Skip to content
Guidance · EDPB ·392021-on-whether-article-582g-gdpr-could-serve-as-a EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Opinion 39/2021 on whether Article 58(2)(g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject

Summary

Adopted 1 Opinion 39 /2021 on whether Article 58(2) ( g) GDPR coul d serve as a legal basis for a s upervisory a uthority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject Adopted on 14 December 2021 Adopted 2 Adopted 3 The European Data Protection Board Having regard to Article 63 and Article 64 (2) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural…

How it connects

28 of 29 paragraphs apply legislation or carry a topic — see them in the full text ↓

Full text 29 sections

Paragraphs carrying a topic or an applied provision show those connections inline Original at the source →
¶1

Opinion 39 /2021 on whether Article 58(2) ( g) GDPR coul d serve as a legal basis for a s upervisory a uthority to order ex officio the erasure of personal data, in a situation where such request was not submitted by the data subject Adopted on 14 December 2021 Adopted

¶2

Adopted

¶3

The European Data Protection Board Having regard to Article 63 and Article 64 (2) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (herei nafter “GDPR”), Having regard to the EEA Agreement and in particular to Annex XI and Protocol 37 thereof, as amended by the Decision of the EEA joint Committee No 154/2018 of 6 July 2018 1 , Having regard to Article 10 and Article 22 of its Rules of Proced ure , Whereas: (1) The main role of the European Data Protection Board (hereafter the “Board”) is to ensure the consistent application of the GDPR throughout the European Economic Area. Article 64(2) GDPR provides that any supervisory authority, the Chair of the Board or the Commission may request that any matter of general application or producing effects in more than one EEA Member State be examined by the Board with a view to obtaining an opinion. The aim of this opinion is to examine a matter of general application or which produces effects in more than one EEA Member State. (2) On 6 th October 2021 , the Hungarian Data Protec tion Authority requested the Board to examine and issue an opinion on whether Article 58(2) ( g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of personal data, in a situation where such request was no t submitt ed by the data subject . (3) The opinion of the Board shall be adopted pursuant to A rticle 64(3) GDPR in conjunction with A rticle 10(2) of the Rules of Procedure within eight weeks from the first working day after the Chair and the competent supervisory aut horities have decided that the file is complete. Upon decision of the Chair, this period may be extended by a further six weeks taking into account the complexity of the subject matter. HAS ADOPTED THE FOLLOWING OPINION : 1 I NTRODUCTION 1 Each Member States’ supervisory authority is responsible for monitoring the application of the GDPR, in order to protect the fundamental rights and freedoms of natural persons in relation to data processing and to facilitate the free flow of personal data within the European Economic Area (“ EEA ”) . In this regard , Article 57 (1) ( a) GDPR provides that each supervisory authority shall on its territory enforce the application of the GDPR. This duty applies regardless of whether the supervisory authority acts ex officio or on the ba sis of a complaint. However, i n order to carry out this task the supervisory authorities must have effective toolsets, which allow them to take action against infringements of the 1 References to “Member States” made throughout this opinion should be understood as references to “EEA Member States”. Adopted

¶4

R egulation. For this reason , Article 58 ( 2 GDPR provides for a s et of corrective powers that a supervisory authority can use . 2 As a matter of fact , “ strong enforcement ”, “ consistent and homogenous application of the rules ”, “ equivalent powers for monitoring and ensuring compliance ”, “ equivalent sanctions for infringement s ” and “ same tasks and effective powers, including (…) corrective powers ” are all called for by the recitals of the GDPR. 2 3 Hence, for the sake of the consistent application of the R egulation by the supervisory authorities , on 6 th October 2021, the Hungarian Data Protection Authority requested the Board to examine and issue an opinion on whether Article 58(2) ( g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of unlawfully processed personal data, in a situation where such a request was not submitted by the data subject 4 T his question of interpretation concerns a “ matter of general application ” of the GDPR, which has the potential to infringe the fundamental right to data protection. Indeed, the power s conferred upon supervisory authorities by Article 58 GDPR should be interpreted and applied in a consistent manner in order to ensure the consistent application of the GDPR , also in lig ht of the fact that the supervisory authorities’ use of such powers m ay produce legal effects in more than one Member State (e.g., in the context of One - Stop - Shop procedures) .

