Article 52 GDPR: Difference between revisions
(50 intermediate revisions by 10 users not shown) | |||
Line 185: | Line 185: | ||
== Legal Text == | == Legal Text == | ||
'''Article 52 - Independence''' | |||
<span id="1">1. Each supervisory authority shall act with complete independence in performing its tasks and exercising its powers in accordance with this Regulation.</span> | <span id="1">1. Each supervisory authority shall act with complete independence in performing its tasks and exercising its powers in accordance with this Regulation.</span> | ||
Line 199: | Line 199: | ||
<span id="6">6. Each Member State shall ensure that each supervisory authority is subject to financial control which does not affect its independence and that it has separate, public annual budgets, which may be part of the overall state or national budget.</span> | <span id="6">6. Each Member State shall ensure that each supervisory authority is subject to financial control which does not affect its independence and that it has separate, public annual budgets, which may be part of the overall state or national budget.</span> | ||
== Relevant Recitals== | ==Relevant Recitals== | ||
{{Recital/117 GDPR}} | |||
{{Recital/118 GDPR}} | |||
{{Recital/120 GDPR}} | |||
{{Recital/121 GDPR}} | |||
== Commentary == | ==Commentary== | ||
Primary Union law necessitates the independence of supervisory authorities under Article 8(3) of the Charter of Fundamental Rights of the European Union ("''CFR''"), Article 16(2) of the Treaty on the Functioning of the European Union ("''TFEU''") and Article 39 of the Treaty on the European Union ("''TEU''"). These Articles provide that Member States must ensure that compliance with data protection rules are be subject to the "''control of independent authorities''." Article 52 GDPR gives effect to this requirement. | |||
'' | Article 52 GDPR codifies the concept of "''complete independence''" developed by the European Court of Justice ("''CJEU''") in several landmark cases concerning the interpretation of Article 28(1) of Directive 95/46/EC (''"DPD"''), the Regulation's predecessor.<ref>Case ''C-518/07, Commisson v Germany''; Case ''C-614/10, Commission v Austria;'' and ''Case C-288/12, Commission v Hungary''. </ref> Article 28(1) DPD established the existence of supervisory authorities and mandated that they were to "''act with complete independence in exercising the functions entrusted to them''." | ||
== Decisions == | Similarly, Article 52(1) GDPR explicitly demands that the independence of SAs must be complete. It has elaborated this to mean that the authority and its members must exercise their functions without any external influence and without conflicts of interest (Article 52(2)(3) GDPR). In order to make these principles operational, the provision requires Member States to provide the SA with adequate financial and organisational means for this purpose (Article 52(4)(5)(6) GDPR). Elements of SAs' complete independence are also addressed in [[Article 53 GDPR]] and [[Article 54 GDPR]]. | ||
The CJEU in the Case of ''Commission v Germany'', notes that the notion of absolute independence for SAs was developed in order to strengthen the protection of individuals, not for the purpose of granting special status to SAs.<ref>See CJEU, case ''C-518/07 - Commission v Germany'', paragraph 25.</ref> Moreover, this understanding was affirmed in ''Commission v Austria'', wherein the CJEU held that “''the guarantee of the independence of national supervisory authorities is intended to ensure the effectiveness and reliability of the supervision of compliance with the provisions on the protection of individuals with regard to the processing of personal data'' [...]''.''”<ref name=":0">''See CJEU, case C-614/10 - Commission v Austria, paragraph 25.'' </ref> | |||
The notion independence reoccurs throughout the regulation. For instance, the principle of independence is also referred to in [[Article 4 GDPR|Article 4(12) GDPR]] (definition of SA), [[Article 45 GDPR|Article 45(2)(b) GDPR]] (personal data transfers to a third country or an international organisation outside of the outside of the European Economic Area), and [[Article 69 GDPR]] (on the independence of the European Data Protection Board ("''EDPB''")).<ref>''See Zerdick'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 52 GDPR, p. 876 (Oxford University Press 2020).</ref> | |||
===(1) Complete independence of supervisory authorities (SAs)=== | |||
Article 52(1) GDPR acts as a catch-all clause that applies as a general standard,<ref>''Ziebarth,'' in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 6 (Nomos 2022).</ref> regardless if more specific provisions of the GDPR do not apply. | |||
==== Each supervisory authority (SA) ==== | |||
Member States can establish one or several SAs for monitoring the implementation of the GDPR ([[Article 51 GDPR]]). Article 52(1) GDPR clarifies that ''"each"'' of them must ("shall") act with complete independence.<ref>''Zerdick'', in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 52 GDPR, p. 879 (Oxford University Press 2020).</ref> | |||
==== Shall act ==== | |||
This condition mandates that Member States, SAs and each of their members ensure that the the requirement of complete independence is fulfilled. In the event that the provision is not implemented, the Commission may start infringement proceedings against the state under Article 258 TFEU. In addition, other Member States may bring an action before the CJEU under Article 259 TFEU. | |||
Infringement proceedings against Member States have occurred before. In three separate cases instigated by the Commission, the CJEU found that Germany, Austria, and Hungary had not fulfilled their obligations, as they had failed to ensure the complete independence of their SAs.<ref>''See CJEU, case [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-518/07 C-518/07 - Commission v Germany,] case [https://curia.europa.eu/juris/liste.jsf?num=C-614/10&language=EN C-614/10 - Commission v Austria],'' and case ''[https://curia.europa.eu/juris/liste.jsf?language=en&num=C-288/12 C-288/12 - Commission v Hungary].''</ref> | |||
==== Complete independence ==== | |||
In ''Commission v Germany'' the Court specified that the notion of “''complete independence''” must be given a broad and autonomous interpretation. Other provisions on the independence of SAs and the European Data Protection Supervisor ("''EDPS''") are to be interpreted homogenously, as they are based on the same general principle of independence.<ref>See CJEu, case [https://gdprhub.eu/C-518/07%20-%20Commission%20v%20Germany ''C-518/07 - Commission v Germany''], paragraphs 17-39 and 51 and paragraphs 26-28, available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-518/07 here]. See also ''Zerdick'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 52 GDPR, pages 875 and 878 (Oxford University Press 2020). The independence of EDPS is now regulated in Article 55 EUDPR (Regulation (EU) 2018/1725, available [https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32018R1725 here]), which has replaced Article 44 of the Regulation 45/2001. | |||
</ref> | |||
Complete independence requires that the decisions of SAs and SAs themselves, are objective and impartial and remain above any suspicion of partiality.<ref>CJEU, case ''C-518/07 - Commission v Germany'', paragraph 36, available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-518/07 here].</ref> To fulfil the requirement of complete independence, SAs must remain free from any external influence, which is liable to have an effect on their decisions.<ref>CJEU, case ''C-518/07 - Commission v Germany'', paragraph 41, available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-518/07 here].</ref> According to the CJEU, this freedom is necessary for SAs to carry out their functions, which include ''"ensuring a fair balance between fundamental rights, on the one hand, observance of the fundamental right to private life and, on the other hand, the interests requiring free movement of personal data''.”<ref>CJEU, case ''C-518/07 - Commission v Germany'', paragraph 24, available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-518/07 here].</ref> | |||
Consequently, an SA must enjoy independence in all possible forms, including: | |||
* institutional and organizational independence (see below); | |||
* independence in decision making, without any external influence (see Article 52(2) GDPR, below): | |||
* functional independence (see Article 52(3) GDPR, below); | |||
* operational independence, such as having own premises and staff (see Article 52(4)(5) GDPR, below); | |||
* financial and budgetary independence (see Article 52(4)(6) GDPR, below), and | |||
* restrictions regarding premature termination of mandate of SA members (see Article 53 GDPR). | |||
These requirements mean that SAs must be independent with respect to the entities, controllers or processors, over which they are required to exercise control. The concept of independence applies also to the state or any other entity that may exercise any kind of direct or indirect influence over the decision-making capacity of an SA. For example, in practice, this requirement mandates that legislative or executive bodies, such as the government of a Member State or the Commission, cannot change or replace a decision taken by a SA. Moreover, the concept of complete independence extends to SA member's term of office, which cannot end prematurely outside of the GDPR's parameters, even if Member States introduce domestic laws which attempt to restructure the functioning of SAs.<ref>CJEU, case ''[https://curia.europa.eu/juris/liste.jsf?language=en&num=C-288/12 C-288/12 – Commission v Hungary],'' paragraph 61, available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-288/12 here].</ref> | |||
