Legal analyses and updates on Privacy — by Mr. Dr. Antoinette Vlieger.
The Data Protection Officer must not receive instructions or be penalized for his work, is bound by a duty of confidentiality, and must not hold a second role that conflicts with his position.
The GDPR requires organizations not only to appoint a Data Protection Officer (DPO) but also to create the conditions necessary for them to effectively perform their duties. Part 1 on the DPO’s position: involvement, resources, and visibility.
It is argued in various publications that the draft Digital Omnibus (concerning, among other things, amendments to the GDPR) would nullify the legal effect of the Scania judgment. However, a careful reading of the text suggests otherwise. The Commission is not proposing a nullification, but a demarcation of scope.
The free movement of health data is not a novelty of the EHDS: it is enshrined in Article 1 of the GDPR, among other. Dr. Vlieger explains which rights scientists can already claim.
The prohibition on using the civil service number hinders medical-scientific research. Dr. Vlieger analyzes the legal knot and explains why the EHDS offers the opportunity to resolve this.
The GDPR principle of purpose limitation seems to be an obstacle to the reuse of health data for medical big data research. That is incorrect. Dr. Vlieger explains.
When is a Data Protection Impact Assessment mandatory? And what is the role of the Data Protection Officer? Dr. Vlieger explains what a DPIA is and isn't.
Are pseudonymous data personal data? Dr. Vlieger explains the relative concept based on case law of the European Court.