0% found this document useful (0 votes)
12 views10 pages

Spain's Data Protection Law Overview

The document outlines the requirements of the Data Protection Law of Spain and the new General Data Protection Regulation of the EU. As the project manager, you are asked to implement systems and tools to comply with the new requirements before the deadline, including the appointment of a data protection officer, notification of data security breaches, and ensuring explicit consent and data portability. You are granted extensive powers and resources to complete the project.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views10 pages

Spain's Data Protection Law Overview

The document outlines the requirements of the Data Protection Law of Spain and the new General Data Protection Regulation of the EU. As the project manager, you are asked to implement systems and tools to comply with the new requirements before the deadline, including the appointment of a data protection officer, notification of data security breaches, and ensuring explicit consent and data portability. You are granted extensive powers and resources to complete the project.

Translated by

ScribdTranslations
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

1

APPLICATION PROJECT PRACTICAL CASE, IN SPAIN, ORGANIC LAW


15/1999, OF DECEMBER 13, ON DATA PROTECTION
PERSONAL CHARACTER

LILIAN LIANANA FLORES JOA

SUMMA UNIVERSITY

MASTER OF SCIENCE IN PROJECT MANAGEMENT

PROJECT MANAGEMENT II

MIAMI

2022

Teacher: Pedro María Sánchez Faculty


2

Development

In Spain, Organic Law 15/1999, of December 13, on the protection of personal data
the personal was developed to adapt Directive 95/46/EC. This law aimed to
guarantee and protect, in relation to the processing of personal data and rights
fundamentals of individuals, and especially of their honor and personal privacy
familiar.

The law would apply to personal data recorded in physical format, which the
make them susceptible to treatment, and to any subsequent use modality of this data by the
public and private sectors. All processing of personal data would be governed by law.
when the treatment is carried out in Spanish territory within the framework of activities of a
establishment of the data controller.

After several modifications of the organic law, the European Union (EU) develops the
new Regulation (EU) 2016/679 of the European Parliament and of the Council, known as
General Data Protection Regulation, which came into effect 18 months ago from
Today, it will start to be implemented exactly 4 months from today's date.
resulting mandatory for organizations to implement the new measures. This
Regulation repeals Directive 95/46/EC.

The Regulation aims to harmonize the protection across all countries of the European Union.
natural persons regarding the processing of personal data and the free movement
of data. In addition, it seeks to respond to the reality of personal data within the
current information society.

The new requirements of the Regulation pose significant challenges for everyone
entities due to the high volume of personal data they manage, turning

the protection of personal data is a critical aspect that all organizations must
keep in mind. The Regulation is a rule directly applicable to the legal system
Spanish, not requiring specific internal norms either for development or for their application.

The Regulation contains concepts, principles, and mechanisms similar to those established by the
Directive 95/46. Therefore, organizations that currently comply with the LOPD have
good starting point to evolve towards a correct application of the new regulation.
3

In general, the new considerations that must be taken into account are the
next:

Two general elements constitute the greatest innovation of the Regulation for the
responsible and project onto all the obligations of the organizations:

Organizations are required to analyze what data they process, for what purposes.
they do and what type of treatment operations they carry out.
Enhanced consent: consent must be 'unequivocal', being that
that has been provided through a manifestation of the interested party or through a clear
affirmative action. No forms of consent are accepted in any way.
tacit or by omission, since they are based on inaction. Situations are contemplated in
those for which consent, in addition to being unequivocal, must be explicit:
Treatment of sensitive data.
Adoption of automated decisions.
International transfers.

Consent can be unequivocal and granted implicitly when it is inferred from


an action of the interested party, for example: when the interested party continues browsing a website
and thus accepts the use of cookies to monitor your browsing.

The information to the interested parties, both regarding the conditions of the treatments that they
they affect like in the answers to the rights exercises, it must be provided in the form
concise, transparent, intelligible and easily accessible, with clear and simple language.

