AZOP (Croatia) - Croatian School Employees

From GDPRhub
AZOP - Croatian School Employees
Authority: AZOP (Croatia)
Jurisdiction: Croatia
Relevant Law: Article 5(1)(a) GDPR
Article 6 GDPR
Type: Complaint
Outcome: Upheld
Started: 17.03.2024
Decided:
Published:
Fine: 2.000 EUR
Parties: n/a
National Case Number/Name: Croatian School Employees
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Croatian
Original Source: AZOP (in HR)
Initial Contributor: RP

The DPA fined a school €2,000 for disclosing payslips of employees to a city audit office without a legal basis. The DPA held that the city had no competence to audit state-funded salaries; therefore, the disclosure lacked a legal basis under Article 6 GDPR.

English Summary

Facts

Several employees of a primary school filed a complaint with the Croatian Data Protection Authority (AZOP). The data subjects alleged that the school (the controller) had disclosed their payroll slips to the City Office for Internal Audit and Control without a legal basis.

The issue arose during a workers’ council meeting on 25 March 2024, when employees learned that the city was conducting an audit and had obtained payroll slips from the school. The school had transmitted several payroll slips to the city on 6 March 2024.

The data subjects argued that they had never consented to the disclosure. They also maintained that the city was not their employer and therefore had no right to access their payroll data. According to them, payroll slips contain extensive personal information, including names, addresses, personal identification numbers, salary details, deductions, credit obligations, and family-related information. Although some information had been partially covered before the documents were sent, the data subjects claimed that the redaction was ineffective.

During the investigation, the controller confirmed that it had transmitted payroll slips of 18 employees to the city. They argued that the city was the founder of the school and financed certain programmes, such as extended school stay and extracurricular activities. The city therefore claimed that it needed access to payroll data to verify the use of municipal funds and that the processing was lawful under Article 6(1)(c) GDPR.

Holding

AZOP held that the school had unlawfully disclosed personal data to the city and therefore violated the GDPR.

They first assessed whether the disclosure had a valid legal basis under Article 6(1) GDPR. The controller relied on Article 6(1)(c) GDPR, which allows processing that is necessary to comply with a legal obligation. AZOP rejected this argument. They found that the controller and the city had not demonstrated that the payroll slips were necessary for the city’s audit activities. In particular, the city had not shown that the payroll slips contained payments financed by the municipal budget.

AZOP also relied on the explanation provided by the Ministry of Finance. The ministry stated that the city’s internal audit office did not have authority to supervise the use of funds originating from the state budget. Since most salaries at the school were financed by the national government, the city had no legal competence to review the payroll slips. Therefore the disclosure violated the principle of lawful processing under Article 5(1)(a) GDPR and the requirement of a legal basis under Article 6 GDPR.

AZOP also considered the controller’s argument that the data had been anonymised. The authority rejected this argument because the controller had not demonstrated that the data were effectively anonymised before transmission.

When setting the fine, AZOP considered the criteria in Article 83(2) GDPR. They noted that the violation affected the personal data of 18 data subjects and involved the disclosure of detailed payroll information. However, AZOP also found that the controller acted negligently rather than intentionally and cooperated during the investigation. Consequently, they imposed a €2,000 fine.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Croatian original. Please refer to the Croatian original for more details.

REPUBLIC OF CROATIA

PERSONAL DATA PROTECTION AGENCY

CLASS:

NUMBER:
Zagreb,

The Personal Data Protection Agency, OIB: 28454963989, pursuant to Article 57(1) and 58(1) and (2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) Official Journal of the European Union L 119 and Articles 44, 45 and 46 of the Act on the Implementation of the General Data Protection Regulation (Official Gazette, No. 42/2018), acting ex officio against Primary School X, OIB: __, hereby issues the following

DECISION E NJ E

1. It is hereby established that the forwarding of personal data of 18 employees of Primary School X,
contained in the payrolls of the City of Y, in February and March 2024 by the head of the

processing of Primary School X resulted in a violation of the provisions of Articles 5 and 6 of the General Data Protection Regulation.

