{"id":9258,"date":"2018-04-05T07:13:51","date_gmt":"2018-04-05T05:13:51","guid":{"rendered":"http:\/\/zurnalsiepirkumi.lv\/?p=9258"},"modified":"2018-04-05T08:05:41","modified_gmt":"2018-04-05T06:05:41","slug":"vai-esi-gatavs-visparigai-datu-aizsardzibas-regulai","status":"publish","type":"post","link":"https:\/\/zurnalsiepirkumi.lv\/?p=9258","title":{"rendered":"Vai esi gatavs Visp\u0101r\u012bgai datu aizsardz\u012bbas regulai?"},"content":{"rendered":"<p>Jau pavisam dr\u012bz, 2018.gada 25.maij\u0101, sp\u0113k\u0101 st\u0101sies Visp\u0101r\u012bg\u0101 datu aizsardz\u012bbas regula (turpm\u0101k \u2013 Regula), un t\u0101s pras\u012bbas attieksies uz komersantiem (tostarp maziem un vid\u0113jiem uz\u0146\u0113mumiem), da\u017e\u0101d\u0101m organiz\u0101cij\u0101m, valsts un pa\u0161vald\u012bbas iest\u0101d\u0113m, k\u0101 ar\u012b fizisk\u0101m person\u0101m. L\u012bdz \u0161im personas datu aizsardz\u012bbas joma Eiropas Savien\u012bbas l\u012bmen\u012b bija regul\u0113ta ar direkt\u012bvas pal\u012bdz\u012bbu, kuras normas bija ieviestas Fizisko personu datu aizsardz\u012bbas likum\u0101. No regul\u0113juma viedok\u013ca b\u016btisk\u0101k\u0101 at\u0161\u0137ir\u012bba ir t\u0101da, ka Regulas normas tiks piem\u0113rotas tie\u0161i. Vienlaikus atsevi\u0161\u0137us jaut\u0101jumus aizvien regul\u0113s nacion\u0101laj\u0101 l\u012bmen\u012b, un \u0161obr\u012bd izskat\u012b\u0161anai Saeim\u0101 ir nodots likumprojekts \u201cPersonas datu apstr\u0101des likums\u201d.<\/p>\n<p>Viens no iemesliem, k\u0101d\u0113\u013c Regulai tiek piev\u0113rsta pastiprin\u0101ta uzman\u012bba, saist\u012bts ar iesp\u0113ju piem\u0113rot iev\u0113rojamus administrat\u012bvos naudas sodus par datu aizsardz\u012bbas p\u0101rk\u0101pumiem. Ja l\u012bdz \u0161im liel\u0101kais sods, ko paredz Latvijas Administrat\u012bvo p\u0101rk\u0101pumu kodekss par p\u0101rk\u0101pumiem datu aizsardz\u012bbas jom\u0101, ir 14 000 eiro, tad Regula paredz sodus l\u012bdz pat 20 miljoniem eiro vai uz\u0146\u0113muma gad\u012bjum\u0101 l\u012bdz 4% no uz\u0146\u0113muma kop\u0113j\u0101 vis\u0101 pasaul\u0113 iepriek\u0161\u0113j\u0101 gad\u0101 g\u016bt\u0101 apgroz\u012bjuma. Tiesa, bie\u017ei vien Regul\u0101 ietverto sodu piesauk\u0161ana tiek izmantota, lai baid\u012btu uz\u0146\u0113m\u0113jus un praks\u0113 tik lieli sodi Latvij\u0101 var\u0113tu ar\u012b nekad netikt piem\u0113roti. Datu valsts inspekcija ir aprobe\u017eojusies ar pietic\u012bg\u0101k\u0101m prognoz\u0113m un Personas datu apstr\u0101des likumprojekta anot\u0101cij\u0101 ir ietverta inform\u0101cija, ka sodos pl\u0101nots iekas\u0113t kopum\u0101 461 t\u016bkstoti eiro gad\u0101. Tom\u0113r tas liecina, ka kontrole p\u0101r Regulas iev\u0113ro\u0161anu tiks \u012bstenota un pret personas datu aizsardz\u012bbu b\u016btu j\u0101attiecas pavisam nopietni. Turkl\u0101t nedr\u012bkst\u0113tu aizmirst, ka par p\u0101rk\u0101pumiem \u0161aj\u0101 jom\u0101 var tikt piem\u0113rota ne tikai administrat\u012bv\u0101 atbild\u012bba, bet pat krimin\u0101latbild\u012bba, k\u0101 ar\u012b datu subjekti sev nodar\u012bto kait\u0113jumu var piedz\u012bt ar\u012b civiltiesisk\u0101 k\u0101rt\u012bb\u0101.