{"id":166,"date":"2026-01-20T00:00:00","date_gmt":"2026-01-19T23:00:00","guid":{"rendered":"https:\/\/helloblog.io\/lv\/gdpr-atbilstibas-kontrolsaraksts-vietnu-ipasniekiem\/"},"modified":"2026-01-20T00:00:00","modified_gmt":"2026-01-19T23:00:00","slug":"gdpr-atbilstibas-kontrolsaraksts-vietnu-ipasniekiem","status":"publish","type":"post","link":"https:\/\/helloblog.io\/lv\/gdpr-atbilstibas-kontrolsaraksts-vietnu-ipasniekiem\/","title":{"rendered":"GDPR atbilst\u012bbas kontrolsaraksts viet\u0146u \u012bpa\u0161niekiem: pilna praktisk\u0101 rokasgr\u0101mata"},"content":{"rendered":"\n<p>GDPR (General Data Protection Regulation) joproj\u0101m ir viena no stingr\u0101kaj\u0101m un visaptvero\u0161\u0101kaj\u0101m datu priv\u0101tuma sist\u0113m\u0101m pasaul\u0113. Ja tu apstr\u0101d\u0101 ES iedz\u012bvot\u0101ju personas datus \u2014 neatkar\u012bgi no t\u0101, vai vadi mazu blogu, e-veikalu vai SaaS \u2014 atbilst\u012bba nav izv\u0113les lieta. Neatbilst\u012bbas gad\u012bjum\u0101 sods var sasniegt l\u012bdz <strong>20 miljoniem \u20ac vai 4% no glob\u0101l\u0101 gada apgroz\u012bjuma<\/strong> (atkar\u012bb\u0101 no t\u0101, kur\u0161 skaitlis ir liel\u0101ks).<\/p>\n\n\n\n<p>\u0160aj\u0101 rakst\u0101 es salieku vien\u0101 viet\u0101 pilnu <strong>GDPR atbilst\u012bbas kontrolsarakstu<\/strong> viet\u0146u \u012bpa\u0161niekiem un izstr\u0101d\u0101t\u0101jiem: kas ir j\u0101sak\u0101rto datos, procesos, piekri\u0161an\u0101s meh\u0101nismos, lietot\u0101ju ties\u012bbu izpild\u0113, k\u0101 ar\u012b ko \u012bpa\u0161i p\u0101rbaud\u012bt WordPress vid\u0113. Katr\u0101 sada\u013c\u0101 saglab\u0101ju ar\u012b atsauces uz atbilsto\u0161ajiem GDPR pantiem (Article 6, 7, 12, 13 u.c.), lai ir viegl\u0101k piesiet pras\u012bbas konkr\u0113tam normat\u012bvajam pamatojumam.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Kas ir GDPR (un uz ko tas attiecas)?<\/h2>\n\n\n\n<p><strong>GDPR<\/strong> ir Eiropas Savien\u012bbas regula, kas ir sp\u0113k\u0101 kop\u0161 <strong>2018. gada 25. maija<\/strong>. T\u0101 defin\u0113, k\u0101 organiz\u0101cijas dr\u012bkst v\u0101kt, izmantot, glab\u0101t un nodot t\u0101l\u0101k <strong>personas datus<\/strong>. B\u016btiski: GDPR attiecas ne tikai uz uz\u0146\u0113mumiem ES, bet ar\u012b uz organiz\u0101cij\u0101m \u0101rpus ES, ja t\u0101s apstr\u0101d\u0101 ES iedz\u012bvot\u0101ju personas datus.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Pirms s\u0101c: saproti savu lomu (Controller\/Processor)<\/h2>\n\n\n\n<p>GDPR terminolo\u0123ija viet\u0146u pasaul\u0113 bie\u017ei \u0161\u0137iet \u201cjuridiska\u201d, bet tehniskaj\u0101 praks\u0113 t\u0101 pal\u012bdz saprast atbild\u012bbu robe\u017eas.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Data Controller<\/strong> (p\u0101rzinis): organiz\u0101cija, kas nosaka, <em>k\u0101p\u0113c<\/em> un <em>k\u0101<\/em> personas dati tiks apstr\u0101d\u0101ti. Parasti tas ir vietnes\/biznesa \u012bpa\u0161nieks, kas lemj par form\u0101m, m\u0101rketingu, anal\u012btiku u.tml. P\u0101rzinim ir prim\u0101r\u0101 atbild\u012bba par atbilst\u012bbu.<\/li>\n\n\n<li><strong>Data Processor<\/strong> (apstr\u0101d\u0101t\u0101js): tre\u0161\u0101 puse, kas apstr\u0101d\u0101 datus p\u0101rzi\u0146a v\u0101rd\u0101 (piem., hostings, e-pasta s\u016bt\u012b\u0161anas serviss, CRM). Ar\u012b apstr\u0101d\u0101t\u0101jam j\u0101ievie\u0161 atbilsto\u0161i tehniskie un organizatoriskie pas\u0101kumi.<\/li>\n\n\n<li><strong>Data Subject<\/strong> (datu subjekts): persona, kuras dati tiek apstr\u0101d\u0101ti. GDPR m\u0113r\u0137is ir aizsarg\u0101t tie\u0161i datu subjekta ties\u012bbas.<\/li>\n\n<\/ul>\n\n\n\n<p>Svar\u012bga nianse: vien\u0101 biznes\u0101 tu vari b\u016bt gan p\u0101rzinis, gan apstr\u0101d\u0101t\u0101js (atkar\u012bb\u0101 no konkr\u0113t\u0101 datu pl\u016bsmas scen\u0101rija).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">7 GDPR pamatprincipi, kas j\u0101\u0146em v\u0113r\u0101 visur<\/h2>\n\n\n\n<p>Pirms \u0137eries pie kontrolsaraksta, ir v\u0113rts nostiprin\u0101t b\u0101zi \u2014 \u0161ie 7 principi praktiski nosaka, k\u0101 \u201cpareizi\u201d dizain\u0113t datu pl\u016bsmas, UI un procesus:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li><strong>Lawfulness, fairness, and transparency<\/strong>: apstr\u0101d\u0101 datus likum\u012bgi un godpr\u0101t\u012bgi, un skaidri inform\u0113 cilv\u0113kus, k\u0101p\u0113c un k\u0101 dati tiks lietoti.<\/li>\n\n\n<li><strong>Purpose limitation<\/strong>: v\u0101c datus tikai konkr\u0113tam, le\u0123it\u012bmam m\u0113r\u0137im.<\/li>\n\n\n<li><strong>Data minimization<\/strong>: v\u0101c tikai minimumu, kas ir nepiecie\u0161ams.<\/li>\n\n\n<li><strong>Accuracy<\/strong>: dati j\u0101uztur prec\u012bzi un aktu\u0101li.<\/li>\n\n\n<li><strong>Storage limitation<\/strong>: neglab\u0101 ilg\u0101k, nek\u0101 nepiecie\u0161ams.<\/li>\n\n\n<li><strong>Integrity and confidentiality<\/strong>: aizsarg\u0101 datus pret nesankcion\u0113tu piek\u013cuvi ar atbilsto\u0161iem dro\u0161\u012bbas pas\u0101kumiem.<\/li>\n\n\n<li><strong>Accountability<\/strong>: sp\u0113j pier\u0101d\u012bt, ka iev\u0113ro atbilst\u012bbu (ne tikai \u201cdom\u0101, ka iev\u0113ro\u201d).