2. The violation described in point 1 of the Ruling Decision, in accordance with the provisions of Article 83 of the General
Regulation on Data Protection, shall be imposed on Primary School X, an administrative fine in the amount of

EUR 2,000.00

(in words: two thousand euros)

3. Primary School X shall pay the imposed administrative fine to the state

budget within 15 days from the date of entry into force of this Decision to the account number:
HR1210010051863000160, model HR64 and reference to the approval number: with the indication –
“administrative fines imposed by the AZOP”.

4. If Primary School X, within 15 days from the entry into force of this Decision, does not pay
the imposed administrative fine, the Personal Data Protection Agency will, in accordance with

Article 46, paragraph 2 of the Act on the Implementation of the General Data Protection Regulation, notify
the Regional Office of the Tax Administration of the Ministry of Finance in whose territory the headquarters

of the aforementioned controller is located, in order to collect the administrative fine by force in accordance with
the regulations on forced tax collection.

5. Primary School X, is obliged to submit proof of payment
to the Personal Data Protection Agency within 15 days from the payment.

R e p o n t i o n

I. FINDING OF VIOLATION

The Personal Data Protection Agency (hereinafter: the Agency) has received a complaint from employees of Primary School X (hereinafter: the complainants), represented by Sunčica Lončar, a lawyer from Sesvete, 144th Brigade of the Croatian Army 3, in which they essentially state that on 25 March 2024, at the Workers' Council of Primary School X, members of the said Workers' Council were informed that an inspection by the City Office for Internal Audit and Control was underway, which concerned the payrolls of employees. The payrolls of individual members of the Workers' Council were, as they state, submitted to the City Office for Internal Audit and Control by the acting principal of Primary School X on 6 March 2024, and the payrolls of the head of accounting were submitted in February 2024. The petitioners point out that they did not give any consent for the aforementioned delivery of the payslips. The petitioners add that City Y has not stated, explained or documented the procedure within which the data in question is requested, whether a control procedure has been initiated at City Y, on what basis and by what act, or has not proven the legal basis for collecting the data in question, which action, as they state, constitutes a serious violation of privacy and the right to the protection of personal data. The petitioners further point out that City Y is not the employer of the employees whose payslips were delivered, nor does it pay their salaries, and does not have the right to inspect the payslips even under the conditions of interinstitutional cooperation, as this is not in accordance with the principle of proportionality of the processing of employees' personal data. The petition reiterates that there is no act on the implementation of supervision, no authority or legal basis for City Y to conduct financial supervision over the payslips of employees whose salaries are not financed from the city budget. Furthermore, the petition describes an event that followed the delivery of the payroll for City Y, which the petitioners allege was directly related to unauthorized data processing, when an employee of City Y, City Office for Internal Audit and Control, in the presence of the acting school principal and another employee of City Y, conducted a search on the acting school principal's school computer in the LABIS program. The petitioners add that it is possible to derive information or conclusions about the individual to whom they refer from the payroll, which, in addition to the name and surname, OIB and residential address, also show other data, such as union membership, credit indebtedness (administrative ban), income amount, number of children and other data. The following documentation was submitted as an attachment to the petition: Official Note dated February 8, 2024, City Y, City Office for Internal Audit and Control, CLASS:_, FILE NUMBER: __;
email correspondence dated March 6, 2024 between the City Office for Internal Audit

and Control and the Acting Principal of Elementary School X; electronic correspondence dated March 11, 2024
between the Acting Principal of Elementary School X and the Accounting Officer of Elementary School X;
electronic correspondence dated March 20, 2024 containing an official note from the Accounting Officer of Elementary School X; electronic correspondence dated March 17, 2024 from the Accounting Officer of Elementary School X sent to the email addresses _ and __; electronic
correspondence dated March 18, 2024 from the Personal Data Protection Officer of City Y;

electronic correspondence dated March 20, 2024 where the school employee addresses the AZOP;
Unverified minutes of the ninth session of the Workers' Council held on March 25, 2024 at
Primary School X, CLASS: __, ISSUE NUMBER: __; letter sent to the email address

__, __, __, __, the subject of which is the implementation of unauthorized activities for the purpose of obtaining and processing
personal data (payrolls) of school employees by City Y, through the acting school principal

(GDPR).