<br \/>\n<!--more--><br \/>\nRegula paredz se\u0161us personas datu apstr\u0101des pamatprincipus, kuri j\u0101iev\u0113ro, lai datu apstr\u0101di var\u0113tu uzskat\u012bt par atbilsto\u0161u Regulas pras\u012bb\u0101m. Turkl\u0101t uz\u0146\u0113mumam vai iest\u0101dei ir j\u0101sp\u0113j uzskat\u0101mi demonstr\u0113t, ka \u0161ie principi tik tie\u0161\u0101m tiek iev\u0113roti, apstr\u0101d\u0101jot personas datus:<\/p>\n<ol>\n<li> Personas dati tiek apstr\u0101d\u0101ti likum\u012bgi, godpr\u0101t\u012bgi un datu subjektam p\u0101rredzam\u0101 veid\u0101;\n<li> Tie tiek v\u0101kti konkr\u0113tos, skaidros un le\u0123it\u012bmos nol\u016bkos, un to turpm\u0101ku apstr\u0101di neveic ar min\u0113tajiem nol\u016bkiem nesavietojam\u0101 veid\u0101;\n<li> Dati ir adekv\u0101ti, atbilst\u012bgi un ietver tikai to, kas nepiecie\u0161ams to apstr\u0101des nol\u016bkos;\n<li> Dati ir prec\u012bzi un, ja vajadz\u012bgs, atjaunin\u0101ti; ir j\u0101veic visi sapr\u0101t\u012bgi pas\u0101kumi, lai nodro\u0161in\u0101tu, ka neprec\u012bzi personas dati, \u0146emot v\u0113r\u0101 nol\u016bkus, k\u0101dos tie tiek apstr\u0101d\u0101ti, bez kav\u0113\u0161an\u0101s tiktu dz\u0113sti vai laboti;\n<li> Tie tiek glab\u0101ti veid\u0101, kas pie\u013cauj datu subjektu identifik\u0101ciju, ne ilg\u0101k k\u0101 nepiecie\u0161ams nol\u016bkiem, k\u0101dos attiec\u012bgos personas datus apstr\u0101d\u0101;\n<li> Dati tiek apstr\u0101d\u0101ti t\u0101d\u0101 veid\u0101, lai tiktu nodro\u0161in\u0101ta atbilsto\u0161a personas datu dro\u0161\u012bba, tostarp aizsardz\u012bba pret neat\u013cautu vai nelikum\u012bgu apstr\u0101di un pret nejau\u0161u nozaud\u0113\u0161anu, izn\u012bcin\u0101\u0161anu vai saboj\u0101\u0161anu, izmantojot atbilsto\u0161us tehniskos vai organizatoriskos pas\u0101kumus.\n<\/ol>\n<p>Lai iev\u0113rotu \u0161os principus, k\u0101 ar\u012b konkr\u0113t\u0101kas no Regulas izrieto\u0161as pras\u012bbas un sp\u0113tu demonstr\u0113t atbilst\u012bbu, uz\u0146\u0113mumam vai iest\u0101dei ir svar\u012bgi apzin\u0101t, k\u0101di dati un k\u0101p\u0113c tiek apstr\u0101d\u0101ti. Ja personas datu aizsardz\u012bbai l\u012bdz \u0161im nav piev\u0113rsta \u012bpa\u0161a uzman\u012bba, \u013coti iesp\u0113jams, ka \u0161obr\u012bd uz\u0146\u0113mum\u0101 vai iest\u0101d\u0113 gadu gait\u0101 ir uzkr\u0101ts liels apjoms personas datu, un neviens vairs neatceras, k\u0101 \u0161\u0101di dati tika ieg\u016bti, k\u0101p\u0113c tie tika ieg\u016bti un vai \u0161ie dati visp\u0101r ir aktu\u0101li un nepiecie\u0161ami. Izv\u0113rt\u0113jot, vai