{"id":72286,"date":"2021-10-14T22:29:21","date_gmt":"2021-10-14T20:29:21","guid":{"rendered":"https:\/\/www.lexxion.eu\/dpi\/data-protection-insider-issue-56\/"},"modified":"2021-10-14T22:29:21","modified_gmt":"2021-10-14T20:29:21","slug":"data-protection-insider-issue-56","status":"publish","type":"dpi","link":"https:\/\/www.lexxion.eu\/en\/dpi\/data-protection-insider-issue-56\/","title":{"rendered":"Data Protection Insider, Issue 56"},"content":{"rendered":"<div class=\"txtTinyMce-wrapper\" style=\"font-family: Arial, Helvetica Neue, Helvetica, sans-serif; font-size: 12px; line-height: 18px; text-align: justify;\">\n<p style=\"line-height: 21px; word-break: break-word; font-size: 14px; text-align: justify;\"><a style=\"text-decoration: none;\" href=\"https:\/\/hudoc.echr.coe.int\/eng#{%22article%22:[%228%22],%22documentcollectionid2%22:[%22GRANDCHAMBER%22,%22CHAMBER%22],%22itemid%22:[%22001-211794%22]}\" target=\"_blank\" rel=\"noopener\"><strong>&#8211; \u00a0<\/strong><\/a><strong>AG Bobek Reads the Judicial Capacity Exception Broadly <\/strong><a style=\"text-decoration: none;\" href=\"https:\/\/hudoc.echr.coe.int\/eng#{%22article%22:[%228%22],%22documentcollectionid2%22:[%22GRANDCHAMBER%22,%22CHAMBER%22],%22itemid%22:[%22001-211794%22]}\" target=\"_blank\" rel=\"noopener\"><strong><em>&#8211;<\/em><\/strong><\/a><\/p>\n<p style=\"line-height: 18px; word-break: break-word;\">\n<p style=\"line-height: 18px; word-break: break-word;\"><span style=\"font-size: 14px; line-height: 21px;\">On 6th October, the AG Bobek delivered his Opinion in the case of <em>X, Z v Autoriteit Persoonsgegevens<\/em>. As to the facts of the case, as a standard practice, in the Netherlands journalists are granted access to certain judicial documents before the hearing of a court case in order to be able to better report on it. The applicants in the present case, whose case was heard in Dutch courts and relevant materials disclosed to journalists, submitted a complaint with the Dutch Supervisory Authority (SA), claiming, amongst others, that they had not consented to the disclosure. The SA did not consider itself competent to examine the complaint, because it concluded that \u2018the processing at issue was carried out in the national courts\u2019 \u2018judicial capacity\u2019, pursuant to Article 55(3) of the GDPR.\u2019 The local courts, with which the decision was appealed, submitted a question to the CJEU whether this is indeed the case. Based on the CJEU case law, AG Bobek noted that the disclosure in question should indeed constitute a personal data processing operation, which is in principle subject to the rules of the GDPR. However, he argued that it could be exempt from the supervision by the SAs set up under the GDPR, pursuant to Article 55 (3), because the disclosure should be considered to be performed in the court\u2019s judicial capacity. <u><a style=\"text-decoration: underline;\" href=\"https:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;docid=247105&amp;pageIndex=0&amp;doclang=EN&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=10934177\" target=\"_blank\" rel=\"noopener\">AG Bobek gave a very broad reading of the scope of \u2018judicial capacity\u2019, arguing that a data processing does not need to prejudice the independence of the courts for it to fall within this exception, but that one \u2018should employ a broad interpretation of the concept of \u2018judicial capacity\u2019 that goes beyond mere judicial decision-making in an individual case. It must also cover all activities that may indirectly impact upon the judicial independence of the courts. As such, courts should, by default, be considered to be acting in a \u2018judicial capacity\u2019 unless it is established, as regards a specific type of activity, that it is of administrative nature only.<\/a>\u2019<\/u> In addition, he argued that it is enough that there is a general legal basis, which allows the disclosure, and it is not necessary that the proportionality of each disclosure is examined in advance. We find that the Opinion makes a very interesting read for all those who are trying to define the scope and limits of EU data protection law and its role within the legal system of other laws and social norms.