The independence of SAs extends to adequacy decisions adopted by the Commission. An SA is not bound by an adequacy decision adopted by the Commission under [[Article 45 GDPR]], if it considers it to not comply with the GDPR's requirements. For instance, in ''Schrems I,'' the CJEU made it clear that the competent SA when examining a data subject's claim relating to the third-country transfer of data ''"must be able to examine, with complete independence, whether the transfer of that data complies with the requirements laid down by the [law]."''<ref>CJEU in case ''C-362/14 - Schrems I'', paragraph 57, available [https://curia.europa.eu/juris/liste.jsf?num=C-362/14 here].</ref> | |||
The aim of such complete independence is to ensure that SAs are free from political influence. For this reason, the CJEU has highlighted that their governance must remain outside of a State's ''"classic hierarchical administration.''”<ref>CJEU in case ''C-518/07 - Commission v Germany'', paragraphs 42.</ref> The requirement of independence does not jeopardise their democratic legitimation, as an SAs' democratic legitimacy stems from the appointment of their members, which is to be done by means of a transparent procedure by a Member State's parliament, government, head of State, or an independent body entrusted with the appointment under Member State law ([[Article 53 GDPR]]). SAs are also accountable to the political bodies of their Member States. | |||
Nevertheless, complete independence should not be taken to mean unaccountability.<ref>See ''Ziebarth,'' in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 30 (Nomos 2022).</ref> Pursuant to Article 59 GDPR, they must provide annual reports to the national parliament, the government and any other authorities as designated by member state law. Moreover, in line with the rule of law, decisions of SAs are subject to judicial review, under Article 78 GDPR. | |||
==== Performing its tasks and exercising its powers ==== | |||
===== Tasks of supervisory authorities (SAs) ===== | |||
Among the tasks of each SA is handling of complaints of data subjects and cooperation with other SAs under the Article 63 GDPR consistency mechanism. The tasks of SAs are laid down in [[Article 57 GDPR]].<ref>For further analysis on this point please refer to [[Article 57 GDPR]].</ref> | |||
===== Powers of supervisory authorities (SAs) ===== | |||
The powers of SAs are both investigative and corrective, which are set out in [[Article 58 GDPR]].<ref>For further analysis, please refer to [[Article 58 GDPR]].</ref> | |||
The fact that SAs' legally binding decisions are subject to full judicial review (see commentary on [[Article 78 GDPR]]) does not diminish the SAs' independence: | |||
{{Quote-CJEU|"[…] it is true that, in accordance with Article 8(3) of the Charter, compliance with the rules on the protection of personal data is subject to control by an independent authority. In that context, Article 52 of the GDPR specifies, in particular, that each supervisory authority is to act with complete independence in performing its tasks and exercising its powers in accordance with that regulation […]. | |||
However, those guarantees of independence are in no way compromised by the fact that the legally binding decisions of a supervisory authority are subject to full judicial review."|CJEU - Joined Cases C‑26/22 and C‑64/22 - SCHUFA|64 et seq.}} | |||
===(2) Freedom from external influence=== | |||
Article 52(2) GDPR requires two things from members of SAs in the performance of their duties. Firstly, it requires them to remain free from external influences, whether direct or indirect, and secondly, it prohibits them from seeking or taking instructions from anyone. | |||
As the guardians of the right to data privacy, SAs must be able to act objectively and impartially, free from any external influence that might affect their decision-making process. In particular, this prohibition is primarily targetted towards undue governmental and political influence.<ref>See CJEU, case ''C-518/07 – Commission v Germany'', paragraph 35, available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-518/07 here].</ref> <blockquote> | |||
<u>Case law</u>: In ''Commission v Germany'', CJEU considered that a government may, among others, tend to favour economic interests in the application of data protection provisions by certain establishments which are economically significant for their state or a region.<ref>CJEU explained in Commission v Germany that “the government of the ''Land'' concerned might have an interest in not complying with the provisions of the GDPR”. They might be an interested party in a processing, for example, in the case of contracts with the private sector. They might have an interest in having access to a data base, in particularly for taxation or law enforcement purposes. Also, a government might tend to favour economic interests in the application of data protection provisions by certain companies which are economically important for the ''Land'' or region. See CJEU, case ''C-518/07 – Commission v Germany'', paragraph 35, available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-518/07 here].</ref> The Court decided that the requirement of independence was not met, as SAs competences over the private sector were subject to governmental supervision and state scrutiny, which allowed the government to directly and indirectly influence the decisions of Germany's SAs.<ref>CJEU in case ''C-518/07 - Commission v Germany,'' paragraphs 19, 25, 30 and 50 available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-518/07 here].</ref> In ''Commission v Austria'', the CJEU among others held that the fact that the office of SAs was composed of officials of the Federal Chancellery (Office of the Head of Austrian Government), which was itself subject to supervision by the Austrian SA, carried a risk of influence over SA’s decisions and prevented it from being above all suspicion of partiality and therefore incompatible with the requirement of independence.<ref>CJEU, case ''C-614/10 - Commission v Austria'', paragraph 61, available [https://curia.europa.eu/juris/liste.jsf?num=C-614/10&language=EN here].</ref></blockquote> | |||
==== Member(s) of supervisory authority (SA) ==== | |||
Members of SAs are the carriers of the principle of independence of SAs. Members are the lead personnel appointed in accordance with [[Article 53 GDPR|Article 53(1) GDPR]].<ref>''Ziebarth,'' in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin numbers 21 to 24 (Nomos 2022).</ref> In addition to at least one member, every SA also has staff. The concept of independence does not apply to staff. They must follow instructions of members of the SAs but must remain independent from any influence from outside of the SA (see Article 52(4) GDPR section below).<ref>See ''Boehm'', in Kühling, Buchner, DS-GVO BDSG, Article 52 GDPR, margin number 18 (C.H. Beck 2020, 3rd Edition). See also ''Ziebarth,'' in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 26 (Nomos 2022).</ref> | |||
==== Remain free from external influence ==== | |||
===== Direct influence ===== | |||
The prohibition under Article 52(2) GDPR is broad and forbids any form of direct influence. Forms of direct influence are more explicit that indirect influence, and could include instructions given to an SA on any aspect of its work, direct political influence, or prior compliance. <ref>Polenz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 52 GDPR, margin number 5 (Nomos 2019); to that end see also Article 58(4) GDPR.</ref> These examples are non-exhaustive. In practice, this prohibition forbids situations such as the following:<blockquote><u>Example</u>: The government cannot review a decision of an SA for its correct interpretation and application of the GDPR and replace it. | |||
<u>Example</u>: The Commission cannot instruct an SA as to which company should or should not be investigated. | |||
<u>Example</u>: An SA will not decide to impose a fine for the repeated violation of the GDPR, as they are aware that their state's ministry as the scrutinising authority, will annul and replace their decision because the government does not want to impose any fines for political reasons.</blockquote> | |||
===== Indirect influence ===== | |||
Indirect influence is implicit, and occurs in instances where an SA’s actions or decisions are swayed by external factors. CJEU case law suggests that the mere suspicion of partiality is sufficient to constitute an infringement upon an SA's independence. In the Court’s view, this risk may generate a form of ‘prior compliance’ which is incompatible with the free and independent exercise of an SA's functions. Indirect influence equally may result from external control over an SA member's career prospects, including external control over disciplinary action, especially in circumstances where political incentives exist for the GDPR's non-enforcement. <blockquote><u>Case law</u>: In ''Commission v Germany'', the CJEU explained that “''the mere risk that the state scrutinizing authorities could exercise political powers over the decisions of SAs is enough to hinder the latter in the independent performance of their tasks. First, as was stated by the Commission, there could be ‘prior compliance’ on the part of those authorities in the light of the scrutinising authority’s decision-making practice. Secondly, for the purposes of the role adopted by those authorities as guardians of the right to private life, it is necessary that their decisions, and therefore the authorities themselves, remain above any suspicion of partiality.''” <ref>CJEU, case ''C-518/07 – Commission v Germany'', paragraph 36, available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-518/07 here].</ref> | |||
