Article 51 GDPR: Difference between revisions

From GDPRhub
No edit summary
 
(28 intermediate revisions by 7 users not shown)
Line 185: Line 185:


==Legal Text==
==Legal Text==
<br /><center>'''Article 51 - Supervisory authority'''</center><br />
<br /><center>'''Article 51 - Supervisory authority'''</center>


<span id="1">1.  Each Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation, in order to protect the fundamental rights and freedoms of natural persons in relation to processing and to facilitate the free flow of personal data within the Union (‘supervisory authority’).</span>
<span id="1">1.  Each Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation, in order to protect the fundamental rights and freedoms of natural persons in relation to processing and to facilitate the free flow of personal data within the Union (‘supervisory authority’).</span>
Line 201: Line 201:


==Commentary==
==Commentary==
Chapter VI of the GDPR is dedicated to supervisory authorities. Section 1 regulates the establishment of SAs and the requirements that the Member State must enforce to ensure their independence and proper functioning. Section 2 defines the tasks and powers of SAs.
Chapter VI of the GDPR is dedicated to supervisory authorities ("''SAs''"). SA is defined in [[Article 4 GDPR|Article 4(21) GDPR]] as an independent public authority which is established by a Member State pursuant to Article 51 GDPR. Chapter VI is divided into two sections. The former regulates SAs' establishment (Articles 52-54 GDPR), staffing and other organizational requirements that the Member State must enforce to ensure their independent and proper functioning. While the latter defines the competences, tasks and powers of SAs (Articles 55-59 GDPR).  


=== (1) Establishment of One or More Competent Authorities ===
The GDPR provides for exceptions from provisions entailed in Chapter VI (independent supervisory authorities). [[Article 85 GDPR|Article 85(2) GDPR]] mandates Member States to, among others provide for exemptions or derogations from Chapter VI (independent supervisory authorities) when processing is carried out for journalistic purposes or the purpose of academic, artistic or literary expression, where necessary to reconcile the right to the protection of personal data with the freedom of expression and information.   
Pursuant to Article 51(1)GDPR, each Member State must appoint at least one independent supervisory authority (SA). This means that several SAs can co-exist in one Member State due to their constitutional organisation (''e.g.'' see Germany of Spain ) or due to the division of competence (''e.g.'' one SA competent for private sector and another one for the public sector).<ref>See, [https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A12012E%2FTXT Article 16 (2) TFEU] and [https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A12012P%2FTXT#d1e189-393-1 Article 8 (3) CFR].</ref>  


The SA's main task is to monitor the correct application of the GDPR for the specific purpose of protecting the fundamental rights and freedoms of individuals. This includes, of course, the right to fair, transparent and lawful data processing as well as, among the other, the rights of access, rectification, erasure and objection. Protection also extends to all rights and freedoms guaranteed by the EU Charter of Fundamental Rights and the Treaty on the Functioning of the European Union''.''<ref>''Polenz'', in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 51 GDPR, margin numbers 11-13 (Nomos 2019).</ref>
Article 51 GDPR is the fundamental article governing the establishment of SAs and its duties providing a basis upon which other articles build upon. It is followed by articles that are laying down more detailed rules. Article 51 GDPR and the related articles provide the institutional framework for the enforcement of the data protection rules, one of the main objectives of the GDPR.<ref>A c''omprehensive approach'' on personal ''data protection'' in the ''European Union''<nowiki/>', Communication from the Commission to the European Parliament, the Council, the Economic and Social Committee and the Committee of the Regions, (''2010'') COM(''2010'') ''609 final'' (available [https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2010:0609:FIN:EN:PDF here]).</ref> As noted in Recital 117 the effective and independent functioning of SAs constitutes an essential element of a data subject's fundamental right to data protection.


At the same time, in line with the general objectives of the GDPR (Article 1 GDPR), SAs will also be required to facilitate the free flow of information within the European Union, thus taking into account the requirements of the single market. The role of SAs is therefore double: not only protecting personal data as a fundamental right, but also <span id="1">facilitating the free flow of personal data within the Union.</span><ref>''Schneider'', in BeckOK DatenschutzR, Article 51 GDPR, margin number 6 (Beck 2020, 38th ed.).</ref>  
==== Closely connected articles ====
Article 51 GDPR is closely connected to [[Article 4 GDPR|Article 4(21)]] (definition of SA), [[Article 52 GDPR|Article 52]] (independence), [[Article 53 GDPR|Article 53]] (General conditions for the members of SA), [[Article 54 GDPR|Article 54]] (Rules on the establishment of SA), [[Article 55 GDPR|Articles 55]]-[[Article 59 GDPR|59]] (Competence, tasks and powers), [[Article 60 GDPR|Articles 60]]-[[Article 62 GDPR|62]] (Cooperation), [[Article 63 GDPR|Articles 63]]-[[Article 67 GDPR|67]] (Consistency) and [[Article 68 GDPR|Article 68]]-[[Article 76 GDPR|76]] (European Data Protection Board).<ref>''Hijmans'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 51 GDPR, p. 867 (Oxford University Press 2020).</ref>


=== (2) Consistent Application of the GDPR ===
=== (1) Establishment of a supervisory authority (SA) ===
SAs must ''contribute'' to the ''consistent application'' of the GDPR throughout the entire EU.<ref>This is an additional obligation to the primary one linked to the application of the GDPR on the territory of one's own Member State, reflecting a certain "Europeanisation" of the action of independent authorities. See, ''Hijmans'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 51 GDPR, p. 869 (Oxford University Press 2020).</ref> The use of the verb "contribute" denotes a form of proactive participation specifically aimed at (i) the "''consistent monitoring and enforcement of this Regulation''" and, according to Recital 135, (ii) the uniform application of the law.<ref>Recital 129.</ref> Accordingly, SAs are required to identify any problems (e.g. inactivity of a DPA involved in a collegial decision-making process) and act for its prompt resolution.  
==== Establishment of SAs ====
Each Member State must appoint one or more supervisory authorities (SAs), which are to be independent public authorities. For more details see commentary to Article 51(3) GDPR bellow.


The second part of Article 51(2) SAs must cooperate with each other and the Commission in accordance with Chapter VII of the GDPR. This is an essential feature of the SAs' action, considered as one of the tools for fostering "contribution" to the consistent application of the GDPR.  
===== Independent =====
Article 8(3) of the Charter of Fundamental Rights of the European Union ("''CFR''") and Article 16(2) of the Treaty on the Functioning of the European Union ("''TFEU''") require the independence of SAs. Both Articles provide that compliance with data protection law must be subject to ''"control by an independent authority."''<ref>For further analysis on independence, refer to the Commentary on[[Article 52 GDPR]].</ref> Independent supervisory authorities are also considered an essential component of the right to data protection under CJEU case law.<ref>''Hijmans'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 51 GDPR, p. 864-868 (Oxford University Press 2020).</ref> The independence of SAs was developed by CJEU case law and codified in Article 52 GDPR and subsequent articles. For further analysis on independence, refer to the Commentary on [[Article 52 GDPR]].  


Article 51(2) confirms the "''hybrid position of DPAs between the EU and national levels. DPAs are not the only such hybrid bodies within the EU, since many EU agencies and national agencies are similarly positioned. However, the status of DPAs is specific, in view of their complete independence, which excludes any direct or indirect influence by national governments or the Commission''".<ref>''Hijmans'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 51 GDPR, p. 870 (Oxford University Press 2020).</ref>  
===== Public =====
By definition, SAs must be public bodies (see [[Article 4 GDPR|Article 4(21) GDPR]]). Member States cannot outsource the enforcement of the GDPR to private entities.<ref>''Ziebarth,'' in Sydow, Marsch DS-GVO/BDSG, Article 51 GDPR, margin number 8 (Nomos 2022).</ref>


=== (3) Several SAs are Established in one Member State ===
==== Monitoring the application ====
Where a Member State establishes several supervisory authorities, it should establish by law mechanisms for ensuring the effective participation of those supervisory authorities in the consistency mechanism. That Member State should in particular designate the supervisory authority which functions as a single contact point for the effective participation of those authorities in the mechanism, to ensure swift and smooth cooperation with other supervisory authorities, the Board and the Commission (see also [[Article 68 GDPR|Article 68(4) GDPR]]).  
A SA's main task is to monitor the correct application of the GDPR. This aim should be understood in line with the wording used by [https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A12008E258 Article 16(2) TFEU] and [https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A12012P%2FTXT#d1e189-393-1 Article 8(3) CFR], which provides that enforcement of the GDPR itself, is something that must be managed by "''an independent authority''."


