Article 27 GDPR: Difference between revisions
m (→Commentary) |
|||
Line 205: | Line 205: | ||
==Commentary== | ==Commentary== | ||
The aim of Article 27 GDPR is to ensure that the level of protection afforded to EU-based data subjects is not reduced where non-EU based controllers or processors process their data. It aims to both | The aim of Article 27 GDPR is to ensure that the level of protection afforded to EU-based data subjects is not reduced where non-EU based controllers or processors process their data. It aims to both, providing a contact point for data subjects and ensuring that there is legal accountability for processing activities by mandating the appointment of a representative. This representative can be subject to enforcement proceedings in the event of non-compliance with the GDPR. Article 27 GDPR also helps to clarify the scope of obligations placed on controllers and processors based outside of the EU. | ||
EDPB Guidelines: for this Article see EDPB, 'Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)', 12 November 2019 (Version 2.1), (available [https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32018-territorial-scope-gdpr-article-3-version_en here]). | |||
===(1) Conditions for applicability=== | ===(1) Conditions for applicability=== | ||
Where [[Article 3 GDPR|Article 3(2) GDPR]] applies,<ref>Article 3(2) GDPR can be divided into two requirements: first, there must be processing by a controller or processor who is not established in the Union, and second, the processing activities must relate either to the offering of goods or services, or to the monitoring of the behaviour of the data subjects within the Union.</ref> the controller or processor must designate a representative in the Union.<ref>If a “''controller or processor not established in the Union but subject to the GDPR fails to designate a representative in the Union it would therefore be in breach of the Regulation''”. See EDPB, ‘Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)’, 12 November 2019 (Version 2.1), p. 23 (available [https://edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_3_2018_territorial_scope_after_public_consultation_en_1.pdf here]).</ref> In practice, the function of | |||
==== Where Article 3(2) applies ==== | |||
In case the territorial scope of [[Article 3 GDPR|Article 3(2) GDPR]] applies to a controller or processor not established in the Union (due to the processing of personal data of data subjects in the Union related to either the offering of goods or services to such data subjects or the monitoring of their behaviour in the Union),<ref>Article 3(2) GDPR can be divided into two requirements: first, there must be processing by a controller or processor who is not established in the Union, and second, the processing activities must relate either to the offering of goods or services, or to the monitoring of the behaviour of the data subjects within the Union.</ref> the controller or processor must designate a ''representative'' in the Union.<ref>If a “''controller or processor not established in the Union but subject to the GDPR fails to designate a representative in the Union it would therefore be in breach of the Regulation''”. See EDPB, ‘Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)’, 12 November 2019 (Version 2.1), p. 23 (available [https://edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_3_2018_territorial_scope_after_public_consultation_en_1.pdf here]).</ref> | |||
{{Quote-EDPB|"Data controllers or processors subject to the GDPR as per its Article 3(2) are under the obligation to designate a representative in the Union. A controller or processor not established in the Union but subject to the GDPR failing to designate a representative in the Union would therefore be in breach of the Regulation."|EDPB, 'Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)', 12 November 2019 (Version 2.1), page 23.|4=https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32018-territorial-scope-gdpr-article-3-version_en}} | |||
==== The controller or processor shall designate in writing ==== | |||
The obligation to designate a representative in the Union is directed at controllers and processors established outside of the union but performing some kind of processing targeting data subject in the Union (i.e. falling under [[Article 3 GDPR|Article 3(2) GDPR]]). The designation of the representative must be done in writing. This is necessary to guarantee the authenticity of the mandate and to ensure a certain tangibility of the parties involved. Qualified electronic signature or other equivalent method would also be admissible. However, this agreement could not be concluded by email.<ref>''Martini'', in Paal, Pauly, DS-GVO BDSG, Article 27, margin numbers 17-20 (C.H.Beck 2021, 3rd Edition).</ref> | |||
In practice, the function of ''representative in the Union'' can be exercised based on a contract concluded between the controller or processor and an individual or an organization, provided that the individual or organization is established in the Union. The role can be assumed by a wide range of commercial and non-commercial entities, such as law firms, consultancies, or private companies.''<ref>''Gola'', in Gola, Heckmann, DS-GVO, Article 4 GDPR, margin number 131 (C.H. Beck 2022).</ref>'' However, according to the EDPB, the role should not overlap with the DPO’s given its requirement for independence.<ref>EDPB, ‘Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)’, 12 November 2019 (Version 2.1), p. 24 (available [https://edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_3_2018_territorial_scope_after_public_consultation_en_1.pdf here]).</ref> | |||
