{"id":40422,"date":"2024-03-13T08:25:00","date_gmt":"2024-03-13T07:25:00","guid":{"rendered":"https:\/\/zuniclaw.com\/the-law-on-personal-data-protection-a-few-guidelines-on-how-to-get-compliant\/"},"modified":"2024-09-20T11:37:55","modified_gmt":"2024-09-20T09:37:55","slug":"law-on-personal-data-protection","status":"publish","type":"post","link":"https:\/\/zuniclaw.com\/en\/law-on-personal-data-protection\/","title":{"rendered":"The Law on Personal Data Protection &#8211; A Few Guidelines On How To Get Compliant"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"40422\" class=\"elementor elementor-40422 elementor-33340\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-42ea1758 e-flex e-con-boxed e-con e-parent\" data-id=\"42ea1758\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-446d97ee elementor-widget elementor-widget-text-editor\" data-id=\"446d97ee\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p>In our previous blog post, <a href=\"https:\/\/zuniclaw.com\/en\/serbia-personal-data-protection-law\/\">Basic Concepts of The Law on Personal Data Protection In Serbia<\/a>, we explained when the Law applies, what is personal data and what are the principles and legal grounds for personal data processing. In this blog, we will cover the technical measures of personal data protection, the Data Protection Officer, and the rights of the data subject.<\/p><\/div><\/section><div class=\"av-special-heading av-anet3en-1252dc4a805d681a073afa66a8c6bf42 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-13 el_after_av_textblock el_before_av_hr av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">TECHNICAL MEASURES FOR THE PERSONAL DATA PROTECTION<\/h2><\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p>Ensuring the security of personal data stands as a fundamental pillar of the Law. Consequently, the Law mandates the controller to implement appropriate technical, organizational, and personnel measures to ensure that the processing of personal data aligns with legal standards. Moreover, the controller should consider factors such as the nature, scope, context, and purpose of processing, along with conducting a risk assessment concerning the rights and freedoms of individuals.<\/p><p>If needed, the controller has to be able to demonstrate to have acted in compliance with this legal requirement.<\/p><p>Even though it may seem that the above-mentioned provision is imprecise, the Law actually follows the approach of the <a href=\"https:\/\/zuniclaw.com\/en\/personal-data-protection-law-serbia\/\">General Data Protection Regulation (GDPR)<\/a> which takes into account the more and more rapid technological progress as well as various areas in which personal data processing takes place. That is the reason why the Law hesitantly specifies in detail what are the \u201ctechnical, organizational and personnel measures\u201d that the controller should implement.<\/p><p>Once the protection measures have been implemented, they should not be seen as permanent and unchangeable. On the contrary, the controller should assess and update them, if needed.<\/p><p>The security of personal data protection means that the controller and the processor conduct the appropriate technical, organizational, and personnel measures, to ensure the adequate level of security of the personal data in relation to the specific risk threatening their security. When doing that, one should have in mind the degree of technological advancements and the expenses of their implementation, the nature, the scope, the circumstances, and the purpose of processing, as well as the chances of the risk occurring and the degree of risk for the rights and freedoms of natural persons.<\/p><p>The significance of the implementation of the above-mentioned measures is best reflected in the fact that a great number of penalties for violations of the GDPR has been imposed due to the lack of technical security. For example, a penalty of EUR 204,000,000.00 has been imposed upon the company British Airways in the United Kingdom, for the personal data violation due to the hackers\u2019 attack, as we talked about in our news\u00a0<a href=\"https:\/\/zuniclaw.com\/en\/gdpr-breach\/\">British Airways and Marriott International Violated GDPR \u2013 What Consequences Could They Face?.<\/a><\/p><\/div><\/section><div class=\"av-special-heading av-a8by20v-fbe616115b5a63e172b0e1f9fc081252 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-17 el_after_av_textblock el_before_av_heading av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">WHAT CAN YOU DO TO PROTECT THE PERSONAL DATA?<\/h2><\/div><div class=\"av-special-heading av-9tpkq3j-681d709a7a306f7a22dc685ca8390f06 av-special-heading-h2 blockquote modern-quote modern-centered avia-builder-el-18 el_after_av_heading el_before_av_textblock av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">RISK ASSESSMENT<\/h2><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>In order to choose the adequate measures for your company, you will first need to identify which risks threaten the security of the personal data which you process, as well as the probability for those risks and possibilities to become reality.