Skip to content
Guidance · EDPB ·012019-on-the-draft-list-of-the-competent-supervisory EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Opinion 01/2019 on the draft list of the competent supervisory authority of the Principality of Liechtenstein regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR)

Adopted 1 EDPB Plenary Meeting, 22 - 23 January 2019 Opinion 01 /201 9 on the draft list of the competent supervisory authority of the Principality of Liechtenstein regarding the processing operations subject to the requirement of a data protection impact assessment (Article 35.4 GDPR) Adopted on 23 January 201 9 Adopted 2 Table of c ontents 1 Summary of the Facts ................................ ................................ ................................ ..................... 4 2…

How it connects

20 of 20 paragraphs apply legislation or carry a topic — see them in the full text ↓

Full text 20 sections

Paragraphs carrying a topic or an applied provision show those connections inline Original at the source →
§

4 GDPR) Adopted on 23 January 201 9 Adopted 2 Table of c ontents 1 Summary of the Facts ................................ ................................ 4 2 Assessment ................................ ................................ ..... 1 General reasoning of the EDPB rega rding the submitted list ................................ 2 Application of the consistency mechanism to the draft list ................................ 3 Analysis of the draft list ................................ ................................ 6 B IOMETRIC DATA ................................ ................................ 6 G ENETIC DATA ................................ ................................ .... 6 P ROCESSING USING INNO VATIVE TECHNOLOGY ................................ ........................ 6 S YSTEMATIC TRACKING ................................ ................................ 7 C OMBINING OR MATCHING PERSONAL DATA OBTAI NED FROM MULTIPLE SO URCES AND FURTHER PR OCESSING THEREOF ................................

§

................................ ............ 7 S YSTEMATIC WORKPLACE MONITORING ................................ ................................ 5 GDPR ..... 7 D ENIAL OF SERVICE BAS ED ( NOT SOLE LY ) ON AUTOMATED DECISI ON - MAKING ( INCLUDING PROFILING ) .............. 8 P ROCESSING OF PERSONA L DATA IF THE DATA ARE EVAL UATED , PROCESSED AND USED BY THE AUTHORITIES CONCERNED AND FORWAR DED TO LAW ENFORCEME NT AUTHORITIES ................................ 8 3 Conclu sions / Recommendations ................................ ................................ 8 4 Final Remarks ................................ ................................ . 9 Adopted 3 The European Data Protection Board Having regard to Article 63, Article 64 (1a), (3) - (8) and Article 35 (1), (3), (4), (6) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons w ith regard to the processing of personal data and on the free movement of such data, and repe aling Directive 95/46/EC (here after “GDPR”), Having regard to Article 51 (1b) of Directive 2016/680 EU on the protection of natural persons with regard to the pro cessing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framewor k Decision 2008/977/JHA (hereafter “Law Enforcement Directive”).

§

Having regard to the EEA Agreement and in particular to Annex XI and Protocol 37 thereof, as amended by the Decision of the EEA joint Committee No 154/2018 of 6 July 2018, Having regard to Article 10 and 22 of its Rules of Procedure of 25 May 2018, as revised on 23 November 2018, Whereas: (1) The main role of the Board is to ensure the consistent application o f the Regulation 2016/679 (here after GDPR) throughout the European Economic Area . 4 GDPR. The aim of this opinion is therefore to create a harmonised approach with regard to processing that is cross border or that can affect the free flow of personal data or natural person across the European Union. Even though the GDPR doesn’t impos e a single list, it does promote consistency. The Board seeks to achieve this objective in its opinions firstly by requesting SAs to include some types of processing in their lists, secondly by requesting them to remove some criteria which the Board doesn ’t consider as necessarily creating high risks for data subjects, and finally by requesting them to use some criteria in a harmonized manner.

§

(2) With reference to Article 35 (4) and (6) GDPR, the competent supervisory authorities shall establish lists of the kind of processing operations which are subject to the requirement for a data protection impact assessment (hereinafter “DPIA” ) . They shall, however, apply the consistency mechanism where such lists involve processing operations, which are related to t he offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union . (3) While the draft lists of the competent supervisory au thorities are subject to the consistency mechanism, this does not mean that the lists should be identical . The competent supervisory authorities have a margin of discretion with regard to the national or regional context and should take into account their local legislation.

