Article 52 GDPR
Legal Text
Article 52 - Independence
1. Each supervisory authority shall act with complete independence in performing its tasks and exercising its powers in accordance with this Regulation.
2. The member or members of each supervisory authority shall, in the performance of their tasks and exercise of their powers in accordance with this Regulation, remain free from external influence, whether direct or indirect, and shall neither seek nor take instructions from anybody.
3. Member or members of each supervisory authority shall refrain from any action incompatible with their duties and shall not, during their term of office, engage in any incompatible occupation, whether gainful or not.
4. Each Member State shall ensure that each supervisory authority is provided with the human, technical and financial resources, premises and infrastructure necessary for the effective performance of its tasks and exercise of its powers, including those to be carried out in the context of mutual assistance, cooperation and participation in the Board.
5. Each Member State shall ensure that each supervisory authority chooses and has its own staff which shall be subject to the exclusive direction of the member or members of the supervisory authority concerned.
6. Each Member State shall ensure that each supervisory authority is subject to financial control which does not affect its independence and that it has separate, public annual budgets, which may be part of the overall state or national budget.
Relevant Recitals
Commentary
Article 8(3) CFR as well as Article 16(2) TFEU and Article 39 TEU require independent authorities (SA) to monitor and enforce the application of data protection law.[1] Article 52 GDPR specifies the elements of such independence, making it clear that the authority and its members must exercise their functions without any external influence and without any conflict of interest. In order to make these principles operational, the provision requires member states to provide the SA with adequate financial and organisational means for this purpose.
(1) Complete Independence of supervisory authorities (SAs)
Under Article 52(1) GDPR, each SA shall act with complete independence in performing its tasks and exercising its powers.
Each SA
Member States can establish one or several SAs for monitoring the implementation of the GDPR (Article 51 GDPR). Article 52(1) GDPR clarifies that "each" of them must act with complete independence.[2]
Shall act
SA must ("shall") act with complete independence when performing its tasks and exercising its powers. This condition necessitates Member States, SAs and each of their members and staff to ensure that SAs and its members act in complete independence when conducting investigations or making decisions.
Complete independence
In order to be “complete”, independence must be achieved in several ways. Evidently, the SA must be independent with respect to the entities, controllers or processors, over which it is required to exercise control. However, independence also applies to any other entity that may exercise any kind of direct or indirect control over the decision-making capacity of the SA, including the Commission.[3] To give an example, while Member States are free (within the parameters of the GDPR) to adopt or amend the institutional model that they consider to be the most appropriate for their supervisory authorities, “in order to comply with the requirement of ‘complete independence’, the supervisory authority must be placed outside the classic hierarchical administration”.[4] Nevertheless, even complete independence has limits. For example, it does not exclude that the appointment of SA members is made by political bodies such as the parliament or the government (Article 53(1) GDPR) or that their actions (including their inactivity) may be subject to judicial review (Article 78 GDPR).
Performing tasks
One of the tasks of each SA is handling of complaints of data subjects and cooperate with other SAs under the consistency mechanism (cross border cases). Tasks of SAs are laid down in Article 57 GDPR. For more information, see commentary on Article 57 GDPR.
Exercising powers
The powers of SAs include several investigative and corrective powers, such as conducting on premises investigations, ordering the controller and its representatives to provide any information the SA requires for handling a case, ordering a processor to stop processing data subject's personal data administer fines for infringements of GDPR. The powers of SAs are set out in Article 58 GDPR. For more information, please refer to Article 58 GDPR.
(2) Freedom from External Influence
Article 52(2) GDPR addresses the members of the SA during the performance of their duties. On the one hand, it requires them to remain free from external influences, whether direct or indirect, and on the other hand, it prohibits them from seeking or taking instructions from anyone.
Member(s) of SAs
Members of SAs are the carriers of the principle of independence of SAs. Members are the lead personnel appointed in accordance with Article 53(1) GDPR.[5] In addition to at least one member, every SA also has own staff. The concept of independence does not apply to staff. They must follow instructions of members of the SAs but must remain independent from any influence from outside of the SA (see Article 52(4) GDPR below).[6]
Remain free from external influence
The provision should be read in the light of the case law of the CJEU. In particular, in Commission vs. Germany, the Court decided that Germany did not correctly respect such standard (Article 28(1) of Directive 95/46) considering that the SAs competent for the private sector were subject to governmental supervision, and state scrutiny. That allowed the government to influence, directly or indirectly, the decisions of the SAs, and even to cancel or replace these decisions. The Court specified that the notion of “complete independence” in Article 28 DPD must be given a broad and autonomous interpretation, and aligned on the Article 44 of Regulation 45/2001. Likewise, in Commission vs. Austria, the Court held that Austria failed to comply with Article 28 DPD by allowing an influence of the government on the SA for the following reasons. The managing member of the SA was an officer working for the Federal Chancellor office and under direct supervision of the Chancellor, the office of the SA was integrated within the department of the Federal Chancellery, and the Chancellor had the right to be informed on all aspects of the work of the SA. Finally, in 2014, in Commission vs. Hungary, the Court found that the complete independence of the SA was not guaranteed due to the possibility of prematurely terminating the mandate of the Commissioner.