Article 51(3) GDPR is particularly relevant for Member States with a federal structure. Germany, for example, consists of 16 Länder each with its own SA (similar situation in Spain, where there are separate SAs for Catalonia and the Basque Country). Under Article 51(3), Member States in this situation must (i) designate which of these authorities represents the Member State in the EDPB<ref>That implies that each member State can only send one representative to the EDPB, as reflected in the Rules of Procedure of the EDPB. See also, Article 4(3) of the [https://edpb.europa.eu/sites/edpb/files/files/file1/edpb_rop_version_7_adopted_20201008_en.pdf EDPB Rules of Procedure].</ref> and (ii) ensure that all federal SAs accept the procedures and effects of the consistency mechanism.
==== In order to ====
Article 51(1) GDPR specifies that the role of SAs is twofold.<ref>''Schneider, in BeckOK DatenschutzR, Article 51 GDPR, margin number 6'' (Beck 2020, 38th edition)''.''</ref> The first is to protect the fundamental rights and freedoms of individuals, and the second is to facilitate the free flow of personal data within the EU/EEA ("Union").
 
===== Protect the fundamental rights and freedoms of natural persons in relation to processing =====
Protecting the fundamental rights and freedoms of individuals includes monitoring the application of ''all'' elements of the GDPR, not only those relating to data subject rights, SAs' structure, tasks and powers serve this purpose.<ref>''Ziebarth,'' in Sydow, Marsch DS-GVO/BDSG, Article 51 GDPR, margin number 19 (Nomos 2022).</ref>
 
When monitoring and enforcing the GDPR SA must not only take into account the fundamental rights to privacy and data protection, but also other fundamental rights and freedoms, given that the right to data protection is not an absolute right.<ref>''Boehm'', in Kühling, Buchner, DS-GVO BDSG, Article 51 GDPR, margin number 13 (C.H. Beck 2020, 3rd Edition)..</ref> For instance the fundamental rights to data protection (Article 8 CFR) and privacy (Article 7 CFR) must be weighed up against the fundamental rights freedom of expression (Article 11 CFR) and right to property (Article 17 CFR). Also, other laws and regulations are not outside of the SAs' jurisdiction, as to correctly apply the GDPR, SA's must regularly determine provisions of the GDPR while taking into account other laws.<blockquote><u>Example:</u> A SA must determine the necessity of processing personal data under applicable tax laws. In this instance, record keeping requirements under other laws become applicable for the purposes of [[Article 5 GDPR|Article 5(1)(e) GDPR]] when determining the duration for which data must be stored. Any such laws would also be relevant for determining whether the processing is necessary for complying with a legal obligation to which the controller is subject, under [[Article 6 GDPR|Article 6(1)(c) GDPR]].</blockquote>
 
===== Facilitate the free flow of personal data within the Union =====
In line with the general objectives of the GDPR, as outlined in [[Article 1 GDPR]] Article 16 TFEU, SAs are also required to take into account the requirements of the free flow of personal data within the EU/EEA ("Union"). This requirement necessitates that SAs in the exercise of their powers, may not impose measures that have the capacity to impair or prevent the free flow of data within the EU/EEA.<ref>''Ziebarth,'' in Sydow, Marsch DS-GVO/BDSG, Article 51 GDPR, margin number 20 (Nomos 2022); see also Kühling, Buchner, Boehm, DS-GVO, Article 51 GDPR, margin number 13 (C.H. Beck 2020).</ref>
 
The aim of this provision should not be understood as an attempt to place the fundamental right to data protection on equal footing with the free flow of personal data within the common market. Instead, the provision should be understood more as an aim to prevent the implementation of national measures relating to data protection, in a manner that would negatively affect the free flow of personal data. Nevertheless, given that the right to data protection is not an absolute right, it is inevitably weighed up against the free flow of personal data through this provision. Also, after the entry into force of the Lisbon Treaty, "''the centre of gravity in data protection is no longer the free flow of data but rather the protection of fundamental rights''."<ref>''Hijmans'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 51 GDPR, p. 868 (Oxford University Press 2020).</ref> This shift is reflective of a wider trend in the CJEU's case law, in which fundamental rights have begun to take a more dominant position.
 
However, some Commentators have taken a different reading of Article 51(1) GDPR's reconciliation of the right to data protection and the free flow of data within the internal market. In their opinion this provision should be read as establishing a dual objective, in which one aim should not take priority over the other. The right to data protection and the right to free flow of personal data should be taken into account to the same extend and balanced equally.<ref>''Boehm'' in Kühling, Buchner, Article 51 GDPR, margin numbers 12 and 13 (C.H. Beck 2020).</ref>
 
=== (2) Consistent application of the GDPR ===
 
==== Shall ====
The use of the imperative "''shall''" imposes a positive legal obligation upon SAs to facilitate the consistent application of the GDPR throughout the EU/EEA.<ref>This is an additional obligation to the primary one linked to the application of the GDPR on the territory of one's own Member State, reflecting a certain “Europeanisation” of the action of independent authorities. See, ''Hijmans'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 51 GDPR, p. 869 (Oxford University Press 2020).</ref>
 
==== Contribute ====
The use of the verb “''contribute''” denotes a form of proactive participation specifically aimed at the “''consistent monitoring and enforcement of this Regulation''” and, according to Recital 135, the uniform application of the law. Accordingly, SAs are required to identify any problems and act for their prompt resolution. For example, prompt action for resolution could be necessary in case of inactivity of a SA or lead supervisory authority in transnational cases, where cooperation and assistance between SAs is required. 
 
==== Consistent application ====
The use of the term "''consistent application''" mandates that the application and interpretation of GDPR provisions should not differ between Member States' respective SAs, as well as where applicable, between the multiple SAs within a Member State (for further analysis on this point, see Article 51(3) GDPR below). All SAs should have the same understanding of GDPR provisions and interpret and enforce the law in the same vein. The GDPR's predecessor, Directive 95/46/EC (''"DPD"''), was criticised for its fragmented enforcement of the right to data protection, which differed significantly from Member State to Member States, this was something that the GDPR sought to remedy by legislating for the consistent application of its provisions.
 
==== Cooperation ====
Under the DPD, there was limited cooperation between supervisory authorities, this too was something that the GDPR sought to remedy.<ref>''Boehm'' in Kühling, Buchner, Article 51 GDPR, margin number 14 (C.H. Beck 2020).</ref> Article 51(2) GDPR provides that SAs must cooperate with each other and the Commission, in accordance with Chapter VII of the GDPR. Cooperation is an essential element of SAs' obligations under the GDPR, it is seen as the primary tool for enabling the GDPR's consistent application. Cooperation is a notion which is embedded in the foundations of Union law, through Article 4(3) of the Treaty on the European Union ("''TEU''"), which imposes a general duty of sincere co-operation. Chapter VII provides rules on cooperation between SAs in cross-border cases, as well as for their participation in the consistency mechanism and the European Data Protection Board, affording SAs responsibilities on a national and European level.
 
When cooperation takes place with other 'independent' SAs, no conflict arises under treaty law for the purposes of Article&nbsp;8(3)&nbsp;CFR and Article&nbsp;16(2)&nbsp;TFEU. However, tensions may arise with the concept of 'independence' when SAs must cooperate with the European Commission, as the Commission is a political body. Consequently, cooperation with the Commission may undermine the independence demanded of SAs, as Article 8(3) CFR and Article&nbsp;16(2) TFEU require complete independence.
 
=== (3) More than one SA in a Member State ===
For the purposes of Article 51 GDPR, it is sufficient if a Member State provides for only one SA.<ref>''Ziebarth,'' in Sydow, Marsch, DS-GVO/BDSG, Article 51 GDPR, margin number 6 (Nomos 2022).</ref> However, several SAs may co-exist in the same Member State in accordance with Article 51(3) GDPR. Article 51(3) GDPR is particularly relevant for Member States with a federal constitutional structure. Germany, for example, consists of 16 Federal States (“''Bundesländer''”) each with its own SA. Currently the German SAs are represented by the German Federal SA ("BfDI"). Similarly, Spain appoints separate SAs for Catalonia and the Basque Country.
 
States may appoint multiple SAs in respect of their territorial division of competences or sectorial division of competences. For instance, a State may choose to appoint an SA responsible for controllers from the private sector and another for controllers from the public sector. Additionally, based on derogations concerning processing of data for journalistic purposes or the purpose of artistic and literary expression under [[Article 85 GDPR|Article 85(2) GDPR]],  some German states have established separate SAs for broadcasting companies. Furthermore, [[Article 91 GDPR|Article 91(2) GDPR]] allows for the establishment of separate SAs for religious groups. This provision has also been relied upon in Germany, where SAs are partly incorporated within the Catholic and Protestant churches.
 
Pursuant to Article 51(3) GDPR, Member States with several SAs must firstly designate which of these authorities represents the Member State in the EDPB,<ref>That implies that each member State can only send one representative to the EDPB, as reflected in the Rules of Procedure of the EDPB. See also, Article 4(3) of the EDPB Rules of Procedure (available [https://edpb.europa.eu/our-work-tools/our-documents/rules-procedure/rules-procedure-version-8_en here]).</ref> and secondly, should by law establish mechanisms for ensuring the effective participation of its SAs in the consistency mechanism. Member States with multiple SAs should designate which one is to function as representative, responsible for functioning as the contact point for other Member States' SAs, the Board and the Commission.<ref>See also [[Article 68 GDPR|Article 68(4) GDPR]].</ref>


=== (4) Notification to the Commission ===
=== (4) Notification to the Commission ===
Member States should notify the Commission of the measures adopted to create their SAs. Non compliance with the requirements of the GDPR relating to the establishment of an independent SA can lead to an infringement procedure under [https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A12008E258 Article 258 TFEU].  
Member States are obligated to notify the Commission of the measures adopted in the appointment of their SAs and of any subsequent changes to these measures. The duty to notify is of significance as non-compliance with GDPR requirements may give rise to the infringement procedure under [https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=celex%3A12008E258 Article 258 TFEU]. In the past infringement procedures before the CJEU were successfully brought by the Commission against Germany, Austria and Hungary with regard to the independence requirement. For more information consult commentary to [[Article  52 GDPR]].


==Decisions==
==Decisions==

Latest revision as of 14:24, 16 January 2024

Article 51 - Supervisory authority
Gdpricon.png
Chapter 10: Delegated and implementing acts

Legal Text


Article 51 - Supervisory authority

1. Each Member State shall provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation, in order to protect the fundamental rights and freedoms of natural persons in relation to processing and to facilitate the free flow of personal data within the Union (‘supervisory authority’).

2. Each supervisory authority shall contribute to the consistent application of this Regulation throughout the Union. For that purpose, the supervisory authorities shall cooperate with each other and the Commission in accordance with Chapter VII.

3. Where more than one supervisory authority is established in a Member State, that Member State shall designate the supervisory authority which is to represent those authorities in the Board and shall set out the mechanism to ensure compliance by the other authorities with the rules relating to the consistency mechanism referred to in Article 63.

4. Each Member State shall notify to the Commission the provisions of its law which it adopts pursuant to this Chapter, by 25 May 2018 and, without delay, any subsequent amendment affecting them.

Relevant Recitals

Recital 117: Establishment of Independent Supervisory Authorities
The establishment of supervisory authorities in Member States, empowered to perform their tasks and exercise their powers with complete independence, is an essential component of the protection of natural persons with regard to the processing of their personal data. Member States should be able to establish more than one supervisory authority, to reflect their constitutional, organisational and administrative structure.

Recital 118: Control and Monitoring of Supervisory Authorities
The independence of supervisory authorities should not mean that the supervisory authorities cannot be subject to control or monitoring mechanisms regarding their financial expenditure or to judicial review.

Recital 119: Participation in Consistency Mechanism in Case of Multiple Supervisory Authorities
Where a Member State establishes several supervisory authorities, it should establish by law mechanisms for ensuring the effective participation of those supervisory authorities in the consistency mechanism. That Member State should in particular designate the supervisory authority which functions as a single contact point for the effective participation of those authorities in the mechanism, to ensure swift and smooth cooperation with other supervisory authorities, the Board and the Commission.

Commentary

Chapter VI of the GDPR is dedicated to supervisory authorities ("SAs"). SA is defined in Article 4(21) GDPR as an independent public authority which is established by a Member State pursuant to Article 51 GDPR. Chapter VI is divided into two sections. The former regulates SAs' establishment (Articles 52-54 GDPR), staffing and other organizational requirements that the Member State must enforce to ensure their independent and proper functioning. While the latter defines the competences, tasks and powers of SAs (Articles 55-59 GDPR).

The GDPR provides for exceptions from provisions entailed in Chapter VI (independent supervisory authorities). Article 85(2) GDPR mandates Member States to, among others provide for exemptions or derogations from Chapter VI (independent supervisory authorities) when processing is carried out for journalistic purposes or the purpose of academic, artistic or literary expression, where necessary to reconcile the right to the protection of personal data with the freedom of expression and information.

Article 51 GDPR is the fundamental article governing the establishment of SAs and its duties providing a basis upon which other articles build upon. It is followed by articles that are laying down more detailed rules. Article 51 GDPR and the related articles provide the institutional framework for the enforcement of the data protection rules, one of the main objectives of the GDPR.[1] As noted in Recital 117 the effective and independent functioning of SAs constitutes an essential element of a data subject's fundamental right to data protection.

Closely connected articles

Article 51 GDPR is closely connected to Article 4(21) (definition of SA), Article 52 (independence), Article 53 (General conditions for the members of SA), Article 54 (Rules on the establishment of SA), Articles 55-59 (Competence, tasks and powers), Articles 60-62 (Cooperation), Articles 63-67 (Consistency) and Article 68-76 (European Data Protection Board).[2]

(1) Establishment of a supervisory authority (SA)

Establishment of SAs

Each Member State must appoint one or more supervisory authorities (SAs), which are to be independent public authorities. For more details see commentary to Article 51(3) GDPR bellow.

Independent

Article 8(3) of the Charter of Fundamental Rights of the European Union ("CFR") and Article 16(2) of the Treaty on the Functioning of the European Union ("TFEU") require the independence of SAs. Both Articles provide that compliance with data protection law must be subject to "control by an independent authority."[3] Independent supervisory authorities are also considered an essential component of the right to data protection under CJEU case law.[4] The independence of SAs was developed by CJEU case law and codified in Article 52 GDPR and subsequent articles. For further analysis on independence, refer to the Commentary on Article 52 GDPR.

Public

By definition, SAs must be public bodies (see Article 4(21) GDPR). Member States cannot outsource the enforcement of the GDPR to private entities.[5]

Monitoring the application

A SA's main task is to monitor the correct application of the GDPR. This aim should be understood in line with the wording used by Article 16(2) TFEU and Article 8(3) CFR, which provides that enforcement of the GDPR itself, is something that must be managed by "an independent authority."

In order to

Article 51(1) GDPR specifies that the role of SAs is twofold.[6] The first is to protect the fundamental rights and freedoms of individuals, and the second is to facilitate the free flow of personal data within the EU/EEA ("Union").

Protect the fundamental rights and freedoms of natural persons in relation to processing

Protecting the fundamental rights and freedoms of individuals includes monitoring the application of all elements of the GDPR, not only those relating to data subject rights, SAs' structure, tasks and powers serve this purpose.[7]

When monitoring and enforcing the GDPR SA must not only take into account the fundamental rights to privacy and data protection, but also other fundamental rights and freedoms, given that the right to data protection is not an absolute right.[8] For instance the fundamental rights to data protection (Article 8 CFR) and privacy (Article 7 CFR) must be weighed up against the fundamental rights freedom of expression (Article 11 CFR) and right to property (Article 17 CFR). Also, other laws and regulations are not outside of the SAs' jurisdiction, as to correctly apply the GDPR, SA's must regularly determine provisions of the GDPR while taking into account other laws.

