<div dir="ltr">



















<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US">Eduardo,<span></span></span></p>

<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US"><span> </span></span></p>

<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US">This
statement is false in part. <span></span></span></p>

<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US"><span> </span></span></p>

<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US">It is
referring to the last paragraph of the <u>article 30 of the GDPR</u> that states:<span></span></span></p>

<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US"><span> </span></span></p>



<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US"><i>The
obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise
or an organisation employing fewer than 250 persons unless the processing it
carries out is likely to result in a risk to the rights and freedoms of data
subjects, the processing is not occasional, or the processing includes special
categories of data as referred to in Article 9(1) or personal data relating to
criminal convictions and offences referred to in Article 10.</i><span></span></span></p>

<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US"><span> </span></span></p>

<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US">The
obligations referred to in paragraphs 1 and 2 are the maintaining of a record
of processing activities under the responsibility of the controllers and the
same obligation to the processor about this record of processing activities. <span></span></span></p>

<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US"><span> </span></span></p>

<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US">It means,
the firms which have 250 employees or less still have to comply with all GDPR
rules as standard but no with the referred obligations about the record of processing
activities (with the exceptions of the same article 30).<span></span></span></p>

<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US"><span> </span></span></p>

<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US">Best
Regards,<span></span></span></p>

<p class="MsoNormal" style="margin:0cm 0cm 0.0001pt;font-size:12pt;font-family:Cambria"><span lang="EN-US">Fatima<span></span></span></p>





<br></div><div class="gmail_extra"><br><div class="gmail_quote">2018-04-30 10:00 GMT-05:00 Eduardo Diaz <span dir="ltr"><<a href="mailto:eduardodiazrivera@gmail.com" target="_blank">eduardodiazrivera@gmail.com</a>></span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Alan:<div><br></div><div>What about the part of the statements that smaller firms do not have to comply with the GRDP rules as a standard. Is it true? </div></div><div class="HOEnZb"><div class="h5"><br><div class="gmail_quote"><div dir="ltr">On Mon, Apr 30, 2018 at 10:50 AM Alan Greenberg <<a href="mailto:alan.greenberg@mcgill.ca" target="_blank">alan.greenberg@mcgill.ca</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div>
GDPR generally applies to all businesses.<br><br>
There is an exemption about not maintaining records of how data is used,
but if a person requests such a record, you would have to reconstruct it
after the fact. <br><br>
I was not aware of any exemption on publishing why and how data is
collected and processed, but that may be ignorance on my part.<br><br>
Alan</div><div><br><br>
<br>
At 30/04/2018 10:22 AM, Eduardo Diaz wrote:<br><br>
</div><div><blockquote type="cite" class="m_6992259376750652696m_-8967751290910751016cite">A friend of mine quoted the
following from an article written here (bullet #9):
<a href="https://government.diginomica.com/2018/01/22/gdpr-compliance-here-are-the-14-things-you-actually-need-to-do/" target="_blank">
https://government.diginomica.<wbr>com/2018/01/22/gdpr-<wbr>compliance-here-are-the-14-<wbr>things-you-actually-need-to-<wbr>do/</a>
<br><br>
<br>
</blockquote></div><div><blockquote type="cite" class="m_6992259376750652696m_-8967751290910751016cite"><b><i>"Smaller firms – those defined as hhaving 250 employees or
less – do not have to comply with all GDPR rrules as standard. If your
organisation falls into this band, there’s no need to have
documentation of why personal data is being collected and processed, the
information you’re storing or how long for. Smaller firms are not
required to maintain a record of processing activities unless this
carries a risk to the rights and freedoms of data subjects, it is a
regular occurrence, or it relates to certain data like criminal
convictions and offences."<br>
</i></b></blockquote></div><div><blockquote type="cite" class="m_6992259376750652696m_-8967751290910751016cite"><br>
The question: Is this statement true or false. If false what 's the real
thing?<br><br>
Thanks to whomever answers this.<br><br>
-ed<br><br></blockquote></div><div><blockquote type="cite" class="m_6992259376750652696m_-8967751290910751016cite">
Content-Type: text/plain; charset="us-ascii"<br>
Content-Transfer-Encoding: 7bit<br>
Content-Disposition: inline<br>
X-Microsoft-Exchange-<wbr>Diagnostics:<br>
<u></u>        <u></u>
1;YTOPR01MB0396;27:Ytj/<wbr>AIpssqiibmKnz50JsE2dlIuhl4mAZZ<wbr>7KgUS70r3MLVG2H5KbNLby1tvjuxmL<wbr>9xkihjOX8lTqRqdvkojOVcdFn+<wbr>7J6Rg9dLd4q6K0sBwFMmlBydtVxY/<wbr>DHJHtiGSJ<br>
X-Microsoft-Antispam-Message-<wbr>Info:<br>
<u></u>        <u></u>
Z0icQu+yvOTMi4oe2M5K8h3rXupR/<wbr>WWSGm7yxmyO/<wbr>qZWHZyK6igFkjfsOJ8Zvdr+<wbr>SypqAETDIqcyY01/<wbr>xxTWorzEcbGFCOU0ZJh44OAwgSSTfu<wbr>7epif694StzjXqCHQEoWJqrZLOQvKA<wbr>H1JvkHIcRi7scwaHt8PwvCirITtXjd<wbr>RNdJb9dw2QXEvB2r2Pol6vnyfj+<wbr>CoqdP/6R67D3vRK35H2W+<wbr>crSTRIVjKjWrgFIDYnC1d06+<wbr>3i59oO+<wbr>dGHw1Vwhuiu977GlToeSv5XpProXMg<wbr>oWCVNBZZJ+j+<wbr>vEq5FH1IKTZV8W1BohpSeFQXvXSHGh<wbr>LbcAL8WKH2Jqn4AkB9PsLeVIZYN/<wbr>ZNDXrKXjtf6mCJcPSDJjK+<wbr>VxHsUB4px4RlVEe54ay1Dy0rFX9vxi<wbr>eiG2ll4Dd2uFoQfPdGjTcedFQg+<wbr>mW9clPueIWcYO1lBuNZW1RVVwC4xRp<wbr>b/AE09YMbCVv/O8mMq9+2j+zhX/<wbr>7K9jf6ZLgTZ3NxwCkSoAmRhcQo0<br>
<br>
------<br>
NA-Discuss mailing list<br>
<a href="mailto:NA-Discuss@atlarge-lists.icann.org" target="_blank">NA-Discuss@atlarge-lists.<wbr>icann.org</a><br>
<a href="https://atlarge-lists.icann.org/mailman/listinfo/na-discuss" target="_blank">
https://atlarge-lists.icann.<wbr>org/mailman/listinfo/na-<wbr>discuss</a><br><br>
Visit the NARALO online at
<a href="http://www.naralo.org/" target="_blank">
http://www.naralo.org</a><br>
------</blockquote></div>