<u>Case law</u>: In ''Commission v Austria'', the CJEU held that the fact that the Federal Chancellor had an unconditional right to be informed on all aspects of the work of the SA was enough to subject the SA to indirect influence from the Federal Chancellor. The Court also noted that the professional evaluation of an SA member by their hierarchical superior for the purposes of a promotion had the capacity to constitute a form of prior compliance.<ref>CJEU in case ''C-614/10 - Commission v Austria'', paragraphs 63 and 51, available [https://curia.europa.eu/juris/liste.jsf?num=C-614/10&language=EN here].</ref> | |||
<u>Case law</u>: Similarly, in ''Commission v Hungary'', the CJEU clarified that an SA member's risk of premature termination from their term of office could lead them to enter into a form of prior compliance with the political authority in question. The mere risk of prior compliance was incompatible with the requirement of independence.<ref>CJEU in case ''C-288/12 - Commission v Hungary'', available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-288/12 here].</ref></blockquote>Given these conditions, the question arises as to what should be the scale of national legislative intervention to ensure effective independence during SA members' term of office. The problem is particularly pressing where certain professional categories are concerned, such as legal advisors in the private sector. In instances such as these, a form of prior compliance can be envisaged, not so much with respect to political or governmental bodies, but rather with respect to positions taken previously, or to the risk that certain ‘unpopular’ decisions may reduce the number of job opportunities after the end of members' term. | |||
==== Freedom from instructions ==== | |||
Included in the wording of Article 52(2) GDPR, is an explicit prohibition on SAs from seeking or taking instructions from anybody. The CJEU has clarified, that freedom from external interference is an essential element of the principle of independence.<blockquote><u>Case law</u>: In ''Commission v Hungary'', CJEU held that “''[t]he operational independence of supervisory authorities, in that their members are not bound by instructions of any kind in the performance of their duties, is thus an essential condition that must be met if those authorities are to satisfy the criterion of independence.''”<ref>CJEU in case ''C-288/12 - Commission v Hungary'', para 52. Available [https://curia.europa.eu/juris/liste.jsf?language=en&num=C-288/12 here].</ref></blockquote> | |||
===(3) Prohibition against incompatible actions=== | |||
Under Article 52(3) GDPR, members of each SA during their term of office, are forbidden from engaging in any incompatible actions or occupations with their duties, whether gainful or not. The purpose of this provision is to protect the independence of SAs, as well as to ensure the lawfulness of their actions and to ensure the maintenance of their reputation.<ref>''Ziebarth,'' in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 31 (Nomos 2022</ref> The GDPR provides no list of actions or occupations that are considered "''incompatible"'', as under Article 54(1)(f) GDPR, Member States must regulate the matter through their national legislation. Recital 121 also confirms that Member States are to regulate for the general conditions of SA members, and in addition, this Recital necessitates that SA members act with integrity. | |||
Unlike the members of other supervisory bodies, such as the EDPS, members of SAs are permitted to hold other positions in addition to those with the SA, so long as these do not conflict with their duties under the GDPR. This freedom allows members of SAs to hold other competences. For example, in Germany on a federal level and in some German individual federal states, as well as in Malta and Slovenia, SAs are the public authority in charge of freedom of information legislation. | |||
====Incompatible action==== | |||
The prohibition of incompatible actions applies both to SA members' professional and private life. As noted above, the concept incompatibility is left to Member States to define. Nonetheless, examples of actions which would be considered incompatible with the function of an SA member are those which risk giving rise to external influence or partiality. For example, the receipt of gifts, promises or any other form of benefit is certainly incompatible. In addition, SA members should avoid frequent private contact with potential counterparties or representatives of controllers or processors to the extent possible, and in the least should avoid contact with those against whom investigations are being conducted. | |||
====Incompatible occupation==== | |||
Regarding the concept of "''incompatible occupation,"'' the wording of Article 52(3) GDPR makes no differentiation to the nature of the occupation. It makes no difference for the purpose of the provision whether these are professional, part-time, or voluntary. The decisive factor is the occupation's incompatibility. This prohibition aims to curb against external occupational activities of SA members which have the potential to undermine the body's independence and neutrality. | |||
The concept of incompatibility is to be judged on a prognostic scale. Therefore, an occupation will be deemed incompatible if it has the potential to lead to undue influence or conflicts of interest with an SA's independent exercise of office, regardless of whether these are economic or political and so forth. The mere risk of incompatibility is sufficient to fall under the Article's prohibition. | |||
Typically, incompatible conduct would be, for example, accepting a position within a company whose actions are liable to scrutiny by the DPA, or the provision of legal advice within the SA’s own jurisdiction. However, even in circumstances such as these, each case must be examined to determine whether a conflict of interest arises. For instance, if an SA member were to take on an additional role as as a tax consultant or lawyer in their individual capacity, the potential risk of conflict with supervisory tasks would have to be assessed, as in principle, such activities are not inherently incompatible with the office.<ref>''Polenz'', in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 53 GDPR, margin numbers 12-14 (NOMOS 2019).</ref> | |||
===(4) Sufficient resources === | |||
Article 52(4) GDPR and Article 52(6) GDPR establish the framework for SAs financial governance. Article 52(4) GDPR stipulates that SAs must enjoy material independence. To be able to efficiently carry out their tasks, SAs must receive the necessary financial, organisational, technical and human resources to fulfil their multiple obligations under the GDPR. Included in SAs' material independence is autonomy in relation to the distribution of resources within the allocated budget.<ref>''Polenz'', in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 52 GDPR, margin number 15 (Nomos 2019).</ref> | |||
This provision attempts to ensure that SAs' independent functioning and effective performance is not compromised by inadequate staffing and financial resources.<ref>''Boehm'', in Kühling, Buchner, DS-GVO BDSG, Article 52 GDPR, margin number 22 (C.H. Beck 2020, 3rd Edition).</ref> The powers granted to SAs under the GDPR are hollow if an authority is unable to carry out its tasks, or can only do so ineffectively, because it lacks the necessary resources.<ref>''Ziebarth,'' in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 40 (Nomos 2022).</ref> For this reason, the adequacy of resources should be periodically reviewed.<ref>''Zerdick'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 52 GDPR, p. 881 (Oxford University Press 2020).</ref> | |||
==== Human resources ==== | |||
Human resources refer to the necessary number of staff and to the availability of qualified personnel to carry out the tasks and exercise of powers. This provision requires that SAs have employees with a training background in the fields of law and computer science, including communication technology. To do so, the applicable salary structures of SAs must be designed in such a way to ensure that high-quality employees can be recruited in competition with the private sector.<ref>''Polenz'', in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 53 GDPR, margin number 17 (NOMOS 2019).</ref> The structure of staff should enable SAs to take prompt and effective action.<ref>''Zerdick'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 52 GDPR, p. 881 (Oxford University Press 2020).</ref> | |||
==== Technical resources ==== | |||
Technical resources refer to the availability of appropriate hardware and software equipment to SAs, in order for them to be able to carry out their monitoring tasks.<ref>''Polenz'', in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 52 GDPR, margin number 18 (NOMOS 2019).</ref> | |||