¶5

The EDPB has not yet issued guidelines or statements on the matter outlined above . Thus , to enable the consistent application of the GDPR across the EEA, an objective interpretation must be found as to whether or not Article 58(2) ( g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of unlawfully processed personal data, in a situation where such request was not submitted by the data subject. 2 RELEVANT PRO VISIONS OF THE GDPR

¶6

Recital 7 GDPR states that due to the rapid technological developments and globalisation “ a strong and more coherent data protection framework ” is required in the Union, “ backed by strong enforcement, given the importance of creating the trust that will allow the digital economy to develop across the internal market. ”

¶7

Recital 10 GDPR provides that “ In order to ensure a consistent and high level of protection of natural persons and to remov e the obstacles to flows of personal data within the Union, the level of protection of the rights and freedoms of natural persons with regard to the processing of such data should be equivalent in all Member States. Consistent and homogenous application of the rules for the protection of the fundamental rights and freedoms of natural persons with regard to the processing of personal data should be ensured throughout the Union. ”

¶8

Recital 11 GDPR states that “ Effective protection of personal data throughout t he Union requires (…) equivalent powers for monitoring and ensuring compliance with the rules for the protection of personal data and equivalent sanctions for infringements in the Member States. ”

¶9

Recital 129 GDPR provides that “ In order to ensure consiste nt monitoring and enforcement of this Regulation throughout the Union, the supervisory authorities should have in each Member State the same tasks and effective powers, including powers of investigation, corrective powers and sanctions (…) . ” 2 Recital 7, 10, 11 and 129 GDPR. Adopted 5

¶10

Article 5(1)( a) and (e) provides that personal data shall be processed lawfully and, as a rule, shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. Article 5(2 ) further enshrines the controller’s responsibility to comply with paragraph 1.

¶11

Chapter VI GDPR, entitled “ Independent supervisory authorities ”, defines the competence, tasks and powers of the data protection authorities in order to contribute to a consistent application GDPR.

¶12

Article 57 (1) ( a) GDPR provides that each supervisory authority shall on its territory enforce the application GDPR.

¶13

Article 58(2) ( g) GDPR provides that each supervisory authority shall have the ri ght to order the rectification or erasure of personal data or restriction of processing pursuant to Articles 16, 17 and 18 and the notification of such actions to recipients to whom the personal data have been disclosed pursuant to Article 17(2) and Articl e 19.

¶14

Article 17 (1) GDPR provides that t he data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies: a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; b) the data subject withdraws consent on which the processing is based accordin g to point (a) of Article 6(1), or point (a) of Article 9(2), and where there is no other legal ground for the processing; c) the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processin g, or the data subject objects to the processing pursuant to Article 21(2); d) the personal data have been unlawfully processed; e) the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject; f) the personal data have been collected in relation to the offer of information society services referred to in Article 8(1). 3 SUBJECT MATTER OF TH E OPINION

¶15

First of all, the Board considers that the consistent application of the corrective powers o f the supervisory authorities is of key importance for the consistent level of protection in the European Economic Area.

¶16

T o enable the consistent application and effective implementation GDPR across the EEA , t he Board considers that there is a clear need to interpret Article 58(2) ( g) GDPR to assess whether it could serve as a legal basis for a supervisory authority to order ex officio the erasure of unlawfully processed personal data in a situation where such request was not submitted by the d ata subject . In this regard, t he supervisory authorities need legal certainty to exercise their powers in a consistent manner, and to avoid the creation of diverging administrative practices on this sensitive subject.

