EU GDPR - Expert Advice Community

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • GDPR - specific protections for children

    I am in independent assessor for dyslexia. I would like some advice on the wording of a consent form which I would ask parents to sign. This would give their consent for gathering personal details, information from other professionals, assessing their child and storing the information for six years following their 18th birthday.
  • Data subject access requests

    As a processor we have been requested by one of our clients (controller) to share some basic information (comprising transaction reference and email address) with their website provider. Am I correct in thinking this should be covered in the client's own privacy policy, and that any data access request relating to this shared information would be made via the client (controller)?
  • Legitimate interest for marketing emails

    Can we claim legitimate interest for marketing emails ?If we contact people to say, email us if you want to be removed from our mailing list, is that ok? Or do we need to say, contact us if you want to remain on our mailing list ?
  • Employee Privacy Notice

    1. What is the best way to deliver this document to employee? Do we need any acknowledgement for all the employees?
  • Privacy Statement/Privacy Notice

    Could you please let me know if a Privacy Statement is the same as a Privacy Notice?
  • DPO v/s Data Protection Compliance Officer

    We’ve been advised that due to the small scale of our business it’s unnecessary to appoint a Data Protection Officer, but instead we will need to appoint the DPO’s responsibilities to a “Data Protection Compliance Officer”. Could you please confirm that’s correctand if Yes, should we use that title in all the documentation referring to the DPO?
  • Data Subject Right

    From the time a data subject have exercised these rights what is the response time from the controller/processor. Is these response time stipulated in the GDPR? I have looked but couldn't find any hints.
  • Handling consents

    I own 3 different IT companies. I want to create a disclaimer that states when a candidates submits his website to one of our job postings that he gives consent for XXX to share his CV / personal information with our partners. I would prefer not to specially name my other two companies directly, but I would like to name them indirectly by saying partners. Do you think this would be possible?
  • Customer telephone acquisition

    Has the new GDPR changed anything with regard to new customer telephone acquisition? I acquire dealers or companies, no end customers. May I go to the 25.05. continue to contact companies by phone?
Page 66 of 97 pages