Data Protection
Total Page:16
File Type:pdf, Size:1020Kb
Handbook on the Techniques of Judicial Interactions in the Application of the EU Charter DATA PROTECTION IN THE FRAMEWORK OF THE PROJECT ‘E-LEARNING NATIONAL ACTIVE CHARTER TRAINING (E-NACT)’ FUNDED BY THE EUROPEAN COMMISSION FUNDAMENTAL RIGHTS & CITIZENSHIP PROGRAMME Researcher responsible for the Handbook: Dr Mariavittoria Catanzariti 1 NATIONAL EXPERTS AND COLLABORATORS The e-NACT team would like to thank the following experts and collaborators who contributed to the selection of the national and European case law upon which this Handbook is built. Federica Casarosa Madalina Moraru Karolina Podstawa Joan Soares Mullor Sara Azevedo Afonso Brás Sergiu Popovici Rita de Brito Gião Hanek Diana Lavinia Botău Francesco Perrone Florentino Gregorio Ruiz Yamuza 2 Contents Part I - Data protection and privacy as EU fundamental rights ......................................... 8 Setting the scene ..................................................................................................................... 8 From the Directive 95/46/EC to the GDPR.......................................................................... 11 The European culture of data protection .............................................................................. 12 The Data Protection Reform of 2016: the GDPR and the Law Enforcement Directive ...... 13 Main principles of data processing ....................................................................................... 14 The basics: what’s personal data? ............................................................................................... 14 Lawfulness, Fairness and Transparency ..................................................................................... 15 Accountability ............................................................................................................................. 16 Data minimisation ....................................................................................................................... 16 Accuracy ..................................................................................................................................... 16 Integrity and confidentiality ....................................................................................................... 16 Purpose limitation principle ........................................................................................................ 16 The main novelties of the GDPR ......................................................................................... 17 1. The Scope of the GDPR ...................................................................................................... 17 The material scope .................................................................................................................. 17 The territorial Scope................................................................................................................ 17 2. Data transfers to third countries .......................................................................................... 22 2.1. Transfers on the basis of an adequacy decision ............................................................. 23 2.2. Transfers subject to appropriate safeguards ................................................................... 24 2.3. Derogations for specific situations ............................................................................. 25 3. Special categories of data .................................................................................................... 25 4. Automated decision-making................................................................................................ 26 5. The right in the scope of consent (in case it is the legal ground for data processing) ......... 26 5.1. Conditions of consent................................................................................................. 26 6. One-stop-shop mechanism .................................................................................................. 27 7. Data portability .................................................................................................................... 27 8. Organisational measures...................................................................................................... 27 9. European Data Protection Board ......................................................................................... 28 10. Sanctions ........................................................................................................................ 28 The rights of data subjects .................................................................................................... 28 The right of access (Article 15 GDPR) ....................................................................................... 28 The right to rectification and erasure (Articles 16 & 17 GDPR) ................................................ 29 The right to restriction of processing (Article18 GDPR) ........................................................... 29 The right to object (Article 21 GDPR) ....................................................................................... 30 Controllers and processors ................................................................................................... 30 Main obligations of controllers and processors .......................................................................... 31 3 Responsibility, liability, accountability .................................................................................. 31 Data security ........................................................................................................................... 31 Privacy by design and privacy by default ............................................................................... 32 Cooperation with Supervisory Authorities ............................................................................. 32 Personal Data Breach .............................................................................................................. 32 Data protection impact assessment ......................................................................................... 33 Designation obligation ............................................................................................................ 33 Processors’ obligations ........................................................................................................... 33 Supervisory Authorities ........................................................................................................ 33 Legal remedies under the GDPR .......................................................................................... 36 Individual and collective action .................................................................................................. 37 Civil liability ............................................................................................................................... 37 Penalties and fines ...................................................................................................................... 37 Balancing data protection and other fundamental rights and interests ................................. 38 Law enforcement vs Data protection .......................................................................................... 38 Property vs Data protection ........................................................................................................ 39 Scientific research vs Data protection ........................................................................................ 39 Part II - Selected cases ........................................................................................................... 41 Methodological remarks ....................................................................................................... 41 Brief glossary of judicial interaction techniques .................................................................. 42 INTERPRETATIVE TECHNIQUES ......................................................................................... 42 Consistent interpretation ......................................................................................................... 42 Comparative reasoning ........................................................................................................... 42 INTERACTION BETWEEN LEGAL PROVISIONS ............................................................... 42 Disapplication ......................................................................................................................... 43 INTERACTION BETWEEN RIGHTS (NATIONAL/EU) ....................................................... 43 Proportionality test .................................................................................................................. 43 INTERACTION BETWEEN COURTS ..................................................................................... 43 Preliminary ruling ................................................................................................................... 43 DEFERENTIAL APPROACH ................................................................................................... 43 Margin of appreciation ............................................................................................................ 43 Judicial self-restraint ..............................................................................................................