<\/li>\n\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Pilns GDPR atbilst\u012bbas kontrolsaraksts (ar pantiem)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Dati<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">1) Tev ir saraksts ar visiem personas datu tipiem, avotiem, koplieto\u0161anu, nol\u016bkiem un glab\u0101\u0161anas termi\u0146iem (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>Praktiski tas noz\u012bm\u0113: uzskaiti nevis tikai \u201cmums ir lietot\u0101ji\u201d, bet konkr\u0113tos datu laukus (kolonnas) \u2014 piem\u0113ram, v\u0101rds, e-pasts, adrese, identifikatori utt. Katram tipam dokument\u0113: no kurienes tas n\u0101k, ar ko dalies, ko tie\u0161i dari ar \u0161o datu tipu un cik ilgi glab\u0101si.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 30 \u2013 Records of processing activities<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2) Tev ir saraksts ar viet\u0101m, kur glab\u0101 personas datus, un datu pl\u016bsma starp t\u0101m (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>\u0160eit ietilpst gan klasisk\u0101s datub\u0101zes (piem., MySQL), gan \u0101r\u0113jie servisi, gan ar\u012b offline glab\u0101tuves (piem., pap\u012bra dokumenti). Galvenais \u2014 saprast, kur dati re\u0101li \u201cdz\u012bvo\u201d un k\u0101 tie p\u0101rvietojas.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 30 \u2013 Records of processing activities<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">3) Tev ir publiski pieejama Privacy Policy, kas apraksta visus procesus ar personas datiem (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>Priv\u0101tuma politik\u0101 ir j\u0101atspogu\u013co visi procesi, kas skar personas datu apstr\u0101di. Taj\u0101 j\u0101iek\u013cauj (vai j\u0101ieliek saites uz) datu tipi, kurus glab\u0101, un vietas\/sist\u0113mas, kur tie tiek glab\u0101ti.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 30 \u2013 Records of processing activities<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">4) Priv\u0101tuma politik\u0101 ir nor\u0101d\u012bts likum\u012bgais pamats (lawful basis), k\u0101p\u0113c apstr\u0101d\u0101 personas datus (<em>Controller<\/em>)<\/h4>\n\n\n\n<p>Tev ir j\u0101sp\u0113j izskaidrot \u201ck\u0101p\u0113c mums tas ir vajadz\u012bgs\u201d juridisk\u0101 noz\u012bm\u0113 \u2014 piem\u0113ram, l\u012bguma izpilde (pas\u016bt\u012bjuma apstr\u0101de), le\u0123it\u012bm\u0101s intereses utt.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 6 \u2013 Lawfulness of processing<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Atbild\u012bba un p\u0101rvald\u012bba (Accountability &#038; Management)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">5) Ir iecelts DPO (Data Protection Officer) tad, ja tas ir oblig\u0101ti (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>DPO (datu aizsardz\u012bbas speci\u0101lists) ir oblig\u0101ts tikai 3 gad\u012bjumos:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Apstr\u0101di veic valsts iest\u0101de vai instit\u016bcija (iz\u0146emot tiesas, kas darbojas tiesu varas ietvaros).<\/li>\n\n\n<li>Biznesa pamatdarb\u012bbas ietver apstr\u0101di, kas p\u0113c b\u016bt\u012bbas, apjoma un\/vai m\u0113r\u0137a prasa regul\u0101ru un sistem\u0101tisku datu subjektu uzraudz\u012bbu liel\u0101 m\u0113rog\u0101.<\/li>\n\n\n<li>Biznesa pamatdarb\u012bbas ietver liel\u0101 m\u0113rog\u0101 \u012bpa\u0161u kategoriju (sensit\u012bvu) datu apstr\u0101di saska\u0146\u0101 ar <strong>Article 9<\/strong>, k\u0101 ar\u012b personas datus par sod\u0101m\u012bbu un p\u0101rk\u0101pumiem saska\u0146\u0101 ar <strong>Article 10<\/strong>.<\/li>\n\n<\/ol>\n\n\n\n<p>Ja DPO ir vajadz\u012bgs, vi\u0146am j\u0101orient\u0113jas GDPR vadl\u012bnij\u0101s un ar\u012b j\u0101saprot iek\u0161\u0113jie procesi, kuros tiek lietoti personas dati.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 37 \u2013 Designation of the data protection officer<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">6) L\u0113mumu pie\u0146\u0113m\u0113jiem organiz\u0101cij\u0101 ir izpratne par GDPR pras\u012bb\u0101m (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>Tehniski pareizi risin\u0101jumi bie\u017ei \u201csal\u016bzt\u201d pie biznesa l\u0113mumiem (m\u0101rketings, integr\u0101cijas, datu eksports). T\u0101p\u0113c atsl\u0113gas cilv\u0113kiem zin\u0101\u0161an\u0101m j\u0101b\u016bt aktu\u0101l\u0101m.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 25 \u2013 Data protection by design and by default<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">7) Tehnisk\u0101 dro\u0161\u012bba ir atjaunin\u0101ta un atbilst m\u016bsdienu l\u012bmenim (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>SaaS un t\u012bmek\u013ca produktiem parasti ir v\u0113rts balst\u012bties uz dro\u0161\u012bbas checklist\u2019iem k\u0101 starta punktu, lai p\u0101rliecin\u0101tos, ka tehniskie pas\u0101kumi re\u0101li ir ieviesti, nevis tikai aprakst\u012bti dokumentos.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 25 \u2013 Data protection by design and by default<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">8) Darbinieki ir apm\u0101c\u012bti datu aizsardz\u012bb\u0101 (<em>Processor<\/em>)<\/h4>\n\n\n\n<p>Da\u013ca dro\u0161\u012bbas incidentu notiek t\u0101p\u0113c, ka k\u0101ds ar piek\u013cuvi iek\u0161\u0113j\u0101m sist\u0113m\u0101m net\u012b\u0161i pal\u012bdz uzbrukumam (phishing, soci\u0101l\u0101 in\u017eenierija, nejau\u0161a datu nopl\u016bde). Apm\u0101c\u012bb\u0101m ir j\u0101b\u016bt re\u0101l\u0101m un regul\u0101r\u0101m.