==== Financial resources ==== | |||
Financial resources consist of the funding needed for the effective functioning of SAs, as well as resources for unforeseen tasks. According to Article 52(6) GDPR each SA must have its own budget (see below). Sufficient financial resources must be provided an SA's basic running costs, such as for the necessary human and technical resources, the premises, and the infrastructure. Included in the financial resources, for example, could be funds for travel expenses, participation in further education and training, the implementation of conferences and workshops, obtaining external legal expertise, legal representation, or for the short-term reinforcement of staff coverage in the event of special workload.<ref>''Polenz'', in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 52 GDPR, margin number 19 (NOMOS 2019).</ref> | |||
Sufficient financial resources are crucial to the impartiality of SAs. Otherwise, there is a risk that SAs may be more lenient in the enforcement of the GDPR and may refrain from imposing heavy fines to avoid their decisions being challenged. Especially, if they do not have the necessary financial resources to defend their decision in the event of an appeal in court.<ref>''Polenz'', in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 52 GDPR, margin number 16 (Nomos 2019)</ref> | |||
==== Premises and infrastructure ==== | |||
Other essential elements for the proper functioning of the SA are the premises and the infrastructure. The SA should be equipped with premises with adequate space to ensure the permanence of its members and the confidentiality of meetings. Communication and security infrastructures commensurate with the sensitivity of the task are obviously needed.<ref>''Polenz'', in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 52 GDPR, margin numbers 20 and 21 (Nomos 2019)</ref> | |||
==== Necessary for effective performance of its tasks and exercise of its powers ==== | |||
===== Necessary ===== | |||
Article 52(4) GDPR explicitly relates the criteria of sufficient resources to the effective performance of an SA's tasks and exercise of its powers. The provision does not specify what minimum threshold of resource allocation is "''sufficient''" for the purposes of the GDPR. However, what is considered sufficient is likely to differ significantly from SA to SA, as this depends on varying factors, such as the size of the territory and number of subjects within it, the number of complaints it receives, and the complexity of those complaints. Another significant factor is the size of companies and their respective processing operations within an SA's territory. Naturally, larger technology companies are more complex and time consuming to monitor than smaller businesses. | |||
===== Effective performance ===== | |||
Effective performance refers to the efficient functioning of an SA, in both the fulfilment of its tasks and the exercise of its powers. In practice, the notion of effective performance suggests that the majority of GDPR violations are identified, investigated and sanctioned. In general, the likelihood of severe sanctioning against infringements is a crucial element of ensuring voluntary compliance with the law. Nonetheless, the concept of effective sanctioning remains far from the current reality where most GDPR violations are not addressed, mass violations are tolerated and complaints in most states take several years to be decided.<ref>From lodging the complaint with a SA until a decision is issued it usualy takes 2.5 to 5 years. For more information see statistics of DPA’s handling of noyb cases, available [https://noyb.eu/en/project/dpa here].</ref> | |||
===== In the context of mutual assistance, cooperation and participation in the EDPB ===== | |||
Finally, Member States must provide sufficient resources not only for SAs on national level, but also on a European level. Member States must additionally provide sufficient resources for activities carried out ''“in the context of mutual assistance, cooperation and participation in the Board.”'' These activities relate to SAs' participation in the cooperation and consistency mechanism under Chapter 7 of the GDPR, and include staff attendance of EDPB meetings and cooperation with other SAs under the consistency mechanism (one-stop shop). In short, SAs must be provided with the sufficient technical and financial resources to cooperate with other authorities. An SA should therefore have at its disposal, for example, translators for when collegial work requires the translation of documents or the interaction with colleagues of a different language, encrypted communication systems to maintain the secrecy of the investigations and, more generally, the adequate financial resources for the instigation of joint investigations.<ref>''Selmayr'', in Ehmann, Selmayr, DS-GVO Kommentar, Article 52 GDPR, margin number 23 (C.H. Beck 2017).</ref> | |||
===(5) Recruitment and staff supervision=== | |||
The independence and efficiency of SAs may be compromised if its staff is chosen by another body or employed elsewhere. Unsuitable and incompetent staff cannot efficiently monitor the application of the GDPR. Therefore, Article 52(5) GDPR specifies that each SA must be able to choose and employ its own staff, who must then be subject to the exclusive direction of the SA.<ref>''Ziebarth,'' in Sydow, Marsch, DS-GVO/BDSG, Article 53 GDPR, margin number 47 (Nomos 2022).</ref> | |||
==== Chooses and has own staff ==== | |||
An SAs' ability to choose and have its own staff enables SAs to employ suitable staff with the expertise, experience, qualifications and skills required to perform their tasks.<ref>''Ziebarth,'' in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 23 (Nomos 2022).</ref> Each SA must select its own staff. Taking into account Recital 121, this requirement can be met not only if the SA recruits and selects the staff itself, but also if the selection of staff is carried out by an independent body.<ref>Recital 121, sentence 3 reads: ''"The supervisory authority should have its own staff, chosen by the supervisory authority or an independent body established by Member State law, which should be subject to the exclusive direction of the member or members of the supervisory authority."''</ref> Autonomy and independence in the selection of staff gives SA an opportunity to better respond to its existing professional and staffing needs.<ref>''Ziebarth,'' in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 23 (Nomos 2022).</ref><blockquote><u>Case law</u>: In ''Commission v Austria'', the CJEU decided among others that Austria did not fulfil the conditions of independence because the SA's office was integrated within the department of the Federal Chancellery composed of officials of the Federal Chancellery.<ref>CJEU, case ''C-614/10 - Commission v Austria'' paragraphs 61 and 66.</ref></blockquote> | |||
==== Exclusive direction of member(s) of supervisory authorities (SAs) ==== | |||
Staff of an SA are subject to the exclusive supervision and direction of the member(s) of the SA, as any supervision or directions by another body could influence the work of the staff and thus the work of the SA. This requirement also excludes the possibility of staff working for the SA, having any organisational links or being subject to the supervision of any other body.<ref>''Zerdick'', in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 52 GDPR, p. 882 (Oxford University Press 2020).</ref> | |||
===(6) Financial control and budget=== | |||
Article 52(6) GDPR addresses a crucial aspect of SAs' financial independence, their freedom from financial oversight which has the capacity to affect their independence. Moreover, this provision necessitates that SAs have their own <span id="6">separate, public annual budgets.</span> | |||
==== Financial control ==== | |||
Naturally, the concept of independence does not suggest that SAs should not be subject to any financial oversight, Recital 118 GDPR provides that "''the independence of supervisory authorities should not mean that the supervisory authorities cannot be subject to control or monitoring mechanisms regarding their financial expenditure or to judicial review''." Although, Article 52(6) GDPR should not be understood as obliging Member States to subject its SA(s) to financial controls,<ref>''Ziebarth,'' in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 52 (Nomos 2022).</ref> the provision does clearly set limits on the scope of financial controls, as these cannot compromise the independence of SAs. They must only be used as a mechanism for accountability, and may not be implemented in a way that would impede an SA's functioning. | |||
==== Budget ==== | |||
Each SA must have a separate annual budget, which allows SAs a sense of financial autonomy. For the purposes of Article 52(6) GDPR, SAs must be able to independently determine the allocation of their funds. | |||
== Decisions== | |||
→ You can find all related decisions in [[:Category:Article 52 GDPR]] | → You can find all related decisions in [[:Category:Article 52 GDPR]] | ||
== References == | ==References== | ||
<references /> | <references /> | ||
[[Category:GDPR Articles]] | [[Category:GDPR Articles]] |
Latest revision as of 13:50, 2 October 2024
Legal Text
Article 52 - Independence
1. Each supervisory authority shall act with complete independence in performing its tasks and exercising its powers in accordance with this Regulation.