Information to stakeholders must be provided in writing, including the means.


electronics when appropriate.
New rights such as 'Right to Be Forgotten': consequence of the application of the law
of the deletion of personal data.
New rights such as 'portability': it implies that personal data of
interested parties are transmitted directly from one responsible person to another, without the need for

they have been transmitted to the interested party themselves in advance, as long as this is

technically possible. The right to portability is an advanced form of the right to


access through which the copy provided to the interested party must be offered in a
structured format, commonly used and mechanical reading.
4

Right of access: the right to obtain a copy of the data is recognized


personal data subject to processing. The controllers may address this right
facilitating remote access to a secure system that provides the interested party with access
directly to your personal data.
The data will be collected for specified purposes: if data is collected with a
determined purpose data cannot be used for a different purpose
Obligation to implement encryption systems and two-factor authentication, including
about the data considered basic level.
Identify, as a key figure, the 'Data Protection Officer' (DPO) or 'Delegate of Data Protection'.
Data Protection (DPD), which will be mandatory in:

Authorities and public bodies.

Responsible individuals or those in charge whose main activities include operations of


treatment that requires regular and systematic observation of interested parties on a large scale.

Responsible individuals or those in charge whose main activities include the handling of
large scale of sensitive data.

Notifications of "data security breaches." Security breaches are


commonly known as 'security breaches' which includes any incident that causes
the destruction, loss, or accidental or unlawful alteration of personal data transmitted,
preserved or treated in another way, or unauthorized communication or access to them
data. For example: the loss of a laptop, unauthorized access to databases
data of an organization (including by its own staff) or the accidental deletion of some

records constitute security violations under the GDPR and must be addressed
appropriately. Some obligations on the part of organizations are as follows:

When a data security breach occurs, the responsible party must notify
to the competent data protection authority, unless it is unlikely that the
violation poses a risk to the rights and freedoms of those affected.

The bankruptcy notification to the authorities must occur without undue delay and be
possible, within 72 hours following the responsible party's awareness of it.

The notification must include a minimum content:

. The nature of rape.


. Categories of data and affected stakeholders.
. Measures adopted by the responsible party to address the bankruptcy.
. If applicable, the measures taken to mitigate the possible negative effects on the
interested parties.
5

Those responsible must document all security breaches.

The GDPR adds to the contents of the notification the recommendations on the measures.
What can those interested take to cope with the consequences of bankruptcy?
Questions

What is Requested Based on the Previous Information?

The organization you work for is a large engineering company that is composed of
by various departments such as:

1. Human resources.
2. Financial.
3. Wind engineering.
4. Hydraulic engineering.
Geothermal engineering.
6. Civil engineering
7. Legal and processing.
8. Systems.
9. Project Management Office (PMO).

As a member of the Systems Department of the organization, you are appointed Director of the
Project to adapt or modify existing systems and tools or create systems or
necessary tools to implement all the previously mentioned measures,
included in the GDPR, which must be implemented before the date set by
the Regulation (+4 months from today), under the possibility of incurring high penalties
for their non-compliance. Systems or tools can affect any department
within the organization.

The project is considered critical by the organization, whose structure is matrix-based.


strong, so that a level of authority, decision-making capacity, and is provided to him
availability of resources very high. You can request human resources from both
department of systems like other departments of the organization.

At the same time, you are offered the possibility of hiring an external expert if you consider it.
necessary due to the absence or unavailability of a specific profile within the organization.
A budget of €200,000 is assigned as a maximum. Considering the importance of
The project sponsor will be the director of the project management office (PMO).

The following assumptions will need to be taken into account to properly develop the
subsequent analysis:
6

. Your organization fully complies with the existing regulations regarding the
Data protection (LOPD 15/1999).
. As of today, your organization has not yet begun to adapt its systems and
tools to the considerations of the new Data Protection Regulation
(GDPR), so you must start from scratch.
. Your organization has processes, procedures, and policies that must be
respected and like, for example, the following:
Policy for risk control and management.
Compliance Policy.
Cybersecurity Policy.
. Any other data or information not included in this document will be assumed for the
Project Director.

With the available information, the development of the REGISTRATION OF


INTERESTED PARTIES AND A MATRIX OF INTEREST/INFLUENCE for this project, using the
attached format.
7

MATRIX OF INTEREST/INFLUENCE
8

Conclusions

An Interest/Influence matrix is developed, with the registration of stakeholders, which


it allows to determine the type of relationship that is established between each of the interested parties, the

owner of the project in this case to the European Union and is established as the project director to
systems manager as the person responsible within the company.

The level of influence is established on a scale from 1 to 6, with one being the level of
lowest influence and 6 the highest which in this case would be occupied by the European Union and
The project manager of the company.

The level of interest is established on a scale from 1 to 6, with one being the level of
lowest interest and 6 the highest. Understanding interest as the level of impact that
You can have the project about your management and from there derive your level of interest.