<\/p><\/div><\/section><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p><strong>An example<\/strong>:<\/p><p><strong>If you process personal data in electronic form, the risks which threaten their security might include unauthorized access to the databases, alteration or deleting the personal data, physical damage to servers and other hardware that stores the data, or which are used for other processing operations, due to fire, flood, etc.<\/strong><\/p><\/div><\/section><div class=\"av-special-heading av-9ia41xb-8540b38d520c30bee3561a39536a1f52 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-21 el_after_av_textblock el_before_av_heading av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">PROTECTION MEASURES AGAINST RISKS<\/h2><\/div><div class=\"av-special-heading av-92pe0e7-e753195cc3a6c195086611853a7b1222 av-special-heading-h2 blockquote modern-quote avia-builder-el-22 el_after_av_heading el_before_av_textblock av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">A. PSEUDONYMIZATION<\/h2><\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p><strong>Pseudonymization<\/strong> is personal data processing that disables the connection of personal data with a particular data subject, without using the additional information. In other words, pseudonymization \u201chides\u201d the data subject, but it is still possible to ascertain the identity of that person by using additional information. It is very important to keep such additional information separate, as well as to take technical, organizational, and personnel measures to prevent the attribution of personal data to an identified or identifiable data subject.<\/p><\/div><\/section><div class=\"av-special-heading av-ult5kv-bc750d5a447f16494a749d2e5c17fcf1 av-special-heading-h2 blockquote modern-quote avia-builder-el-24 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">B. ANONYMIZATION<\/h2><\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p><strong>Anonymization<\/strong> is data processing that causes the permanent inability to ascertain the identity of the data subject. Starting from the moment when the personal data are anonymized, you are no longer in the field of the Law on Personal Data Protection i.e. you are no longer obliged to treat that data in accordance with the Law.<\/p><\/div><\/section><div class=\"av-special-heading av-7ypw5z3-4ac19a6e54e56ff31eca2c83657f9a9a av-special-heading-h2 custom-color-heading blockquote modern-quote avia-builder-el-26 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">C. ENCRYPTION<\/h2><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p><strong>Encryption<\/strong> of data is a protection method which encrypts information and enables the access solely to a person which has the encryption key. The encrypted data are shown in unreadable form to whomever wishes to access them without the encryption key.<\/p><\/div><\/section><div class=\"av-special-heading av-7phoaf3-1f7306c230b333731cf88eb26cc79479 av-special-heading-h2 custom-color-heading blockquote modern-quote avia-builder-el-28 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">D. SUPERVISORY AUTHORITIES<\/h2><\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p>Filing systems have to be kept far from the persons who are not authorized to have insight into the filing systems within the company. The compliance process with the Law on Personal Data Protection means that the rights, obligations, and responsibilities of employees in terms of storing and using the filing systems need to be clearly determined. Some data may be available to all employees of the company (for instance, business email addresses), while other data can be available solely to the employees with special authorizations (for example, specific persons within the HR department).<\/p><\/div><\/section><div class=\"av-special-heading av-79bzse7-6e6628c3e99365605415d537ba083f21 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-32 el_after_av_image el_before_av_textblock av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">NOTIFYING THE COMMISSIONER ABOUT THE PERSONAL DATA BREACH<\/h2><\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p>In the event that a personal data breach occurs, regardless of the implementation of the protection measures, which can cause a risk to the rights and freedoms of natural persons, the controller must notify theCommissioner about the breach as soon as possible but within 72 hours as of the date of being aware of the breach.<\/p><p>On the other hand, the processor must notify the controller about every data breach, regardless of the degree of risk to the rights and freedoms of natural persons, without undue delay.<\/p><p>The controller needs to keep a record of all data breaches, which contains details of a breach, the consequences of a breach, and the actions taken for their removal.<\/p><\/div><\/section><div class=\"av-special-heading av-6l59c67-89c013c394a6cfac7792e392d2113e47 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-34 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">NOTIFYING THE DATA SUBJECT ABOUT THE PERSONAL DATA BREACH<\/h2><\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p>If the data breach can cause a high risk to the rights and freedoms of natural persons, the controller needs to notify the data subject, without the undue delay, unless the controller has taken adequate measures as its reaction to the breach.