<\/span><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<div class=\"txtTinyMce-wrapper\" style=\"font-size: 12px; line-height: 18px; text-align: justify; font-family: Arial, 'Helvetica Neue', Helvetica, sans-serif;\">\n<p style=\"line-height: 21px; word-break: break-word; font-size: 14px;\"><a style=\"text-decoration: none;\" href=\"https:\/\/hudoc.echr.coe.int\/eng#{%22itemid%22:[%22002-13390%22]}\" target=\"_blank\" rel=\"noopener\"><strong>&#8211; <\/strong><\/a><strong>ECtHR Rules on Secret Surveillance in <em>Gladkiy and Others v. Russia<\/em><\/strong><a style=\"text-decoration: none;\" href=\"https:\/\/hudoc.echr.coe.int\/eng#{%22itemid%22:[%22002-13390%22]}\" target=\"_blank\" rel=\"noopener\"><strong>&#8211;<\/strong><\/a><\/p>\n<p style=\"line-height: 21px; word-break: break-word; font-size: 14px;\">\n<p style=\"line-height: 21px; word-break: break-word; font-size: 14px;\"><span style=\"font-size: 14px; line-height: 21px;\"><a style=\"text-decoration: underline;\" href=\"https:\/\/hudoc.echr.coe.int\/eng#{%22itemid%22:[%22001-212002%22]}\" target=\"_blank\" rel=\"noopener\"><u>On 30th September, the European Court of Human Rights ruled in the case of Gladkiy and Others v. Russia.<\/u><\/a> The Case was decided by Committee. The case concerned the secret surveillance of the plaintiffs by law enforcement agencies, which had suspected the plaintiffs of engaging in smuggling activities. The plaintiffs complained on the basis of Article 8 \u2013 right to respect for private and family life \u2013 and Article 13 \u2013 right to an effective remedy \u2013 of the ECHR that the secret surveillance constituted a violation of their rights. With regards to Article 8, the Court found a violation. The Court highlighted that: \u2018measures aimed at interception of telephone communications amounted to an interference with the exercise of the rights set out in Article 8\u2026Such interference will give rise to a breach of the Convention unless it can be shown that it was \u201cin accordance with law\u201d, pursued one or more legitimate aim or aims\u2026and was \u201cnecessary in a democratic society\u201d to achieve those aims\u2019. After recalling comparable cases, the Court found: \u2018There is no evidence that any information or document confirming the suspicion against the applicants was submitted to the courts which authorised interception of the applicants\u2019 telephone conversations. Nor is there any indication that those courts applied the test of \u201cnecessity in a democratic society\u201d, and in particular assessed whether the surveillance measures carried out against the applicants were proportionate to any legitimate aim pursued. These complaints are therefore admissible and disclose a breach of Article 8 of the Convention.\u2019 The case is short and easy to read but \u2013 as to be expected from a Committee ruling \u2013 predominantly reiterates previous considerations concerning secret surveillance measures and comes to a predictable conclusion.<\/span><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<div class=\"txtTinyMce-wrapper\" style=\"font-size: 12px; line-height: 18px; text-align: justify; font-family: Arial, 'Helvetica Neue', Helvetica, sans-serif;\">\n<p style=\"line-height: 21px; word-break: break-word; font-size: 14px;\"><span style=\"font-size: 14px; line-height: 21px;\"><a style=\"text-decoration: none;\" href=\"https:\/\/edpb.europa.eu\/news\/news\/2021\/edpb-requests-irish-sa-amends-whatsapp-decision-clarifications-transparency-and_en\" target=\"_blank\" rel=\"noopener\"><strong>&#8211; <\/strong><\/a><\/span><strong>EP Resolution to Ban Mass (Biometric) Surveillance<\/strong><span style=\"font-size: 14px; line-height: 21px;\"><a style=\"text-decoration: none;\" href=\"https:\/\/edpb.europa.eu\/news\/news\/2021\/edpb-requests-irish-sa-amends-whatsapp-decision-clarifications-transparency-and_en\" target=\"_blank\" rel=\"noopener\"><strong>&#8211;<\/strong><\/a><\/span><\/p>\n<p style=\"line-height: 21px; word-break: break-word; font-size: 14px;\">\n<p style=\"line-height: 18px; word-break: break-word;\"><span style=\"font-size: 14px; line-height: 21px;\">On 6th October, the European Parliament adopted a resolution, in which the MEPs called for strong safeguards in relation to AI technologies, in particular against discrimination, especially those in the law enforcement field and border control context. In addition, \u2018[t]o ensure that fundamental rights are upheld when using these technologies, algorithms should be transparent, traceable and sufficiently documented, MEPs ask. Where possible, public authorities should use open-source software in order to be more transparent.\u2019<a style=\"text-decoration: underline;\" href=\"https:\/\/www.europarl.europa.eu\/news\/en\/press-room\/20210930IPR13925\/use-of-artificial-intelligence-by-the-police-meps-oppose-mass-surveillance\" target=\"_blank\" rel=\"noopener\"> Most importantly, the Resolution goes as far as to call for an explicit ban on \u2018on the automated recognition of individuals in public spaces\u2019, \u2018the use of private facial recognition databases (like the Clearview AI system, which is already in use) and predictive policing based on behavioural data\u2019, and \u2018social scoring systems, which try to rate the trustworthiness of citizens based on their behaviour or personality.