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 25 \u2013 Data protection by design and by default<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">9) Tev ir sub-processor saraksts, un Privacy Policy skaidri min \u0161o sub-processor izmanto\u0161anu (<em>Processor<\/em>)<\/h4>\n\n\n\n<p>Ja tu k\u0101 apstr\u0101d\u0101t\u0101js izmanto apak\u0161apstr\u0101d\u0101t\u0101jus (sub-processors), klientiem par to ir j\u0101zina un tiem j\u0101piekr\u012bt (praktiski \u2014 pie\u0146emot tavu priv\u0101tuma politiku\/terms, atkar\u012bb\u0101 no mode\u013ca).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 28 \u2013 Processor<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">10) Ja str\u0101d\u0101 \u0101rpus ES, bet apstr\u0101d\u0101 ES iedz\u012bvot\u0101ju datus, ir iecelts p\u0101rst\u0101vis ES (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>Ja bizness ir \u0101rpus ES un tom\u0113r v\u0101c\/apstr\u0101d\u0101 ES iedz\u012bvot\u0101ju datus, ir j\u0101nor\u012bko p\u0101rst\u0101vis k\u0101d\u0101 dal\u012bbvalst\u012b. \u0160im p\u0101rst\u0101vim j\u0101sp\u0113j risin\u0101t ar apstr\u0101di saist\u012btie jaut\u0101jumi, un uzraudz\u012bbas iest\u0101d\u0113m j\u0101b\u016bt iesp\u0113jai ar vi\u0146u sazin\u0101ties.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 27 \u2013 Representatives of controllers or processors not established in the Union<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">11) Personas datu p\u0101rk\u0101pumi tiek zi\u0146oti uzraudz\u012bbas iest\u0101dei un datu subjektiem (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>Ja notiek personas datu p\u0101rk\u0101pums, tas j\u0101zi\u0146o uzraudz\u012bbas iest\u0101dei <strong>72 stundu laik\u0101<\/strong>. Zi\u0146ojum\u0101 j\u0101nor\u0101da, k\u0101di dati ir zaud\u0113ti\/nopl\u016bdu\u0161i, k\u0101das ir sekas un k\u0101di pretpas\u0101kumi veikti. Ja nopl\u016bdu\u0161ie dati nav biju\u0161i \u0161ifr\u0113ti, par incidentu parasti j\u0101inform\u0113 ar\u012b pa\u0161i datu subjekti, kuru dati skarti.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 33 \u2013 Notification of a personal data breach to the supervisory authority<\/strong>; GDPR <strong>Article 34 \u2013 Communication of a personal data breach to the data subject<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">12) Ir l\u012bgumi ar visiem apstr\u0101d\u0101t\u0101jiem, kam nodod datus (piem., hostings) (<em>Controller<\/em>)<\/h4>\n\n\n\n<p>Ja tu nodod datus apstr\u0101d\u0101t\u0101jam, l\u012bgum\u0101 ir j\u0101b\u016bt skaidr\u0101m instrukcij\u0101m par to, k\u0101 apstr\u0101d\u0101t\u0101js dr\u012bkst glab\u0101t\/apstr\u0101d\u0101t datus. L\u012bgumam j\u0101defin\u0113: apstr\u0101des priek\u0161mets un ilgums, apstr\u0101des veids un m\u0113r\u0137is, personas datu tipi, datu subjektu kategorijas, k\u0101 ar\u012b p\u0101rzi\u0146a ties\u012bbas un pien\u0101kumi.<\/p>\n\n\n\n<p>Tas pats princips attiecas ar\u012b uz situ\u0101ciju, kad apstr\u0101d\u0101t\u0101js piesaista sub-processor, lai pal\u012bdz\u0113tu izpild\u012bt apstr\u0101di p\u0101rzi\u0146a v\u0101rd\u0101.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 28 \u2013 Processor<\/strong>; GDPR <strong>Article 29 \u2013 Processing under the authority of the controller or processor<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Jaun\u0101s ties\u012bbas (New Rights) \u2014 ko lietot\u0101jam j\u0101sp\u0113j izdar\u012bt<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">13) Lietot\u0101js var viegli piepras\u012bt piek\u013cuvi saviem personas datiem (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>Tev j\u0101b\u016bt skaidram procesam, k\u0101 apstr\u0101d\u0101 datu subjekta piek\u013cuves piepras\u012bjumus (access requests) \u2014 gan organizatoriski, gan tehniski.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 15 \u2013 Right of access by the data subject<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">14) Lietot\u0101js var viegli labot savus datus, lai tie b\u016btu prec\u012bzi (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>Nodro\u0161ini meh\u0101nismu, k\u0101 lietot\u0101js var izlabot neprec\u012bzus datus (piem., profil\u0101) vai k\u0101 to var izdar\u012bt, iesniedzot piepras\u012bjumu.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 16 \u2013 Right to rectification<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">15) Tu autom\u0101tiski dz\u0113s datus, kas vairs nav vajadz\u012bgi (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>Praks\u0113 \u0161eit bie\u017ei \u201ciek\u0101rtojas\u201d tehniskais par\u0101ds: dati kr\u0101jas bez termi\u0146iem. M\u0113r\u0137is ir automatiz\u0113t dz\u0113\u0161anu, piem\u0113ram, dz\u0113st klientu datus, ja l\u012bgums nav atjaunots un nav cita likum\u012bga pamata glab\u0101\u0161anai.