Furthermore, on November 26, 2024, the applicants submitted additional information related to the submitted application. They initially state that on the payrolls submitted to the City Office for Internal Audit and Control of City Y, the data on the employee's OIB and address were partially crossed out with a felt-tip pen, but are still visible at a certain angle. However, as they explain, the names, surnames and other personal data of employees, which form an integral part of each payroll (e.g. data on salary, suspensions, personal deductions), were not covered, which did not ensure adequate protection of privacy. They further state that City Y is not the employer of employees of Elementary School X nor does it finance their salaries, which come from the state budget, and that there is no evidence of a legal basis for collecting and processing this data, nor did the school employees give consent for their payrolls to be submitted to the City Office. They point out that supervision of funds from the state budget, including salary payments and overtime calculations, falls within the exclusive competence of the Ministry of Finance, and that the City Internal Audit Office did not have the authority to supervise the salaries of school employees. In view of the above, the petitioners indicate that even the partial anonymization of the OIB and address was not carried out in accordance with the standards of proper anonymization. Using a marker is not a sufficiently secure method because it does not provide complete protection of personal data; in proper data anonymization, a method is used that completely removes or permanently obscures sensitive data, such as digital data removal or other permanent and impenetrable obscurations. Only permanent anonymization prevents any type of de-anonymization and ensures the privacy of the respondents.

The following documentation is attached: a copy of one of the submitted payslips;
reports sent to the Ministry of Finance, the Education Inspectorate and City Y and the report to the Administrative Inspectorate, as well as the responses received (City Y, Primary School X and the Education Inspectorate); other available evidence such as individual reports from school employees, all correspondence from City Y and Primary School X with a request for data delivery, minutes from the session of the Workers' Council of Primary School

3X (draft) and other documentation of the case file; and an example of the Instructions on the Processing of Personal Data of City Y.

Furthermore, the applicants subsequently supplemented the petition by submitting relevant information and the position of the Ministry of Finance regarding the issue of financial supervision competence in Primary School X, based on important facts from their letters CLASS: __, URBROJ:__ and URBROJ:__,

both dated 27 November 2024. In their supplement, the applicants point out that the Ministry of Finance clearly stated in its letter that City Y, the City Office for Internal Audit and Control, is not authorised to carry out financial supervision over funds coming from the

state budget of the Republic of Croatia. It is further explained that according to the Fiscal Responsibility Act and the regulations governing the system of internal controls in the public sector, a local self-government unit (in this case City Y) may provide professional assistance to budget users within its competence, but is not authorised to supervise funds from the state budget.

The Agency, in accordance with its legal powers in the related case CLASS: __
REGISTRATION NUMBER: __, requested from City Y a statement on the allegations of the petitioner, namely
to state the legal basis and purpose of processing the personal data of employees of Primary School X, as well as
whether they forwarded the personal data of employees of Primary School X to third parties, and if so, to explain
to whom and on what legal basis.

Following the submission of the supervisory body, City Y responded by submitting a submission
which it sent to the petitioner's attorney on the same day. In its submission, City Y states that, following the objection to the processing of personal data filed by the proxy on behalf of the employees of Primary School X, which objection also requests the deletion of personal data and the prohibition of their use for unauthorized purposes, within the scope of the provisions of the General Data Protection Regulation, it is apparent that City Y is processing the personal data of employees of Primary School X for a lawful (permitted) purpose and that the conditions for the deletion of personal data are not met, in accordance with the provisions of the General Regulation.

