Opinion 7/2019 on the draft list of the competent supervisory authority of Iceland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)
Adopted 1 EDPB Plenary m eeting, 12 - 13 March 2019 - Item 2.3.1 Opinion 7 /201 9 on the draft list of the competent supervisory authority of Iceland regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 12 March 201 9 Adopted 2 Contents 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2 Assessment…
How it connects
Related across sources
Full text 11 sections
4 GDPR) Adopted on 12 March 201 9 Adopted 2 Contents 1 Summary of the Facts ................................ ................................ 4 2 Assessment ................................ ................................ ..... 1 General reasoning of the EDPB regarding the submitted list ................................ 2 Application of the consistency mechanism to the draft list ................................ 3 Analysis of the draft list ................................ ................................ 6 S COPE OF THE DRAFT DE CISION ................................ ................................ 6 E MPLOYEE MONITORING ................................ ................................ 6 3 Conclusions / Recommendations ................................ ................................ 6 4 Final Remarks ................................ ................................ . 6 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64 (1a), (3) - (8) and Article 35 (1), (3), (4), (6) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repe aling Directive 95/46/EC (here after “GDPR”), Havin g regard to Article 51 (1b) of Directive 2016/680 EU on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offen ces or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (hereafter “Law Enforcement Directive”).
Having regard to the EEA Agreement and in particular to Annex XI and Protocol 37 thereof, as amended by the Decision of the EEA joint Committee No 154/2018 of 6 July 2018, Having regard to Article 10 and 22 of its Rules of Procedure of 25 May 2018, as revised on 23 November 2018, Whereas: (1) The main role of the Board is to ensur e the consistent application o f the Regulation 2016/679 (here after GDPR) throughout the European Economic Area . 4 GDPR. The aim of this opinion is therefore to create a harmonised approach with regard to processing that is cross border or that can affect the free flo w of personal data or natural person across the European Union. Even though the GDPR doesn’t impose a single list, it does promote consistency. The Board seeks to achieve this objective in its opinions firstly by requesting SAs to include some types of pr ocessing in their lists, secondly by requesting them to remove some criteria which the Board doesn’t consider as necessarily creating high risks for data subjects, and finally by requesting them to use some criteria in a harmonized manner.
(2) With referen ce to Article 35 (4) and (6) GDPR, the competent supervisory authorities shall establish lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment (hereinafter “DPIA” ) . They shall, however, appl y the consistency mechanism where such lists involve processing operations, which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movem ent of personal data within the Union . (3) While the draft lists of the competent supervisory authorities are subject to the consistency mechanism, this does not mean that the lists should be identical . The competent supervisory authorities have a margin of discretion with regard to the national or regional context and should take into account their local legislation.
The aim of the EDPB assessment/opinion is not to reach a single EU list but rather to avoid significant inconsistencies that may affect the equivalent protection of the data subjects. Adopted 4 (4) The carrying out of a DPIA is only mandatory for the controller pursuant to Article 35 (1) GDPR where processing is “likely to result in a high risk to the rights and freedoms of natural persons”. Article 35 (3) GDPR illustrates what is likely to result in a high risk. This is a non - exhaustive list. The Working Party 29 in the Guidelines on data protection impact assessment 1 , as endorsed by the EDPB 2 , has clarified criteria that can help to identify when pr ocessing operations are subject to the requirement for a DPIA. The Working Party 29 Guidelines WP248 state that in most cases, a data controller can consider that a processing meeting two criteria would require a DPIA to be carried out, however, in some ca ses a data controller can consider that a processing meeting only one of these criteria requires a DPIA.
(5) The lists produced by the competent supervisory authorities support the same objective to identify processing operations likely to result in a hi gh risk and processing operations, which therefore require a DPIA. As such , the criteria developed in the Working Party 29 Guidelines should be applied when assessing whether the draft lists of the competent supervisory authorities does not affect the cons istent application of the GDPR. (6 ) Twenty - two competent supervisory authorities received an opinion on their draft lists from the EDPB on 5 September 2018 . A further four SAs received an opinion on their draft lists on 4 December 2018 and two further re ceived an opinion on their list on 23 January 2019 . (7) The opinion of the EDPB shall be adopted pursuant to Article 64 (3) GDPR in conjunction with Article 10 (2) of the EDPB Rules of Procedure within eight weeks from the first working day after the Chair and the competent supervisory authority have decided that the file is complete.
