{"id":72190,"date":"2020-10-29T21:37:33","date_gmt":"2020-10-29T20:37:33","guid":{"rendered":"https:\/\/www.lexxion.eu\/dpi\/data-protection-insider-issue-34\/"},"modified":"2020-10-29T21:37:33","modified_gmt":"2020-10-29T20:37:33","slug":"data-protection-insider-issue-34","status":"publish","type":"dpi","link":"https:\/\/www.lexxion.eu\/en\/dpi\/data-protection-insider-issue-34\/","title":{"rendered":"Data Protection Insider, Issue 34"},"content":{"rendered":"<div class=\"txtTinyMce-wrapper\" style=\"font-family: inherit; font-size: 12px; line-height: 18px; text-align: justify;\">\n<p style=\"text-align: justify; margin: 0px; direction: ltr; color: inherit; line-height: 18px; font-size: 12px; word-break: break-word;\">\n<p style=\"text-align: justify; margin: 0px; direction: ltr; color: inherit; line-height: 18px; font-size: 12px; word-break: break-word;\"><a style=\"text-decoration: none;\" href=\"https:\/\/hudoc.echr.coe.int\/eng#{%22itemid%22:[%22002-12961%22]}\" target=\"_blank\" rel=\"noopener\"><span style=\"font-size: 14px; line-height: 21px;\"><strong>&#8211; ECtHR Rules on Archival Research and Privacy<\/strong><strong>\u00a0&#8211;<\/strong><\/span><\/a><\/p>\n<p style=\"line-height: 18px; word-break: break-word;\">\n<p style=\"word-break: break-word; line-height: 18px;\"><span style=\"font-size: 14px; line-height: 21px;\">On 13<sup>th<\/sup> October the ECtHR handed down its decision in <em>Gafiuc v. Romania<\/em>. The case concerned a journalist who had been granted accreditation to conduct research in the Romanian Securitate archives \u2013 the archives of the Romanian Secret Police under the Communist Regime. Such access is granted only provided an individual is conducting research into the historical truth about the period. The journalist then went on to publish a series of articles including information on individuals who had collaborated with the regime in informing on sportspersons who had been under state surveillance. The journalist\u2019s accreditation was subsequently withdrawn on the ground that they had illegitimately violated individuals\u2019 privacy and that they had not acted in line with the original purposes of their research. <a style=\"text-decoration: underline;\" href=\"https:\/\/hudoc.echr.coe.int\/eng#{%22itemid%22:[%22002-12961%22]}\" target=\"_blank\" rel=\"noopener\">The journalist appealed to the Court claiming the removal of accreditation illegitimately interfered with their Article 10 right to freedom of expression. The Court decided there was no infringement<\/a>. In particular, the Court highlighted that the information published included information relating to the private sphere of sportspersons, which did not concern their athletic performance, which had not been published by the sportspersons concerned themselves, which was in general inaccessible to the public, which could not be effectively assessed and which could not be considered to serve the public interest. In this regard, the Court considered that the privacy interests involved outweighed the journalist\u2019s Article 10 rights and that the removal of accreditation was legitimate. Whilst not ostensibly about the Article 8 right to privacy, the case is significant in relation to data protection in terms of its consideration of the privacy interests tied up with state archives. In this regard, the case takes its place among the range of case law dealing with the legitimate limitations on the access and use of Communist period archives.<\/span><\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<div class=\"txtTinyMce-wrapper\" style=\"font-family: inherit; font-size: 12px; line-height: 18px; text-align: justify;\">\n<p style=\"text-align: justify; margin: 0px; direction: ltr; color: inherit; line-height: 18px; font-size: 12px; word-break: break-word;\"><a style=\"text-decoration: none;\" href=\"https:\/\/hudoc.echr.coe.int\/eng-press#{%22fulltext%22:[%2258208\/14%22]}\" target=\"_blank\" rel=\"noopener\"><span style=\"font-size: 14px; line-height: 21px;\"><strong>&#8211; <em>Maris v Romania<\/em>: Rectification Requests Not Always Recognised<\/strong><\/span><span style=\"font-size: 14px; line-height: 21px;\"><strong>\u00a0&#8211;<\/strong><\/span><\/a><\/p>\n<p style=\"text-align: justify; margin: 0px; direction: ltr; color: inherit; line-height: 18px; font-size: 12px; word-break: break-word;\">\n<p style=\"line-height: 18px; word-break: break-word;\"><span style=\"font-size: 14px; line-height: 21px;\">On 22<sup>nd<\/sup> October the ECtHR declared Maris\u2019s application alleging a breach of Article 9 ECHR on freedom of religion inadmissible. Superficially, the case does not look relevant for data protection. When one looks deeper however, a different picture appears. According to the facts of the case, the applicant is a prisoner whose prison records indicate his religion to be \u201corthodox Christian.