Personal data protection aims to ensure that information relating to natural persons is processed and protected lawfully. Businesses, institutions and service providers should determine legal grounds, processing purposes and retention periods when processing data.
Privacy Notice Obligation
The data controller must clearly inform data subjects about which data is processed, for what purpose, to whom it may be transferred, the collection method and their rights. Privacy notices should be prepared in line with the specific data processing activity.
Explicit Consent and Legal Grounds
Not every data processing activity must be based on explicit consent. If legal grounds provided by law exist, data may be processed without explicit consent. However, special categories of personal data and marketing activities require careful assessment.
Data Security
Data security includes technical and administrative measures. Access permissions, retention policies, destruction processes, employee information and data breach management should be reviewed regularly.