In conclusion, the SAs must be able to act objectively and impartially and free from any influence that might influence their decision-making process, tasks and powers.
Direct influence
Direct influence refers to instructions given to a SA, on whatever aspect of its work. This means that instructions to SAs regarding service or performance related aspects are prohibited, as well as instructions regarding issues of legality. It is not necessary that instructions were given. The mere possibility to exercise a political influence over their decisions is enough to conclude to the absence of independence of the SA. Only courts may scrutinize the work of SAs.[7]
Indirect influence
Indirect influence, on the other hand, occurs whenever the SA’s actions may be affected by external factors, which could motivate members of SAs act in a certain manner out of their “own free” will. In the Court’s view, this generates a form of ‘prior compliance’ which is incompatible with the free and independent exercise of its functions.
Given these conditions, the question arises as to what is, or rather what should be, the scale of national legislative intervention to ensure effective independence during the term of office. The problem is particularly pressing where certain professional categories are concerned, such as legal advisers in the private sector. In this case, too, a form of prior compliance can be envisaged, not so much with respect to political or governmental bodies, but rather with respect to positions taken previously, or to the risk that certain ‘unpopular’ decisions may reduce the number of job opportunities after the end of the mandate. In this sense, one possible solution might be to provide the SA’s appointed members with a medium to long-term financial emolument that would allow them to free themselves from reductive calculations on their professional future.
Not seek nor take
- Limits: Cooperation Article 60 GDPR, Consistency mechanism Article 63 ff.
Take
- passively
Performance of tasks and exercise of its powers
Tasks and powers of SAs include among others monitoring and enforcing the application of the GDPR, promotion of public awareness, handling of complaints lodged by data subjects, carrying out investigations in the form of data protection audits and issuing of warnings, reprimsnds and fines to controllers and processors.
For more information on the tasks and powers of SAs, see Article 57 GDPR, which sets out the tasks, and Article 58 GDPR, which entails the powers of SAs.
Instructions
(3) Prohibition Against Incompatible Actions
Under Article 52(3) GDPR, members of each SA shall refrain from any action incompatible with their duties and shall not, during their term of office, engage in any incompatible occupation, whether gainful or not. The provision lists neither the actions nor the occupations that are supposed to be incompatible with a function within the SA. However, Article 54(1)(f) GDPR requires the Member States to regulate the matter in their national legislation.
Incompatible Action
Given that, as mentioned above, the matter of which action or activity is incompatible must be defined by the individual Member States, it is possible to outline some examples of actions which can be said to be certainly incompatible with the function of an SA member. The receipt of gifts, whether tangible or intangible, promises or any other form of benefit is certainly incompatible. At the same time, and to the extent possible, SA members should avoid frequent private contact with potential counterparties or representatives of controllers or processors, at least those against whom investigations are being conducted.
Incompatible Activity
In the case of activities, the wording of Article 52(3) GDPR makes no difference whether these are professional, part-time, or voluntary. The decisive factor is whether the respective activity is “incompatible” with the office. This is meant to avoid the evil appearance of reduced independence and neutrality, comparable to the rules on bias. This is to be judged according to a prognostic scale. Therefore, there will be an incompatibility if the activity may lead to conflicts of interest with the independent exercise of office and influence on the office, whether in an economic, political or other way. Typically, incompatible conduct is, for example, accepting a position within a company that can be scrutinised by the DPA. Same goes for paid or unpaid legal advice unless the client is located outside the SA’s own jurisdiction. However, even in these cases, it must be examined whether there can be a connection to one’s own official business. The latter may be the case, for example, if it is the establishment or processor of a body to be controlled in its own jurisdiction. When carrying out activities as a tax consultant or lawyer, it must be analyzed, especially regarding the mandate and the task to be assigned, whether collisions with supervisory tasks can occur. However, at least in principle, such freelance activities are not incompatible with the office.[8]
(4) Sufficient Resources
To be efficient, and carry out their tasks, the SAs should receive the financial, organisational, technical and human resources necessary to deal with their multiple tasks, and use their powers. These tasks include the participation in the cooperation and consistency mechanisms. Data protection law at a high level and an independent supervisory authority with numerous powers are pointless if this authority cannot carry out its tasks or can only do so ineffectively because it lacks the necessary staff, technical equipment, financial and other resources.[9]
Example: If considering its resources a SA can carry out a control of each controller and processor in its area of responsibility only every 45.000 years the conditions of this provision are not met.[10]
Article 52(4) GDPR and Article 52(6) GDPR specify the elements of material independence of SAs. Part of its material independence is autonomy in relation to the allocation and disposal of resources within the allocated budget.[11]
Shall ensure
Thus member states are under the obligation (“shall ensure”) that each SA is provided with the resources, premises and infrastructure necessary for the effective performance of its tasks. Additionally adequacy of resources should be periodically reviewed.[12]
Human resources
