| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Implementacija GDPR v organizacijo : študija primera izvajalca
Authors:ID Pavli, Kristina (Author)
ID Dvojmoč, Miha (Mentor) More about this mentor... New window
Files:.pdf MAG_Pavli_Kristina_2022.pdf (2,68 MB)
MD5: CC62343292F903134F2351855E6CC6A2
 
Language:Slovenian
Work type:Master's thesis/paper
Typology:2.09 - Master's Thesis
Organization:FVV - Faculty of Criminal Justice and Security
Abstract:Nesprejetje novega nacionalnega Zakona o varstvu osebnih podatkov (ZVOP-2) na izpolnjevanje zakonskih skladnosti v organizacijah vpliva negativno. Onemogoča polno uveljavljanje Splošne uredbe o varstvu podatkov (GDPR), urejanje določenih področij v luči obstoječega zakona ZVOP-1 je nepregledno, določene določbe pa je nujno v celoti nadomestiti s posodobitvami upoštevajoč GDPR. Oteženo je tudi delo nadzornega organa, tj. Informacijskega pooblaščenca Republike Slovenije (IP). Težave imajo tudi izvajalci implementacije GDPR v organizacijah, kar se ugotavlja preko študije primera izvajalca v tem delu. Med ključna področja in poudarke področja varstva osebnih podatkov pri implementaciji se uvrščajo vgrajeno in privzeto varstvo podatkov, načela in pravne podlage za obdelavo osebnih podatkov, veljavna privolitev, transparentnost obdelave z zagotavljanjem informacij do osebnih podatkov (za posameznike), izvajanje pravic posameznikov, pogodbe o pogodbeni obdelavi osebnih podatkov, evidenca dejavnosti obdelave, varnost obdelave, kršitve varstva osebnih podatkov, ocena učinka v zvezi z varstvom podatkov, pooblaščena oseba za varstvo podatkov, prenos podatkov v tretje države ali mednarodne organizacije. Za implementacijo so pomembni še analiza stanja pred vpeljavo in obdobne revizije, preko katerih se prepozna stanje sistema v organizaciji in izpostavijo pomanjkljivosti za podajo priporočil za potrebno nadgradnjo. Upoštevati je potrebno pravni in informacijsko-tehnološki (IT) vidik skladnosti, priporoča se uporaba PDCA kroga, implementacija pa je na ta način (preko načrtovanja, izvajanja, preverjanja in ukrepanja) stalno, kontinuirano dejanje, ki zaradi zahtev poslovnega in zakonodajnega okolja zahteva celovit oziroma sistemski pristop. K njemu v svojih smernicah in priporočilih stremi tako nadzorni organ kot tudi izvajalec implementacije, kar se odraža v obravnavani dokumentaciji.
Keywords:osebni podatki, upravljanje z osebnimi podatki, podjetja, varstvo osebnih podatkov, GDPR, implementacija GDPR, študija primera, magistrska dela
Place of publishing:Ljubljana
Place of performance:Ljubljana
Publisher:[K. Pavli]
Year of publishing:2022
Year of performance:2022
Number of pages:XIII f., 99 str.
PID:20.500.12556/DKUM-82630 New window
UDC:342.738(043.2)
COBISS.SI-ID:122977027 New window
Publication date in DKUM:26.09.2022
Views:1185
Downloads:181
Metadata:XML DC-XML DC-RDF
Categories:FVV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:28.08.2022

Secondary language

Language:English
Title:Implementation of GDPR in an organisation: contractor case study : magistrsko delo
Abstract:The failure to adopt the new Personal Data Protection Act (ZVOP-2) has a negative impact on the fulfillment of legal compliance in organizations. It prevents the full enforcement of the General Data Protection Regulation (GDPR), the regulation of certain areas in the light of the existing Act ZVOP-1 is unclear, and certain provisions must be completely replaced with updates taking into account the GDPR. The work of the supervisory authority is also made more difficult, i.e. Information Commissioner of the Republic of Slovenia. GDPR implementation contractors in organizations also have problems, which is established through the case study of the contractor in this master's thesis. Key aspects and highlights of the field of personal data protection and GDPR implementation include: data protection by design and by default, principles relating to processing of personal data and lawfulness of processing, conditions for (valid) consent, transparency with information and access to personal data (for data subjects), exercise of individual's rights, contractual processing of personal data, records of processing activities, security of processing, data breaches and notifications (to the supervisory authority and to the data subject), data protection impact assessment, Designation of the data protection officer, transfer of personal data to third countries or international organizations. Analysis of the situation before implementation and periodic audits are also important for implementation, in order to assess the state of the system in the organization by highlighting shortcomings and giving recommendations for the necessary upgrade. It is necessary to take into account the legal and information technology (IT) aspects of compliance, the use of the PDCA circle is recommended, and implementation in this way (through planning, implementation, verification and action) is a constant, continuous action, which, due to the requirements of the business and legislative environment, requires a comprehensive or systematic approach. In their guidelines and recommendations, both the supervisory authority and the implementation contractor strive for it, which is reflected in the reviewed documentation.


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica