{"id":74358,"date":"2024-09-12T10:09:52","date_gmt":"2024-09-12T08:09:52","guid":{"rendered":"https:\/\/www.lexxion.eu\/?post_type=dpi&#038;p=74358"},"modified":"2024-09-12T10:09:52","modified_gmt":"2024-09-12T08:09:52","slug":"data-protection-insider-issue-117","status":"publish","type":"dpi","link":"https:\/\/www.lexxion.eu\/en\/dpi\/data-protection-insider-issue-117\/","title":{"rendered":"Data Protection Insider, Issue 117"},"content":{"rendered":"<h3><a href=\"https:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;docid=289830&amp;pageIndex=0&amp;doclang=EN&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=708288#Footnote19\" target=\"_blank\" rel=\"noopener\">&#8211;<strong>AG de la Tour: High Number of Complaints Does Not Make Them Automatically \u2018Excessive\u2019-<\/strong><\/a><\/h3>\n<p><a href=\"https:\/\/curia.europa.eu\/juris\/document\/document.jsf?text=&amp;docid=289830&amp;pageIndex=0&amp;doclang=EN&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=708288#Footnote19\" target=\"_blank\" rel=\"noopener\"><u>On 5<sup>th<\/sup> September, AG de la Tour advised the Court to rule that a high number of complaints, submitted over a short period of time does not automatically make them \u2018excessive\u2019 in <em>\u00d6sterreichische Datenschutzbeh\u00f6rde<\/em>.<\/u> <\/a>As to the facts of the case, a data subject (FT), submitted to the Austrian Data Protection Commission 77 complaints within about 20 months, concerning the failure of different controllers to respond to their access requests within one month, as prescribed by the GDPR. The Commission refused to react, claiming that the complaints were \u2018excessive\u2019 and constituted a huge burden for the Commission. Eventually, the case reached the Austrian courts, which wondered whether the Commission could rely on Article 54(7) GDPR, which \u2018offers the supervisory authorities, when confronted with requests which are manifestly unfounded or excessive, in particular because of their repetitive character, the possibility of charging a reasonable fee based on the administrative costs or of refusing to act on those requests.\u2019 Three concrete questions were formulated on the basis of Article 54(7) GDPR: (1) whether the concept of \u2018requests\u2019 covers also \u2018complaints\u2019; (2) whether a high number of complaints makes them \u2018excessive\u2019 and (3) whether a data protection authority may choose between charging a fee and refusing to act on a complaint in case of \u2018excessive\u2019 or \u2018manifestly unfounded\u2019 requests. With respect to the first question, AG de la Tour suggested that the concept of requests should be interpreted to cover also complaints. As to the second question, he argued that a high number of requests may not in itself classify them as excessive, especially where such a key data subject right as the right of access to one\u2019s data is concerned and where the complaints concern the failure of different controllers to respond to the data subject\u2019s access requests. He also recalled that it is for the data protection authority to prove that the complaints are excessive and that challenging the resources of the data protection authority is not a convincing argument. With regard to the third question, he argued that the GDPR does not set out a priority between charging a fee and refusing to act on a complaint. Thus, he suggested, a data protection authority should decide on a case-by-case basis which option to make use of: \u2018a supervisory authority may consider it appropriate, in the light of the relevant circumstances and with a view to halting an abusive practice which is liable to hamper its proper functioning, to charge a reasonable fee based on the administrative costs of the additional workload created by excessive complaints. The dissuasive effect of that option may lead the authority to prefer it over an immediate refusal to act on such complaints. (\u2026) I would add that the principle of proportionality and the objective of ensuring a high level of protection of personal data should also predispose supervisory authorities to charge a reasonable fee based on the administrative costs before refusing to act on such complaints, given that the former measure is less harmful to the rights of data subjects under the GDPR\u2019.<\/p>\n<h3><a href=\"https:\/\/hudoc.echr.coe.int\/#{%22itemid%22:[%22001-235491%22]}\" target=\"_blank\" rel=\"noopener\"><strong>-ECtHR Considers the need for Judicial Authorisation in Mobile Telephone Searches-<\/strong><\/a><\/h3>\n<p><a href=\"https:\/\/hudoc.echr.coe.int\/#{%22itemid%22:[%22001-235491%22]}\" target=\"_blank\" rel=\"noopener\"><u>On the 5<sup>th<\/sup> of September, the ECtHR decided in the case of <\/u><em><u>Mukhtarli v. Azerbaijan and Georgia.<\/u><\/em><\/a> In terms of the facts, the case essentially concerned the alleged abduction of the plaintiff, his extradition to Azerbaijan from Georgia, and his detention in Azerbaijan. Whilst in detention in Azerbaijan, the plaintiff\u2019s mobile phone, on the order of the investigator, was thoroughly searched. Following a series of unsuccessful complaints at national level regarding the legality of this search, the plaintiff appealed to the ECtHR. In this regard, the plaintiff complained to the ECtHR that their Article 8 rights were violated by virtue of \u2018the search of the contents of his mobile telephone by the investigating authorities\u2019 in Azerbaijan \u2013 other complaints, relating to other Articles were also brought, which will not be considered in this summary. In this regard, the Court decided that the investigating authorities\u2019 search had not been in accordance with the law. They highlighted, in particular, the fact that the search had been conducted as part of an \u2018investigation\u2019 which did not, under national law, require advance judicial authorisation. The Court highlighted \u2018that a search of the contents of a mobile telephone \u2013 which constitutes a measure seriously interfering with a person\u2019s private life and correspondence \u2013 cannot be in compliance with Article 8 of the Convention if it is left to an investigator\u2019s unfettered discretion; Article 8 requires the issuance of a warrant by an independent body when interference with the privacy of a person is at stake.\u2019 Whilst the Court did recognise certain circumstances \u2013 for example concerning the authorities need to act expediently in specific cases \u2013 in which such authorisation might not be strictly necessary, the Court considered that none of these applied in the present case.<\/p>\n<h3><a href=\"https:\/\/hudoc.echr.coe.int\/#{%22itemid%22:[%22001-235479%22]}\" target=\"_blank\" rel=\"noopener\"><strong>-ECtHR Considers the Monitoring of Documents Exchanged between Prisoners and Lawyers-<\/strong><\/a><\/h3>\n<p><a href=\"https:\/\/hudoc.echr.coe.int\/#{%22itemid%22:[%22001-235479%22]}\" target=\"_blank\" rel=\"noopener\"><u>On the 3<sup>rd<\/sup> of September, the ECtHR, sitting as a Committee, decided, in a brief judgment, the case <\/u><em><u>Halla\u00e7o\u011flu v. T\u00fcrkiye.<\/u><\/em><\/a> In terms of the facts, the case essentially concerned the monitoring, by prison authorities, of documents exchanged between a prisoner and their lawyer during meetings in prison. The monitoring of these documents was argued to be legitimated in national law under \u2018section 59(5) of Law no. 5275 on the enforcement of sentences and preventive measures\u2026as amended by Article\u00a06 of Emergency Legislative Decree no. 676 adopted in the framework of the state of emergency declared in the aftermath of the attempted\u00a0<em>coup d\u2019\u00e9tat<\/em>\u2019. In this regard, the plaintiff complained to the ECtHR that \u2018the impugned measure of monitoring the documents exchanged with his lawyer had constituted a breach of his right to respect for his private life under Article 8 of the Convention.\u2019 The Court found a violation. The Court, recalling the decision and the logic in the prior case of <em>Mehmet Demir, <\/em>highlighted that: the \u2018Court has already concluded that the interpretation and application by the domestic courts of the impugned legislation was wide and vague and that such an extensive interpretation and application of the relevant domestic provision did not comply with the Convention requirements of foreseeability and thus lawfulness.\u2019<\/p>\n<h3><a href=\"https:\/\/hudoc.echr.coe.int\/#{%22itemid%22:[%22001-235490%22]}\" target=\"_blank\" rel=\"noopener\"><strong>-ECtHR Considers Data Retention in Russia-<\/strong><\/a><\/h3>\n<p><a href=\"https:\/\/hudoc.echr.coe.int\/#{%22itemid%22:[%22001-235490%22]}\" target=\"_blank\" rel=\"noopener\"><u>On 5<sup>th<\/sup> of September, the ECtHR, sitting as a Committee, decided, in a brief judgment, the case of <\/u><em><u>Vorobyev and Others v. Russia.<\/u><\/em> <\/a>The case essentially concerned the \u2018statutory requirement for Internet communications providers to store the content of all Internet communications and related communications data, and to submit those data to law\u2011enforcement authorities or security services at their request together with information necessary to decrypt electronic messages if they were encrypted\u2019. Th applicants thus complained to the ECtHR regarding the violation of their Article 8 rights implied by this requirement \u2013 other complaints were also made, which will not be considered in this summary. The Court reiterated that it had \u2018earlier found that the contested legislation providing for the retention of all Internet communications of all users, the security services\u2019 direct access to the data stored without adequate safeguards against abuse and the requirement to decrypt encrypted communications, as applied to end-to-end encrypted communications, cannot be regarded as necessary in a democratic society. In so far as this legislation permits the public authorities to have access, on a generalised basis and without sufficient safeguards, to the content of electronic communications, it impairs the very essence of the right to respect for private life under Article 8 of the Convention\u2019. The Court then further highlighted that, in relation \u2018to its case-law on the subject, the Court considers that in the instant case the continuous storage of the applicants\u2019 Internet communications and related communications data by their Internet communications providers, the authorities\u2019 potential access to these data and the obligation to decrypt them if they are encrypted, pursuant to the domestic law, violated the applicants\u2019 Article 8 rights\u2019. Given the current political situation, we wonder how such judgments from the ECtHR are now received in Russia, and how this might impact the response to the judgment.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8211;AG de la Tour: High Number of Complaints Does Not Make Them Automatically \u2018Excessive\u2019- On [&hellip;]<\/p>\n","protected":false},"author":144,"featured_media":74354,"menu_order":0,"comment_status":"open","ping_status":"closed","template":"","dpi-category":[],"dpi-tag":[],"class_list":["post-74358","dpi","type-dpi","status-publish","has-post-thumbnail","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi\/74358","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi"}],"about":[{"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/types\/dpi"}],"author":[{"embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/users\/144"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/comments?post=74358"}],"version-history":[{"count":1,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi\/74358\/revisions"}],"predecessor-version":[{"id":74431,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi\/74358\/revisions\/74431"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/media\/74354"}],"wp:attachment":[{"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/media?parent=74358"}],"wp:term":[{"taxonomy":"dpi-category","embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi-category?post=74358"},{"taxonomy":"dpi-tag","embeddable":true,"href":"https:\/\/www.lexxion.eu\/en\/wp-json\/wp\/v2\/dpi-tag?post=74358"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}