Screening as Data Processing Operation
摘要
The purpose of this chapter is to introduce the territorial and material scope of GDPR, to conceptualize screening as a data processing operation, to introduce the related notification obligations prescribed by the EUs General Data Protection Regulation 2016/679 (GDPR), and to map how EU/EEA-registered NGOs notify their data subjects about screening. To do so it is needed, as a minimum, to review what personal data is collected and processed during screening; how screening can be unpacked as a series of data processing operation, what is the typical legal bases for collecting personal data and what is to be communicated to data subjects—provided that restrictions do not apply. Sources selected for analysis equally included legal instruments and academic sources in the field of law and social science. Findings indicate that if screening is communicated to data subjects, it is communicated vaguely and selectively, while publicly available privacy notices are rarely used for such purpose.