPR/privacy matter stating h e can't keep the e-mail recipients on the "To" field. This is impacting the legitimacy of the decisions taken during our meetings since only a small number of members are present at the time of voting and probably this is being done purposely to avoid majority of the members being coming into the meetings. I just wanted to know how to deal with this kind of situation? Whether the GDPR law talks about this kind of situation and what is the right thing to do in such situations?
GDPR Consent Forms
We are running through our GDPR Policies and we are wondering whether an agency employee would need to sign a consent form for us to store their cv for 30 days.
Working from Home Monitoring
Can you give me some advice on monitoring in respect of remote and home working - the use of, for example, software which logs keystrokes and mouse movements or captures screenshots, logging of applications used and remotely enabling webcams.
Cookie acceptance
I wondered if you have any advice regarding possibility of changes to Cookie acceptance, from currently being passive to more active? We are thinking of changing ours and wondering where the regulations might be going with this one? Many thanks and warm regards.
EU GDPR question
I just had a question regarding the GDPR document signed during a job interview. The employer refused to provide me with a copy of signed papers for confidentiality. So I was curious if I can request to know for what they will use my data and ask for the right to forget as I will refuse a job offer.
Data processing and transferring
Good morning. I would have a question relative to the management of the data. In particular when an Italian parent company collects personal data (name, surname, mail, country) of its visitors during an event / fair in Germany, can it transfer these contacts to its foreign branch (EU)? Need a data co-ownership?
Right of erasure
What is the best was to automate deletion? Hard delete or anonymize
Data Processor Articles in GDPR
My company is data processor but i do not know how many article applies to my company since most of the requirement has to be fulfilled by data controller. what are the mandatory documents for data processor only.