Article 80 GDPR: Difference between revisions
No edit summary |
No edit summary |
||
Line 195: | Line 195: | ||
== Commentary == | == Commentary == | ||
Article 80 GDPR grants data subjects the right to mandate not-for-profit entities ('''NPOs''<nowiki/>') for representation. The purpose of this provision is to remedy the deficits of legal protection for individuals and facilitate the enforcement of data subject rights.<ref>''Leupold, Schrems'' in Knyrim, Der Datkomm, Article 80 GDPR, margin number 2 (rdb.at 2018).</ref> | Article 80 GDPR grants data subjects the right to mandate not-for-profit entities ('''NPOs''<nowiki/>') for representation. The purpose of this provision is to remedy the deficits of legal protection for individuals and facilitate the enforcement of data subject rights.<ref>''Leupold, Schrems'' in Knyrim, Der Datkomm, Article 80 GDPR, margin number 2 (rdb.at 2018).</ref> The Article regulates how and which not-for-profit entities (NPOs) may lodge complaints and exercise the rights referred to in [[Article 77 GDPR|Articles 77]], [[Article 78 GDPR|78]], [[Article 79 GDPR|79]] and [[Article 82 GDPR|82 GDPR]], on data subjects' behalf. Notably, the second paragraph of Article 80 GDPR contains an opening clause,<ref>Opening clauses permit a Member State to modify the provisions of an Article. In practice, opening clauses allow Member States to legislate for a more restrictive application of the provision concerned. </ref> which allows Member States to introduce a right of appeal and a right of action for NPOs, independent of a data subject's mandate.<ref>''Leupold, Schrems'' in Knyrim, Der Datkomm, Article 80 GDPR, margin number 6 (rdb.at 2018).</ref> | ||
Article 80 GDPR | === (1) Data subject right to mandate an NPO === | ||
Article 80(1) GDPR establishes the data subject right to mandate a not-for-profit body, organisation or association to lodge a complaint on their behalf, to exercise the rights referred to in [[Article 77 GDPR|Articles 77]], [[Article 78 GDPR|78]], [[Article 79 GDPR|79]] and [[Article 82 GDPR|82 GDPR]]. The majority of Commentators have interpreted the conditional phrase '''where provided for by Member State law''<nowiki/>' in Article 80(1) GDPR, as only applying to the mandate for the exercise of the right to receive compensation under [[Article 82 GDPR]].<ref>See for example ''Fuster'' in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 80 GDPR, p. 1148 (Oxford University Press 2020); ''Kreße'' in Sydow, Europäische Datenschutzverordnung, Artikel 80 GDPR, margin number 11 (Nomos 2018, 2<sup>nd</sup> edition); ''Moos, Schefzig'' in Taeger, Gabel, DSGVO – BDSG, Article 80 GDPR, margin number 13 (Deutscher Fachverlag 2019, 3<sup>rd</sup> edition); ''Werkmeister'' in Gola, Datenschutz-Grundverordnung, Artikel 80 GDPR, margin number 9 (C.H. Beck 2018, 2<sup>nd</sup> edition); the only German legal scholars disagreeing seem to be ''Nemitz'' in Ehmann, Selmayr, DS-GVO, Article 80 GDPR, margin number 9 (C.H. Beck 2018, 2<sup>nd</sup> edition) and ''Karg'' in Wolff, Brink, BeckOK DatenschutzR, Article 80 GDPR, margin number 8 (C.H. Beck 2021, 36<sup>th</sup> edition). The latter take the view that Article 80(1) GDPR shall apply only if and to the extent that Member State law provides that natural persons may be represented by organisations.</ref> In relation to the right to mandate an NPO for the exercise of the rights under [[Article 77 GDPR|Articles 77]], [[Article 78 GDPR|78]], and [[Article 79 GDPR|79 GDPR]], there is no prior requirement for further legislation by the Member State. | |||
