BETA

26 Amendments of Pilar DEL CASTILLO VERA related to 2012/0011(COD)

Amendment 254 #
Proposal for a regulation
Recital 62
(62) The protection of the rights and freedoms of data subjects as well as the responsibility and liability of controllers and processor, also in relation to the monitoring by and measures of supervisory authorities, requires a clear attribution of the responsibilities under this Regulation, including where a controller determines the purposes, conditions and means of the processing jointly with other controllers or where a processing operation is carried out on behalf of a controller.
2012/12/20
Committee: ITRE
Amendment 257 #
Proposal for a regulation
Recital 65
(65) In order to demonstrate compliance with this Regulation, the controller or processor should document each processing operation. Each controller and processor should be obliged to co-operate with the supervisory authority and make this documentation, on request, available to it, so that it might serve for monitoring those processing operations.
2012/12/20
Committee: ITRE
Amendment 334 #
Proposal for a regulation
Article 4 – paragraph 1 – point 5
(5) 'controller' means the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes, conditions and means of the processing of personal data; where the purposes, conditions and means of processing are determined by Union law or Member State law, the controller or the specific criteria for his nomination may be designated by Union law or by Member State law;
2012/12/20
Committee: ITRE
Amendment 374 #
Proposal for a regulation
Article 6 – paragraph 1 – point f a (new)
(fa) processing is limited to pseudonymised data and the recipient of the service is given a right to object pursuant to Art. 19 (3) (new).
2012/12/21
Committee: ITRE
Amendment 431 #
Proposal for a regulation
Article 10 – paragraph 1
If the data processed by a controller do not permit the controller to identify a natural person, in particular when rendered anonymous or pseudonymous, the controller shall not be obliged to acquire additional information in order to identify or to individualise the data subject for the sole purpose of complying with any provision of this Regulation.
2012/12/21
Committee: ITRE
Amendment 510 #
Proposal for a regulation
Article 18 – paragraph 2 a (new)
2a. Paragraphs 1 and 2 do not apply to the processing of anonymised and pseudonymised data, insofar as the data subject is not sufficiently identifiable on the basis of such data, or identification would require the controller to undo the process of pseudonymisation.
2012/12/21
Committee: ITRE
Amendment 512 #
Proposal for a regulation
Article 18 – paragraph 3
3. The Commission may specify the electronic format, referred to in paragraph 1 and the technical standards, modlated functionalities and procedures for the transmission of personal data pursuant to paragraph 2. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 87(2), shall be determined by the controller by reference to the most appropriate industry standards available or as defined by industry stakeholders or standardisation bodies. The Commission shall promote and assist industry, stakeholders and standardisation bodies in the mapping and adoption of technical standards, modalities and procedures for the transmission of personal data pursuant to paragraph 2.
2012/12/21
Committee: ITRE
Amendment 520 #
Proposal for a regulation
Article 19 – paragraph 3 a (new)
3a. Where pseudonymised data is processed pursuant to point (g) of Art. 6 (1) the data subject shall have the right to object free of charge. This right shall be offered to the data subject in an intelligible manner and shall be clearly distinguishable from other information.
2012/12/21
Committee: ITRE
Amendment 547 #
Proposal for a regulation
Article 20 – paragraph 2 – point c a (new)
(ca) is limited to pseudonymised data. Such pseudonymised data must not be collated with data on the bearer of the pseudonym. Art. 19 (3) [new] shall apply correspondingly.
2012/12/21
Committee: ITRE
Amendment 624 #
Proposal for a regulation
Article 26 – paragraph 2 – point d
(d) enlist another processor only with the prior permission of the controller;deleted
2012/12/21
Committee: ITRE
Amendment 636 #
Proposal for a regulation
Article 26 – paragraph 4
4. If a processor processes personal data other than as instructed by the controller, the processor shall be considered to be a controller in respect of that processing and shall be subject to the rules on joint controllers laid down in Article 24.deleted
2012/12/21
Committee: ITRE
Amendment 639 #
Proposal for a regulation
Article 26 – paragraph 5
5. The Commission shall be empowered to adopt delegated acts in accordance with Article 86 for the purpose of further specifying the criteria and requirements for the responsibilities, duties and tasks in relation to a processor in line with paragraph 1, and conditions which allow facilitating the processing of personal data within a group of undertakings, in particular for the purposes of control and reporting.