\u201d Whilst he had requested that the records be amended to indicate his religion to be \u201cJewish\u201d, the prison authorities had failed to correct the records. Accordingly, the applicant claimed a violation of his freedom of religion rights. The ECtHR concluded that the complaint was inadmissible, mainly because the applicant was never prevented from manifesting his religion or exercising and practising it. From a data protection perspective, it is interesting that the Court did not consider the relevance of the fact that the prisoner\u2019s data had not been updated despite an explicit request. <a style=\"text-decoration: underline;\" href=\"https:\/\/hudoc.echr.coe.int\/eng-press#{%22fulltext%22:[%2258208\/14%22]}\" target=\"_blank\" rel=\"noopener\">It seems the Court did not feel that the right to have one\u2019s religion accurately reflected in official records related in any meaningful way to the ability to manifest one\u2019s religion<\/a>. This conclusion seems at least debatable given the very real form of manifestation of religion implied by state recording and recognition of one\u2019s religious identity. It is also interesting that the case dealt with issues concerning rights to access and rectification whilst the case did not deal directly with Article 8. The data protection community tends to look at the Article 8 right to privacy as the locus for evaluating the ECtHR\u2019s elaboration of fundamental rights connected to personal data processing. This case highlights that the locus of the ECtHR\u2019s data protection thinking may, on occasion, lie elsewhere. It is possible, for example, that there are considerably more cases dealing with data access and rectification than those traditionally discussed, simply by virtue of the fact that these are not raised under Article 8. Finally, if a similar question would be raised under the GDPR\/LED, it would be interesting to know what the courts and data protection supervisory authorities would deem to be adequate evidence of change of religious identity when requesting a rectification such as that in the Maris case.<\/span><\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<div class=\"txtTinyMce-wrapper\" style=\"font-family: inherit; font-size: 12px; line-height: 18px; text-align: justify;\">\n<p style=\"text-align: justify; margin: 0px; direction: ltr; color: inherit; line-height: 18px; font-size: 12px; word-break: break-word;\"><a style=\"text-decoration: none;\" href=\"https:\/\/edpb.europa.eu\/news\/news\/2020\/european-data-protection-board-40th-plenary-session-guidelines-data-protection-design_en\" target=\"_blank\" rel=\"noopener\"><span style=\"font-size: 14px; line-height: 21px;\"><strong>&#8211;\u00a0<\/strong><\/span><span style=\"font-size: 14px; line-height: 21px;\"><strong>EDPB Holds 40<sup>th<\/sup> Plenary Session &#8211;<\/strong><\/span><\/a><\/p>\n<p style=\"text-align: justify; margin: 0px; direction: ltr; color: inherit; line-height: 18px; font-size: 12px; word-break: break-word;\">\n<p style=\"line-height: 18px; word-break: break-word;\"><span style=\"font-size: 14px; line-height: 21px;\">On 20<sup>th<\/sup> October the EDPB held its <a style=\"text-decoration: underline;\" href=\"https:\/\/edpb.europa.eu\/news\/news\/2020\/european-data-protection-board-40th-plenary-session-guidelines-data-protection-design_en\" target=\"_blank\" rel=\"noopener\">40<sup>th<\/sup> Plenary Session<\/a>. During the Session, the EDPB decided to establish a Coordinated Enforcement Framework (CEF), which provides \u201ca structure for coordinating recurring annual activities by EDPB Supervisory Authorities (SAs).\u201d The framework will ensure the coordination and flexibility of joint actions across the wide range of tasks and powers of the SAs \u2013 from awareness raising through investigations to enforcement actions. The EDPB also adopted the following documents:<\/span><\/p>\n<p style=\"line-height: 18px; word-break: break-word;\">\n<ul>\n<li style=\"line-height: 18px;\"><span style=\"font-size: 14px; line-height: 21px;\">A final version of the Guidelines on Data Protection by Design &amp; Default after the public consultation on a draft version. As well as focusing on the requirements stemming from Article 25 GDPR, the Guidelines also focus on how to ensure compliance with the principles set out in Article 5 GDPR.<\/span><\/li>\n<li style=\"line-height: 18px;\"><span style=\"font-size: 14px; line-height: 21px;\">A letter in response to the Europ\u00e4ische Akademie f\u00fcr Informationsfreiheit und Datenschutz with regards to the data protection implications of Article 17 of the Copyright Directive \u2013 focusing, in particular, on upload filters.<\/span><\/li>\n<\/ul>\n<p style=\"line-height: 18px; word-break: break-word;\">\n<p style=\"line-height: 18px; word-break: break-word;\"><span style=\"font-size: 14px; line-height: 21px;\">The documents will be made available on the EDPB\u2019s website following the standard linguistic, formatting and legal checks.