Organizations should assess which of these grounds are most appropriate for different processing activities and then comply with any other requirements set out in the GDPR for those conditions (Article 5 GDPR). In this case, the natural person does not necessarily have to be a data subject, he can also be another natural person. Of course, it is not up to the controller to define what a vital interest is. We are talking here about life-threatening circumstances, where there is no other legal basis for processing, but where not processing personal data would essentially mean that someone would die if you did nothing and therefore would need to know certain things about the natural person who is at risk. Article 6(1) of the GDPR lays down the conditions that must be met for the processing of personal data to be lawful. Under the GDPR, data subjects have the right to withdraw their consent at any time. Therefore, mechanisms should be put in place to ensure that the procedure is both simple and effective. They should also be informed of this right before giving their consent. Every contract, by definition, means that personal data is processed.
You cannot enter into a contractual relationship without providing personal data and identifiers depending on the type of contract. At least this concerns contact information, for certain types of contracts such as an insurance contract, much more is required. It is best not to expand the definition of a contract too much, for example to avoid consent. Ultimately, everything can be considered a contract, and there will be cases where controllers will take far too broad an approach to use a contract as a basis for lawful processing. On the other hand, the definition is unnecessarily vague and it is up to you to determine whether your interests in the processing of personal data are legitimate or not. 2 Paragraph 1 let. f, shall not apply to processing carried out by public authorities in the performance of their duties. If you are processing data from a special category, you must ensure that you can identify an appropriate condition that applies to your new processing.
«The processing of personal data is generally prohibited, unless expressly permitted by law or the data subject has consented to the processing.» You must include information about your legal basis (or your bases if more than one applies) in your privacy policy. In accordance with the transparency provisions of the UK GDPR, the information you must provide to individuals includes: The legal bases for processing are set out in Article 6 of the UK GDPR. At least one of them must apply when processing personal data: this legitimate basis must be established by law, the law being the General Data Protection Regulation itself or other laws of the EU or its member states. Vital interests of the individual. An organization can probably invoke vital interests as a legal basis if it wants to protect a person`s life. However, it cannot invoke vital interests for health data or other special category data if the person is able to give consent, even if he refuses consent. You might think that more than one base applies, in which case you should identify and document them all from the start. Since consent must be voluntary, organizations can no longer use automatically ticked boxes to prove that data subjects have consented to the use of their data. The consent process should be clear and sometimes separate. For example, if an organization uses email to send marketing messages to a data subject, an organization might use a separate box for email than for other forms of communication, text messages, or phone calls.
However, the university must carefully consider their basis – it is the responsibility of the controller to be able to prove which legal basis applies to the purpose of the respective processing. Legitimate interests already existed as a legal basis for the processing of personal data in the Directive, but the GDPR complements them in the form of provisions where it is NOT applicable. Article 6 clarifies that processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party.