uz\u0146\u0113mums vai iest\u0101de ir sagatavojusies Regulai, b\u016btu v\u0113lams apsv\u0113rt un nepiecie\u0161am\u012bbas gad\u012bjum\u0101 dokument\u0113t atbildes uz vismaz \u0161\u0101diem jaut\u0101jumiem: <\/p>\n<ol>\n<li> K\u0101dus personas datus es apstr\u0101d\u0101ju? Vai personas datus apstr\u0101d\u0101ju kop\u0101 ar citu uz\u0146\u0113mumu vai iest\u0101di? Vai apstr\u0101d\u0101ju \u012bpa\u0161o kategoriju datus, personas datus par sod\u0101m\u012bbu un p\u0101rk\u0101pumiem un\/vai nepilngad\u012bgu personu datus? Vai dati ir aktu\u0101li un pareizi?\n<li> K\u0101p\u0113c man\u0101 r\u012bc\u012bb\u0101 ir personas dati un k\u0101diem nol\u016bkiem tos \u0161obr\u012bd izmantoju? K\u0101ds bija s\u0101kotn\u0113jais iemesls, k\u0101p\u0113c \u0161\u0101di dati tika ieg\u016bti? Vai datu apstr\u0101des nol\u016bks ir prec\u012bzi formul\u0113ts, skaidrs un noteikts pirms datu ieg\u016b\u0161anas? Vai \u0161obr\u012bd nepiecie\u0161ami visi ieg\u016btie dati vai pietiek tikai ar da\u013cu no tiem, vai varb\u016bt dati vair\u0101k nav nepiecie\u0161ami? Kur\u0161 konkr\u0113ti no Regul\u0101 min\u0113tajiem tiesiskajiem pamatiem dod man ties\u012bbas apstr\u0101d\u0101t personas datus? Vai es varu pier\u0101d\u012bt un pamatot \u0161\u0101du tiesisko pamatu datu apstr\u0101dei?\n<li> K\u0101d\u0101 veid\u0101 es ieguvu personas datus (persona pati sniedza datus vai tos ieguvu cit\u0101 veid\u0101)? Ja datus ieguvu, pamatojoties uz personas piekri\u0161anu, vai esmu izv\u0113rt\u0113jis, vai piekri\u0161ana atbilst Regulas pras\u012bb\u0101m?\n<li> Cik ilgi es glab\u0101ju personas datus? K\u0101ds ir pamatojums \u0161\u0101dam laika posmam? Vai ir noteikts, kas, kad un k\u0101 dz\u0113\u0161 neprec\u012bzus vai nevajadz\u012bgus datus?\n<li> Vai datus esmu nodevis, nododu vai var\u0113tu nodot ar\u012b tre\u0161aj\u0101m person\u0101m? K\u0101d\u0101m person\u0101m un uz k\u0101da pamata es nododu personas datus? Vai personu datu nodo\u0161ana cit\u0101m person\u0101m atbilst Regulas pras\u012bb\u0101m? Ja nododu personas datus uz cit\u0101m valst\u012bm, vai esmu nodro\u0161in\u0101jis visu nepiecie\u0161amo personas datu aizsardz\u012bbu atbilsto\u0161i Regulas pras\u012bb\u0101m?\n<li> Vai esmu veicis pas\u0101kumus, lai nodro\u0161in\u0101tu, ka, ieg\u016bstot personas datus, es sniedzu visu oblig\u0101to inform\u0101ciju personai (datu subjektam) saska\u0146\u0101 ar Regulas pras\u012bb\u0101m? Vai priv\u0101tuma pazi\u0146ojumi, cookies pazi\u0146ojumi, pazi\u0146ojumi, veicot videonov\u0113ro\u0161anu, atbilst Regulas pras\u012bb\u0101m?\n<li> Vai esmu gatavs personas (datu subjekta) piepras\u012bjumam, ar kuru \u0161\u012b persona \u012bstenotu savas ties\u012bbas saska\u0146\u0101 ar Regulu? Cik ilgu laiku man pras\u012bs konstat\u0113t, kur glab\u0101jas personas dati vis\u0101s man\u0101s sist\u0113m\u0101s, datu b\u0101z\u0113s un pap\u012bra failos? Vai ir noz\u012bm\u0113tas atbild\u012bg\u0101s personas par personas datu labo\u0161anu, dz\u0113\u0161anu? Vai manas datu sist\u0113mas sp\u0113s nodro\u0161in\u0101t datu p\u0101rnesam\u012bbu saska\u0146\u0101 ar Regulu?