<\/span><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<div class=\"txtTinyMce-wrapper\" style=\"font-family: inherit; font-size: 12px; line-height: 18px; text-align: justify;\">\n<p style=\"text-align: justify; margin: 0px; direction: ltr; color: inherit; line-height: 18px; font-size: 12px; word-break: break-word;\"><a style=\"text-decoration: none;\" href=\"https:\/\/techcrunch.com\/2020\/10\/16\/iab-europes-ad-tracking-consent-framework-found-to-fail-gdpr-standard\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-size: 14px; line-height: 21px;\"><strong>&#8211; Investigatory Division of Belgian DPA considers IAB TCF Problematic<\/strong><\/span><span style=\"font-size: 14px; line-height: 21px;\"><strong>\u00a0&#8211;<\/strong><\/span><\/a><\/p>\n<p style=\"text-align: justify; margin: 0px; direction: ltr; color: inherit; line-height: 18px; font-size: 12px; word-break: break-word;\">\n<p style=\"text-align: justify; margin: 0px; direction: ltr; color: inherit; line-height: 18px; font-size: 12px; word-break: break-word;\"><span style=\"font-size: 14px; line-height: 21px;\">In the latest addition to the range of ongoing investigations into online behavioural advertising, <a style=\"text-decoration: underline;\" href=\"https:\/\/techcrunch.com\/2020\/10\/16\/iab-europes-ad-tracking-consent-framework-found-to-fail-gdpr-standard\/\" target=\"_blank\" rel=\"noopener\">the investigatory division of the Belgian DPA has concluded that the Internet Advertising Bureau\u2019s (IAB) Transparency and Consent Framework (TCF) is not compatible with the requirements of the GDPR<\/a>. The TCF was adopted by the IAB in 2018 as an effort to update the practices of online advertisers such that these would be compatible with the GDPR. Since then, the TCF has had wide uptake amongst companies operating in the online behavioural advertising space. The investigatory division of the Belgian DPA, however, according to TechCrunch, has published a preliminary report in which the TCF is highlighted as problematic for a number of reasons, including: that the TCF does not comply with fairness, transparency and accountability principles; that the TCF does not adhere to lawfulness of processing requirements; and that the TCF does not include sufficient conditions to legitimate the processing of sensitive personal data. The report also includes other problematic findings concerning the IAB\u2019s internal data processing practices, including that the organisation has not met its obligation to appoint a DPO. The IAB has provided a response to the report disputing the findings \u2013 also linked below. The investigatory division\u2019s report will now be taken forward by the litigation division which will now examine the case on its merits.<\/span><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<div class=\"txtTinyMce-wrapper\" style=\"font-family: inherit; font-size: 12px; line-height: 18px; text-align: justify;\">\n<p style=\"text-align: justify; margin: 0px; direction: ltr; line-height: 18px; font-size: 12px; word-break: break-word;\"><a style=\"text-decoration: none;\" href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/right-of-access\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #123256; font-size: 14px; line-height: 21px;\"><strong>&#8211; ICO Adopts Guidelines on the Right of Access &#8211;<\/strong><\/span><\/a><\/p>\n<p style=\"text-align: justify; font-size: 14px; margin: 0px; direction: ltr; line-height: 21px; word-break: break-word;\">\n<p style=\"text-align: justify; font-size: 14px; margin: 0px; direction: ltr; line-height: 21px; word-break: break-word;\">On 21<sup>st<\/sup> October the ICO released its <a style=\"text-decoration: underline;\" href=\"https:\/\/ico.org.uk\/for-organisations\/guide-to-data-protection\/guide-to-the-general-data-protection-regulation-gdpr\/right-of-access\/\" target=\"_blank\" rel=\"noopener\">Guidelines on the Data Subject Access Right (DSAR)<\/a> to their own personal data under the GDPR. The Guidelines are addressed to large companies \u2013 specifically to their Data Protection Officers (DPOs) and staff members with data protection responsibilities. They focus on seven general topics: i) how to recognise an access request; ii) how to fulfil the requirements of Article 15 read in conjunction with Article 12 GDPR with regards to charging reasonable fees; iii) recognising manifestly ill-founded and excessive requests; iv) verifying the identity of the requesting individual; v) dealing with requests which concern multiple individuals\u2019 personal data simultaneously; vi) the collaboration between joint controllers and the controller and processor(s) in responding to DSARs; vii) and the possibility for applying restrictions to DSARs under the GDPR and UK law. The Guidelines further