Upon decision of the Chair , this period may be extended by a further six weeks taking into account the complexity of the subject matter. HAS ADOPTED THE FOLLOWING OPINION: 1 SUMMARY OF THE FACTS 1. The competent supervisory authority of Iceland has submitted its draft list to the EDPB. The decision on the completeness of the file was taken on 4 February 2019 . 2. Th e period until which the opinion has to be adopted has been set unt il 2 April 2019 . 1 WP29, Guidelines on Data Protection Impact Assessment and determining whether processing is “likely to result in a high risk” for the purposes of Regulation 2016/679 (WP 248 rev. 01). 2 EDPB, Endorsement 1/2018 . 1 General reasoning of the EDPB regarding the submitted list 3. 1, which will prevail in any case. Thus , no list can be exhaustive. 4. 10 GDPR, the Board is of the opinion that if a DPIA has already been carried out as part of a general impact assessment in the context of the adoption of the legal basis the obligation to carry out a DPIA in accordance with paragraphs 1 to 7 of article 35 GDPR does not apply, unless the Member State deems it necessary.
5. Further, if the Board requests a DPIA for a certain category of processing and an equivalent measure is already required by national law, the Persónuvernd (hereafter Icelandic Supervisory Authority ) shall add a reference to this measure. 6. 6 GDPR. T h is refers to items that neither relate “to the offering of goods or services to data subjects” in several Member States nor to the monitoring of the behaviour of data subjects in several Member States . Additionally , they are not likely to “ substantially affect the free movement of personal data within the Union” . This is especially the case for items relating to national legislation and in particular where the obligation to carry out a DPIA is stipulated in national legislation . Further, any processing operations that relate to law enforcement we re deemed out of scope, as they are not in scope of the GDPR. 7. The Board has noted that several supervisory authorities have included in their lists some types of processing which are necessarily local processing.
6, the Board will not comment on those local processing. 8. The opinion aims at defining a consistent core of processing operations that are recurrent in the lists provided by the SAs. 9. This means that, for a limited number of types of processing operations that will be defined in a harmonised way, all the Supervisory Authorities will require a DPIA to be carried out and the Board will recommend the SAs to amend their lists accordingly in order to ensure consistency. 10. When this opinion remains silent on DPIA list entries submitted, it means that the Board is not asking the Icelandic Supervisory Authority to take further action. 11. Finally, the Board recalls th at transparency is key for data controllers and data processors. In order to clarify the entries in the list, the Board is of the opinion that making an explicit reference in the lists, for each type of processing, to the criteria set out in the guidelines could improve this transparency.
2 Application of the consistency mechanism to the draft list 12. The draft list submitted by the Icelandic Supervisory Authority relate s to the offering of goods or services to data subjects, relate s to the monitoring of their behaviour in several Member States and/or may substantially affect the free movement of personal data within the Union mainly because the processing operations in the submitted draft list are not limited to data subjects in this country. 3 Analysis of the draft list 13. Taking into account that: a. Article 35 (1) GDPR requires a DPIA when the processing activity is likely to result in a high risk to the rights and freedoms of natural persons; and b. Article 35 (3) GDPR provides a non - exhaustive list of types of processing that require a DPIA, the Board is of the opinion that: S COPE OF THE DRAFT DE CISION 14. The Icelandic SA states in some cases that its list includes processing activities that the Icelandic DPA considers to be of high risk to the rights and freedoms of data subjects .
However, t he Board recalls that the GDPR states that the list that have to be published by the supervisory authorities are the lists of processing that are likely to re sult in a high risk for the rights and freedoms of data subjects . The Board therefore requests the Icelandic Authority to amend its list by aligning its wording with the wording of Article 35. 1 of the GDPR. E MPLOYEE MONITORING 15. The Board takes note of the i nclusion of “processing of personal data involving measures for systematic monitoring of employee activities” in the Icelandic DPIA list . T he Board recalls that in its view WP249 of the Article 29 wo rking party remain valid w hen defining the concept of sys tematic processing of employee data. 3 CONCLUSIONS / RECOMM ENDATIONS 16. The draft list of the Icelandic Supervisory Authority may lead to an inconsistent application of the requirement for a DPIA and the following changes need to made: Regarding the scope of the list : the Board requests the Icelandic Supervisory Authority to amend its list by stating that the types of processing listed are the one that are likely to present high risks for the rights and freedom of data subjects.
4 FINAL REMARKS
17. This opinion is a ddressed to the Icelandic Supervisory Authority and will be made public pursuant to Article 64 (5b) GDPR. 18. According to Article 64 (7) and (8) GDPR, the supervisory authority shall communicate to the Chair by electronic means within two weeks after receivin g the opinion, whether it will amend or maintain its draft list. The supervisory authority shall communicate the final decision to the Board for inclusion in the register of decisions which have been subject to the consistency mechanism, in accordance with article 70 (1) (y) GDPR. For the European Data Protection Board The Chair (Andrea Jelinek)