§

The aim of the EDPB assessment/opinion is not to reach a single EU list but rather to avoid significant inconsistencies that may affect the equivalent protection of the data subjects. Adopted 4 (4) The carrying out of a DPIA is only mandatory for the controller pursuant to Article 35 (1) GDPR where processing is “likely to result in a high risk to the rights and freedoms of natural persons”. Article 35 (3) GDPR illustrates what is likely to result in a high risk. This is a non - exhaustive list. The Working Party 29 in the Guidelines on data protection impact assessment 1 , as endorsed by the EDPB 2 , has clarified criteria that can help to identify when processing operations are subject to the requirement for a DPIA. The Working Party 29 Guidelines WP248 state that in most cases, a data controller can consider that a processing meeting two criteria would require a DPIA to be carried out, however, in some cases a data controller can consider that a processing meeting only one of these criteria requires a D PIA.

§

(5) The lists produced by the competent supervisory authorities support the same objective to identify processing operations likely to result in a high risk and processing operations, which therefore require a DPIA. As such , the criteria developed i n the Working Party 29 Guidelines should be applied when assessing whether the draft lists of the competent supervisory authorities does not affect the consistent application of the GDPR. (6 ) Twenty - two competent supervisory authorities received an opini on on their draft lists from the EDPB on 5 September 2018 . A further 4 SAs received an opinion on their draft lists on 7 December 2018 . (7) The opinion of the EDPB shall be adopted pursuant to Article 64 (3) GDPR in conjunction with Article 10 (2) of the EDPB Rules of Procedure within eight weeks from the first working day after the Chair and the competent supervisory authority have decided that the file is complete.

§

Upon decision of the Chair , this period may be extended by a further six weeks taking into account the complexity of the subject matter. HAS ADOPTED THE FO LLOWING OPINION: 1 SUMMARY OF THE FACTS 1. The competent supervisory authority of the Principality of Liechtenstein has submitted its draft list to the EDPB. The decision on the completeness of the file was taken on 29 October 2018 . 2. Th e period until which the opinion has to be adopted has been extended until 5 February 2019 taking into account the complexity of the subject matter , in particular the need to factor in the outcome of the review of the twenty - six draft lists previously submitted by competent supervisory authorities and the need for a global assessment of all of them . 1 WP29, Guidelines on Data Protection Impact Assessment and determining whether processing is “likely to result in a high risk” for the purposes of Regulation 2016/679 (WP 248 rev.

§

01). 2 EDPB, Endorsement 1/2018 . 1 General reasoning of the EDPB regarding the submitted list 3. 1, which will prevail in any case. Thus , no list can be exhaustive. 4. 10 GDPR, the Board is of the opinion that if a DPIA has already been carried out as part of a general impact assessment i n the context of the adoption of the legal basis the obligation to carry out a DPIA in accordance with paragraphs 1 to 7 of article 35 GDPR does not apply, unless the Member State deems it necessary. 5. Further, if the Board requests a DPIA for a certain category of processing and an equivalent measure is already required by national law, the Data Protection Office of the Principality of Liechtenstein (hereafter Liechtenstein Supervisory Authority ) shall add a reference to this measur e. 6. 6 GDPR. T h is refers to items that neither relate “to the offering of goods or services to data subjects” in several Member States nor to the monitoring of the behaviour of data subjects in several Member States .

§

Additionally , they are not likely to “ substantially affect the free movement of personal data within the Union” . This is especially the case for items relating to national legislation and in particular where the obligation to carry out a DPIA is stipulated in national legislation . Further, any processing operations that relate to law enforcement were deemed out of scope, as they are not in scope of the G DPR. 7. The Board has noted that several supervisory authorities have included in their lists some types of processing which are necessarily local processing. 6 GDPR , the Board will not comment on those local processing. 8. 6 GDPR, however the Board may issue recommendations based on article 51 (1b) of the Law Enforcement Directive. 9. The opinion aims at defining a consistent core of processing operations that are recurrent in the lists provided by the SAs. 10. This means that, for a limited number of types of processing operations that will be defined in a harmonised way, all the Supervisory Authorities will require a DPIA to be carried out and the Board will recommend the SAs to amend their lists accordingly in order to ensure consistency.

§

11. When this opinion remains silent on DPIA list entries submitted, it means that the Board is not asking the Liechtenstein Supervisory Authority to take further action. 12. Finally, the Board recalls that transparency is key for data controllers and data processors. In order to clarify the entries in the list, the Board is of the opinion that making an explicit reference in the lists, for each type of processing, to the criteria set out in the guidelines could improve this transpa rency. Therefore, the Board considers that an explanation on which criteria have been taken into account by the Liechtenstein Supervisory Authority to create its list could be added. 2 Application of the consistency mechanism to the draft list 13. The draft list submitted by the Liechtenstein Supervisory Authority relate s to the offering of goods or services to data subjects, relate s to the monitoring of their behaviour in several Member States and/or may substantially affect the free movement of pe rsonal data within the Union mainly because the processing operations in the submitted draft list are not limited to data subjects in this country.