\n<li> Vai ir ieviesti atbilsto\u0161i personas datu dro\u0161\u012bbas un konfidencialit\u0101tes pas\u0101kumi? Vai datiem var piek\u013c\u016bt tikai autoriz\u0113tas personas un tikai t\u0101d\u0101 apjom\u0101, k\u0101 nepiecie\u0161ams? Vai sp\u0113ju izsekot, kas un k\u0101d\u0101 apm\u0113r\u0101 ir piek\u013cuvis personas datiem? Vai esmu nosl\u0113dzis atbilsto\u0161us konfidencialit\u0101tes l\u012bgumus? Vai esmu apstiprin\u0101jis un ieviesis datu dro\u0161\u012bbas politikas?\n<li> Vai iek\u0161\u0113jie dokumenti, kas regul\u0113 datu apstr\u0101di (datu apstr\u0101des noteikumi, procesu apraksti, proced\u016bras) atbilst Regulas pras\u012bb\u0101m un re\u0101lajai situ\u0101cijai uz\u0146\u0113mum\u0101 vai iest\u0101d\u0113?\n<li> Vai, ievie\u0161ot jaunus procesus, sist\u0113mas, produktus, apsveru un \u0146emu v\u0113r\u0101 datu aizsardz\u012bbas noteikumus (priv\u0101tumu p\u0113c noklus\u0113juma)?\n<li> Vai esmu p\u0101rskat\u012bjis l\u012bguma nosac\u012bjumus ar datu apstr\u0101d\u0101t\u0101jiem (piem\u0113ram, apsardzes firmu, kas veic videonov\u0113ro\u0161anu, gr\u0101matved\u012bbas firmu, kas \u0101rpakalpojum\u0101 apstr\u0101d\u0101 darbinieku datus, u.c.) un \u0161o noteikumu atbilst\u012bbu Regulas pras\u012bb\u0101m? Vai esmu ieviesis proced\u016bru, k\u0101 izv\u0113rt\u0113ju datu apstr\u0101d\u0101t\u0101ju atbilst\u012bbu Regulas pras\u012bb\u0101m?\n<li> Vai esmu izv\u0113rt\u0113jis, vai saska\u0146\u0101 ar Regulu ir nepiecie\u0161ams iecelt datu aizsardz\u012bbas speci\u0101listu? (Datu aizsardz\u012bbas speci\u0101lista iecel\u0161ana ir oblig\u0101ta valsts un pa\u0161vald\u012bbu iest\u0101d\u0113m (iz\u0146emot tiesas), savuk\u0101rt citos gad\u012bjumos j\u0101v\u0113rt\u0113, vai saska\u0146\u0101 ar Regulu datu speci\u0101lista iecel\u0161ana ir nepiecie\u0161ama).\n<li> Vai esmu gatavs savlaic\u012bgi (saska\u0146\u0101 ar Regulu ne v\u0113l\u0101k k\u0101 72 stundu laik\u0101 no br\u012b\u017ea, kad k\u013cuva zin\u0101ms par p\u0101rk\u0101pumu) identific\u0113t personas datu aizsardz\u012bbas p\u0101rk\u0101pumu un zi\u0146ot par to Datu valsts inspekcijai, k\u0101 ar\u012b datu subjektam? Vai ir noz\u012bm\u0113tas atbild\u012bg\u0101s personas par \u0161o noteikumu iev\u0113ro\u0161anu un izstr\u0101d\u0101tas atbilsto\u0161as proced\u016bras un r\u012bc\u012bbas pl\u0101ns?\n<li> Vai uz\u0146\u0113muma vai iest\u0101des darbinieki ir inform\u0113ti un apm\u0101c\u012bti datu aizsardz\u012bbas jom\u0101 (ne tikai form\u0101li)?\n<li> Vai esmu nodro\u0161in\u0101jis regul\u0101ras p\u0101rbaudes un atbilst\u012bbas izv\u0113rt\u0113juma veik\u0161anu Regulas pras\u012bb\u0101m?