Human resources relate, on the one hand, to the necessary level of staff and, on the other hand, to the presence of qualified personnel to carry out the tasks and exercise of powers. This requires above all employees with a training background in the fields of law and computer science, including communication technology. Within the framework of the applicable salary structures, it must be ensured that the remuneration is designed in such a way that high-quality employees can be recruited in competition with the private sector.[13] The structure of staff should enable the SAs to take prompt and effective action.[14]
Technical resources
Technical resources are aimed at an appropriate equipment with hardware and software in order to be able to carry out the transferred official business. The supervisory authorities must be at the cutting edge of information and communication technology in order to be able to carry out their monitoring tasks.[15]
Financial resources
Financial resources consist of the budget needed for the stable functioning of the SA as well as resources for unforeseen tasks. This includes, for example, funds for travel expenses, also for participation in further education and training, for the implementation of conferences and workshops, for obtaining external expertise in difficult legal issues or in legal representation or for the short-term reinforcement of staff coverage in the event of special workload.[16] Also, sufficient financial resources must be provided for the costs of necessary human and technical resources, the premises and the infrastructure.
Sufficient financial resources are very important for uninfluenced and impartial monitoring and decision making of SAs. Otherwise, there is a risk that SAs may be more lenient, look for amicable solutions and refrain from imposing heavy fines to avoid their decisions being challenged. In particularly, if they do not have the neccessary financial resources to defend its decision in the event of an appeal in court.[17]
According to Article 52(6) GDPR each SA must have its own budget (see below).
Premises and infrastructure
Other essential elements for the proper functioning of the SA are the premises and the infrastructure. The SA should be equipped with premises with adequate space to ensure the permanence of its members and the confidentiality of meetings. Communication and security infrastructures commensurate with the sensitivity of the task are obviously needed.[18]
Necessary for effective performance of its tasks and exercise of its powers
Necessary
Article 52(4) GDPR links the criterea of sufficient resources to the effective performance of SA's tasks and exercise of its powers. It does not further specify how much resources is sufficient resources. The resources that an SA will need depend on different factors, such as the size of the territory and number of subjects it is bound to monitor, the size and complexity of data processing by controlling subjects, on how many complaints it receives. Another factor is the size of companies. Typically, big tech companies are more complex and time consuming to monitor than smaller businesses.
Effective performance
Effective performance means that a SA are efficiently performs all its tasks and efficiently exercises all its powers. In case of violations of the GDPR this means that every or most violations are identified, investigated and sanctioned. In general, high likelihood of sanctioning in case of infringements is a very significant factor for individual’s voluntary compliance with the laws. This is far from current reality where most violations of GDPR are not addressed, mass violations are tolerated and complaint procedures in most states take several years to be decided.[19]
Example: In Austria in case of driving over the speed limit and being caught, a speed ticket with a fine (1/2 of full fine) is automatically send to the driver. If he pays no procedure is started. This is a very effective way of dealing with violations of traffic rules.
In the context of mutual assistance, cooperation and participation in the EDPB
Finally, members states must provide sufficient resources not only for performing the tasks and powers on national lvel, but also for the activities carried out “in the context of mutual assistance, cooperation and participation in the Board”. The tasks relating to SAs participation in the cooperation and consistency mechanism enshrined in Chapter 7 of GDPR. That involves staff attending the EDPB meetings, cooperation with the other SAs under the consistency mechanism (one-stop shop) but also technical and financial resources to cooperate with the other authorities. The SA should therefore have at its disposal, for example, linguistic interpreters when the collegial work requires the translation of documents or the interaction with colleagues of a different language, encrypted communication systems to maintain the secrecy of the investigations and, more generally, adequate financial cover for travel and joint investigations.[20]
(5) Recruitment and Staff Supervision
The independence and efficiency of SAs may be compromised if its staff is chosen by another body or employed elsewhere. Unsuitable and incompetent staff cannot efficiently monitor the application of the GDPR. Therefore, Article 52(5) GDPR specifies that each SA must be able to choose and employ its own staff, who then must be subject to the exclusive direction of the member or members of the SAs.[21]
Chooses and has own staff
The ability to choose and have own staff enables a SA to employ suitable staff with the expertise, experience, qualifications and skills required to perform their tasks.[22]
Each SA must select its own staff. Taking into account Recital 121, this requirement can be met not only if the SA recruits and selects the staff itself, but also if the selection of staff is carried out by an independent body.[23] Autonomy and independence in the selection of staff gives SA an opportunity to better respond to existing professional and staffing needs.[24]
Exclusive direction of member(s) of supervisory authorities (SAs)
Staff of a SA is subject to exclusive supervision and direction of the member(s) of the SA, as any supervision or directions by another body could influence the work of the staff and thus also the work of the SA. This also “excludes making available staff to the supervisory authority whilst that staff remains linked in an organisational way to or remains subject to any form of supervision by the body which made the staff available”.[25]
(6) Financial Control and Budget
Article 52(6) GDPR addresses another aspect of financial independence of SAs, financial control and own budget.[26] In addition, Article 52(4) GDPR requires member states to ensure sufficient financial and other resources.
Financial control
Naturally, the independence of the SAs does not mean that their financial expenditure cannot be subject to any monitoring and control mechanisms.[27] However, it does set limits on the scope of financial controls. Member states must ensure that the financial controls do not compromise the independence of SAs.
Example: In a complaint case against a processor the SA spent 10.000 EUR on the investigation. The financial audit can verify whether the SA spent the amount in accordance with the relevant financial rules, e.g. public procurement rules, but not whether the investigation itself was necessary.
However, Article 52(6) GDPR should not be understood as obliging member states to subject the SAs to financial controls.[28]
Budget
Each SA must now also have a separate annual budget. Separate budget gives a SA the ability to plan its own budget and to decide where allocate and spend the funds.
Decisions
→ You can find all related decisions in Category:Article 52 GDPR
References
- ↑ Only convention 108 of the Council of Europe did not require that Supervisory Authorities (“SA”) are established by the contracting countries. However, the modernised Convention 108 (Article 15) now refers to the requirement of an independent authority.
- ↑ Zerdick, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 52 GDPR, p. 879 (Oxford University Press 2020).
- ↑ In Schrems I, the Court made it clear that the DPA must carry out a check on the transfer of data even where there is an adequacy decision. CJEU, Schrems I, §57
- ↑ Zerdick, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 52 GDPR, p. 879 (Oxford University Press 2020).
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin numbers 21 to 24 (Nomos 2022).
- ↑ See Boehm, in Kühling, Buchner, DS-GVO BDSG, Article 52 GDPR, margin number 18 (C.H. Beck 2020, 3rd Edition). See also Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 26 (Nomos 2022).
- ↑ Polenz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 52 GDPR, margin number 5 (Nomos 2019). To that end see also Article 58(4) GDPR.
- ↑ Polenz, in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 53 GDPR, margin numbers 12-14 (NOMOS 2019).
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 40 (Nomos 2022).
- ↑ This was the case in Baden-Württemberg in Germany. See Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 42 (Nomos 2022).
- ↑ Polenz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 52 GDPR, margin number 15 (Nomos 2019).
- ↑ Zerdick, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 52 GDPR, p. 881 (Oxford University Press 2020).
- ↑ Polenz, in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 53 GDPR, margin number 17 (NOMOS 2019).
- ↑ Zerdick, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 52 GDPR, p. 881 (Oxford University Press 2020).
- ↑ Polenz, in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 52 GDPR, margin number 18 (NOMOS 2019).
- ↑ Polenz, in Simitis, Hornung, Spiecker, Datenschutzrecht, Article 52 GDPR, margin number 19 (NOMOS 2019).
- ↑ Polenz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 52 GDPR, margin number 16 (Nomos 2019)
- ↑ Polenz, in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 52 GDPR, margin numbers 20 and 21 (Nomos 2019)
- ↑ From lodging the complaint with a SA until a decision is issued it usualy takes 2.5 to 5 years. For more information see statistics of DPA’s handling of noyb cases, available here.
- ↑ Selmayr, in Ehmann, Selmayr, DS-GVO Kommentar, Article 52 GDPR, margin number 23 (C.H. Beck 2017).
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 53 GDPR, margin number 47 (Nomos 2022).
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 23 (Nomos 2022).
- ↑ Recital 121, sentence 3 reads: "The supervisory authority should have its own staff, chosen by the supervisory authority or an independent body established by Member State law, which should be subject to the exclusive direction of the member or members of the supervisory authority."
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 23 (Nomos 2022).
- ↑ Zerdick, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 52 GDPR, p. 882 (Oxford University Press 2020).
- ↑ Boehm, in Kühling, Buchner, DS-GVO BDSG, Article 52 GDPR, margin number 21 (C.H. Beck 2020, 3rd Edition).
- ↑ Recital 118 GDPR provides that "the independence of supervisory authorities should not mean that the supervisory authorities cannot be subject to control or monitoring mechanisms regarding their financial expenditure or to judicial review."
- ↑ Ziebarth, in Sydow, Marsch, DS-GVO/BDSG, Article 52 GDPR, margin number 52 (Nomos 2022).