The new General Data Protection Regulation
On the 4th of May 2016 the two normative acts which are part of the legislative package on data protection at EU level were published in the Official Journal of the European Union:
- Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation),
- Directive (EU) 2016/680 on the protection of natural persons with regard to the processing of personal data by competent law enforcement authorities.
Regulation (EU) 2016/679 updates the principles established two decades ago by Directive 95/46/EC which was repealed by the Regulation.
- Regulation (UE) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
- Law no. 102 of 3rd of May on the set up, organisation and functioning of the National Supervisory Authority for Personal Data Processing, with further amendments and completions – Republished
- Law no. 190 of 18th of July 2018 on implementing measures of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation)
- Law no. 363 of the 28th of December 2018 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data
- Guidelines issued by the National Supervisory Authority for Personal Data Processing
- Other informative materials for the application of General Data Protection Regulation issued by the National Supervisory Authority for Personal Data Processing
- Documents of European Data Protection Board
- Frequently asked questions addressed to the National Supervisory Authority for Personal Data Processing
- Press releases of the Supervisory Authority with reference to the participation to events dedicated to the General Data Protection Regulation
Guidelines issued by the National Supervisory Authority for Personal Data Processing
- Guidelines on the application of Law no. 363/2018
- Indicative guidelines for the application of the General Data Protection Regulation intended for the controllers
- Guidelines for the application of the General Data Protection Regulation by the data controllers issued by the National Supervisory Authority for Personal Data Processing
- Guidelines Q&A with reference to the application of Regulation (EU) 2016/679
Other informative materials for the application of General Data Protection Regulation issued by the National Supervisory Authority for Personal Data Processing
- Rights of the data subjects – Except from Regulation (EU) 2016/679
- New Regulation 2016/679 applicable as of 25th of May 2018 – Novelty elements (flyer)
- New Regulation 2016/679 applicable as of 25th of May 2018 – Novelty elements (brochure)
- Data Protection Officer – general information
Documents of European Data Protection Board
Pursuant to Article 68 of General Data Protection Regulation, the European Data Protection Board is established as a body of the Union with legal personality and is composed of the head of one supervisory authority of each Member State and of the European Data Protection Supervisor, or their respective representatives.
Guidelines issued by the European Data Protection Board
- Guidelines on derogations applicable to international transfers (Article 49 of General Data Protection Regulation)
- EDPB Guidelines on codes of conduct and monitoring bodies under Regulation 2016/679 – version for public consultation
- EDPB Guidelines on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679)
Annex 1 to the Guidelines 4/2018 – version for public consultation
- EDPB Guidelines 3/2018 on the territorial scope of the GDPR (2016/679) (Article 3) – version for public consultation
- EDPB Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of General Data Protection Regulation (2016/679) – revised version after public consultation
Annex 2 to the EDPB Guidelines 1/2018 – version for public consultation
Guidelines adopted by Article 29 Working Party related to General Data Protection Regulation and endorsed by the European Data Protection Board
During its first plenary meeting on the 25th of May 2018, the European Data Protection Board endorsed the following Article 29 Working Party Guidelines related to General Data Protection Board, applicable as of this date, as well as other documents:
- Guidelines on consent under Regulation 2016/679 (ro/en)
- Guidelines on transparency under Regulation 2016/679 (ro/en)
- Guidelines on Automated individual decision-making and Profiling (ro/en)
- Guidelines on Personal data breach notification (ro/en)
- Guidelines on the right to data portability pursuant to Article 20 of GDPR (ro/en)
- Guidelines on Data Protection Impact Assessment of Article 29 Working Party (ro/en)
- Guidelines on Data Protection Officers (DPO), according to Articles 37-39 of GDPR (ro/en)
- Guidelines for identifying a controller or processor's lead supervisory authority (ro/en)
- Guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679, WP 253 (ro/en)
- Recommendation on the Standard Application for Approval of Controller Binding Corporate Rules for the Transfer of Personal Data, WP 264 (en)
- Recommendation on the Standard Application form for Approval of Processor Binding Corporate Rules for the Transfer of Personal Data, WP 265 (en)
- Position Paper on the derogations from the obligation to maintain records of processing activities pursuant to Article 30(5) GDPR (en)
- Working Document Setting Forth a Co-Operation Procedure for the approval of “Binding Corporate Rules” for controllers and processors under the GDPR, WP 263 rev.01 (en)
- Working Document setting up a table with the elements and principles to be found in Binding Corporate Rules, WP 256 rev.01 (ro/en)
- Working Document setting up a table with the elements and principles to be found in Processor Binding Corporate Rules, WP 257 rev.01 (ro/en)
- Adequacy Referential, WP 254 rev.01 (ro/en)
Other documents issued by the European Data Protection Board
Statements
- EDPB Statement 3/2019 on an ePrivacy regulation
- EDPB Statement 2/2019 on the use of personal data in the course of political campaigns
Annex I to Statement 2/2019 on the use of personal data in the course of political campaigns
- EDPB Statement 01/2019 on the US Foreign Account Tax Compliance Act (FATCA)
- EDPB statement on Economic Concentration - 27/08/2018
- EDPB statement on ePrivacy - 25/05/2018
Reports
- EDPB LIBE Report on the implementation of the GDPR - 26/02/2019
- EU - U.S. Privacy Shield - Second Annual Joint Review report – 22/01/2019
Information notes
- Information note on data transfers under the GDPR in the event of a no-deal Brexit - 12/02/2019
- Information note on BCRs for companies which have ICO as BCR Lead Supervisory Authority - 12/02/2019
Opinions
- Opinion 7/2019 on the draft list of the competent supervisory authority of Iceland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)
- Opinion 6/2019 on the draft list of the competent supervisory authority of Spain regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)
- Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities
- Opinion 04/2019 on the draft Administrative Arrangement for the transfer of personal data between European Economic Area (“EEA”) Financial Supervisory Authorities and non-EEA Financial Supervisory Authorities
Draft administrative arrangement for the transfer of personal data
- Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR) - 23/01/2019
- Opinion 2/2019 on the draft list of operations subject to the requirements of a data protection impact assessment – Norway
- Opinion 1/2019 on the draft list of operations subject to the requirements of a data protection impact assessment – Liechtenstein
- Opinion 28/2018 regarding the European Commission Draft Implementing Decision on the adequate protection of personal data in Japan
- Opinion 23/2018 on Commission proposals on European Production and Preservation Orders for electronic evidence in criminal matters
- Opinions on the draft lists of operations subject to the requirements of a data protection impact assessment (no. 1-22; 24-27 from 2018)
Press releases of the Supervisory Authority with reference to the participation to events dedicated to the General Data Protection Regulation
2019
- European Data Protection Day
- Open doors Day
2018
- International Conference of the national supervisory authority on personal data protection
- Open doors Day – 25th of May 2018
- Conferences on the application of GDPR
- Open doors Day
- European Data Protection Day
2017
- Event “Application of the New General Data Protection Regulation in the public sector – obligations and responsibilities”
- Round table “The application of the New General Data Protection Regulation in the public sector” – obligations and responsibilities
- Awareness reunions in Timiș and Caraș-Severin counties
- Reunion – Practical aspects regarding the implementation of the General Data Protection Regulation
- Conference “New European Order in the data protection field”
- Conferences on the application of the General Data Protection Regulation
- OPEN DOORS DAY
- EUROPEAN DATA PROTECTION DAY