2012/12/21
Committee: ITRE
Amendment 641 #
Proposal for a regulation
Article 28 – paragraph 1
1. Each controller and processor and, if any, the controller's representative, shall maintain documentation of all processing operations under its responsibility.
2012/12/21
Committee: ITRE
Amendment 647 #
Proposal for a regulation
Article 28 – paragraph 2 – point c
(c) the purposes of the processing, including the legitimate interests pursued by the controller where the processing is based on point (f) of Article 6(1);deleted
2012/12/21
Committee: ITRE
Amendment 649 #
Proposal for a regulation
Article 28 – paragraph 2 – point d
(d) a description of categories of data subjects and of the categories of personal data relating to them;deleted
2012/12/21
Committee: ITRE
Amendment 650 #
Proposal for a regulation
Article 28 – paragraph 2 – point e
(e) the recipients or categories of recipients of the personal data, including the controllers to whom personal data are disclosed for the legitimate interest pursued by them;deleted
2012/12/21
Committee: ITRE
Amendment 651 #
Proposal for a regulation
Article 28 – paragraph 2 – point f
(f) where applicable, transfers of data to a third country or an international organisation, including the identification of that third country or international organisation and, in case of transfers referred to in point (h) of Article 44(1), the documentation of appropriate safeguards;deleted
2012/12/21
Committee: ITRE
Amendment 652 #
Proposal for a regulation
Article 28 – paragraph 2 – point g
(g) a general indication of the time limits for erasure of the different categories of data;deleted
2012/12/21
Committee: ITRE
Amendment 653 #
Proposal for a regulation
Article 28 – paragraph 2 – point h
(h) the description of the mechanisms referred to in Article 22(3).deleted
2012/12/21
Committee: ITRE
Amendment 660 #
Proposal for a regulation
Article 28 – paragraph 5
5. The Commission shall be empowered to adopt delegated acts in accordance with Article 86 for the purpose of further specifying the criteria and requirements for the documentation referred to in paragraph 1, to take account of in particular the responsibilities of the controller and the processor and, if any, the controller's representative.
2012/12/21
Committee: ITRE
Amendment 663 #
Proposal for a regulation
Article 28 – paragraph 6
6. The Commission, after consulting the European Data Protection Board, may lay down standard forms for the documentation referred to in paragraph 1. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 87(2).
2012/12/21
Committee: ITRE
Amendment 695 #
Proposal for a regulation
Article 33 – paragraph 1
1. Where processing operations present specific risks to the rights and freedoms of data subjects by virtue of their nature, their scope or their purposes, the controller or the processor acting on the controller's behalf shall carry out an assessment of the impact of the envisaged processing operations on the protection of personal data.
2013/01/09
Committee: ITRE
Amendment 707 #
Proposal for a regulation
Article 33 – paragraph 4
4. The controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of the processing operations.deleted
2013/01/09
Committee: ITRE
Amendment 862 #
Proposal for a regulation
Article 77 – paragraph 1
1. Any person who has suffered damage as a result of an unlawful processing operation or of an action incompatible with this Regulation shall have the right to receive compensation from the controller or the processor for the damage suffered.
2013/01/09
Committee: ITRE
Amendment 865 #
Proposal for a regulation
Article 77 – paragraph 2
2. Where more than one controller or processor is involved in the processing, each controller or processor shall be jointly and severally liable for the entire amount of the damage.
2013/01/09
Committee: ITRE
Amendment 866 #
Proposal for a regulation
Article 77 – paragraph 3
3. The controller or the processor may be exempted from this liability, in whole or in part, if the controller or the processor proves that they areit is not responsible for the event giving rise to the damage.
2013/01/09
Committee: ITRE