Briefly
Briefly
European Securities and Markets Authoritypolicy
policy

ESMA EU Regulation 2018/1725 data protection obligations

European Union·European Securities and Markets Authority·⏱️ 3 min readBriefly Analysis

Summary

  • ESMA is subject to Regulation (EU) 2018/1725 on data protection obligations.
  • The regulation requires ESMA to maintain a central register of records detailing its activities involving personal data.
  • Data subjects have rights under this regulation, including the right to withdraw consent and access their personal data.
  • ESMA's website provides links to third-party sites with their own privacy policies.

What Happened

Data subjects have the right to receive information about the processing of their personal data, to access the personal data and to correct any inaccurate or incomplete personal data, as well as to request the erasure, restriction of processing or to object to the processing of their personal data on written request.

The European Securities and Markets Authority (ESMA) has implemented Regulation (EU) 2018/1725 on data protection obligations. This regulation requires ESMA to protect individuals' personal data when processing it for various purposes, including the provision of e-services. Although most of the ESMA website can be browsed without providing personal information, some pages require users to input their details in order to access certain services. These pages adhere to a clear policy on data protection as outlined in Regulation 2018/1725.

Relevant Legal and Regulatory Context

Regulation (EU) 2018/1725 is the cornerstone of ESMA's data protection obligations. This regulation, which repeals previous directives such as EC No 45/2001 and Decision No 1247/2002/EC, sets out strict guidelines for the processing of personal data by EU institutions, bodies, offices, and agencies, including ESMA. One key aspect of this regulation is the requirement for ESMA to maintain a central register of records detailing its activities involving personal data (Article 31). This register must contain specific information, including the list of records with hyperlinks to each relevant entry.

Why It Matters

Companies and organizations subject to EU Regulation 2018/1725 must ensure they have a clear data protection policy in place. This includes procedures for accessing and correcting personal data, as well as mechanisms for handling subject access requests. ESMA's adherence to this regulation underscores the importance of transparency and accountability in personal data processing. Data subjects have rights under this regulation, including the right to withdraw consent at any time without affecting the lawfulness of previous processing.

Practical Implications

Lawyers advising on compliance with EU Regulation 2018/1725 should note that companies must ensure they have a clear data protection policy in place, including procedures for accessing and correcting personal data, as well as mechanisms for handling subject access requests.

Source

Source: Original reporting via ESMA's Legal Notice and Data Protection webpage.

AI Business Impact

How does this affect your business?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

ESMA EU Regulation 2018/1725 data protection obligations | Briefly | Briefly