pay special attention to access in relation to unstructured manual records, credit files, health data, educational data, and social work data. Finally, they discuss the possibility for administrative and judicial remedies. The ICO explicitly states that it constitutes a criminal offence to force someone to make an access request concerning their own data. We note that the present Guidelines are to be read together with prior Guidelines concerning the explainability of automated decisions and profiles from May 2020. This is because the present Guidelines do not delve into detail about how the right of access applies and is to be exercised in relation to automated decisions and profiles, whilst the topic is subject to much debate. In addition, we note that the Guidelines apply primarily to the GDPR and almost no attention is paid to the exercise of data subjects\u2019 rights under the so-called \u201cPolice\u201d Directive. Bearing in mind the sensitivity of processing in the law enforcement sector and the novelty of data protection legislation in this sector, such guidance would be welcome indeed.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<div class=\"txtTinyMce-wrapper\" style=\"font-family: inherit; font-size: 12px; line-height: 18px; text-align: justify;\">\n<p style=\"text-align: justify; margin: 0px; direction: ltr; line-height: 18px; font-size: 12px; word-break: break-word;\"><a style=\"text-decoration: none;\" href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:62020CN0319&amp;from=EN\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #123256; font-size: 14px; line-height: 21px;\"><strong>&#8211; CJEU and Representative Organisations\u2019 Standing &#8211;<\/strong><\/span><\/a><\/p>\n<p style=\"text-align: justify; font-size: 14px; margin: 0px; direction: ltr; line-height: 21px; word-break: break-word;\">\n<p style=\"word-break: break-word; line-height: 18px;\"><span style=\"font-size: 14px; line-height: 21px;\">Previously in Data Protection Insider, we reported on a case in front of the German Bundesgerichtshof BGH) involving Facebook and Bundesverband der Verbraucherzentralen und Verbraucherverb\u00e4nde \u2014 Verbraucherzentrale Bundesverband e.V. We reported that the BGH had chosen to refer the case to the CJEU pending an answer to the following question: \u2018Do\u2026Article 80(1) and (2) and Article 84(1), of Regulation (EU) 2016\/679 ( 1 ) preclude national rules which \u2014 alongside the powers of intervention of the supervisory authorities responsible for monitoring and enforcing the Regulation and the options for legal redress for data subjects \u2014 empower, on the one hand, competitors and, on the other, associations, entities and chambers entitled under national law, to bring proceedings for breaches of Regulation (EU) 2016\/679, independently of the infringement of specific rights of individual data subjects and without being mandated to do so by a data subject, against the infringer before the civil courts on the basis of the prohibition of unfair commercial practices or breach of a consumer protection law or the prohibition of the use of invalid general terms and conditions?\u2019 In an update to the case, on 26<sup>th<\/sup> October the Official Journal recorded that <a style=\"text-decoration: underline;\" href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:62020CN0319&amp;from=EN\" target=\"_blank\" rel=\"noopener\">the case is now included in the official proceedings of the CJEU<\/a>. The CJEU\u2019s eventual decision looks likely to have significant ramifications for the ability to bring proceedings for violations of data protection law and the progression of the case should be followed with utmost interest.<\/span><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>&#8211; ECtHR Rules on Archival Research and Privacy\u00a0&#8211; On 13th October the ECtHR handed down [&hellip;]<\/p>\n","protected":false},"author":144,"featured_media":0,"menu_order":0,"comment_status":"open","ping_status":"closed","template":"","dpi-category":[],"dpi-tag":[],"class_list":["post-72190","dpi","type-dpi","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi\/72190","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi"}],"about":[{"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/types\/dpi"}],"author":[{"embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/users\/144"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/comments?post=72190"}],"version-history":[{"count":0,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi\/72190\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/media?parent=72190"}],"wp:term":[{"taxonomy":"dpi-category","embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi-category?post=72190"},{"taxonomy":"dpi-tag","embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi-tag?post=72190"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}