==== Representative in the Union ==== | |||
A representative is defined in [[Article 4 GDPR|Article 4(17) GDPR]] as a "a natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27, represents the controller or processor with regard to their respective obligations under this Regulation". See commentary on [[Article 4 GDPR|Article 4(17) GDPR]] for more information on the representative. | |||
The GDPR does not specify any particular requirements for the representative.<ref>Though the Article does little to elaborate on the nature of this requirement, such as what the consequences are if this requirement is breached, it is one step towards establishing accountability for non-EU based actors who process data. Indeed, this is what ''Millard'' and ''Kamarinou'' have labeled as enhancing the “''practical-procedural traction of the GDPR''”. See, ''Millard, Kamarinou'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 27 GDPR, pp. 595-596 (Oxford University Press 2020).</ref> However, under Article 1(17) GDPR, the representative must be capable of representing the controller or processor "''with regard to their obligations under this Regulation''".<ref>''Millard, Kamarinou'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 27 GDPR, pp. 595-596 (Oxford University Press 2020).</ref> The designation of a representative does not exclude the responsibility or liability of the controller or processor themselves.<ref>Recital 80 sentence 5 GDPR.</ref> However, it remains unclear how entities not providing a representative may be tackled by the GDPR.<ref>''Ziebarth'', in Sydow, Europäische Datenschutzgrundverordnung, Article 4 GDPR, margin number 204 (Nomos 2018).</ref> This goes especially for public authorities that are excluded from the designation of a representative.''<ref>''Klabunde'', in Ehmann, Selmayr, DS-GVO, Article 4 GDPR, margin number 52 (C.H. Beck 2017).</ref>'' | |||
===(2) Exemptions=== | ===(2) Exemptions=== | ||
The requirement to designate a representative is not absolute. Article 27(2) GDPR presents two instances in which the requirement to have a representative does not apply. These are (a) when the processing is occasional, does not include data covered by [[Article 9 GDPR]] or [[Article 10 GDPR]], and is unlikely to result in a risk to the rights and freedoms of natural persons, and (b) when the processing is done by a public authority or body. | The requirement to designate a representative is not absolute. Article 27(2) GDPR presents two instances in which the requirement to have a representative does not apply. These are (a) when the processing is occasional, does not include data covered by [[Article 9 GDPR]] or [[Article 10 GDPR]], and is unlikely to result in a risk to the rights and freedoms of natural persons, and (b) when the processing is done by a public authority or body. |
Revision as of 11:01, 14 November 2024
Legal Text
1. Where Article 3(2) applies, the controller or the processor shall designate in writing a representative in the Union.
2. The obligation laid down in paragraph 1 of this Article shall not apply to:
- (a) processing which is occasional, does not include, on a large scale, processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10, and is unlikely to result in a risk to the rights and freedoms of natural persons, taking into account the nature, context, scope and purposes of the processing; or
- (b) a public authority or body.
3. The representative shall be established in one of the Member States where the data subjects, whose personal data are processed in relation to the offering of goods or services to them, or whose behaviour is monitored, are.
4. The representative shall be mandated by the controller or processor to be addressed in addition to or instead of the controller or the processor by, in particular, supervisory authorities and data subjects, on all issues related to processing, for the purposes of ensuring compliance with this Regulation.
5. The designation of a representative by the controller or processor shall be without prejudice to legal actions which could be initiated against the controller or the processor themselves.
Relevant Recitals
Commentary
The aim of Article 27 GDPR is to ensure that the level of protection afforded to EU-based data subjects is not reduced where non-EU based controllers or processors process their data. It aims to both, providing a contact point for data subjects and ensuring that there is legal accountability for processing activities by mandating the appointment of a representative. This representative can be subject to enforcement proceedings in the event of non-compliance with the GDPR. Article 27 GDPR also helps to clarify the scope of obligations placed on controllers and processors based outside of the EU.
EDPB Guidelines: for this Article see EDPB, 'Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)', 12 November 2019 (Version 2.1), (available here).
(1) Conditions for applicability
Where Article 3(2) applies
In case the territorial scope of Article 3(2) GDPR applies to a controller or processor not established in the Union (due to the processing of personal data of data subjects in the Union related to either the offering of goods or services to such data subjects or the monitoring of their behaviour in the Union),[1] the controller or processor must designate a representative in the Union.[2]
"Data controllers or processors subject to the GDPR as per its Article 3(2) are under the obligation to designate a representative in the Union. A controller or processor not established in the Union but subject to the GDPR failing to designate a representative in the Union would therefore be in breach of the Regulation."
The controller or processor shall designate in writing
The obligation to designate a representative in the Union is directed at controllers and processors established outside of the union but performing some kind of processing targeting data subject in the Union (i.e. falling under Article 3(2) GDPR). The designation of the representative must be done in writing. This is necessary to guarantee the authenticity of the mandate and to ensure a certain tangibility of the parties involved. Qualified electronic signature or other equivalent method would also be admissible. However, this agreement could not be concluded by email.[3] In practice, the function of representative in the Union can be exercised based on a contract concluded between the controller or processor and an individual or an organization, provided that the individual or organization is established in the Union. The role can be assumed by a wide range of commercial and non-commercial entities, such as law firms, consultancies, or private companies.[4] However, according to the EDPB, the role should not overlap with the DPO’s given its requirement for independence.[5]
Representative in the Union
A representative is defined in Article 4(17) GDPR as a "a natural or legal person established in the Union who, designated by the controller or processor in writing pursuant to Article 27, represents the controller or processor with regard to their respective obligations under this Regulation". See commentary on Article 4(17) GDPR for more information on the representative. The GDPR does not specify any particular requirements for the representative.[6] However, under Article 1(17) GDPR, the representative must be capable of representing the controller or processor "with regard to their obligations under this Regulation".[7] The designation of a representative does not exclude the responsibility or liability of the controller or processor themselves.[8] However, it remains unclear how entities not providing a representative may be tackled by the GDPR.[9] This goes especially for public authorities that are excluded from the designation of a representative.[10]
(2) Exemptions
The requirement to designate a representative is not absolute. Article 27(2) GDPR presents two instances in which the requirement to have a representative does not apply. These are (a) when the processing is occasional, does not include data covered by Article 9 GDPR or Article 10 GDPR, and is unlikely to result in a risk to the rights and freedoms of natural persons, and (b) when the processing is done by a public authority or body.
(a) Processing Which is Occasional and Does Not Include Data in the Sense of Articles 9 and 10 GDPR
Article 27(2)(a) GDPR states that the requirement to designate a representative does not apply if the processing meets three cumulative conditions. First, the processing must be "occasional". Second, it must not include "processing of special categories of data as referred to in Article 9(1) or processing of personal data relating to criminal convictions and offences referred to in Article 10" on a large scale. Third, the processing must be "unlikely to result in a risk to the rights and freedoms of natural persons".
The term "occasional" has been interpreted by the WP29 to mean processing that is not carried out regularly and that falls outside of the scope of the regular activities of the controller or processor.[11] Similarly, Millard and Kamarinou have interpreted the term "occasional" to mean "non-systematic" processing, or in other words, processing that happens on an ad hoc and infrequent basis and not in a regular way.[12]
The second condition requires that the processing does not use the categories of data covered by Articles 9 and 10 GDPR on a “large scale”. What meaning should be assigned to the expression “large scale” is not entirely clear.[13] According to Recital 91, it should concern "a considerable amount of personal data [...] which could affect a large number of data subjects".
Finally, the third requirement specifies that the processing must be “unlikely to result in a risk to the rights and freedoms of a natural person”. Recital 75 GDPR sets out that when the risk to the rights and freedom of data subjects is being assessed, special consideration should be given to both its likelihood and severity. This includes, inter alia, risks of discrimination, identity theft or fraud, financial loss, damage to the reputation, loss of confidentiality of personal data protected by professional secrecy, unauthorised reversal of pseudonymisation, or any other significant economic or social disadvantage.
The unifying factor of these three conditions is the existence of processing which is in some way 'non-negligible' because of its scale, the data processed, or its possible negative consequences. In all the other cases, an EU representative must be appointed and the exemption in Article 27(1)(a) GDPR cannot apply.
(b) Processing carried out by a public authority or body
The second exemption to the requirement to designate a representative applies if the non-EU controller or processor is a public authority or body. It is up for the supervisory authority to assess on a case-by-case basis what constitutes a public authority or body. However, instances in which a public authority or body in a third country would be monitoring the behaviour of data subjects in the Union, or offering them goods or services, are likely to be limited.
(3) Place of establishment of the representative
Article 27(3) GDPR states that the representative of the controller or processor shall be established in one of the Member States where the data subjects are located. The EDPB has recommended that “where a significant proportion of data subjects whose personal data are processed are located in one particular Member State […] the representative is established in that same Member State”. The main criterion for establishing where a representative should be designated is the location of the data subjects who are subject to the processing.[14] One way to interpret this is in the event that there are two member states in which processing takes place, the country which has more data subjects who are subject to the processing should be the country in which the representative is established.
(4) Obligations and responsibilities of the representative
Under Article 27(4) GDPR, data subjects and supervisory authorities can address the representative on "all issues related to processing" in order to ensure compliance with the Regulation. This can be done "in addition to or instead of" addressing the controller or processor themselves.