This reading is further supported by Recital 142 GDPR, which clarifies that the words '''where provided for by Member State law''<nowiki/>' only apply to the exercise of the right to receive compensation referred to in [[Article 82 GDPR]]. Furthermore, the legislative history of Article 80 GDPR affirms this interpretation. The right to mandate a NPO when exercising the right to receive compensation under [[Article 82 GDPR|Article 82 GDPR]] was not included in the initial draft of Article 80 GDPR (then Article 73) and was only inserted later by the European Parliament. Following the submission of the original draft, during the Trialogue proceedings, the right to mandate NPOs when exercising the right to compensation was made subject to an opening clause.<ref>''Boehm'' in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 80 GDPR, margin number 5 (C.H. Beck 2019); ''Bergt'' in Kühling, Buchner, DS-GVO BDSG, Artikel 80 GDPR, margin number 4 (C.H. Beck 2020, 3rd edition).</ref> | |||
==== Requirements under Article 80(1) GDPR ==== | ==== Requirements under Article 80(1) GDPR ==== |
Revision as of 13:07, 9 November 2023
Legal Text
1. The data subject shall have the right to mandate a not-for-profit body, organisation or association which has been properly constituted in accordance with the law of a Member State, has statutory objectives which are in the public interest, and is active in the field of the protection of data subjects’ rights and freedoms with regard to the protection of their personal data to lodge the complaint on his or her behalf, to exercise the rights referred to in Articles 77, 78 and 79 on his or her behalf, and to exercise the right to receive compensation referred to in Article 82 on his or her behalf where provided for by Member State law.
2. Member States may provide that any body, organisation or association referred to in paragraph 1 of this Article, independently of a data subject’s mandate, has the right to lodge, in that Member State, a complaint with the supervisory authority which is competent pursuant to Article 77 and to exercise the rights referred to in Articles 78 and 79 if it considers that the rights of a data subject under this Regulation have been infringed as a result of the processing.
Relevant Recitals
Commentary
Article 80 GDPR grants data subjects the right to mandate not-for-profit entities ('NPOs') for representation. The purpose of this provision is to remedy the deficits of legal protection for individuals and facilitate the enforcement of data subject rights.[1] The Article regulates how and which not-for-profit entities (NPOs) may lodge complaints and exercise the rights referred to in Articles 77, 78, 79 and 82 GDPR, on data subjects' behalf. Notably, the second paragraph of Article 80 GDPR contains an opening clause,[2] which allows Member States to introduce a right of appeal and a right of action for NPOs, independent of a data subject's mandate.[3]
(1) Data subject right to mandate an NPO
Article 80(1) GDPR establishes the data subject right to mandate a not-for-profit body, organisation or association to lodge a complaint on their behalf, to exercise the rights referred to in Articles 77, 78, 79 and 82 GDPR. The majority of Commentators have interpreted the conditional phrase 'where provided for by Member State law' in Article 80(1) GDPR, as only applying to the mandate for the exercise of the right to receive compensation under Article 82 GDPR.[4] In relation to the right to mandate an NPO for the exercise of the rights under Articles 77, 78, and 79 GDPR, there is no prior requirement for further legislation by the Member State.