\n<\/ol>\n<p>Sp\u0113ja god\u012bgi apsv\u0113rt un sniegt atbildes uz min\u0113tajiem jaut\u0101jumiem, ir noz\u012bm\u012bgs s\u0101kuma punkts uz\u0146\u0113mumam vai iest\u0101dei ce\u013c\u0101 uz atbilst\u012bbu Regulas pras\u012bb\u0101m. Tom\u0113r, lai past\u0101v\u012bgi nodro\u0161in\u0101tu atbilst\u012bbu, ir j\u0101ievie\u0161 procesi un proced\u016bras, ar kuru pal\u012bdz\u012bbu iesp\u0113jams regul\u0101ri un efekt\u012bvi sekot l\u012bdzi datu aizsardz\u012bbas pras\u012bbu izpildei.<\/p>\n<p><b>Kalvis Kr\u016bmi\u0146\u0161<\/b>, advok\u0101ts ZAB TGS Baltic, sertific\u0113ts datu aizsardz\u012bbas speci\u0101lists<br \/>\n<b>Dace Ind\u0101ne<\/b>, advok\u0101te ZAB TGS Baltic, sertific\u0113ta datu aizsardz\u012bbas speci\u0101liste<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Jau pavisam dr\u012bz, 2018.gada 25.maij\u0101, sp\u0113k\u0101 st\u0101sies Visp\u0101r\u012bg\u0101 datu aizsardz\u012bbas regula (turpm\u0101k \u2013 Regula), un t\u0101s pras\u012bbas attieksies uz komersantiem (tostarp maziem un vid\u0113jiem uz\u0146\u0113mumiem), da\u017e\u0101d\u0101m organiz\u0101cij\u0101m, valsts un pa\u0161vald\u012bbas iest\u0101d\u0113m, k\u0101 ar\u012b fizisk\u0101m person\u0101m. L\u012bdz \u0161im personas datu aizsardz\u012bbas joma Eiropas Savien\u012bbas l\u012bmen\u012b bija regul\u0113ta ar direkt\u012bvas pal\u012bdz\u012bbu, kuras normas bija ieviestas Fizisko personu datu aizsardz\u012bbas likum\u0101. No regul\u0113juma viedok\u013ca b\u016btisk\u0101k\u0101 at\u0161\u0137ir\u012bba ir t\u0101da, ka Regulas normas tiks piem\u0113rotas tie\u0161i. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[71,1],"tags":[],"_links":{"self":[{"href":"https:\/\/zurnalsiepirkumi.lv\/index.php?rest_route=\/wp\/v2\/posts\/9258"}],"collection":[{"href":"https:\/\/zurnalsiepirkumi.lv\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zurnalsiepirkumi.lv\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zurnalsiepirkumi.lv\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zurnalsiepirkumi.lv\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9258"}],"version-history":[{"count":3,"href":"https:\/\/zurnalsiepirkumi.lv\/index.php?rest_route=\/wp\/v2\/posts\/9258\/revisions"}],"predecessor-version":[{"id":9319,"href":"https:\/\/zurnalsiepirkumi.lv\/index.php?rest_route=\/wp\/v2\/posts\/9258\/revisions\/9319"}],"wp:attachment":[{"href":"https:\/\/zurnalsiepirkumi.lv\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9258"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zurnalsiepirkumi.lv\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9258"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zurnalsiepirkumi.lv\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9258"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}