<\/p><p>Therefore, we can see that only a high risk rights and freedoms of natural persons produces the obligation of notification of the data subjects, while the Commissioner has to be notified in case of less significant risk.<\/p><\/div><\/section><div class=\"av-special-heading av-62ruw8v-ef841a1f53c4d59702d28159cd2530f6 av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-38 el_after_av_image el_before_av_heading av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">DATA PROTECTION OFFICER (DPO)<\/h2><\/div><div class=\"av-special-heading av-5s5e18f-4e423d163ce40175e0d61cabe453bda2 av-special-heading-h3 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-39 el_after_av_heading el_before_av_textblock av-inherit-size av-linked-heading\"><h3 class=\"av-special-heading-tag\">When to Designate a DPO?<\/h3><\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p>In general, the controller and the processor <a href=\"https:\/\/www.poverenik.rs\/en\/data-protection\/%D0%BB%D0%B8%D1%86%D0%B5-%D0%B7%D0%B0-%D0%B7%D0%B0%D1%88%D1%82%D0%B8%D1%82%D1%83-%D0%BF%D0%BE%D0%B4%D0%B0%D1%82%D0%B0%D0%BA%D0%B0-%D0%BE-%D0%BB%D0%B8%D1%87%D0%BD%D0%BE%D1%81%D1%82%D0%B8.html\" target=\"_blank\" rel=\"noopener\">may designate a DPO<\/a> but are not obliged to do that. However, when it comes to business entities, the Law on Personal Data Protection stipulates when the assignment of a DPO is mandatory:<\/p><ul><li>The main roles of a controller or a processor consist of the processing activities which, due to their nature, scope, or purposes require regular and systematic supervision of a great number of data subjects;<\/li><li>The main activities of a controller or a processor consist of the processing of special categories of personal data (relating to the racial or ethnical origin, political opinion, religious belief, etc.), on a large scale.<\/li><\/ul><p>If a controller, or a processor, which are legal entities, do not designate a DPO in the above-mentioned cases, they will be sentenced with a fine for a misdemeanor in the range of RSD 50,000 \u2013 RSD 2,000,000.<\/p><p>A controller or a processor is obliged to publish the contact information of a DPO and to deliver them to the Commissioner.<\/p><\/div><\/section><div class=\"av-special-heading av-ivkjcv-15082d5b04a6cfcf2f5dd1e38dc658b6 av-special-heading-h3 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-41 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h3 class=\"av-special-heading-tag\">How to Engage a DPO in Our Company (at a controller or a processor)?<\/h3><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><ul><li>Based on employment.<\/li><li>Based on another contract.<\/li><\/ul><\/div><\/section><div class=\"av-special-heading av-4oe1tsv-4f9809f734065c6d7d2ce8062dfa4d14 av-special-heading-h3 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-43 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h3 class=\"av-special-heading-tag\">Position of the DPO<\/h3><\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p>DPO is available to data subjects, who can turn to the DPO concerning all matters related to the processing of their data, as well as concerning the realization of their rights.<\/p><p>DPO directly responds to the manager of the controller or the processor for the fulfillment of the DPO\u2019s legal obligations.<\/p><p>The Law allows for DPO, besides the activities relating to the personal data protection at the controller or the processor, to perform other activities and fulfill other obligations. The controller or the processor is obliged to ensure that the performance of other activities and the fulfillment of other obligations do not lead the DPO into a conflict of interest.<\/p><\/div><\/section><div class=\"av-special-heading av-fdtse7-0e5f73c24482a07c1b7409959bf260bb av-special-heading-h3 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-45 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h3 class=\"av-special-heading-tag\">What are the Responsibilities of the DPO?<\/h3><\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><ul><li>To inform and provide an opinion to the controller or the processor, as well as to the employees which conduct the processing activities, about their legal obligations concerning the personal data protection;<\/li><li>To supervise the enforcement of the provisions of the Law on Personal Data Protection and other laws, as well as internal regulations of the controller or the processor which are related to the personal data protection, including the matters of division of responsibility, raising awareness and training of the employees which take part in the processing activities, as well as of control;<\/li><li>To provide an opinion, when asked, about the estimation of the impact of processing on personal data protection and to follow the actions taken in relation to that estimation;<\/li><li>To serve as a liaison for collaboration with the Commissioner and to seek advice from the Commissioner regarding matters pertaining to the processing of personal data.