\u2019<\/a> Finally, the Resolution calls for border control projects like iBorderCtrt and technologies for remote identification of travellers to be discontinued.<\/span><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<div class=\"txtTinyMce-wrapper\" style=\"font-size: 12px; line-height: 18px; text-align: justify; font-family: Arial, 'Helvetica Neue', Helvetica, sans-serif;\">\n<p style=\"line-height: 21px; word-break: break-word; font-size: 14px;\"><span style=\"font-size: 14px; line-height: 21px;\"><a style=\"text-decoration: none;\" href=\"https:\/\/hudoc.echr.coe.int\/eng#{%22article%22:[%228%22],%22documentcollectionid2%22:[%22GRANDCHAMBER%22,%22CHAMBER%22],%22itemid%22:[%22001-210766%22]};%20https:\/\/hudoc.echr.coe.int\/eng-press#{%22fulltext%22:[%227796\/16%22]}\" target=\"_blank\" rel=\"noopener\"><strong>&#8211; <\/strong><\/a><\/span><strong>Council Agrees Position on Data Governance Act<\/strong><span style=\"font-size: 14px; line-height: 21px;\"><span style=\"line-height: 18px;\"><strong><a href=\"https:\/\/hudoc.echr.coe.int\/eng#{%22article%22:[%228%22],%22documentcollectionid2%22:[%22GRANDCHAMBER%22,%22CHAMBER%22],%22itemid%22:[%22001-210766%22]};%20https:\/\/hudoc.echr.coe.int\/eng-press#{%22fulltext%22:[%227796\/16%22]}\" target=\"_blank\" rel=\"noopener\">&#8211;<\/a><\/strong><\/span><\/span><\/p>\n<p style=\"line-height: 21px; word-break: break-word; font-size: 14px;\">\n<p style=\"line-height: 18px; word-break: break-word;\"><span style=\"font-size: 14px; line-height: 21px;\"><a style=\"text-decoration: underline;\" href=\"https:\/\/www.consilium.europa.eu\/en\/press\/press-releases\/2021\/10\/01\/eu-looks-to-make-data-sharing-easier-council-agrees-position-on-data-governance-act\/;%20https:\/\/data.consilium.europa.eu\/doc\/document\/ST-12124-2021-INIT\/en\/pdf\" target=\"_blank\" rel=\"noopener\"><u>On 1st October, the Council announced that the Member States had agreed a position on the Data Governance Act.<\/u><\/a> In principle the Act aims to \u2018set up solid mechanisms to facilitate the reuse of certain categories of protected public-sector data, increase trust in data intermediation services and promote data altruism across the EU.\u2019 The Council position includes a number of deviations from the initial proposition adopted by the Commission. The Council position, for example, suggests: \u2018introduc[ing] more flexibility in the text and tak[ing] account of national specificities that already exist in some member states [in relation to the reuse of public data]\u2019, \u2018clarif[ying] the scope of [data intermediation] provisions, in particular to indicate more clearly which types of companies can be data intermediaries\u2019 and \u2018add[ing] compliance with a code of conduct as a requirement for registration as a recognised data altruism organisation.\u2019 The adoption of the position will now allow the Council to negotiate with the European Parliament toward a final text.<\/span><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<div class=\"txtTinyMce-wrapper\" style=\"font-size: 12px; line-height: 18px; text-align: justify; font-family: Arial, 'Helvetica Neue', Helvetica, sans-serif;\">\n<p style=\"line-height: 21px; word-break: break-word; font-size: 14px;\"><strong><a style=\"text-decoration: none;\" href=\"https:\/\/edpb.europa.eu\/system\/files\/2021-08\/edpb_letter_out_2021_00130_mepveld_facialrecognition_publication.pdf\" target=\"_blank\" rel=\"noopener\">&#8211; <\/a>EDPB Adopts Opinion on Adequacy in relation to the Republic of Korea <a style=\"text-decoration: none;\" href=\"https:\/\/hudoc.echr.coe.int\/eng#{%22article%22:[%228%22],%22documentcollectionid2%22:[%22GRANDCHAMBER%22,%22CHAMBER%22],%22itemid%22:[%22001-210766%22]};%20https:\/\/hudoc.echr.coe.int\/eng-press#{%22fulltext%22:[%227796\/16%22]}\" target=\"_blank\" rel=\"noopener\">&#8211;<\/a><\/strong><\/p>\n<p style=\"line-height: 21px; word-break: break-word; font-size: 14px;\">\n<p style=\"line-height: 18px; word-break: break-word;\"><span style=\"font-size: 14px; line-height: 21px;\"><u><a style=\"text-decoration: underline;\" href=\"https:\/\/edpb.europa.eu\/system\/files\/2021-09\/edpb_opinion322021_republicofkoreaadequacy_en.pdf\" target=\"_blank\" rel=\"noopener\">On 24th September 2021, the EDPB adopted \u2018Opinion 32\/2021 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016\/679 on the adequate protection of personal data in the Republic of Korea Version 1.0\u2019<\/a>.