This reading is further supported by Recital 142 GDPR, which clarifies that the words 'where provided for by Member State law' only apply to the exercise of the right to receive compensation referred to in Article 82 GDPR. Furthermore, the legislative history of Article 80 GDPR affirms this interpretation. The right to mandate a NPO when exercising the right to receive compensation under Article 82 GDPR was not included in the initial draft of Article 80 GDPR (then Article 73) and was only inserted later by the European Parliament. Following the submission of the original draft, during the Trialogue proceedings, the right to mandate NPOs when exercising the right to compensation was made subject to an opening clause.[5]
Requirements under Article 80(1) GDPR
The NPO acting on behalf of the data subject (Article 80(1) GDPR) or, if possible, on its own accord (Article 80(2) GDPR) must be (i) a not-for-profit body, organisation or association (ii) properly constituted in accordance with the law of a Member State, (iii) have statutory objectives which are in the public interest, and (iv) must be active in the field of the protection of data subjects’ rights and freedoms with regard to the protection of their personal data. The term “body, organisation or association” encompasses only legal persons independent of their legal form under Member State law, but not natural persons.[6] The NPO can be organised under public law of a Member State (such as national chambers of labour or consumer protection organisations foreseen by statutory law) or under civil law (such as private associations).[7] It is not required that the NPO is exclusively active in the field of data protection but it must at least be active in the public interest with a connection to data protection.[8] This includes for example consumer protection organisations,[9] workers unions or chambers of labour but excludes entities pursuing commercial interests.[10]
Representation of a data subject under Articles 77, 78 and 79 GDPR
Under Article 80(1) first case GDPR, the data subject has the right to mandate a NPO that fulfils the requirements described above with the following tasks. First, the data subject can task the NPO with lodging a complaint under Article 77(1) GDPR on behalf of the data subject and representing the them before all supervisory authorities (“SA”) (Article 4(21) GDPR) involved the further course of the proceedings.[11] Second, the NPO can be tasked with filing a legal remedy under Article 78(1) GDPR against a legally binding SA decision concerning the data subject. Third, the NPO can file a legal remedy under Article 78(2) GDPR for the data subject where the SA competent under Articles 55 and 56 GDPR does not handle a complaint or does not inform the data subject within three months on the progress or outcome of the complaint lodged pursuant to Article 77 GDPR. Last, the NPO may file a legal remedy under Article 79 GDPR against a controller or processor regarding a GDPR infringement.
Representation of a data subject to claim damages under Article 82 GDPR where provided for by Member State law
Where foreseen by Member State law, a NPO can exercise the right to receive compensation under Article 82 GDPR on behalf of a data subject. Details of the rules on representation in damages proceedings are left to the Member States.[12] Even where the Member State has not made use of the opening clause in Article 80(1) second case GDPR, claims for damages can be assigned to the NPO if such assignment is possible under civil law of the Member State. In such cases, the NPO would not represent the data subject but claim the assigned damages on its own behalf and forward any compensations received through the court proceedings to the data subject. The Collective Redress Directive[13] foresees that qualified non-profit entities[14] shall be entitled to bring representative actions on behalf of consumers for certain infringements of EU law. According to Article 2 and Annex 1 of the Collective Redress Directive, this includes GDPR infringements. Depending on the respective national implementation of the Collective Redress Directive, Article 80(1) second case GDPR might become somewhat redundant, as Member States would have to entitle NPOs to represent data subjects in connection with claims for compensation under Article 82 GDPR.
(2) Abstract complaints and lawsuits where provided for by Member State law
According to the opening clause in Article 80(2) GDPR, Member States may enable NPOs to (i) file complaints under Article 77 GDPR, (ii) bring legal proceedings under Article 78 GDPR against a SA and (iii) bring legal proceedings against controllers or processors under Article 79 GDPR, independent of the mandate of a specific data subject. As the last sentence of Recital 142 GDPR clarifies, this does not extend to Article 82 GDPR. Thus, a NPO may not be allowed by Member State law to claim compensation on a data subject’s behalf independently of the data subject’s mandate.
Article 80(2) GDPR does not permit Member States to allow NPOs to take legal actions against any kind of GDPR infringement. The wording of Article 80(2) GDPR specifically requires that the NPO “[…] considers that the rights of a data subject under this Regulation have been infringed as a result of the processing.” Hence, Member States may only provide for the NPO’s right to lodge complaints/bring legal proceedings with regard to GDPR provisions that grant subjective rights to data subjects.[15]
However, this does not mean that a SA or court would need to assess if a specific data subject’s right under the GDPR has been violated. Rather it must be assessed on an abstract level, if any data subjects’ GDPR rights could have been violated by the processing activity in question.[16]
Decisions
→ You can find all related decisions in Category:Article 80 GDPR
References
- ↑ Leupold, Schrems in Knyrim, Der Datkomm, Article 80 GDPR, margin number 2 (rdb.at 2018).
- ↑ Opening clauses permit a Member State to modify the provisions of an Article. In practice, opening clauses allow Member States to legislate for a more restrictive application of the provision concerned.