2. The member or members of each supervisory authority shall, in the performance of their tasks and exercise of their powers in accordance with this Regulation, remain free from external influence, whether direct or indirect, and shall neither seek nor take instructions from anybody.
3. Member or members of each supervisory authority shall refrain from any action incompatible with their duties and shall not, during their term of office, engage in any incompatible occupation, whether gainful or not.
4. Each Member State shall ensure that each supervisory authority is provided with the human, technical and financial resources, premises and infrastructure necessary for the effective performance of its tasks and exercise of its powers, including those to be carried out in the context of mutual assistance, cooperation and participation in the Board.
5. Each Member State shall ensure that each supervisory authority chooses and has its own staff which shall be subject to the exclusive direction of the member or members of the supervisory authority concerned.
6. Each Member State shall ensure that each supervisory authority is subject to financial control which does not affect its independence and that it has separate, public annual budgets, which may be part of the overall state or national budget.
Relevant Recitals
Commentary
Primary Union law necessitates the independence of supervisory authorities under Article 8(3) of the Charter of Fundamental Rights of the European Union ("CFR"), Article 16(2) of the Treaty on the Functioning of the European Union ("TFEU") and Article 39 of the Treaty on the European Union ("TEU"). These Articles provide that Member States must ensure that compliance with data protection rules are be subject to the "control of independent authorities." Article 52 GDPR gives effect to this requirement.
Article 52 GDPR codifies the concept of "complete independence" developed by the European Court of Justice ("CJEU") in several landmark cases concerning the interpretation of Article 28(1) of Directive 95/46/EC ("DPD"), the Regulation's predecessor.[1] Article 28(1) DPD established the existence of supervisory authorities and mandated that they were to "act with complete independence in exercising the functions entrusted to them."
Similarly, Article 52(1) GDPR explicitly demands that the independence of SAs must be complete. It has elaborated this to mean that the authority and its members must exercise their functions without any external influence and without conflicts of interest (Article 52(2)(3) GDPR). In order to make these principles operational, the provision requires Member States to provide the SA with adequate financial and organisational means for this purpose (Article 52(4)(5)(6) GDPR). Elements of SAs' complete independence are also addressed in Article 53 GDPR and Article 54 GDPR.
The CJEU in the Case of Commission v Germany, notes that the notion of absolute independence for SAs was developed in order to strengthen the protection of individuals, not for the purpose of granting special status to SAs.[2] Moreover, this understanding was affirmed in Commission v Austria, wherein the CJEU held that “the guarantee of the independence of national supervisory authorities is intended to ensure the effectiveness and reliability of the supervision of compliance with the provisions on the protection of individuals with regard to the processing of personal data [...].”[3]
The notion independence reoccurs throughout the regulation. For instance, the principle of independence is also referred to in Article 4(12) GDPR (definition of SA), Article 45(2)(b) GDPR (personal data transfers to a third country or an international organisation outside of the outside of the European Economic Area), and Article 69 GDPR (on the independence of the European Data Protection Board ("EDPB")).[4]
(1) Complete independence of supervisory authorities (SAs)
Article 52(1) GDPR acts as a catch-all clause that applies as a general standard,[5] regardless if more specific provisions of the GDPR do not apply.
Each supervisory authority (SA)
Member States can establish one or several SAs for monitoring the implementation of the GDPR (Article 51 GDPR). Article 52(1) GDPR clarifies that "each" of them must ("shall") act with complete independence.[6]
Shall act
This condition mandates that Member States, SAs and each of their members ensure that the the requirement of complete independence is fulfilled. In the event that the provision is not implemented, the Commission may start infringement proceedings against the state under Article 258 TFEU. In addition, other Member States may bring an action before the CJEU under Article 259 TFEU.
Infringement proceedings against Member States have occurred before. In three separate cases instigated by the Commission, the CJEU found that Germany, Austria, and Hungary had not fulfilled their obligations, as they had failed to ensure the complete independence of their SAs.[7]
Complete independence
In Commission v Germany the Court specified that the notion of “complete independence” must be given a broad and autonomous interpretation. Other provisions on the independence of SAs and the European Data Protection Supervisor ("EDPS") are to be interpreted homogenously, as they are based on the same general principle of independence.[8]
Complete independence requires that the decisions of SAs and SAs themselves, are objective and impartial and remain above any suspicion of partiality.[9] To fulfil the requirement of complete independence, SAs must remain free from any external influence, which is liable to have an effect on their decisions.[10] According to the CJEU, this freedom is necessary for SAs to carry out their functions, which include "ensuring a fair balance between fundamental rights, on the one hand, observance of the fundamental right to private life and, on the other hand, the interests requiring free movement of personal data.”[11]
Consequently, an SA must enjoy independence in all possible forms, including:
- institutional and organizational independence (see below);
- independence in decision making, without any external influence (see Article 52(2) GDPR, below):
- functional independence (see Article 52(3) GDPR, below);
- operational independence, such as having own premises and staff (see Article 52(4)(5) GDPR, below);
- financial and budgetary independence (see Article 52(4)(6) GDPR, below), and
- restrictions regarding premature termination of mandate of SA members (see Article 53 GDPR).