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 5 \u2013 Principles relating to processing of personal data<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">16) Lietot\u0101js var viegli piepras\u012bt savu datu dz\u0113\u0161anu (\u201cright to be forgotten\u201d) (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>Tev j\u0101b\u016bt procesam \u201cdz\u0113\u0161anas piepras\u012bjumiem\u201d (erasure requests) un skaidriem so\u013ciem, k\u0101 dz\u0113\u0161ana tiek izpild\u012bta sist\u0113m\u0101s (ar\u012b integr\u0101cij\u0101s), ja vien nav citu tiesisku iemeslu datus patur\u0113t.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 17 \u2013 Right to erasure (&#8216;right to be forgotten&#8217;)<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">17) Lietot\u0101js var viegli piepras\u012bt apstr\u0101des ierobe\u017eo\u0161anu (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>Tas noz\u012bm\u0113 iesp\u0113ju aptur\u0113t noteiktus apstr\u0101des veidus, ja lietot\u0101js to prasa un ir pamats. Tehniski bie\u017ei tas ir \u201cflag\u201d + darb\u012bbu atsl\u0113g\u0161ana (piem., m\u0101rketinga s\u016bt\u012bjumi).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 18 \u2013 Right to restriction of processing<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">18) Lietot\u0101js var piepras\u012bt savu datu izsnieg\u0161anu sev vai tre\u0161ajai pusei (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>Datu p\u0101rnesam\u012bba noz\u012bm\u0113: dati j\u0101izsniedz struktur\u0113t\u0101, pla\u0161i izmantot\u0101 un ma\u0161\u012bnlas\u0101m\u0101 form\u0101t\u0101, lai cilv\u0113ks tos var\u0113tu p\u0101rcelt pie cita pakalpojuma sniedz\u0113ja.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 20 \u2013 Right to data portability<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">19) Lietot\u0101js var iebilst pret profil\u0113\u0161anu vai automatiz\u0113tu l\u0113mumu pie\u0146em\u0161anu, kas vi\u0146u ietekm\u0113 (<em>Controller<\/em>)<\/h4>\n\n\n\n<p>\u0160is punkts ir aktu\u0101ls tikai tad, ja tav\u0101 biznes\u0101 tie\u0161\u0101m notiek profil\u0113\u0161ana vai automatiz\u0113ta l\u0113mumu pie\u0146em\u0161ana (piem., scoring, autom\u0101tiska atteik\u0161ana u.tml.).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 22 \u2013 Automated individual decision-making, including profiling<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Piekri\u0161ana (Consent)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">20) Ja apstr\u0101de balst\u0101s uz piekri\u0161anu, tai j\u0101b\u016bt br\u012bvpr\u0101t\u012bgai, konkr\u0113tai, inform\u0113tai un atsaucamai (<em>Controller<\/em>)<\/h4>\n\n\n\n<p>Ja vietne v\u0101c personas datus un pamats ir piekri\u0161ana, blakus ir j\u0101b\u016bt skaidrai saitei uz priv\u0101tuma politiku un lietot\u0101jam j\u0101veic akt\u012bva darb\u012bba, lai piekristu. <strong>Iepriek\u0161 at\u0137eks\u0113tas izv\u0113les (pre-ticked checkboxes) nav at\u013cautas<\/strong>, jo piekri\u0161anai j\u0101b\u016bt nep\u0101rprotami apstiprino\u0161ai.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 7 \u2013 Conditions for consent<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">21) Priv\u0101tuma politika ir uzrakst\u012bta skaidri un saprotami (<em>Controller<\/em>)<\/h4>\n\n\n\n<p>Tekstam j\u0101b\u016bt vienk\u0101r\u0161am, nep\u0101rprotamam un nedr\u012bkst sl\u0113pt nol\u016bku. Ja tas nav iev\u0113rots, piekri\u0161ana var tikt atz\u012bta par neder\u012bgu. Ja sniedz pakalpojumus b\u0113rniem, tekstam j\u0101b\u016bt saprotamam ar\u012b vi\u0146iem.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 7.2 \u2013 Conditions for consent<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">22) Atsaukt piekri\u0161anu ir tikpat viegli, k\u0101 to iedot (<em>Controller<\/em>)<\/h4>\n\n\n\n<p>Ja piekri\u0161ana tiek dota ar vienu klik\u0161\u0137i, ar\u012b atsauk\u0161anai nevajadz\u0113tu b\u016bt \u201cslepen\u0101\u201d iestat\u012bjumu lap\u0101 ar pieciem so\u013ciem.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 7.3 \u2013 Conditions for consent<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">23) Ja apstr\u0101d\u0101 b\u0113rnu datus, p\u0101rbaudi vecumu un prasi aizbild\u0146a piekri\u0161anu (<em>Controller<\/em>)<\/h4>\n\n\n\n<p>B\u0113rniem, kas jaun\u0101ki par 16 gadiem, ir j\u0101nodro\u0161ina, ka piekri\u0161anu dod likum\u012bgais aizbildnis. Ja piekri\u0161ana tiek ieg\u016bta vietn\u0113, tev j\u0101m\u0113\u0123ina p\u0101rliecin\u0101ties, ka apstiprin\u0101jumu tie\u0161\u0101m sniedzis aizbildnis, nevis pats b\u0113rns.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 8 \u2013 Conditions applicable to child&#8217;s consent in relation to information society services<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">24) Atjauninot priv\u0101tuma politiku, tu inform\u0113 eso\u0161os klientus (<em>Controller<\/em>)<\/h4>\n\n\n\n<p>Praktisks piem\u0113rs: e-pasts ar gaid\u0101maj\u0101m izmai\u0146\u0101m un vienk\u0101r\u0161u izkl\u0101stu, kas ir main\u012bjies.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 7 \u2013 Conditions for consent<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">P\u0113cp\u0101rbaude (Follow-up)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">25) Tu regul\u0101ri p\u0101rskati politikas, efektivit\u0101ti, datu apstr\u0101des izmai\u0146as un izmai\u0146as valst\u012bs, uz kur\u0101m pl\u016bst dati (<em>Controller<\/em>)<\/h4>\n\n\n\n<p>GDPR atbilst\u012bba nav vienreiz\u0113js uzdevums. Main\u0101s integr\u0101cijas, r\u012bki, datu pl\u016bsmas, k\u0101 ar\u012b starptautiskais regul\u0113jums. Regul\u0101rs p\u0101rskats ir da\u013ca no \u201cprivacy by design\/default\u201d dom\u0101\u0161anas.