Lawful and appropriate data processing
If an entity or individual uses your personal data, it interferes with your human right to private life, namely, the right to control the use of your private information which is one of its aspects. In order to optimally protect you in such situations, data users must process your data lawfully and follow certain obligations regarding appropriate data processing.
Every data processing activity interferes with your privacy. However, if the data processing is lawful, it will not result in a violation of your right to private life. For data processing to be lawful, it has to meet certain criteria.
Fair and transparent data processing requires that your personal data is processed in a fair and transparent way. Transparency can be ensured by informing you about the purpose of your data processing:
- what kind data will be (is) processed
- in what manner it will be (is) done
You also have to be informed about who is processing your data and how to reach this institution or person in case you want to access your data or submit a question or request.
You are entitled to access your data at any moment. Covert data processing is prohibited. However, there may be exceptions provided by law, for example, where operational activities are carried out without a person’s knowledge.
Your data can only be processed for a specific and lawful purpose, defined before the processing has started. Your data can be used for other purposes or given to other persons and entities only if it is permitted by law or if you have consented to it.
example Use of a person’s data for another purpose is allowed if it does not violate the rights of this person and is carried out for the needs of scientific or statistical research. In addition, the data user is obliged to disclose a person’s data to public authorities in specific situations provided by law, for example, if you are suspected of having committed a crime.
Your data shall not be kept longer than is necessary for the purposes for which the information was collected and processed. When the initial purpose has been fulfilled, the data should be deleted.
If you believe that there is no further need for the data user to keep your personal data, you may request that it be deleted. However, in accordance with the law, your data may be kept for future scientific or statistical use, as well as for the establishment of the national documentary heritage.
Data users are obliged to collect and process only relevant and accurate personal data which is closely related to the purpose for which the processing was needed. Data should not be incomplete, outdated or false. If your personal data has been changed, you can request that it be rectified and updated by the data user.
Data minimization means that data users may process only those of your personal data which are actually necessary to achieve the purposes for which they are processed.
Articles 96, 116
Applicable as of 25 May 2018
Articles 5-6, 9-10
4 May 2000
28 January 2003
28 April 2009
29 April 2014
4 December 2008
4 June 2013
18 April 2013
Joint publication by the the EU Agency for Fundamental Rights and the Council of Europe