Namely, as stated in the submission of the City of Y, from the statement of the competent city administrative body

(City Office for Internal Audit and Control) dated April 23, 2024, it follows that
the provision of Article 150, paragraph 2 of the Law on Education in Primary and Secondary Schools

(Official Gazette, No. 87/08, 86/09, 92/10, 105/10, 90/11, 5/12, 16/12, 86/12, 126/12 - official

consolidated text, 94/13, 152/14, 7/17, 68/18, 98/19, 64/20, 133/20, 151/22, 155/23 and 156/23),
prescribes that the supervision and control of the intended spending of funds which school institutions
are ensured from the state budget by the Ministry, and the supervision and control of the dedicated

expenditure of funds provided to school institutions from the budget of the local unit i
local (regional) self-government and other sources are performed by the founder.


Furthermore, City Y states in its submission that the payrolls do not contain exclusively data on the spending of funds provided to school institutions from the state budget, but rather payrolls may also contain data on compensation paid from funds provided to school institutions from the budget of local and regional self-government units and other sources. Thus, the Public Needs Program in Primary Education of City Y, from the Budget of City Y, provides significant funds for financing broader public needs of City Y in the field of primary education, including programs such as: extended stay, school board fees, extracurricular and other activities, School in Nature, Weekends in Sports Halls, teaching assistants / professional communication mediators, co-financing of the preparation and implementation of projects submitted to European Union tenders, civic education. Additionally, City Y states that in accordance with the provisions of the Ordinance on the internal organization of the City Office for Internal Audit and Control (No. (1/23, 26/23, 32/23 and 4/24), the Department for Control in Institutions, the Control Sector, the City Office for Internal Audit and Control performs control tasks in institutions of which the City is the founder, which are aimed at detecting possible errors, deviations and irregularities in business operations with the aim of correcting them and preventing their recurrence; ensuring the legal, purposeful and timely collection and use of budgetary funds and funds from other sources and achieving expected business results; preparing professional documents for filing reports or requests for initiating misdemeanor, criminal and disciplinary proceedings due to irregular and illegal work, preparing reports on the performed controls that are submitted to the Mayor, preparing reports on the work of the Department and other tasks within the scope of the Department. Considering the identified irregularities in the use of financial resources by the Education Inspectorate of the Ministry of Science, City Y explains that the City Office for Internal Audit and Control has initiated an audit of the correctness of the use of financial resources in the institution in question.
It further states that the provisions of Article 6 of the General Regulation prescribe the conditions for the lawfulness of the processing of personal data, and thus paragraph 1, item c) of the said Article stipulates that the processing is lawful if it is necessary to comply with the legal obligations of the controller (the employee's consent - consent is not required because it is sufficient to meet one of the conditions for the lawfulness of the processing in order for the processing of personal data to be considered lawful). Finally, City Y states that the purpose of the processing of personal data is to control the use of financial resources in the institution.

In connection with the above, the Agency requested a statement from Primary School X, as the controller, and that statement on the allegations of the applicant, namely to state what the legal basis is for the transfer of personal data of employees of Primary School X to City Y, the City Office for Internal Audit and Control. Furthermore, a list of all employees whose personal data has been forwarded to

City Y, as well as information on which personal data has been forwarded. Furthermore, information on

whether City Y pays employees compensation from funds provided to school institutions from the budget of local and regional self-government units and other sources is requested.

If so, information on all employees whose personal data has been forwarded to City Y is being paid such compensation. Information on the supervision of Elementary School X by the Education Inspectorate of the Ministry of Science and Education, along with the need to submit

a report on the supervision thereof, is requested. Finally, information on who is the founder of Elementary School X, and what is the status of the employees of the school in question, i.e. who is the employer of the employees is requested.

5Further to the above, on 23 May 2024, the Agency received a statement from Primary School X (hereinafter referred to as the controller) CLASS: __, NUMBER: __ dated 20 May 2024, which listed the names of employees whose payrolls were exempted for the 2022-2023 school year (September - June), while all payrolls were submitted for one employee. Furthermore, in the statement, the controller notes that all personal data is blacked out on the payrolls. Also, the statement explains that the founder of the school in question is City Y, and

the employer is the Ministry of Science, Education and Youth, while for teachers working on extended leave, the employer is City Y. Attached to the statement is a submission that was sent to the petitioner's attorney, a letter from the Independent Sector of the Education Inspectorate, the Regional Office of the Education Inspectorate Rijeka, and the school's response.

