Tuesday, August 1, 2017

GDPR and Legitimate Interest


Legitimate Interest. The GDPR provides six (6) grounds for processing personal data and "Legitimate Interest" is one of them. [GDPR Article 6, paragraph (1)].  Legitimate Interest is also one of the exceptional basis for data transfer outside of the EU. [GDPR Article 49, paragraph (g)].

For compliance, the controller must also disclose at the time of personal data collection, the purpose for processing the data, as well as the legal basis for collecting the data. [GDPR Article 13, paragraph (1c)]. If the legal basis it "legitimate interest", the controller must describe that legitimate interest. [GDPR Article 13, paragraph (1d)].

No comments:

Post a Comment