These requirements mean that SAs must be independent with respect to the entities, controllers or processors, over which they are required to exercise control. The concept of independence applies also to the state or any other entity that may exercise any kind of direct or indirect influence over the decision-making capacity of an SA. For example, in practice, this requirement mandates that legislative or executive bodies, such as the government of a Member State or the Commission, cannot change or replace a decision taken by a SA. Moreover, the concept of complete independence extends to SA member's term of office, which cannot end prematurely outside of the GDPR's parameters, even if Member States introduce domestic laws which attempt to restructure the functioning of SAs.[12]
The independence of SAs extends to adequacy decisions adopted by the Commission. An SA is not bound by an adequacy decision adopted by the Commission under Article 45 GDPR, if it considers it to not comply with the GDPR's requirements. For instance, in Schrems I, the CJEU made it clear that the competent SA when examining a data subject's claim relating to the third-country transfer of data "must be able to examine, with complete independence, whether the transfer of that data complies with the requirements laid down by the [law]."[13]
The aim of such complete independence is to ensure that SAs are free from political influence. For this reason, the CJEU has highlighted that their governance must remain outside of a State's "classic hierarchical administration.”[14] The requirement of independence does not jeopardise their democratic legitimation, as an SAs' democratic legitimacy stems from the appointment of their members, which is to be done by means of a transparent procedure by a Member State's parliament, government, head of State, or an independent body entrusted with the appointment under Member State law (Article 53 GDPR). SAs are also accountable to the political bodies of their Member States.
Nevertheless, complete independence should not be taken to mean unaccountability.[15] Pursuant to Article 59 GDPR, they must provide annual reports to the national parliament, the government and any other authorities as designated by member state law. Moreover, in line with the rule of law, decisions of SAs are subject to judicial review, under Article 78 GDPR.
Performing its tasks and exercising its powers
Tasks of supervisory authorities (SAs)
Among the tasks of each SA is handling of complaints of data subjects and cooperation with other SAs under the Article 63 GDPR consistency mechanism. The tasks of SAs are laid down in Article 57 GDPR.[16]
Powers of supervisory authorities (SAs)
The powers of SAs are both investigative and corrective, which are set out in Article 58 GDPR.[17]
The fact that SAs' legally binding decisions are subject to full judicial review (see commentary on Article 78 GDPR) does not diminish the SAs' independence:
"[…] it is true that, in accordance with Article 8(3) of the Charter, compliance with the rules on the protection of personal data is subject to control by an independent authority. In that context, Article 52 of the GDPR specifies, in particular, that each supervisory authority is to act with complete independence in performing its tasks and exercising its powers in accordance with that regulation […].
However, those guarantees of independence are in no way compromised by the fact that the legally binding decisions of a supervisory authority are subject to full judicial review."
CJEU - Joined Cases C‑26/22 and C‑64/22 - SCHUFA, margin number 64 et seq..
(2) Freedom from external influence
Article 52(2) GDPR requires two things from members of SAs in the performance of their duties. Firstly, it requires them to remain free from external influences, whether direct or indirect, and secondly, it prohibits them from seeking or taking instructions from anyone.
As the guardians of the right to data privacy, SAs must be able to act objectively and impartially, free from any external influence that might affect their decision-making process. In particular, this prohibition is primarily targetted towards undue governmental and political influence.[18]
Case law: In Commission v Germany, CJEU considered that a government may, among others, tend to favour economic interests in the application of data protection provisions by certain establishments which are economically significant for their state or a region.[19] The Court decided that the requirement of independence was not met, as SAs competences over the private sector were subject to governmental supervision and state scrutiny, which allowed the government to directly and indirectly influence the decisions of Germany's SAs.[20] In Commission v Austria, the CJEU among others held that the fact that the office of SAs was composed of officials of the Federal Chancellery (Office of the Head of Austrian Government), which was itself subject to supervision by the Austrian SA, carried a risk of influence over SA’s decisions and prevented it from being above all suspicion of partiality and therefore incompatible with the requirement of independence.[21]
Member(s) of supervisory authority (SA)
Members of SAs are the carriers of the principle of independence of SAs. Members are the lead personnel appointed in accordance with Article 53(1) GDPR.[22] In addition to at least one member, every SA also has staff. The concept of independence does not apply to staff. They must follow instructions of members of the SAs but must remain independent from any influence from outside of the SA (see Article 52(4) GDPR section below).[23]
Remain free from external influence
Direct influence
The prohibition under Article 52(2) GDPR is broad and forbids any form of direct influence. Forms of direct influence are more explicit that indirect influence, and could include instructions given to an SA on any aspect of its work, direct political influence, or prior compliance. [24] These examples are non-exhaustive. In practice, this prohibition forbids situations such as the following:
Example: The government cannot review a decision of an SA for its correct interpretation and application of the GDPR and replace it.
Example: The Commission cannot instruct an SA as to which company should or should not be investigated.
Example: An SA will not decide to impose a fine for the repeated violation of the GDPR, as they are aware that their state's ministry as the scrutinising authority, will annul and replace their decision because the government does not want to impose any fines for political reasons.
Indirect influence
Indirect influence is implicit, and occurs in instances where an SA’s actions or decisions are swayed by external factors. CJEU case law suggests that the mere suspicion of partiality is sufficient to constitute an infringement upon an SA's independence. In the Court’s view, this risk may generate a form of ‘prior compliance’ which is incompatible with the free and independent exercise of an SA's functions. Indirect influence equally may result from external control over an SA member's career prospects, including external control over disciplinary action, especially in circumstances where political incentives exist for the GDPR's non-enforcement.
Case law: In Commission v Germany, the CJEU explained that “the mere risk that the state scrutinizing authorities could exercise political powers over the decisions of SAs is enough to hinder the latter in the independent performance of their tasks. First, as was stated by the Commission, there could be ‘prior compliance’ on the part of those authorities in the light of the scrutinising authority’s decision-making practice. Secondly, for the purposes of the role adopted by those authorities as guardians of the right to private life, it is necessary that their decisions, and therefore the authorities themselves, remain above any suspicion of partiality.” [25]
Case law: In Commission v Austria, the CJEU held that the fact that the Federal Chancellor had an unconditional right to be informed on all aspects of the work of the SA was enough to subject the SA to indirect influence from the Federal Chancellor. The Court also noted that the professional evaluation of an SA member by their hierarchical superior for the purposes of a promotion had the capacity to constitute a form of prior compliance.[26]
Case law: Similarly, in Commission v Hungary, the CJEU clarified that an SA member's risk of premature termination from their term of office could lead them to enter into a form of prior compliance with the political authority in question. The mere risk of prior compliance was incompatible with the requirement of independence.[27]
Given these conditions, the question arises as to what should be the scale of national legislative intervention to ensure effective independence during SA members' term of office. The problem is particularly pressing where certain professional categories are concerned, such as legal advisors in the private sector. In instances such as these, a form of prior compliance can be envisaged, not so much with respect to political or governmental bodies, but rather with respect to positions taken previously, or to the risk that certain ‘unpopular’ decisions may reduce the number of job opportunities after the end of members' term.
Freedom from instructions
Included in the wording of Article 52(2) GDPR, is an explicit prohibition on SAs from seeking or taking instructions from anybody. The CJEU has clarified, that freedom from external interference is an essential element of the principle of independence.
Case law: In Commission v Hungary, CJEU held that “[t]he operational independence of supervisory authorities, in that their members are not bound by instructions of any kind in the performance of their duties, is thus an essential condition that must be met if those authorities are to satisfy the criterion of independence.”[28]
(3) Prohibition against incompatible actions
Under Article 52(3) GDPR, members of each SA during their term of office, are forbidden from engaging in any incompatible actions or occupations with their duties, whether gainful or not. The purpose of this provision is to protect the independence of SAs, as well as to ensure the lawfulness of their actions and to ensure the maintenance of their reputation.[29] The GDPR provides no list of actions or occupations that are considered "incompatible", as under Article 54(1)(f) GDPR, Member States must regulate the matter through their national legislation. Recital 121 also confirms that Member States are to regulate for the general conditions of SA members, and in addition, this Recital necessitates that SA members act with integrity.
Unlike the members of other supervisory bodies, such as the EDPS, members of SAs are permitted to hold other positions in addition to those with the SA, so long as these do not conflict with their duties under the GDPR. This freedom allows members of SAs to hold other competences. For example, in Germany on a federal level and in some German individual federal states, as well as in Malta and Slovenia, SAs are the public authority in charge of freedom of information legislation.
Incompatible action
The prohibition of incompatible actions applies both to SA members' professional and private life. As noted above, the concept incompatibility is left to Member States to define. Nonetheless, examples of actions which would be considered incompatible with the function of an SA member are those which risk giving rise to external influence or partiality. For example, the receipt of gifts, promises or any other form of benefit is certainly incompatible. In addition, SA members should avoid frequent private contact with potential counterparties or representatives of controllers or processors to the extent possible, and in the least should avoid contact with those against whom investigations are being conducted.
Incompatible occupation
Regarding the concept of "incompatible occupation," the wording of Article 52(3) GDPR makes no differentiation to the nature of the occupation. It makes no difference for the purpose of the provision whether these are professional, part-time, or voluntary. The decisive factor is the occupation's incompatibility. This prohibition aims to curb against external occupational activities of SA members which have the potential to undermine the body's independence and neutrality.
The concept of incompatibility is to be judged on a prognostic scale. Therefore, an occupation will be deemed incompatible if it has the potential to lead to undue influence or conflicts of interest with an SA's independent exercise of office, regardless of whether these are economic or political and so forth. The mere risk of incompatibility is sufficient to fall under the Article's prohibition.
Typically, incompatible conduct would be, for example, accepting a position within a company whose actions are liable to scrutiny by the DPA, or the provision of legal advice within the SA’s own jurisdiction. However, even in circumstances such as these, each case must be examined to determine whether a conflict of interest arises. For instance, if an SA member were to take on an additional role as as a tax consultant or lawyer in their individual capacity, the potential risk of conflict with supervisory tasks would have to be assessed, as in principle, such activities are not inherently incompatible with the office.[30]
(4) Sufficient resources
Article 52(4) GDPR and Article 52(6) GDPR establish the framework for SAs financial governance. Article 52(4) GDPR stipulates that SAs must enjoy material independence. To be able to efficiently carry out their tasks, SAs must receive the necessary financial, organisational, technical and human resources to fulfil their multiple obligations under the GDPR. Included in SAs' material independence is autonomy in relation to the distribution of resources within the allocated budget.[31]
This provision attempts to ensure that SAs' independent functioning and effective performance is not compromised by inadequate staffing and financial resources.[32] The powers granted to SAs under the GDPR are hollow if an authority is unable to carry out its tasks, or can only do so ineffectively, because it lacks the necessary resources.[33] For this reason, the adequacy of resources should be periodically reviewed.[34]
Human resources
Human resources refer to the necessary number of staff and to the availability of qualified personnel to carry out the tasks and exercise of powers. This provision requires that SAs have employees with a training background in the fields of law and computer science, including communication technology. To do so, the applicable salary structures of SAs must be designed in such a way to ensure that high-quality employees can be recruited in competition with the private sector.[35] The structure of staff should enable SAs to take prompt and effective action.[36]
Technical resources
Technical resources refer to the availability of appropriate hardware and software equipment to SAs, in order for them to be able to carry out their monitoring tasks.[37]
Financial resources
Financial resources consist of the funding needed for the effective functioning of SAs, as well as resources for unforeseen tasks. According to Article 52(6) GDPR each SA must have its own budget (see below). Sufficient financial resources must be provided an SA's basic running costs, such as for the necessary human and technical resources, the premises, and the infrastructure. Included in the financial resources, for example, could be funds for travel expenses, participation in further education and training, the implementation of conferences and workshops, obtaining external legal expertise, legal representation, or for the short-term reinforcement of staff coverage in the event of special workload.[38]
Sufficient financial resources are crucial to the impartiality of SAs. Otherwise, there is a risk that SAs may be more lenient in the enforcement of the GDPR and may refrain from imposing heavy fines to avoid their decisions being challenged. Especially, if they do not have the necessary financial resources to defend their decision in the event of an appeal in court.[39]
Premises and infrastructure
Other essential elements for the proper functioning of the SA are the premises and the infrastructure. The SA should be equipped with premises with adequate space to ensure the permanence of its members and the confidentiality of meetings. Communication and security infrastructures commensurate with the sensitivity of the task are obviously needed.[40]
Necessary for effective performance of its tasks and exercise of its powers
Necessary
Article 52(4) GDPR explicitly relates the criteria of sufficient resources to the effective performance of an SA's tasks and exercise of its powers. The provision does not specify what minimum threshold of resource allocation is "sufficient" for the purposes of the GDPR. However, what is considered sufficient is likely to differ significantly from SA to SA, as this depends on varying factors, such as the size of the territory and number of subjects within it, the number of complaints it receives, and the complexity of those complaints. Another significant factor is the size of companies and their respective processing operations within an SA's territory. Naturally, larger technology companies are more complex and time consuming to monitor than smaller businesses.
Effective performance
Effective performance refers to the efficient functioning of an SA, in both the fulfilment of its tasks and the exercise of its powers. In practice, the notion of effective performance suggests that the majority of GDPR violations are identified, investigated and sanctioned. In general, the likelihood of severe sanctioning against infringements is a crucial element of ensuring voluntary compliance with the law. Nonetheless, the concept of effective sanctioning remains far from the current reality where most GDPR violations are not addressed, mass violations are tolerated and complaints in most states take several years to be decided.[41]
In the context of mutual assistance, cooperation and participation in the EDPB
Finally, Member States must provide sufficient resources not only for SAs on national level, but also on a European level. Member States must additionally provide sufficient resources for activities carried out “in the context of mutual assistance, cooperation and participation in the Board.” These activities relate to SAs' participation in the cooperation and consistency mechanism under Chapter 7 of the GDPR, and include staff attendance of EDPB meetings and cooperation with other SAs under the consistency mechanism (one-stop shop). In short, SAs must be provided with the sufficient technical and financial resources to cooperate with other authorities. An SA should therefore have at its disposal, for example, translators for when collegial work requires the translation of documents or the interaction with colleagues of a different language, encrypted communication systems to maintain the secrecy of the investigations and, more generally, the adequate financial resources for the instigation of joint investigations.[42]
(5) Recruitment and staff supervision
The independence and efficiency of SAs may be compromised if its staff is chosen by another body or employed elsewhere. Unsuitable and incompetent staff cannot efficiently monitor the application of the GDPR. Therefore, Article 52(5) GDPR specifies that each SA must be able to choose and employ its own staff, who must then be subject to the exclusive direction of the SA.[43]
Chooses and has own staff
An SAs' ability to choose and have its own staff enables SAs to employ suitable staff with the expertise, experience, qualifications and skills required to perform their tasks.[44] Each SA must select its own staff. Taking into account Recital 121, this requirement can be met not only if the SA recruits and selects the staff itself, but also if the selection of staff is carried out by an independent body.[45] Autonomy and independence in the selection of staff gives SA an opportunity to better respond to its existing professional and staffing needs.[46]
Case law: In Commission v Austria, the CJEU decided among others that Austria did not fulfil the conditions of independence because the SA's office was integrated within the department of the Federal Chancellery composed of officials of the Federal Chancellery.[47]
Exclusive direction of member(s) of supervisory authorities (SAs)
Staff of an SA are subject to the exclusive supervision and direction of the member(s) of the SA, as any supervision or directions by another body could influence the work of the staff and thus the work of the SA. This requirement also excludes the possibility of staff working for the SA, having any organisational links or being subject to the supervision of any other body.[48]
(6) Financial control and budget
Article 52(6) GDPR addresses a crucial aspect of SAs' financial independence, their freedom from financial oversight which has the capacity to affect their independence. Moreover, this provision necessitates that SAs have their own separate, public annual budgets.
