Article 27
Representatives of controllers not established in the Union
There is no recital in the Directive related to article 27.
|
Regulation
Art. 27 1. Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union. 2. The obligation laid down in paragraph 1 of this Article shall not apply to: a) processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or b) a public authority or body. 3. The representative shall be established in one of the Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are. 4. The representative shall be mandated by the controller or processor to be addressed in addition to or instead of the controller or the processor by, in particular, supervisory authorities and data subjects, on all issues related to processing, for the purposes of ensuring compliance with this Regulation. 5. The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves.
|
Directive
Art. 4 1. Each Member State shall apply the national provisions it adopts pursuant to this Directive to the processing of personal data where: (a) the processing is carried out in the context of the activities of an establishment of the controller on the territory of the Member State; when the same controller is established on the territory of several Member States, he must take the necessary measures to ensure that each of these establishments complies with the obligations laid down by the national law applicable; (b) the controller is not established on the Member State's territory, but in a place where its national law applies by virtue of international public law; (c) the controller is not established on Community territory and, for purposes of processing personal data makes use of equipment, automated or otherwise, situated on the territory of the said Member State, unless such equipment is used only for purposes of transit through the territory of the Community. 2. In the circumstances referred to in paragraph 1 (c), the controller must designate a representative established in the territory of that Member State, without prejudice to legal actions which could be initiated against the controller himself. |
Poland
Starting from May 25, 2018 GDPR came into force and is fully aplicable in Poland. The Act on Protection of Personal Data of 29th August 1997 [unified text: Journal of Laws 2015, item 2135, 2281] is not in force since May 25, 2018. It was replaced by new regulation - The Act on Personal Data Protection of 10th May 2018, which implements GDPR in Poland. The Act on Personal Data Protection of 10th May 2018: Article 2 [Exclusion of the application of certain provisions of Regulation 2016/679] 1. The provisions of Articles 5 to 9, Article 11, Articles 13 to 16, Articles 18 to 22, Article 27, Article 28(2) to (10), and Article 30 of Regulation 2016/679 shall not apply to activities consisting in the editing, preparation, creation or publication of press materials within the meaning of the Act of 26 January 1984 — Press Law (Journal of Laws of 2018, item 1914), as well as to statements made in the course of literary or artistic activity. 2. The provisions of Article 13, Article 15(3) and (4), Article 18, Article 27, Article 28(2) to (10), and Article 30 of Regulation 2016/679 shall not apply to academic ex |