<\/li><\/ul><\/div><\/section><div class=\"av-special-heading av-dw07b3-20ab816a134171ed8335820f1af0c6fe av-special-heading-h2 custom-color-heading blockquote modern-quote modern-centered avia-builder-el-47 el_after_av_textblock el_before_av_image av-inherit-size av-linked-heading\"><h2 class=\"av-special-heading-tag\">THE RIGHTS OF A DATA SUBJECT \u2013 OBLIGATIONS OF THE CONTROLLER<\/h2><\/div><div class=\"avia-image-container av-k0gcf5is-4630702dce2f437ddce6ae0f306eb1b7 av-styling- avia-align-center avia-builder-el-48 el_after_av_heading el_before_av_heading \"><div class=\"avia-image-container-inner\"><div class=\"avia-image-overlay-wrap\"><img fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-17496 avia-img-lazy-loading-not-17496 avia_image \" src=\"https:\/\/zuniclaw.com\/wp-content\/uploads\/2019\/09\/THE-RIGHTS-OF-A-DATA-SUBJECT-%E2%80%93-OBLIGATIONS-OF-THE-CONTROLLER.jpg\" sizes=\"(max-width: 1030px) 100vw, 1030px\" srcset=\"https:\/\/zuniclaw.com\/wp-content\/uploads\/2019\/09\/THE-RIGHTS-OF-A-DATA-SUBJECT-\u2013-OBLIGATIONS-OF-THE-CONTROLLER.jpg 1030w, https:\/\/zuniclaw.com\/wp-content\/uploads\/2019\/09\/THE-RIGHTS-OF-A-DATA-SUBJECT-\u2013-OBLIGATIONS-OF-THE-CONTROLLER-300x203.jpg 300w, https:\/\/zuniclaw.com\/wp-content\/uploads\/2019\/09\/THE-RIGHTS-OF-A-DATA-SUBJECT-\u2013-OBLIGATIONS-OF-THE-CONTROLLER-768x519.jpg 768w, https:\/\/zuniclaw.com\/wp-content\/uploads\/2019\/09\/THE-RIGHTS-OF-A-DATA-SUBJECT-\u2013-OBLIGATIONS-OF-THE-CONTROLLER-705x476.jpg 705w\" alt=\"\" width=\"1030\" height=\"696\" \/><\/div><\/div><\/div><div class=\"av-special-heading av-3kmrrj3-6e1f9851d3db54f417e5cf7f5b595d1f av-special-heading-h3 custom-color-heading blockquote modern-quote avia-builder-el-49 el_after_av_image el_before_av_textblock av-inherit-size av-linked-heading\"><h3 class=\"av-special-heading-tag\">RIGHT TO BE INFORMED<\/h3><\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p>If the data are collected from a person to whom that data is related, the controller has to provide that person with the information which the Law prescribes at the moment of collecting the data, such as identity and the contact information of the controller, the contact information of the DPO, the purpose of the intended processing and legal basis for processing, the recipients, the period of storage of the personal data, the rights of the data subject in relation to their data, as well as other information.<\/p><\/div><\/section><div class=\"av-special-heading av-2y0f2an-c6e2ead62396159a4f8d080661010f33 av-special-heading-h3 custom-color-heading blockquote modern-quote avia-builder-el-51 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h3 class=\"av-special-heading-tag\">RIGHT OF ACCESS<\/h3><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>The data subject is entitled to request information from the controller whether the controller processes their personal data, to request access to that data, as well as information about the purpose of processing, about the types of data which are processed, about the period of storage of personal data, about the rights of the data subject in terms of processing of their data, and other information.<\/p><p>The controller is obliged to, after the request of the data subject, deliver a copy of the personal data which it processes, which are related to that data subject.<\/p><\/div><\/section><div class=\"av-special-heading av-2ge1p8f-c2f980fab6b187f0393e1ea5a980d03b av-special-heading-h3 custom-color-heading blockquote modern-quote avia-builder-el-55 el_after_av_image el_before_av_textblock av-inherit-size av-linked-heading\"><h3 class=\"av-special-heading-tag\">RIGHT TO RECTIFICATION<\/h3><\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p>If the personal data are inaccurate, the data subject is entitled to ask the controller to correct the datawithout undue delay.<\/p><p>If the personal data is incomplete, taking into account the processing purpose, the data subject is entitled to supplement their personal data.<\/p><\/div><\/section><div class=\"av-special-heading av-83omqn-48688f7e6a5e4cf034f4a3f2b2e58987 av-special-heading-h3 custom-color-heading blockquote modern-quote avia-builder-el-57 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h3 class=\"av-special-heading-tag\">RIGHT TO ERASURE<\/h3><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>The data subject has the right to request the deletion of their personal data from the controller.<\/p><p>The controller is obliged to erase the personal data if:<\/p><ul><li>the personal data are no longer necessary for the fulfillment of the purpose for which they have been collected or otherwise processed;<\/li><\/ul><ul><li>the data subject revoked their consent based on which the processing has been conducted, and there is no other legal ground for the processing;<\/li><\/ul><ul><li>the data subject filed their objection on the processing of their personal data;<\/li><\/ul><ul><li>the personal data have been unlawfully processed;<\/li><\/ul><ul><li>the personal data have to be erased for the fulfillment of the controller\u2019s legal obligations.