There is also a classification that is defined in collaborating and communicating, as it does not

Everyone communicates, but everyone is a collaborator; for this reason, they are part of the project.

This type of Matrix helps us initially to define who will form


part of the project. This is determined by the project itself depending on whether it requires them
for its development or not. It is the first step to carry out a project.

Bibliographic references

Summa University. (n.d.). Stakeholders Management. Link where it was obtained from.
document
The provided link does not contain any translatable text.

Invalid URL provided.


unit3_pdf3.pdf

[Link]/resources/
library/pdf/
9

quality assurance/
unit3_pdf1.pd
The provided text is not translatable as it appears to be a URL.
[Link]/resources/
library/pdf/
quality_assurance/
unit3_pdf1.pd
Invalid input: URL provided instead of text for translation.
[Link]/resources/
library/pdf/
quality_assurance/
unit3_pdf1.pd
Summa University. (n.d.). Stakeholder management. Continuous Improvement. Link to where it
obtained the document:
htInvalid URLtto [Link]/resources/libraryteca_summa/pdf/project_managementt_ii/
unit1_pdf1.pdf

Summa University. (n.d.). Cost Management. Link to where the document was obtained:
htps://[Link]/resources/biblioteca_summa/pdf/project_managementt
unit1_pdf1.pdf
10

Summa University. (n.d.). Management of communications. Link from where it was obtained
document:
htInvalid input, please provide a valid text for [Link]/resources/libraryteca_summa/pdf/project_management_ii/
unit1_pdf1.pdf

Common questions

Powered by AI

Implementing GDPR compliance poses several challenges, including coordinating across departments such as HR, finance, and engineering, as data might intersect various operational areas. Aligning organizational policies with GDPR requirements requires collaborative efforts, training, and potentially hiring external experts. Ensuring budget constraints and resource availability, while adapting existing systems to GDPR standards, adds complexity to compliance efforts .

GDPR mandates that information provided to stakeholders must be concise, transparent, and easily understandable. This requirement ensures that stakeholders are well-informed about data processing operations affecting them, reinforcing trust and accountability. Clear information dissemination helps prevent misunderstandings and potential conflicts, thereby facilitating smoother compliance operations .

Organizations should use an Interest/Influence matrix to manage stakeholders in GDPR compliance projects. This matrix assesses the level of influence and interest of each stakeholder, which helps to determine their involvement in the project. The European Union typically holds high influence, guiding the level of interest based on how the project's outcome might impact their operations and compliance with GDPR .

GDPR defines 'data security breaches' as incidents causing destruction, loss, alteration, unauthorized disclosure, or access to personal data. Organizations must notify the competent data protection authority within 72 hours of awareness of the breach unless it is unlikely to pose risks to the affected individuals. The notification should include the breach's nature, data categories affected, measures taken, and mitigation plans. Organizations must document all breaches .

The 'Right to Be Forgotten' under GDPR requires organizations to delete personal data when it's no longer necessary or the data subject withdraws consent, enhancing individual data control. This right challenges organizations to implement robust data management and deletion systems, ensuring compliance without compromising data integrity or operational efficiency .

A Data Protection Officer (DPO) under GDPR is responsible for overseeing data protection strategies and ensuring compliance with GDPR protocols. It is mandatory to appoint a DPO in public authorities, organizations carrying out large-scale systematic monitoring, or processing sensitive data on a large scale .

Under GDPR, consent must be clear and affirmative for data processing, especially for sensitive data, automated decisions, and international transfers. Consent can sometimes be implicit, inferred through user actions like continued website browsing. However, explicit consent is needed for significant data processing actions. Information to stakeholders must be concise and clear, respecting the conditions that affect the exercises of data rights .

Organizations must implement encryption systems and two-factor authentication for data security, even when handling data considered basic level. These measures are part of GDPR's requirements to protect personal data during its collection, storage, and processing .

The GDPR introduces the right to data portability, which allows personal data to be transmitted directly from one data controller to another without requiring transmission to the data subject first, as long as it's technically feasible. This right is an advanced form of the right of access, where the data provided to the data subject must be in a structured, commonly used, and machine-readable format .

GDPR requires organizations to provide remote access to personal data as part of the right of access, where feasible. This allows data subjects direct access to their personal data in a secure manner. The rationale is to enhance data subjects' control and transparency over personal data usage, aligning with GDPR's emphasis on individual rights .

You might also like