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 25 \u2013 Data protection by design and by default<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u012apa\u0161ie gad\u012bjumi (Special Cases)<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">26) Tu saproti, kad j\u0101veic DPIA augsta riska apstr\u0101dei (sensit\u012bvi dati u.c.) (<em>Controller<\/em>)<\/h4>\n\n\n\n<p>DPIA (Data Protection Impact Assessment) parasti k\u013c\u016bst aktu\u0101la, ja notiek liel\u0101 m\u0113rog\u0101 sensit\u012bvu datu apstr\u0101de, profil\u0113\u0161ana vai cita darb\u012bba, kas rada augstu risku cilv\u0113ku ties\u012bb\u0101m un br\u012bv\u012bb\u0101m.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 35 \u2013 Data protection impact assessment<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">27) Datus \u0101rpus ES nodod tikai uz valst\u012bm ar atbilsto\u0161u aizsardz\u012bbas l\u012bmeni, un to atkl\u0101j priv\u0101tuma politik\u0101 (<em>Controller, Processor<\/em>)<\/h4>\n\n\n\n<p>Ja ir datu pl\u016bsmas uz tre\u0161aj\u0101m valst\u012bm, priv\u0101tuma politik\u0101 t\u0101s ir j\u0101atspogu\u013co. Ja valsts netiek uzskat\u012bta par \u201cadequate\u201d, datu nodo\u0161anai tipiski izmanto <strong>Standard Contractual Clauses (SCCs)<\/strong> vai <strong>Binding Corporate Rules (BCRs)<\/strong>.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 45 \u2013 Transfers on the basis of an adequacy decision<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Datu subjekta ties\u012bbas (User Rights): ko tev j\u0101nodro\u0161ina lietot\u0101jam<\/h2>\n\n\n\n<p>Zem\u0101k ir ties\u012bbu kopums, kas attiecas uz visiem <strong>Data Subjects<\/strong> (person\u0101m, kuru dati tiek apstr\u0101d\u0101ti). \u0160eit es to atst\u0101ju k\u0101 praktisku \u201catg\u0101din\u0101juma\u201d sada\u013cu \u2014 daudz kas jau p\u0101rkl\u0101jas ar iepriek\u0161\u0113jiem punktiem, bet panti un nosac\u012bjumi ir svar\u012bgi, lai korekti noform\u0113tu procesu un komunik\u0101ciju.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ties\u012bbas uz caursp\u012bd\u012bgu inform\u0101ciju<\/h3>\n\n\n\n<p>P\u0101rzinim j\u0101nodro\u0161ina inform\u0101cija par apstr\u0101di kodol\u012bgi, caursp\u012bd\u012bgi, saprotami un viegli pieejami, izmantojot skaidru valodu (\u012bpa\u0161i, ja inform\u0101cija adres\u0113ta b\u0113rnam). Inform\u0101ciju var sniegt rakstiski vai cit\u0101 veid\u0101 (ar\u012b elektroniski, ja piem\u0113rojams).<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 12<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ties\u012bbas sa\u0146emt konkr\u0113tu inform\u0101ciju, ja dati tiek ieg\u016bti tie\u0161i no personas<\/h3>\n\n\n\n<p>Ja personas dati tiek iev\u0101kti tie\u0161i no datu subjekta, j\u0101sniedz vismaz \u0161\u0101da inform\u0101cija:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>P\u0101rzi\u0146a identit\u0101te un kontaktinform\u0101cija<\/li>\n\n\n<li>Datu aizsardz\u012bbas speci\u0101lista (DPO) kontaktinform\u0101cija (ja piem\u0113rojams)<\/li>\n\n\n<li>Apstr\u0101des m\u0113r\u0137i un juridiskais pamats<\/li>\n\n\n<li>P\u0101rzi\u0146a le\u0123it\u012bm\u0101s intereses (ja piem\u0113rojams)<\/li>\n\n\n<li>Personas datu sa\u0146\u0113m\u0113ji vai sa\u0146\u0113m\u0113ju kategorijas<\/li>\n\n\n<li>Inform\u0101cija par nodo\u0161anu uz tre\u0161aj\u0101m valst\u012bm<\/li>\n\n<\/ol>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 13<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ties\u012bbas sa\u0146emt konkr\u0113tu inform\u0101ciju, ja dati netiek ieg\u016bti tie\u0161i no personas<\/h3>\n\n\n\n<p>Ja dati tiek ieg\u016bti no cita avota, joproj\u0101m j\u0101sniedz l\u012bdz\u012bga inform\u0101cija, tostarp j\u0101nor\u0101da attiec\u012bgo personas datu kategorijas un datu avots.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 14<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Piek\u013cuves ties\u012bbas (Right of access)<\/h3>\n\n\n\n<p>Personai ir ties\u012bbas sa\u0146emt apstiprin\u0101jumu, vai vi\u0146as dati tiek apstr\u0101d\u0101ti, un piek\u013cuvi vismaz \u0161\u0101dai inform\u0101cijai:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Apstr\u0101des m\u0113r\u0137i<\/li>\n\n\n<li>Attiec\u012bgo personas datu kategorijas<\/li>\n\n\n<li>Sa\u0146\u0113m\u0113ji, kuriem dati ir izpausti vai tiks izpausti<\/li>\n\n\n<li>Pl\u0101notais glab\u0101\u0161anas termi\u0146\u0161<\/li>\n\n\n<li>Ties\u012bbu esam\u012bba: labo\u0161ana, dz\u0113\u0161ana, ierobe\u017eo\u0161ana un iebildums<\/li>\n\n\n<li>Ties\u012bbas iesniegt s\u016bdz\u012bbu uzraudz\u012bbas iest\u0101d\u0113<\/li>\n\n\n<li>Inform\u0101cija par datu avotu (ja dati nav ieg\u016bti no datu subjekta)<\/li>\n\n\n<li>Automatiz\u0113tas l\u0113mumu pie\u0146em\u0161anas esam\u012bba, tostarp profil\u0113\u0161ana<\/li>\n\n<\/ul>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 15<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ties\u012bbas uz labo\u0161anu (Right to rectification)<\/h3>\n\n\n\n<p>Personai ir ties\u012bbas bez nepamatotas kav\u0113\u0161an\u0101s labot neprec\u012bzus personas datus un papildin\u0101t nepiln\u012bgus datus.