<\/li><\/ul><p>If the controller had publicly published the personal data, their obligation to erase the data includes taking all reasonable measures for notification of other controllers which process that data that the data subject filed the request for the erasure of all copies of this data and referrals, i.e. electronic links towards these data.<\/p><\/div><\/section><div class=\"av-special-heading av-l9jrz-51b352cb7dd655e21962fc9bd9529f16 av-special-heading-h3 custom-color-heading blockquote modern-quote avia-builder-el-59 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h3 class=\"av-special-heading-tag\">RIGHT TO RESTRICTION OF PROCESSING<\/h3><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>The data subject is entitled to have their personal data processing restricted by the controller in the following cases:<\/p><ul><li>When the data subject disputes the accuracy of the personal data, in the period which enables the controller to check the accuracy of this data;<\/li><\/ul><ul><li>When the processing is unlawful and the data subject is against the erasure of data and, instead of erasure, requests the restriction of the use of the data;<\/li><\/ul><ul><li>When the controller no longer needs the personal data for the fulfillment of the processing purpose, but the data subject asked for them the filing, the realization or the legal request defense;<\/li><li>When the data subject filed the objection on the data processing, and while the estimation of whether the legal ground for the processing by the controller outweighs the interests of the data subject is taking place.<\/li><\/ul><\/div><\/section><div class=\"av-special-heading av-13f570f-d5b1a70be1aace108f64af65b4410540 av-special-heading-h3 custom-color-heading blockquote modern-quote avia-builder-el-63 el_after_av_image el_before_av_textblock av-inherit-size av-linked-heading\"><h3 class=\"av-special-heading-tag\">\u00a0<\/h3><h3 class=\"av-special-heading-tag\">RIGHT TO DATA PORTABILITY<\/h3><\/div><section class=\"av_textblock_section av-kk59h4i-3bd2149cb8a130352f722c6fc9bf1b0d\"><div class=\"avia_textblock\"><p>The data subject is entitled to transfer their personal data, which it had previously delivered to the controller, to another controller without interference by the controller to whom that data had been initially delivered, if:<\/p><p>1) the processing is based on the consent of the data subject or it is based on the contract;<\/p><p>2) the processing is performed automatically.<\/p><p>The right to data portability also includes direct transfer from the previous to the new controller.<\/p><\/div><\/section><div class=\"av-special-heading av-ji4v6n-2c5b25a99d5b8821a880ecb90b7cf38b av-special-heading-h3 custom-color-heading blockquote modern-quote avia-builder-el-65 el_after_av_textblock el_before_av_textblock av-inherit-size av-linked-heading\"><h3 class=\"av-special-heading-tag\">RIGHT TO OBJECT<\/h3><\/div><section class=\"av_textblock_section av-kk59h4i-86bdef1decbcf57c6d1793bd34733046\"><div class=\"avia_textblock\"><p>The data subject is entitled to, at any time, file an objection against the processing of their personal data to the controller, which is performed in accordance with the public interest or the fulfillment of the legal authorizations of the controller, or the legitimate interests of the controller or the third party, as the legal grounds of the processing.<\/p><p>The controller is obliged to stop the processing of the data of the person who filed the objection, unless it can prove that there are legal reasons for the processing that outweigh the interests, rights, or freedoms of the data subjects or are related to the filing of, the realization of or the legal claim defense.<\/p><p>Finally, in the third and final text in our series of texts about the Law on Personal Data Protection the penalty provisions of the Law.<\/p><\/div><\/section>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>In our previous blog post, Basic Concepts of The Law on Personal Data Protection In Serbia, we explained when the Law applies, what is personal data and what are the principles and legal grounds for personal data processing. In this blog, we will cover the technical measures of personal data protection, the Data Protection Officer, [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":68278,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[126,128,184],"class_list":["post-40422","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-privacy-data-protection-en","category-labor-employment","category-privatnost-i-zastita-podataka-ru"],"_links":{"self":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts\/40422","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/comments?post=40422"}],"version-history":[{"count":43,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts\/40422\/revisions"}],"predecessor-version":[{"id":60059,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/posts\/40422\/revisions\/60059"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/media\/68278"}],"wp:attachment":[{"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/media?parent=40422"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zuniclaw.com\/en\/wp-json\/wp\/v2\/categories?post=40422"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}