Example: A SA must determine the necessity of processing personal data under applicable tax laws. In this instance, record keeping requirements under other laws become applicable for the purposes of Article 5(1)(e) GDPR when determining the duration for which data must be stored. Any such laws would also be relevant for determining whether the processing is necessary for complying with a legal obligation to which the controller is subject, under Article 6(1)(c) GDPR.

Facilitate the free flow of personal data within the Union

In line with the general objectives of the GDPR, as outlined in Article 1 GDPR Article 16 TFEU, SAs are also required to take into account the requirements of the free flow of personal data within the EU/EEA ("Union"). This requirement necessitates that SAs in the exercise of their powers, may not impose measures that have the capacity to impair or prevent the free flow of data within the EU/EEA.[9]

The aim of this provision should not be understood as an attempt to place the fundamental right to data protection on equal footing with the free flow of personal data within the common market. Instead, the provision should be understood more as an aim to prevent the implementation of national measures relating to data protection, in a manner that would negatively affect the free flow of personal data. Nevertheless, given that the right to data protection is not an absolute right, it is inevitably weighed up against the free flow of personal data through this provision. Also, after the entry into force of the Lisbon Treaty, "the centre of gravity in data protection is no longer the free flow of data but rather the protection of fundamental rights."[10] This shift is reflective of a wider trend in the CJEU's case law, in which fundamental rights have begun to take a more dominant position.

However, some Commentators have taken a different reading of Article 51(1) GDPR's reconciliation of the right to data protection and the free flow of data within the internal market. In their opinion this provision should be read as establishing a dual objective, in which one aim should not take priority over the other. The right to data protection and the right to free flow of personal data should be taken into account to the same extend and balanced equally.[11]

(2) Consistent application of the GDPR

Shall

The use of the imperative "shall" imposes a positive legal obligation upon SAs to facilitate the consistent application of the GDPR throughout the EU/EEA.[12]

Contribute

The use of the verb “contribute” denotes a form of proactive participation specifically aimed at the “consistent monitoring and enforcement of this Regulation” and, according to Recital 135, the uniform application of the law. Accordingly, SAs are required to identify any problems and act for their prompt resolution. For example, prompt action for resolution could be necessary in case of inactivity of a SA or lead supervisory authority in transnational cases, where cooperation and assistance between SAs is required.

Consistent application

The use of the term "consistent application" mandates that the application and interpretation of GDPR provisions should not differ between Member States' respective SAs, as well as where applicable, between the multiple SAs within a Member State (for further analysis on this point, see Article 51(3) GDPR below). All SAs should have the same understanding of GDPR provisions and interpret and enforce the law in the same vein. The GDPR's predecessor, Directive 95/46/EC ("DPD"), was criticised for its fragmented enforcement of the right to data protection, which differed significantly from Member State to Member States, this was something that the GDPR sought to remedy by legislating for the consistent application of its provisions.

Cooperation

Under the DPD, there was limited cooperation between supervisory authorities, this too was something that the GDPR sought to remedy.[13] Article 51(2) GDPR provides that SAs must cooperate with each other and the Commission, in accordance with Chapter VII of the GDPR. Cooperation is an essential element of SAs' obligations under the GDPR, it is seen as the primary tool for enabling the GDPR's consistent application. Cooperation is a notion which is embedded in the foundations of Union law, through Article 4(3) of the Treaty on the European Union ("TEU"), which imposes a general duty of sincere co-operation. Chapter VII provides rules on cooperation between SAs in cross-border cases, as well as for their participation in the consistency mechanism and the European Data Protection Board, affording SAs responsibilities on a national and European level.

When cooperation takes place with other 'independent' SAs, no conflict arises under treaty law for the purposes of Article 8(3) CFR and Article 16(2) TFEU. However, tensions may arise with the concept of 'independence' when SAs must cooperate with the European Commission, as the Commission is a political body. Consequently, cooperation with the Commission may undermine the independence demanded of SAs, as Article 8(3) CFR and Article 16(2) TFEU require complete independence.