In the submission that was sent to the petitioner's attorney, the acting The director of the processing manager essentially explains that her powers are prescribed by Article 125 of the Act on Education in Primary and Secondary Schools (Official Gazette, No. 87/08, 86/09, 92/10, 105/10, 90/11, 5/12, 16/12, 86/12, 126/12, 94/13, 152/14, 07/17, 68/18, 98/19, 64/20, 151/23, 155/23, 156/23) and that she is obliged to cooperate with the founder, state administration bodies, institutions and other bodies. The submission further states that the City Office for Internal Audit and Control
on January 30, 2024, received a complaint indicating possible irregularities related to
the findings of the education inspection and was notified by e-mail on February 1, 2024 that
the inspection of CLASS: __ had been opened.

Further to the above, we would like to point out that since May 25, 2018, in all member states of the European Union, including the Republic of Croatia,
Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing
Directive 95/46/EC (General Data Protection Regulation) OJ EU L119, has been directly and bindingly applied in all member states of the European Union, including the Republic of Croatia.

Article 4(1)(1) of the General Data Protection Regulation defines “personal data” as

any information relating to an identified or identifiable natural person (the “data subject”);

an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Accordingly, a video recording obtained by a video surveillance camera constitutes personal data within the meaning of the provisions of the Article in question, since the camera records movements and features by which a person can be identified.

We emphasize that in accordance with Article 5 of the General Data Protection Regulation, personal data must

be processed lawfully, fairly and transparently with regard to the data subject, collected for specified, explicit and legitimate purposes, adequate, relevant and limited to what is necessary in relation to

the purposes for which they are processed, and processed in a manner that ensures appropriate security

of personal data, including protection against unauthorized or unlawful processing and against accidental

loss, destruction or damage by applying appropriate technical or organizational measures

(principle of integrity and confidentiality).

6Article 6 of the General Data Protection Regulation stipulates that processing is lawful only if and to the extent that at least one of the following is met: the data subject has given consent to the processing of his or her personal data for one or more specific purposes, the processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract, the processing is necessary for compliance with a legal obligation of the controller, the processing is necessary to protect the vital interests of the data subject or of another natural person, the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child.

In this administrative matter, the parties' allegations/statements on the circumstances of the specific case were taken into account and the documentation attached to the case file was reviewed.

Accordingly, in this administrative matter, it was determined that the Education Inspectorate of the Ministry of Science established irregularities in the use of financial resources in Primary School X, for which reason the City of Y initiated an inspection of the correctness of the use of financial resources in the institution in question. It was further determined that on February 5, 2024, a meeting was held in the premises of the school in question, attended by the acting principal, the data controller, and representatives of the City of Y. It was determined that on that occasion, the City of Y took over certain documentation from the data controller, including the payroll of individual employees of the school. Additionally, it was established that on 6 March 2024, City Y requested in an electronic message

sent to the data controller the delivery of payrolls for the school year 2022/2023 (September/June) for 14 employees of the school. It was established that the data controller delivered to City Y payrolls for a total of 18 of its employees. Furthermore, on 20 March 2024, employees of the City Office for Internal Control and Audit came to the said school for a meeting.

In this specific case, the allegations made by City Y in its statement cannot be considered as
relevant. Namely, City Y in its statement presents a number of legal provisions and blanket statements, while