Financial control
Naturally, the concept of independence does not suggest that SAs should not be subject to any financial oversight, Recital 118 GDPR provides that "the independence of supervisory authorities should not mean that the supervisory authorities cannot be subject to control or monitoring mechanisms regarding their financial expenditure or to judicial review." Although, Article 52(6) GDPR should not be understood as obliging Member States to subject its SA(s) to financial controls,[49] the provision does clearly set limits on the scope of financial controls, as these cannot compromise the independence of SAs. They must only be used as a mechanism for accountability, and may not be implemented in a way that would impede an SA's functioning.
Budget
Each SA must have a separate annual budget, which allows SAs a sense of financial autonomy. For the purposes of Article 52(6) GDPR, SAs must be able to independently determine the allocation of their funds.
Decisions
→ You can find all related decisions in Category:Article 52 GDPR
References
- ↑ Case C-518/07, Commisson v Germany; Case C-614/10, Commission v Austria; and Case C-288/12, Commission v Hungary.
- ↑ See CJEU, case C-518/07 - Commission v Germany, paragraph 25.
- ↑ See CJEU, case C-614/10 - Commission v Austria, paragraph 25.
- ↑ See Zerdick, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 52 GDPR, p. 876 (Oxford University Press 2020).
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 6 (Nomos 2022).
- ↑ Zerdick, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 52 GDPR, p. 879 (Oxford University Press 2020).
- ↑ See CJEU, case C-518/07 - Commission v Germany, case C-614/10 - Commission v Austria, and case C-288/12 - Commission v Hungary.
- ↑ See CJEu, case C-518/07 - Commission v Germany, paragraphs 17-39 and 51 and paragraphs 26-28, available here. See also Zerdick, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 52 GDPR, pages 875 and 878 (Oxford University Press 2020). The independence of EDPS is now regulated in Article 55 EUDPR (Regulation (EU) 2018/1725, available here), which has replaced Article 44 of the Regulation 45/2001.
- ↑ CJEU, case C-518/07 - Commission v Germany, paragraph 36, available here.
- ↑ CJEU, case C-518/07 - Commission v Germany, paragraph 41, available here.
- ↑ CJEU, case C-518/07 - Commission v Germany, paragraph 24, available here.
- ↑ CJEU, case C-288/12 – Commission v Hungary, paragraph 61, available here.
- ↑ CJEU in case C-362/14 - Schrems I, paragraph 57, available here.
- ↑ CJEU in case C-518/07 - Commission v Germany, paragraphs 42.
- ↑ See Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 30 (Nomos 2022).
- ↑ For further analysis on this point please refer to Article 57 GDPR.
- ↑ For further analysis, please refer to Article 58 GDPR.
- ↑ See CJEU, case C-518/07 – Commission v Germany, paragraph 35, available here.
- ↑ CJEU explained in Commission v Germany that “the government of the Land concerned might have an interest in not complying with the provisions of the GDPR”. They might be an interested party in a processing, for example, in the case of contracts with the private sector. They might have an interest in having access to a data base, in particularly for taxation or law enforcement purposes. Also, a government might tend to favour economic interests in the application of data protection provisions by certain companies which are economically important for the Land or region. See CJEU, case C-518/07 – Commission v Germany, paragraph 35, available here.
- ↑ CJEU in case C-518/07 - Commission v Germany, paragraphs 19, 25, 30 and 50 available here.
- ↑ CJEU, case C-614/10 - Commission v Austria, paragraph 61, available here.
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin numbers 21 to 24 (Nomos 2022).
- ↑ See Boehm, in Kühling, Buchner, DS-GVO BDSG, Article 52 GDPR, margin number 18 (C.H. Beck 2020, 3rd Edition). See also Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 26 (Nomos 2022).
- ↑ Polenz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 52 GDPR, margin number 5 (Nomos 2019); to that end see also Article 58(4) GDPR.
- ↑ CJEU, case C-518/07 – Commission v Germany, paragraph 36, available here.
- ↑ CJEU in case C-614/10 - Commission v Austria, paragraphs 63 and 51, available here.
- ↑ CJEU in case C-288/12 - Commission v Hungary, available here.
- ↑ CJEU in case C-288/12 - Commission v Hungary, para 52. Available here.
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 31 (Nomos 2022
- ↑ Polenz, in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 53 GDPR, margin numbers 12-14 (NOMOS 2019).
- ↑ Polenz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 52 GDPR, margin number 15 (Nomos 2019).
- ↑ Boehm, in Kühling, Buchner, DS-GVO BDSG, Article 52 GDPR, margin number 22 (C.H. Beck 2020, 3rd Edition).
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 40 (Nomos 2022).
- ↑ Zerdick, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 52 GDPR, p. 881 (Oxford University Press 2020).
- ↑ Polenz, in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 53 GDPR, margin number 17 (NOMOS 2019).
- ↑ Zerdick, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 52 GDPR, p. 881 (Oxford University Press 2020).
- ↑ Polenz, in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 52 GDPR, margin number 18 (NOMOS 2019).
- ↑ Polenz, in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 52 GDPR, margin number 19 (NOMOS 2019).
- ↑ Polenz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 52 GDPR, margin number 16 (Nomos 2019)
- ↑ Polenz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 52 GDPR, margin numbers 20 and 21 (Nomos 2019)
- ↑ From lodging the complaint with a SA until a decision is issued it usualy takes 2.5 to 5 years. For more information see statistics of DPA’s handling of noyb cases, available here.
- ↑ Selmayr, in Ehmann, Selmayr, DS-GVO Kommentar, Article 52 GDPR, margin number 23 (C.H. Beck 2017).
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 53 GDPR, margin number 47 (Nomos 2022).
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 23 (Nomos 2022).
- ↑ Recital 121, sentence 3 reads: "The supervisory authority should have its own staff, chosen by the supervisory authority or an independent body established by Member State law, which should be subject to the exclusive direction of the member or members of the supervisory authority."
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 23 (Nomos 2022).
- ↑ CJEU, case C-614/10 - Commission v Austria paragraphs 61 and 66.
- ↑ Zerdick, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 52 GDPR, p. 882 (Oxford University Press 2020).
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 52 (Nomos 2022).