</blockquote></div>
</div></div><br>______________________________<wbr>_________________<br>
ALAC mailing list<br>
<a href="mailto:ALAC@atlarge-lists.icann.org">ALAC@atlarge-lists.icann.org</a><br>
<a href="https://atlarge-lists.icann.org/mailman/listinfo/alac" rel="noreferrer" target="_blank">https://atlarge-lists.icann.<wbr>org/mailman/listinfo/alac</a><br>
<br>
At-Large Online: <a href="http://www.atlarge.icann.org" rel="noreferrer" target="_blank">http://www.atlarge.icann.org</a><br>
ALAC Working Wiki: <a href="https://community.icann.org/display/atlarge/At-Large+Advisory+Committee+(ALAC)" rel="noreferrer" target="_blank">https://community.icann.org/<wbr>display/atlarge/At-Large+<wbr>Advisory+Committee+(ALAC)</a><br></blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div style="text-align:left"><i><b>Fatima Cambronero</b></i><br><div style="text-align:left">Responsable del Área de Derecho Informático de R10S Abogados<br><a href="http://www.riosabogados.com" target="_blank">www.riosabogados.com</a><br>México<br></div><br style="color:rgb(0,0,0)"></div><span style="color:rgb(0,0,0)">Phone: México: +52 (55) 5252 2581<br>
Twitter: @facambronero<br>
Skype: fatima.cambronero</span><br><br><div style="padding:0px;margin-left:0px;margin-top:0px;overflow:hidden;word-wrap:break-word;color:black;font-size:10px;line-height:130%;text-align:left"></div><div style="padding:0px;margin-left:0px;margin-top:0px;overflow:hidden;word-wrap:break-word;color:black;font-size:10px;line-height:130%;text-align:left"></div><div style="padding:0px;margin-left:0px;margin-top:0px;overflow:hidden;word-wrap:break-word;color:black;font-size:10px;line-height:130%;text-align:left"></div><div style="padding:0px;margin-left:0px;margin-top:0px;overflow:hidden;word-wrap:break-word;color:black;font-size:10px;text-align:left;line-height:130%"></div><div style="padding:0px;margin-left:0px;margin-top:0px;overflow:hidden;word-wrap:break-word;color:black;font-size:10px;text-align:left;line-height:130%"></div><div style="padding:0px;margin-left:0px;margin-top:0px;overflow:hidden;word-wrap:break-word;color:black;font-size:10px;text-align:left;line-height:130%"></div></div></div></div></div></div></div></div></div>
</div>