noting how they relate to the case at hand. For example, City Y in its statement states that the payrolls do not contain exclusively data on the spending of funds provided to school institutions from the state budget, but that payrolls may also contain data on compensation paid from funds provided to school institutions from the budget of local and regional self-government units and other sources, i.e. City Y states that the purpose of processing personal data is to control the use of financial resources in the institution. It is important to point out that it does not explain to which payrolls the allegations relate, i.e. to which employees the controller of the processing whose payrolls were delivered
was paid funds/salaries/compensations from the budget of City Y and for what reason. Also, City Y did not prove that the payrolls of the employees in question contained information on the remuneration paid from the budget of City Y. In addition, when making its decision, the Agency took into account the opinion of the Ministry of Finance regarding the issue of the competence of financial supervision in Elementary School X, in which they stated that the City Y, City Office for Internal Audit and Control, is not authorized to conduct financial supervision over funds coming from the state budget of the Republic of Croatia. Accordingly, it was determined that City Y had no legal basis or purpose for processing the personal data of the controller's employees contained in the payrolls. Accordingly, the controller had no legal basis or purpose for forwarding the personal data of its employees to City Y. Furthermore, despite the controller's allegations that the submitted payrolls were anonymized, neither the controller nor City Y provided evidence of this, and therefore the Agency did not take this into account when making its decision. Accordingly, in the specific case, it was established that the controller did not clearly determine or prove the legitimate purpose and legal basis for the transfer of the personal data of the controller's employees contained in the payrolls submitted to City Y, i.e. that such action by the controller was contrary to Articles 5 and 6 of the General Data Protection Regulation.

II. IMPOSITION OF ADMINISTRATIVE FINES

Article 44 of the Act on the Implementation of the General Data Protection Regulation stipulates that the Agency shall impose administrative fines for violations of the provisions of the Act and the General Data Protection Regulation, in accordance with Article 83 of the General Data Protection Regulation. Paragraph 2 of the same Article stipulates that if an administrative fine is imposed against a legal entity with public authority or a legal entity performing a public service, the imposed administrative fine must not jeopardise the exercise of such public authority or public service.

Article 45, paragraph 1 of the aforementioned Act stipulates that administrative fines shall be imposed by decision. Pursuant to paragraph 2 of the same Article, the decision shall determine the amount and manner of payment of the administrative fine. The decision may determine that the administrative fine shall be paid in installments. Pursuant to paragraph 4 of the same Article, no appeal is permitted against the decision, but an administrative dispute may be initiated before the competent administrative court. Pursuant to Article 46 of the same Act, the administrative fine shall be paid within 15 days from the date of entry into force of the decision imposing it. If the party fails to pay the administrative fine within the prescribed period, or upon the maturity of the last installment if payment by installments has been approved, the Agency shall notify the Regional Office of the Tax Administration of the Ministry of Finance in whose territory the party to whom the administrative fine was imposed has its residence or registered office, in order to collect the administrative fine by force in accordance with the regulations on forced tax collection.

Administrative fines shall be paid to the state budget. By way of exception to paragraph 2 of this
Article, no interest shall be calculated on the due but unpaid administrative fine.

Given the established circumstances in this case, the Agency, in accordance with its powers
under Article 58, paragraph 2, item (i) of the General Data Protection Regulation, imposed an administrative fine

8instead of other corrective measures under the relevant Article, all in accordance with the conditions for its imposition under Article 83 of the General Data Protection Regulation and Articles 44, 45 and 46 of the Act on the Implementation of the General Data Protection Regulation. After a detailed examination of the available remedies referred to in

Article 58(2) of the General Data Protection Regulation, which the supervisory authority is empowered to impose on the controller and/or processor in the event of a breach of the provisions of the General Data Protection Regulation, and having assessed all the circumstances of the case, in particular that the chosen remedy must be

effective, proportionate and dissuasive in each individual case, the Agency has decided to impose an administrative fine, paying due regard to the criteria laid down in Article 83(2) of the General Data Protection Regulation.

Namely, Article 83(1) of the General Data Protection Regulation requires each supervisory authority to ensure that the imposition of administrative fines in accordance with this Article in respect of

infringements of this Regulation referred to in paragraphs 4, 5 and 6 is in each individual case effective, proportionate and dissuasive.