The main role of the representative is to serve as a point of contact and be readily available for supervisory authorities and data subjects regarding data protection matters, as stated in Article 27(4). This includes providing relevant information, addressing inquiries,[15] and handling documents. To fulfill these responsibilities effectively, the representative may enlist the support of a team and ensure effective communication in the appropriate languages.[16]
Under Article 30 GDPR the representative of the controller or processor must maintain a record of the processing activities performed by the controller or processor. However, the controller or processor themselves are responsible for updating the content of the record, and must provide the representative with up-to-date information. At the same time, the representative must be ready to share this record.[17]
Finally, as clarified by Recital 80 GDPR, the representative should also perform its tasks according to the mandate received from the controller or processor, including cooperating with the supervisory authorities regarding any action that may need to be taken in order to comply with the GDPR (Article 31 GDPR). Direct liability of the representative is limited to the obligations set out in Article 30 and Article 58(1)(a) GDPR.[18]
(5) Continued liability
Article 27(5) GDPR makes it very clear that the controller or processor cannot escape legal liability by designating a representative. Indeed, it states that legal action can be initiated directly against the controller or processor. This notably happened in a case before the Austrian DPA, in which it chose to address a decision directly to a US company instead of its representative in the Netherlands, because “Article 27(5) GDPR does not entail a transfer of responsibility”.[19]
Decisions
→ You can find all related decisions in Category:Article 27 GDPR
References
- ↑ Article 3(2) GDPR can be divided into two requirements: first, there must be processing by a controller or processor who is not established in the Union, and second, the processing activities must relate either to the offering of goods or services, or to the monitoring of the behaviour of the data subjects within the Union.
- ↑ If a “controller or processor not established in the Union but subject to the GDPR fails to designate a representative in the Union it would therefore be in breach of the Regulation”. See EDPB, ‘Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)’, 12 November 2019 (Version 2.1), p. 23 (available here).
- ↑ Martini, in Paal, Pauly, DS-GVO BDSG, Article 27, margin numbers 17-20 (C.H.Beck 2021, 3rd Edition).
- ↑ Gola, in Gola, Heckmann, DS-GVO, Article 4 GDPR, margin number 131 (C.H. Beck 2022).
- ↑ EDPB, ‘Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)’, 12 November 2019 (Version 2.1), p. 24 (available here).
- ↑ Though the Article does little to elaborate on the nature of this requirement, such as what the consequences are if this requirement is breached, it is one step towards establishing accountability for non-EU based actors who process data. Indeed, this is what Millard and Kamarinou have labeled as enhancing the “practical-procedural traction of the GDPR”. See, Millard, Kamarinou, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 27 GDPR, pp. 595-596 (Oxford University Press 2020).
- ↑ Millard, Kamarinou, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 27 GDPR, pp. 595-596 (Oxford University Press 2020).
- ↑ Recital 80 sentence 5 GDPR.
- ↑ Ziebarth, in Sydow, Europäische Datenschutzgrundverordnung, Article 4 GDPR, margin number 204 (Nomos 2018).
- ↑ Klabunde, in Ehmann, Selmayr, DS-GVO, Article 4 GDPR, margin number 52 (C.H. Beck 2017).
- ↑ WP29, ‘Position paper on the derogations from the obligation to maintain records of processing activities pursuant to Article 30(5) GDPR’, p. 2 (available here). This position paper has been endorsed by the EDPB on 19 April 2018.
- ↑ Millard, Kamarinou, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 27 GDPR, p. 595 (Oxford University Press 2020).
- ↑ Hartnung, in Kühling, Buchner, DS-GVO BDSG, Article 27 GDPR, margin numbers 9 (C.H. Beck 2020, 3rd Edition).
- ↑ EDPB, ‘Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)’, 12 November 2019 (Version 2.1), p. 26 (available here).
- ↑ The obligation includes the handling of data subjects' requests. While not directly responsible for complying with data subject rights, the representative must facilitate the communication between data subjects and the controller or processor represented, in order to make the exercise of data subject rights effective. Martini, in Paal, Pauly, DS-GVO BDSG, Article 27, margin number 52 (C.H.Beck 2021, 3rd Edition).
- ↑ Hartung, in Kühling, Buchner, DS-GVO BDSG, Article 27 GDPR, margin numbers 15 (C.H. Beck 2020, 3rd Edition).
- ↑ Hartung, in Kühling, Buchner, DS-GVO BDSG, Article 27 GDPR, margin numbers 16 (C.H. Beck 2020, 3rd Edition).
- ↑ EDPB, ‘Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)’, 12 November 2019 (Version 2.1), p. 27-28 (available here).
- ↑ Datenschutzbehörde, 7 March 2019, DSB-D130.033/0003-DSB/2019 (available here).