- ↑ Leupold, Schrems in Knyrim, Der Datkomm, Article 80 GDPR, margin number 6 (rdb.at 2018).
- ↑ See for example Fuster in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 80 GDPR, p. 1148 (Oxford University Press 2020); Kreße in Sydow, Europäische Datenschutzverordnung, Artikel 80 GDPR, margin number 11 (Nomos 2018, 2nd edition); Moos, Schefzig in Taeger, Gabel, DSGVO – BDSG, Article 80 GDPR, margin number 13 (Deutscher Fachverlag 2019, 3rd edition); Werkmeister in Gola, Datenschutz-Grundverordnung, Artikel 80 GDPR, margin number 9 (C.H. Beck 2018, 2nd edition); the only German legal scholars disagreeing seem to be Nemitz in Ehmann, Selmayr, DS-GVO, Article 80 GDPR, margin number 9 (C.H. Beck 2018, 2nd edition) and Karg in Wolff, Brink, BeckOK DatenschutzR, Article 80 GDPR, margin number 8 (C.H. Beck 2021, 36th edition). The latter take the view that Article 80(1) GDPR shall apply only if and to the extent that Member State law provides that natural persons may be represented by organisations.
- ↑ Boehm in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 80 GDPR, margin number 5 (C.H. Beck 2019); Bergt in Kühling, Buchner, DS-GVO BDSG, Artikel 80 GDPR, margin number 4 (C.H. Beck 2020, 3rd edition).
- ↑ Karg in Wolff, Brink, BeckOK DatenschutzR, Article 80 GDPR, margin number 10 (C.H. Beck 2021, 36th edition).
- ↑ Moos, Schefzig in Taeger, Gabel, DSGVO – BDSG, Article 80 GDPR margin number 7 (Deutscher Fachverlag 2019, 3rd edition).
- ↑ Karg in Wolff, Brink, BeckOK DatenschutzR, Article 80 GDPR, margin number 11 (C.H. Beck 2021, 36th edition); Moos, Schefzig in Taeger, Gabel, DSGVO – BDSG, Article 80 GDPR margin number 10 (Deutscher Fachverlag 2019, 3rd edition).
- ↑ See the Austrian Supreme Court’s request for the CJEU’s preliminary ruling regarding the legal relationship between Article 80 GDPR and national law granting consumer protection organisations the power to bring abstract lawsuits.
- ↑ Moos, Schefzig in Taeger, Gabel, DSGVO – BDSG, Article 80 GDPR, margin number 6 (Deutscher Fachverlag 2019, 3rd edition).
- ↑ The wording of Article 80(1) GDPR differentiates between “lodging a complaint on behalf of the data subject” and “exercising the right referred to in Article 77 GDPR”. As the right to lodge a complaint is the only right exercisable under Article 77 GDPR, this differentiation is redundant; see Moos, Schefzig in Taeger, Gabel, DSGVO – BDSG, Article 80 GDPR, margin number 12 (Deutscher Fachverlag 2019, 3rd edition).
- ↑ Boehm in Simitis. Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 80 GDPR, margin number 11 (C.H. Beck 2019).
- ↑ Collective Redress Directive (EU) 2020/1828.
- ↑ See, Articles 3(4) and 4 Collective Redress Directive (EU) 2020/1828.
- ↑ See Moos, Schefzig in Taeger, Gabel, DSGVO – BDSG, Article 80 GDPR, margin number 22 (Deutscher Fachverlag 2019, 3rd edition); Boehm in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 80 GDPR, margin numbers 14, 15 (C.H. Beck 2019); Kreße in Sydow, Europäische Datenschutzverordnung, Article 80 GDPR, margin number 13 (Nomos 2018, 2nd edition); Frenzel in Paal, Pauly, Datenschutz-Grundverordnung Bundesdatenschutzgesetz, Article 80 GDPR, margin number 11 (C.H. Beck 2021, 3th edition).
- ↑ Boehm in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 80 GDPR, margin numbers 13, 15 (C.H. Beck 2019).