(3) More than one SA in a Member State

For the purposes of Article 51 GDPR, it is sufficient if a Member State provides for only one SA.[14] However, several SAs may co-exist in the same Member State in accordance with Article 51(3) GDPR. Article 51(3) GDPR is particularly relevant for Member States with a federal constitutional structure. Germany, for example, consists of 16 Federal States (“Bundesländer”) each with its own SA. Currently the German SAs are represented by the German Federal SA ("BfDI"). Similarly, Spain appoints separate SAs for Catalonia and the Basque Country.

States may appoint multiple SAs in respect of their territorial division of competences or sectorial division of competences. For instance, a State may choose to appoint an SA responsible for controllers from the private sector and another for controllers from the public sector. Additionally, based on derogations concerning processing of data for journalistic purposes or the purpose of artistic and literary expression under Article 85(2) GDPR, some German states have established separate SAs for broadcasting companies. Furthermore, Article 91(2) GDPR allows for the establishment of separate SAs for religious groups. This provision has also been relied upon in Germany, where SAs are partly incorporated within the Catholic and Protestant churches.

Pursuant to Article 51(3) GDPR, Member States with several SAs must firstly designate which of these authorities represents the Member State in the EDPB,[15] and secondly, should by law establish mechanisms for ensuring the effective participation of its SAs in the consistency mechanism. Member States with multiple SAs should designate which one is to function as representative, responsible for functioning as the contact point for other Member States' SAs, the Board and the Commission.[16]

(4) Notification to the Commission

Member States are obligated to notify the Commission of the measures adopted in the appointment of their SAs and of any subsequent changes to these measures. The duty to notify is of significance as non-compliance with GDPR requirements may give rise to the infringement procedure under Article 258 TFEU. In the past infringement procedures before the CJEU were successfully brought by the Commission against Germany, Austria and Hungary with regard to the independence requirement. For more information consult commentary to Article 52 GDPR.

Decisions

→ You can find all related decisions in Category:Article 51 GDPR

References

  1. A comprehensive approach on personal data protection in the European Union', Communication from the Commission to the European Parliament, the Council, the Economic and Social Committee and the Committee of the Regions, (2010) COM(2010) 609 final (available here).
  2. Hijmans, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 51 GDPR, p. 867 (Oxford University Press 2020).
  3. For further analysis on independence, refer to the Commentary onArticle 52 GDPR.
  4. Hijmans, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 51 GDPR, p. 864-868 (Oxford University Press 2020).
  5. Ziebarth, in Sydow, Marsch DS-GVO/BDSG, Article 51 GDPR, margin number 8 (Nomos 2022).
  6. Schneider, in BeckOK DatenschutzR, Article 51 GDPR, margin number 6 (Beck 2020, 38th edition).
  7. Ziebarth, in Sydow, Marsch DS-GVO/BDSG, Article 51 GDPR, margin number 19 (Nomos 2022).
  8. Boehm, in Kühling, Buchner, DS-GVO BDSG, Article 51 GDPR, margin number 13 (C.H. Beck 2020, 3rd Edition)..
  9. Ziebarth, in Sydow, Marsch DS-GVO/BDSG, Article 51 GDPR, margin number 20 (Nomos 2022); see also Kühling, Buchner, Boehm, DS-GVO, Article 51 GDPR, margin number 13 (C.H. Beck 2020).
  10. Hijmans, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 51 GDPR, p. 868 (Oxford University Press 2020).
  11. Boehm in Kühling, Buchner, Article 51 GDPR, margin numbers 12 and 13 (C.H. Beck 2020).
  12. This is an additional obligation to the primary one linked to the application of the GDPR on the territory of one's own Member State, reflecting a certain “Europeanisation” of the action of independent authorities. See, Hijmans, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 51 GDPR, p. 869 (Oxford University Press 2020).
  13. Boehm in Kühling, Buchner, Article 51 GDPR, margin number 14 (C.H. Beck 2020).
  14. Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 51 GDPR, margin number 6 (Nomos 2022).
  15. That implies that each member State can only send one representative to the EDPB, as reflected in the Rules of Procedure of the EDPB. See also, Article 4(3) of the EDPB Rules of Procedure (available here).
  16. See also Article 68(4) GDPR.