{"title":"Facebook-hack: stress test for Irish DPC","authors":"Thomas Kahler","doi":"10.5771/9783748921561-71","DOIUrl":null,"url":null,"abstract":"The Facebook-hack provides evidence that new instruments of GDPR are having significant effect. Firstly, Facebook was required to notify the respective DPA of the incident within 72 hours according to Art. 33 GDPR. Secondly, Facebook adressed the hack to the Irish DPC as lead authority. According to Art. 56 GDPR the Irish DPC is the lead authority for Facebook within the EU. Facebook has its headquarters, which dertermines the purpose and means of the data processing of the Group, in Ireland. Following the principle of 'one stop shop' Facebook solely has to report the incident to one single DPA and not to any national DPA within the EU.1","PeriodicalId":326055,"journal":{"name":"Turning Point in Data Protection Law","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-10-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Turning Point in Data Protection Law","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.5771/9783748921561-71","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
The Facebook-hack provides evidence that new instruments of GDPR are having significant effect. Firstly, Facebook was required to notify the respective DPA of the incident within 72 hours according to Art. 33 GDPR. Secondly, Facebook adressed the hack to the Irish DPC as lead authority. According to Art. 56 GDPR the Irish DPC is the lead authority for Facebook within the EU. Facebook has its headquarters, which dertermines the purpose and means of the data processing of the Group, in Ireland. Following the principle of 'one stop shop' Facebook solely has to report the incident to one single DPA and not to any national DPA within the EU.1