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 16<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ties\u012bbas uz dz\u0113\u0161anu (\u201cright to be forgotten\u201d)<\/h3>\n\n\n\n<p>Personai ir ties\u012bbas pan\u0101kt datu dz\u0113\u0161anu, ja:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Dati vairs nav nepiecie\u0161ami s\u0101kotn\u0113jam m\u0113r\u0137im<\/li>\n\n\n<li>Persona atsauc piekri\u0161anu un nav cita juridiska pamata apstr\u0101dei<\/li>\n\n\n<li>Persona iebilst apstr\u0101dei un nepast\u0101v p\u0101r\u0101ki le\u0123it\u012bmi pamati turpin\u0101t apstr\u0101di<\/li>\n\n\n<li>Dati ir apstr\u0101d\u0101ti nelikum\u012bgi<\/li>\n\n\n<li>Dati j\u0101dz\u0113\u0161, lai izpild\u012btu juridisku pien\u0101kumu<\/li>\n\n\n<li>Dati tika iev\u0101kti saist\u012bb\u0101 ar inform\u0101cijas sabiedr\u012bbas pakalpojumiem, kas pied\u0101v\u0101ti b\u0113rnam<\/li>\n\n<\/ol>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 17<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ties\u012bbas uz apstr\u0101des ierobe\u017eo\u0161anu (Right to restriction of processing)<\/h3>\n\n\n\n<p>Personai ir ties\u012bbas pan\u0101kt apstr\u0101des ierobe\u017eo\u0161anu, ja:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n\n<li>Persona apstr\u012bd datu precizit\u0101ti (uz periodu, kas \u013cauj p\u0101rzinim p\u0101rbaud\u012bt)<\/li>\n\n\n<li>Apstr\u0101de ir nelikum\u012bga un persona iebilst dz\u0113\u0161anai<\/li>\n\n\n<li>P\u0101rzinim dati vairs nav vajadz\u012bgi, bet personai tie nepiecie\u0161ami juridisku pras\u012bbu cel\u0161anai\/aizst\u0101v\u012bbai<\/li>\n\n\n<li>Persona ir iebildusi apstr\u0101dei, kam\u0113r tiek p\u0101rbaud\u012bti le\u0123it\u012bmie pamati<\/li>\n\n<\/ol>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 18<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ties\u012bbas tikt inform\u0113tam par labo\u0161anu, dz\u0113\u0161anu vai ierobe\u017eo\u0161anu<\/h3>\n\n\n\n<p>P\u0101rzinim j\u0101inform\u0113 katrs sa\u0146\u0113m\u0113js, kuram dati izpausti, par labo\u0161anu, dz\u0113\u0161anu vai apstr\u0101des ierobe\u017eo\u0161anu, ja vien tas nav neiesp\u0113jami vai neprasa nesam\u0113r\u012bgas p\u016bles.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 19<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ties\u012bbas uz datu p\u0101rnesam\u012bbu (Right to data portability)<\/h3>\n\n\n\n<p>Personai ir ties\u012bbas sa\u0146emt savus datus struktur\u0113t\u0101, pla\u0161i izmantot\u0101 un ma\u0161\u012bnlas\u0101m\u0101 form\u0101t\u0101 un nodot tos citam p\u0101rzinim bez kav\u0113\u0161anas.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 20<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ties\u012bbas iebilst (Right to object)<\/h3>\n\n\n\n<p>Personai ir ties\u012bbas jebkur\u0101 laik\u0101 iebilst pret apstr\u0101di, kas balst\u012bta uz le\u0123it\u012bm\u0101m interes\u0113m vai sabiedr\u012bbas interes\u0113m, ieskaitot profil\u0113\u0161anu, pamatojoties uz savu konkr\u0113to situ\u0101ciju.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 21<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ties\u012bbas netikt pak\u013cautam automatiz\u0113tai l\u0113mumu pie\u0146em\u0161anai<\/h3>\n\n\n\n<p>Personai ir ties\u012bbas netikt pak\u013cautai l\u0113mumam, kas balst\u012bts tikai uz automatiz\u0113tu apstr\u0101di (tostarp profil\u0113\u0161anu), ja tas rada juridiskas sekas vai l\u012bdz\u012bgi b\u016btiski ietekm\u0113 personu.<\/p>\n\n\n\n<p><strong>Reference:<\/strong> GDPR <strong>Article 22<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Praktiskie ievie\u0161anas so\u013ci (no dro\u0161\u012bbas l\u012bdz e-pastiem)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1) Nostiprini vietnes dro\u0161\u012bbu<\/h3>\n\n\n\n<p>Liela da\u013ca GDPR atbilst\u012bbas praks\u0113 s\u0101kas ar element\u0101ru dro\u0161\u012bbu un datu minimiz\u0101ciju. Konkr\u0113ts checklists:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Uzst\u0101di SSL sertifik\u0101tu<\/strong> (HTTPS), lai \u0161ifr\u0113tu datu pl\u016bsmu starp vietni un serveri<\/li>\n\n\n<li><strong>Izmanto stipras paroles<\/strong> visiem admin kontiem<\/li>\n\n\n<li><strong>Pievieno papildu aizsardz\u012bbu<\/strong> maks\u0101jumu inform\u0101cijas apstr\u0101dei<\/li>\n\n\n<li><strong>Izmanto CDN<\/strong> pakalpojumu sniedz\u0113ju ar DDoS aizsardz\u012bbu<\/li>\n\n\n<li><strong>Ievies anti-v\u012brusu risin\u0101jumu<\/strong>, lai nov\u0113rstu nesankcion\u0113tu piek\u013cuvi<\/li>\n\n\n<li><strong>Samazini datu v\u0101k\u0161anu<\/strong> \u2014 v\u0101kt tikai nepiecie\u0161amo<\/li>\n\n\n<li><strong>Pseudonimiz\u0113 vai anonimiz\u0113<\/strong> personas datus pirms glab\u0101\u0161anas (kur iesp\u0113jams)<\/li>\n\n\n<li><strong>Veido rezerves kopijas<\/strong> vair\u0101k\u0101s dro\u0161\u0101s lok\u0101cij\u0101s<\/li>\n\n\n<li><strong>Dz\u0113s datus<\/strong>, kad tie vairs nav vajadz\u012bgi<\/li>\n\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">2) Pievieno s\u012bkdat\u0146u (cookie) piekri\u0161anas baneri<\/h3>\n\n\n\n<p>Ja vietn\u0113 ir ne-oblig\u0101tas s\u012bkdatnes (piem., m\u0101rketinga vai detaliz\u0113ta anal\u012btika), tev vajag <strong>skaidru piekri\u0161anu pirms to aktiviz\u0113\u0161anas<\/strong>.