<\/u> The Opinion highlights positive aspects. For example, the EDPB observes: \u2018With regards to the content, the EDPB notes key areas of alignment between the GDPR framework and the Korean data protection framework with regard to certain core provisions such as, for example, concepts (e.g., \u201cpersonal information\u201d, \u201cprocessing\u201d, \u201cdata subject\u201d); grounds for lawful and fair processing for legitimate purposes; purpose limitation; data quality and proportionality; data retention, security and confidentiality; transparency; and special categories of data.\u2019 The EDPB, however, also highlight a number of challenges related to the Draft Decision. These include, for instance: the legal status of Korean administrative rules bridging the gap between the GDPR and the Korean framework; the scope and function of the concept of pseudonymised data in the Korean framework; the scope of the right to withdraw consent under the Korean framework; and the scope of the obligation to inform data subjects in relation to telecommunications companies\u2019 disclosures of personal data to national security authorities.<\/span><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<div class=\"txtTinyMce-wrapper\" style=\"font-size: 12px; line-height: 18px; text-align: justify; font-family: Arial, 'Helvetica Neue', Helvetica, sans-serif;\">\n<p style=\"line-height: 21px; word-break: break-word; font-size: 14px;\"><span style=\"font-size: 14px; line-height: 21px;\"><a style=\"text-decoration: none;\" href=\"https:\/\/www.irishtimes.com\/business\/technology\/whatsapp-challenges-dpc-s-225-million-fine-1.4675957\" target=\"_blank\" rel=\"noopener\"><strong>&#8211; <\/strong><\/a><\/span><strong>CNIL Issues Injunctions against French Fingerprint Database <\/strong><span style=\"font-size: 14px; line-height: 21px;\"><a style=\"text-decoration: none;\" href=\"https:\/\/hudoc.echr.coe.int\/eng#{%22article%22:[%228%22],%22documentcollectionid2%22:[%22GRANDCHAMBER%22,%22CHAMBER%22],%22itemid%22:[%22001-210766%22]};%20https:\/\/hudoc.echr.coe.int\/eng-press#{%22fulltext%22:[%227796\/16%22]}\" target=\"_blank\" rel=\"noopener\"><strong>&#8211;<\/strong><\/a><\/span><\/p>\n<p style=\"line-height: 21px; word-break: break-word; font-size: 14px;\">\n<p style=\"line-height: 18px; word-break: break-word;\"><span style=\"font-size: 14px; line-height: 21px;\"><a style=\"text-decoration: underline;\" href=\"https:\/\/www.euractiv.com\/section\/data-protection\/news\/french-privacy-watchdog-takes-action-on-government-fingerprint-database-issues\/\" target=\"_blank\" rel=\"noopener\"><u>On 30th September, the CNIL concluded that the French computerised fingerprint and palmprint database (FAED), maintained by the French Interior Ministry, suffers from \u2018apparent illegal storage of data, poor file management, and a lack of information provided to persons whose data is kept on the system\u2019<\/u>.<\/a> More precisely, the databases contained further personal data than envisaged in law and included data of persons who are no longer suspects. It looks like more than 2 million records were kept longer than the legally allowed storage limits. In addition, a huge number of records were stored in a paper form and were not yet digitalized. Finally, the security features of the system were considered to be very poor and individuals were not informed that their data are stored on the FAED, in breach of French law. Now, the Interior Ministry has to bring the FAED in compliance with data protection law. However, it will not be fined, because the CNIL may not fine State institutions, but it can only issue injunctions.<\/span><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>&#8211; \u00a0AG Bobek Reads the Judicial Capacity Exception Broadly &#8211; On 6th October, the AG [&hellip;]<\/p>\n","protected":false},"author":144,"featured_media":0,"menu_order":0,"comment_status":"open","ping_status":"closed","template":"","dpi-category":[],"dpi-tag":[],"class_list":["post-72286","dpi","type-dpi","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi\/72286","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi"}],"about":[{"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/types\/dpi"}],"author":[{"embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/users\/144"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/comments?post=72286"}],"version-history":[{"count":0,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi\/72286\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/media?parent=72286"}],"wp:term":[{"taxonomy":"dpi-category","embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi-category?post=72286"},{"taxonomy":"dpi-tag","embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi-tag?post=72286"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}