§

3 Analysis of the draft list 14. Taking into account that: a. Article 35 (1) GDPR requires a DPIA when the processing activity is likely to result in a high risk to the rights and freedoms of natural persons; and b. Article 35 (3) GDPR provides a non - exhaustive list of types of processing that require a DPIA, the Board is of the opinion that: B IOMETRIC DATA 15. The list submitted by the Liechtenstein Supervisory Authority for an opinion of the Board states, that the extensive processing of biometric data falls under the obligation to perform a DPIA on its own. The Board is of the opinion that the processing of bi ometric data is not necessarily likely to represent a high risk per se. However, the processing of biometric data for the purpose of uniquely identifying a natural person in conjunction with at least one other criterion requires a DPIA to be carried out. T he Board is of the opinion that the wording used to describe the type of processing is not clear enough.

§

Either the extensive nature of the processing means that the processing is made on a large scale, in which case the description should be modified to c learly make a reference to this criterion, or it just means that the criterion is systematically used, in which case another criterion should be added to ensure consistency. G ENETIC DATA 16. The list submitted by the Liechtenstein Supervisory Authority for an opinion of the Board does not currently require a DPIA to be done for the processing of genetic data. The Board is of the opinion that the processing of genetic data is not necessarily likely to represent a high risk per se . However, the processing of gene tic data in conjunction with at least one other criterion requires a DPIA to be carried out. Therefore , the Board requests the Liechtenstein Supervisory Authority to amend its list accordingly, by adding explicitly the processing of genetic data in conjunc tion with at least one other criterion to its list, to be applied without prejudice to article 35(3) GDPR.

P ROCESSING USING INNO VATIVE TECHNOLOGY

§

17. The list submitted by the Liechtenstein Supervisory Authority for an opinion of the Board envisages that the u se of innovative technology, on its own, requires a DPIA. The Board is of the opinion that the use of innovative technology is not necessarily likely to represent a high risk per se. However, the use of innovative technology in conjunction with at least on e other criterion requires a DPIA to be carried out. Therefore, the Board requests the Liechtenstein Supervisory Authority to amend its list accordingly, by adding that the item requires a DPIA to be carried out only when it is done in conjunction with at least one other criterion . Adopted 7 S YSTEMATIC TRACKING 18. The Board recalls that systematic tracking is a factor in determining the likelihood of high risk, however does not necessarily lead to a likely high risk per se . However, where systematic tracking occurs in conjunction with at least one other criterion , a DPIA should be carried out.

§

The list submitted by the Liechtenstein Supervisory Authority for an opinion of the Board does currently require a DPIA to b e carried out when systematic tracking of data subjects occurs . The Board requests the Liechtenstein Supervisory Authority to amend its list accordingly, by requir ing a DPIA to be carried out in cases of systematic tracking of data subjects only when it is done in conjunction with at least one other criterion. C OMBINING OR MATCHING PERSONAL DATA OBTAI NED FROM MULTIPLE SO URCES AND FURTHER PROCESSING THEREOF 19. The Board recalls that matching or combining datasets is a factor in determining the likelihood of high risk, however in its view combining or matching of pe rsonal data obtained from multiple sources does not lead to a likely high risk per se. The Board further recalls that in its view further processing of personal data should not be a criterion leading to an obligation to do a DPIA, alone or with another cri terion.

§

The list submitted by the Liechtenstein Supervisory Authority for an opinion of the Board does currently require a DPIA to be carried out when combining or matching of personal data obtained from multiple sources and further processing thereof occu rs. The Board requests the Liechtenstein Supervisory Authority to amend its list accordingly, by requiring a DPIA to be carried out in case of combining or matching of personal data obtained from multiple sources only when occurring in conjunction with at least one other criterion. S YSTEMATIC WORKPLACE MONITORING 20. The Board takes note of the inclusion of “systematic workplace monitoring” in the Liechtenstein DPIA list. The Board recalls that in its view WP249 of the Article 29 working party remain valid when defining the concept of systematic processing of employee data. 5 GDPR 21. The Board is of the opinion that types of processing activities that could deprive the data subjects from their rights do not represent a high risk per se.

§

5 (b) could require a DPIA to be carried out only in conjunction with at least one other criterion. The list submitted by the Liechtenstein Supervisory Authority for an opinion of the Board does currently require a DPIA to be done for the processing of data wher e article 14(5), para (b) applies extensively . The Board is of the opinion that the wording used to describe the type of processing is not clear enough. Either the extensive nature of the processing means that the processing is made on a large scale, in wh ich case the description should be modified to clearly make a reference to this criterion, or it just means that the criterion is systematically used, in which case another criterion should be added to ensure consistency. Adopted 8 D ENIAL OF SERVICE BAS ED ( NOT SOLE LY ) ON AUTOMATED DECISI ON - MAKING ( INCLUDING PROFILING ) 22. The list submitted by the Liechtenstein Supervisory Authority for an opinion of the Board states, that the processing activities which lead to a denial of service, when based , but not solely, on an aut omated decision (including profiling) fall under the obligation to perform a DPIA.