<\/p>\n\n\n\n<p>S\u012bkdat\u0146u banerim j\u0101izpilda \u0161\u0101das pras\u012bbas:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Blo\u0137\u0113 s\u012bkdatnes l\u012bdz piekri\u0161anai<\/strong>: iel\u0101d\u0113 tikai oblig\u0101t\u0101s s\u012bkdatnes, kam\u0113r lietot\u0101js nav apstiprin\u0101jis p\u0101r\u0113j\u0101s<\/li>\n\n\n<li><strong>Vienk\u0101r\u0161a, skaidra valoda<\/strong>: paskaidro, k\u0101das s\u012bkdatnes tiek lietotas un k\u0101p\u0113c<\/li>\n\n\n<li><strong>Vienl\u012bdz redzamas Accept\/Reject pogas<\/strong>: nedeform\u0113 izv\u0113li, nesl\u0113p \u201cReject\u201d<\/li>\n\n\n<li><strong>Granul\u0101ras opcijas<\/strong>: \u013cauj izv\u0113l\u0113ties kategorijas, nevis tikai \u201cviss vai nekas\u201d<\/li>\n\n\n<li><strong>Iesp\u0113ja atsaukt piekri\u0161anu<\/strong>: viegli main\u012bt izv\u0113li ar\u012b v\u0113l\u0101k<\/li>\n\n\n<li><strong>Piekri\u0161anas pieraksts<\/strong>: glab\u0101 izv\u0113li ar laika z\u012bmogu, lai sp\u0113tu pier\u0101d\u012bt atbilst\u012bbu<\/li>\n\n<\/ul>\n\n\n\n<div class=\"wp-block-group callout callout-warning is-style-warning is-layout-flow wp-block-group-is-layout-flow\" style=\"border-width:1px;border-radius:8px;padding-top:1rem;padding-right:1.5rem;padding-bottom:1rem;padding-left:1.5rem\">\n\n<h4 class=\"wp-block-heading callout-title\">Svar\u012bgi<\/h4>\n\n\n<p>Skroll\u0113\u0161ana vai bezdarb\u012bba NAV piekri\u0161ana.<\/p>\n\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\">3) P\u0101rskati visas vietnes formas (contact, checkout, lead forms u.c.)<\/h3>\n\n\n\n<p>Jebkurai formai, kas v\u0101c personas datus, j\u0101b\u016bt sak\u0101rtotai GDPR gar\u0101:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Pievieno <strong>priv\u0101tuma pazi\u0146ojumu<\/strong>, kas paskaidro, k\u0101p\u0113c dati nepiecie\u0161ami<\/li>\n\n\n<li>Pievieno <strong>neat\u0137eks\u0113tu<\/strong> piekri\u0161anas checkbox (ja pamats ir consent)<\/li>\n\n\n<li>M\u0101rketingam nodro\u0161ini <strong>atsevi\u0161\u0137u opt-in<\/strong> (ne \u201cvien\u0101 paket\u0113\u201d ar formas nos\u016bt\u012b\u0161anu)<\/li>\n\n\n<li>Ieliec saiti uz <strong>Privacy Policy<\/strong><\/li>\n\n\n<li>Lieto <strong>skaidru un vienk\u0101r\u0161u valodu<\/strong><\/li>\n\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">4) Ieg\u016bsti korektu piekri\u0161anu m\u0101rketinga e-pastiem<\/h3>\n\n\n\n<p>E-pasta m\u0101rketing\u0101 visbie\u017e\u0101k kl\u016bp tie\u0161i piekri\u0161anas un pier\u0101d\u0101m\u012bbas aspekts. Praktiskais checklists:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Tikai skaidrs opt-in<\/strong>: neat\u0137eks\u0113ts checkbox tie\u0161i e-pasta piekri\u0161anai<\/li>\n\n\n<li><strong>Double opt-in<\/strong>: apstiprin\u0101jums caur e-pastu p\u0113c pieteik\u0161an\u0101s<\/li>\n\n\n<li><strong>Piekri\u0161anas pieraksti<\/strong>: logi ar datumu, laiku, metodi un m\u0113r\u0137i<\/li>\n\n\n<li><strong>Redzama atteik\u0161an\u0101s saite<\/strong>: one-click unsubscribe katr\u0101 e-past\u0101<\/li>\n\n\n<li><strong>\u0100tra atteikumu apstr\u0101de<\/strong>: ide\u0101li 24 stundu laik\u0101<\/li>\n\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">5) Esi gatavs datu nopl\u016bdei (data breach)<\/h3>\n\n\n\n<p>Incidenti notiek ar\u012b sak\u0101rtot\u0101s sist\u0113m\u0101s. Lai \u201caccountability\u201d b\u016btu re\u0101la, sagatavo procesu iepriek\u0161:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Pazi\u0146o uzraudz\u012bbas iest\u0101dei 72 stundu laik\u0101<\/strong><\/li>\n\n\n<li><strong>Inform\u0113 skartos lietot\u0101jus<\/strong>, ja risks vi\u0146u ties\u012bb\u0101m ir augsts<\/li>\n\n\n<li><strong>Dokument\u0113 visu<\/strong> (kas notika, kad, k\u0101das sist\u0113mas, k\u0101di dati)<\/li>\n\n\n<li><strong>Atjaunini politikas un pas\u0101kumus<\/strong>, lai mazin\u0101tu atk\u0101rto\u0161an\u0101s risku<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">WordPress specifika: ko p\u0101rbaud\u012bt \u012bpa\u0161i r\u016bp\u012bgi<\/h2>\n\n\n\n<p>WordPress ekosist\u0113m\u0101 GDPR atbilst\u012bba parasti sadal\u0101s starp core iesp\u0113jas, spraud\u0146u uzved\u012bbu un to, ko tu re\u0101li esi konfigur\u0113jis.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Uzturi atjaunin\u0101tu <strong>WordPress core<\/strong>, t\u0113mas un spraud\u0146us<\/li>\n\n\n<li>Izmanto kontaktformu spraud\u0146us, kas atbalsta <strong>piekri\u0161anas checkbox<\/strong> un skaidru priv\u0101tuma tekstu<\/li>\n\n\n<li>Ievies korektu <strong>cookie consent<\/strong> risin\u0101jumu<\/li>\n\n\n<li>Izv\u0113lies <strong>GDPR sader\u012bgu analytics<\/strong> risin\u0101jumu (un p\u0101rbaudi, k\u0101di dati tiek s\u016bt\u012bti)<\/li>\n\n\n<li>P\u0101rskati spraud\u0146u datu v\u0101k\u0161anas praksi (da\u017ei s\u016bta telemetriju vai integr\u0113 tre\u0161o pu\u0161u skriptus)<\/li>\n\n\n<li>Ievies lietot\u0101ju datu <strong>eksporta\/dz\u0113\u0161anas<\/strong> funkcionalit\u0101ti (praktiski \u2014 lai izpild\u012btu piepras\u012bjumus)<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Sodi un sekas (ne tikai nauda)<\/h2>\n\n\n\n<p>GDPR soda apm\u0113ri tiek iedal\u012bti divos \u201cl\u012bme\u0146os\u201d:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li><strong>Lower tier violations<\/strong>: l\u012bdz <strong>10 miljoniem \u20ac<\/strong> vai <strong>2%<\/strong> no glob\u0101l\u0101 gada apgroz\u012bjuma<\/li>\n\n\n<li><strong>Upper tier violations<\/strong>: l\u012bdz <strong>20 miljoniem \u20ac<\/strong> vai <strong>4%<\/strong> no glob\u0101l\u0101 gada apgroz\u012bjuma<\/li>\n\n<\/ul>\n\n\n\n<p>Papildus naudassodiem uzraudz\u012bbas iest\u0101des var:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n\n<li>Izteikt br\u012bdin\u0101jumus<\/li>\n\n\n<li>Pagaidu vai past\u0101v\u012bgi aizliegt personas datu apstr\u0101di<\/li>\n\n\n<li>Uzlikt par pien\u0101kumu dz\u0113st datus<\/li>\n\n\n<li>Ierobe\u017eot datu nodo\u0161anu (t.sk. starp valst\u012bm)<\/li>\n\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">BUJ: bie\u017e\u0101kie jaut\u0101jumi par GDPR atbilst\u012bbu<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Kas ir GDPR atbilst\u012bbas kontrolsaraksts?<\/h3>\n\n\n\n<p>Tas ir darb\u012bbu saraksts, kas pal\u012bdz sistem\u0101tiski ieviest pras\u012bbas, kuras izriet no General Data Protection Regulation. Praktiski tas pal\u012bdz atrast \u201ccaurumus\u201d datu aizsardz\u012bbas praks\u0113 un sak\u0101rtot procesus.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Kur\u0161 ir atbild\u012bgs par GDPR iev\u0113ro\u0161anu?<\/h3>\n\n\n\n<p>Prim\u0101r\u0101 atbild\u012bba parasti ir <strong>data controller<\/strong> (bie\u017ei \u2014 vietnes vai biznesa \u012bpa\u0161nieks). Ta\u010du ar\u012b <strong>data processors<\/strong> ir savi atbilst\u012bbas pien\u0101kumi.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Vai GDPR attiecas uz ASV uz\u0146\u0113mumiem?<\/h3>\n\n\n\n<p>J\u0101 \u2014 ja tu apstr\u0101d\u0101 ES iedz\u012bvot\u0101ju personas datus, neatkar\u012bgi no t\u0101, kur atrodas tavs bizness.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">K\u0101ds ir maksim\u0101lais sods par neatbilst\u012bbu?<\/h3>\n\n\n\n<p>L\u012bdz <strong>20 miljoniem \u20ac<\/strong> vai <strong>4%<\/strong> no glob\u0101l\u0101 gada apgroz\u012bjuma (atkar\u012bb\u0101 no t\u0101, kur\u0161 skaitlis ir liel\u0101ks).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Vai man vajag cookie baneri?<\/h3>\n\n\n\n<p>J\u0101, ja vietn\u0113 ir jebk\u0101das ne-oblig\u0101tas s\u012bkdatnes un tev ir ES apmekl\u0113t\u0101ji.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Vai man vajag DPO (Data Protection Officer)?<\/h3>\n\n\n\n<p>Tikai tad, ja: (1) esi publiska iest\u0101de; vai (2) pamatdarb\u012bba ir liela m\u0113roga, regul\u0101ra un sistem\u0101tiska personu uzraudz\u012bba; vai (3) liel\u0101 m\u0113rog\u0101 apstr\u0101d\u0101 sensit\u012bvus datus vai datus par sod\u0101m\u012bbu\/p\u0101rk\u0101pumiem.<\/p>\n\n\n\n<div class=\"wp-block-group callout callout-info is-style-info is-layout-flow wp-block-group-is-layout-flow\" style=\"border-width:1px;border-radius:8px;padding-top:1rem;padding-right:1.5rem;padding-bottom:1rem;padding-left:1.5rem\">\n\n<h4 class=\"wp-block-heading callout-title\">Atruna<\/h4>\n\n\n<p>\u0160is kontrolsaraksts ir visp\u0101r\u012bgs ce\u013cvedis un nav uzskat\u0101ms par juridisku konsult\u0101ciju. Konkr\u0113t\u0101 situ\u0101cij\u0101 ieteicams konsult\u0113ties ar kvalific\u0113tu juristu.<\/p>\n\n<\/div>\n\n\n<div class=\"references-section\">\n                <h2>Atsauces \/ Avoti<\/h2>\n                <ul class=\"references-list\"><li><a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\" target=\"_blank\" rel=\"noopener noreferrer\">Regulation (EU) 2016\/679 (General Data Protection Regulation)<\/a><\/li><\/ul>\n            <\/div>","protected":false},"excerpt":{"rendered":"<p>Ja tav\u0101 vietn\u0113 non\u0101k kaut minim\u0101ls ES iedz\u012bvot\u0101ju personas datu apjoms (kontakta forma, analytics, e-pasts), GDPR pras\u012bbas k\u013c\u016bst par ikdienas tehnisko darbu. \u0160eit ir pilns, praks\u0113 izpild\u0101ms kontrolsaraksts ar atsauc\u0113m uz konkr\u0113tiem GDPR pantiem.<\/p>\n","protected":false},"author":51,"featured_media":165,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[89,87,83,88,10],"class_list":["post-166","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-drosiba","tag-cookies","tag-datu-aizsardziba","tag-gdpr","tag-privatuma-politika","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/helloblog.io\/lv\/wp-json\/wp\/v2\/posts\/166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/helloblog.io\/lv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/helloblog.io\/lv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/helloblog.io\/lv\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/helloblog.io\/lv\/wp-json\/wp\/v2\/comments?post=166"}],"version-history":[{"count":0,"href":"https:\/\/helloblog.io\/lv\/wp-json\/wp\/v2\/posts\/166\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/helloblog.io\/lv\/wp-json\/wp\/v2\/media\/165"}],"wp:attachment":[{"href":"https:\/\/helloblog.io\/lv\/wp-json\/wp\/v2\/media?parent=166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/helloblog.io\/lv\/wp-json\/wp\/v2\/categories?post=166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/helloblog.io\/lv\/wp-json\/wp\/v2\/tags?post=166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}