¶17

The B oard underlines , however , that t he scope of the opinion is limited to the question raised by the Hungarian Data Protection Authority , hence it only provides clarity on whether Article 58 (2) ( g) GDPR could serve as a legal basis for a supervisory authority to order ex officio the erasure of unlawfully processed personal data, in a situation where such request was not submitted by the data subject. Adopted 6

¶18

The Board emphasises that in the context of this opinion it does not assess the different powers listed in Article 58(2) GDPR , and their interplay. For this reason, t he opinion is without prejudice to the other powers listed in Article 58(2) GDPR , and it does not exclude the possibility for supervisory authorities to base their order of erasure on another legal basis provided for in Article 58(2) GDPR .

¶19

For the Board t o be able to assess whether supervisory authorities may order the erasure of personal data under 58(2)(g) GDPR even in the absence of a request for erasure from the data subject, i t is essential to assess if Article 17 GDPR imposes an obligation to erase personal data on the controller only following a request from the data subject.

¶20

Article 17(1) GDPR establishes, on the one hand , the right of the data subject to request the erasure of their pers onal data and , on t he other hand , the obligation of the controller to erase those data where one of the grounds cited in the A rticle apply . The question that arises is whether this obligation is conditional to the exercise of the right by a data subject, or it exists indepen dently of any request of the data subject .

¶21

I t can be argued that the wording of this Article including its title (“Right of erasure”) suggests that the obligation to erase presupposes that the data subject has exercised his/her right to request erasure.

¶22

H owever , it can also be argued that Article 17 GDPR provides for both (i) an independent right for data subjects and (ii) an independent obligation for the controller . In this regard , Article 17 GDPR does not require the data subject to take any specific action, it merely outlines that the data subject “has the right to obtain” erasure and the data controller “has the obligation to erase” if one of cases set forth in Article 17(1) GDPR applies.

¶23

The i nte r pretation that the controller’s erasure obligation is independent from the data subject’s right for erasure is supported by the fact that some cases set forth in Article 17(1) GDPR clearly refer to scenarios that the controllers must detect as part of their obligation for erasure , independently of whether or not the data subjects are aware of these cases . In fact, it would be difficult for data subjects to be aware of (i) legal obligation s to which the controller is subject (letter e); (ii) when the data collected are no longer necessary in relation to the purposes for wh ich they were collected (letter a) ; or (iii) when personal data are unlawfully processed (letter d). Detecting these circ umstances must be the responsibility of the data controller s as part of the ir compliance with the regulations GDPR, and cannot be the responsibility of the data subject s . This responsibility also stem s from Article 5(1) (a) , (e) and (2) GDPR.

¶24

Furthermore, it can be argued that it is of utmost importance for the effective enforcement GDPR, that supervisory authorities possess powerful tools to take efficient actions against infringements. However, an interpretation requiring the prior request for erasure of the data subject for imposing the obligation for erasure on the controller would restrict the s upervisory a uthorities ’ power in regards to Article 58(2) ( g) GDPR. 4 ADOPTED SOLUTION

¶25

For the Board to assess whether the power of the supervisory authorities under Article 58 (2)(g) GDPR applies even in the absence of a request for erasure from the data subject, it first had to consider whether Article 17 GDPR imposes an obligation on the controller only following a request from the data subject , or if this obl igation is independent thereof . Adopted 7

¶26

In this regard the Board found that Article 17 GDPR provides for two separate cases for erasure that are independent from each other: I. the erasure at the request of the data subject , and II. the erasure as a standalone obligation of the controller .

¶27

This conclusion of the Board is supported by the fact that some cases set forth in Article 17(1) GDPR clearly refer to scenarios that the controllers must detect on their own as part of their obligation for compliance with th e provisions GDPR, and by the rationale to allow supervisory authorities to ensure the enforcement of the principles enshrined in the GDPR even in cases where the data subjects are not informed or aware of the processing , or in cases where not all concerne d data subjects have submitted a request for erasure .

¶28

Based on the above reasoning , the EDPB concludes that Article 58(2) ( g) GDPR is a valid legal basis for a supervisory authority to order ex officio the erasure of unlawfully processed personal data in a situation where such request was not submitted by the data subject.

¶29

This opinion will be made public pursuant to Article 64(5)(b) GDPR . For the European Data Protection Board The Chair (Andrea Jelinek)

applies Art. 64(5)(b)