§

The Board is of the opinion that the reference to automated decision - making does not count as a second criterion in this case , since the description states that the processi ng which include a human intervention are also included . This means that any processing that end up with a d enial of service are subject to the obligation to do a DPIA . The Board therefore requests the Liechtenstein Supervisory Authority to amend its list accordingly, by adding that the item referencing the processing which may lead to denial of service based (not solely) on automated decision - making (including profiling) requires a DPIA to be carried out only when it is done in conjunction with at least on e other criterion. P ROCESSING OF PERSONA L DATA IF THE DATA ARE EVAL UATED , PROCESSED AND USED BY THE AUTHORITIES CONCERNE D AND FORWARDED TO L AW ENFORCEMENT AUTHO RITIES 23. The list submitted by the Liechtenstein Supervisory Authority for an opinion of the Boar d states, that the processing activities which are further transmitted to law enforcement fall under the obligation to perform a DPIA.

§

The Board takes note that those processing operations will not always fall within the scope of the Law Enforcement Direct ive: whistle blowing processing for example, will fall under this criterion and will therefore require a DPIA. The Board acknowledges that the fact that data will likely be forwarded to law enforcement authorities can be a factor in determining the likelih ood of high risk, however it does not necessarily lead to a likely high risk per se. The Board therefore requests the Liechtenstein Supervisory Authority to amend its list accordingly, by adding that the item referencing the processing when data are evalua ted, processed and used by the authorities concerned and forwarded to law enforcement authorities requires a DPIA to be carried out only when it is done in conjunction with at least one other criterion. 3 CONCLUSIONS / RECOMM ENDATIONS 24. The draft list of the Liechtenstein Sup ervisory Authority may lead to an inconsistent application of the requirement for a DPIA and the following changes need to be made :  Regarding biometric data: the Board requests the Liechtenstein Supervisory Authority to amend its list by adding explicitly the processing of biometric data for the purpose of uniquely identifying a natural person in conjunction with at least one other criterion to its list;  Regarding genetic data: the Board requests the Liechtenstein Supervisory Authority to amend its list by adding explicitly the processing of genetic data in conjunction with at least one other criterion to its list;  Regarding processing using new or innovative technology: the Board requests the Liechtenstein Supervisory Authority to amend i ts list by adding that the item requires a DPIA to be carried out only when it is done in conjunction of at least one other criterion ;  Regarding systematic tracking: the Board requests the Liechtenstein Supervisory Authority to amend its list by adding tha t the item requires a DPIA to be carried out only when it is done in conjunction with at least one other criterion; Adopted 9  Regarding combining or matching of personal data obtained from multiple sources and further processing thereof: the Board requests the Liech tenstein Supervisory Authority to amend its list by firstly removing the reference to further processing and secondly by adding that the item requires a DPIA to be carried out only when it is done in conjunction with at least one other criterion ;  Regarding exceptions to information to be provided to the data subject according to Art.

§

5 GDPR: the Board request the Liechtenstein Supervisory Authority to amend its list either by clarifying that the extensive nature of the processing means that the processing is made on a large scale or, if it just means that the criterion is systematically used, by adding that the item requires a DPIA to be carried out only when it is done in conjunction wi th at least one other criterion;  Regarding denial of service based (not solely) on automated decision making ( including profiling ) : the Board requests the Liechtenstein Supervisory Authority to amend its list by adding that the item requires a DPIA to be carried out only when it is done in conjunction with at least one other criterion ;  Regarding the data evaluated, processed and used by the authorities concerned and forwarded to law enforcement authorities: the Board requests the Liechtenstein Supervisory Authority to amend its list by adding that the item requires a DPIA to be carried out only when it is done in conjunction with at least one other criterion 4 FINAL REMARKS 25.

§

This opinion is addressed to the Data Protection Office of the Principality of Liechtenstein ( Liechtenstein Supervisory Authority) and will be made public pursuant to Article 64 (5b) GDPR. 26. According to Article 64 (7) and (8) GDPR, the supervisory authority shall communicate to the Chair by electronic means within two weeks after receiving the opinion, whether it will amend or maintain its draft list. Within the same period, it shall provide the amended draft list or where it does not intend to follow the opinion of the Board, it shall provide the relevant grounds for which it does not intend to follow thi s opinion, in whole or in part. For the Europ ean Data Protection Board The Chair (Andrea Jelinek)