The Agency considers that the amount of the imposed administrative fine cannot be effective if it does not have a significant impact on the controller's income, the principle of proportionality cannot be maintained if the violation and the administrative fine imposed in respect of it are considered abstractly, regardless of the impact on the controller or processor, and it should also be a deterrent against future violations. Therefore, the imposed administrative fine cannot be a deterrent if it does not have a financial impact on the controller in question. By imposing an administrative fine, the aim is also to ensure that the rules on personal data protection are respected by both the controller itself and all other controllers/processors who process personal data. This should achieve general deterrence (discourage others from repeating the same violation in the future), as well as specific deterrence (discourage the addressee of this administrative fine from repeating the same violation). Pursuant to Article 83(2) of the General Data Protection Regulation, administrative fines shall be imposed in addition to or instead of the measures referred to in Article 58(2)(a) to (h) and Article 58(2)(j), depending on the circumstances of each case. When deciding whether to impose an administrative fine and when deciding on the amount of that administrative fine in each case, due regard shall be paid to the following:
(a) the nature, gravity and duration of the infringement, taking into account the nature, scope and purposes of the processing concerned, as well as the number of data subjects and the level of harm suffered by them;
(b) whether the infringement was committed intentionally or negligently;
(c) any action taken by the controller or processor to mitigate the harm suffered by data subjects;
(d) the level of responsibility of the controller or processor taking into account the technical and organisational measures implemented by them in accordance with Articles 25 and 32;

(e) any relevant previous infringements by the controller or processor;

(f) the level of cooperation with the supervisory authority to remedy the infringement and mitigate the potential adverse effects of that infringement;

(g) the categories of personal data affected by the infringement;

9(h) the manner in which the supervisory authority became aware of the infringement, in particular whether and to what extent the controller or processor reported the infringement;

(i) where measures referred to in Article 58(2) have previously been imposed on the controller or processor in relation to the same matter, compliance with those measures;

(j) compliance with approved codes of conduct in accordance with Article 40 or approved certification mechanisms in accordance with Article 42; and

(k) any other aggravating or mitigating factors applicable to the circumstances of the case,

such as the financial gain gained from the infringement or the losses avoided, directly or indirectly, by that infringement.

Furthermore, the provision of paragraph 3 of the same Article stipulates that if a controller or processor infringes several provisions of this Regulation in respect of the same or related processing operations, intentionally or negligently, the total amount of the fine shall not exceed the administrative amount determined for the most serious infringement.

Article 83(5) of the GDPR stipulates that administrative fines of up to EUR 20 000 000, or in the case of an undertaking, up to 4% of the total worldwide annual turnover in the preceding business year, whichever is the higher, may be imposed for infringements of the obligations of the controller or processor under Articles 6 and 13 of the GDPR.

In view of the Report on the Budget, Budgetary and Extra-Budgetary Users for 2024, which is attached to the case file, it was determined that in 2024 the total operating income of the controller amounted to EUR 1,801,887.17; while the total operating expenses amounted to EUR 1,737,229.83.

For the violation of Article 5, paragraph 1, item (b) and Article 6, paragraph 1 of the General Data Protection Regulation, the Agency imposed an administrative fine on the controller in the amount of EUR 2,000.00, which is 0.01% of the maximum amount of the administrative fine that the Agency could or was authorized to impose in a specific case, taking into account the provisions of Article 44, paragraph 2 of the Act on the Implementation of the General Data Protection Regulation.

The expression "with due care" in Article 83(2) of the GDPR allows the competent data protection supervisory authorities a wide discretion when assessing the elements referred to in Article 83(2) of the GDPR. When determining the amount of the administrative fine, the Agency was obliged to respect the consistency mechanism, i.e. to ensure that the amount of the administrative fine imposed was in accordance with the fines imposed by other data protection supervisory authorities of other Member States of the European Union, in the same or similar circumstances.

Pursuant to Article 83(2) of the General Data Protection Regulation, when deciding on

imposing an administrative fine and deciding on the amount of that administrative fine, the Agency
in this case paid due attention to the following:

10- The nature, gravity and duration of the infringement, taking into account the nature, scope and purpose of the processing in question
as well as the number of data subjects and the level of damage suffered by them (Article 83(2)(a);

In the specific case, it was established that the controller is a public institution, and that the total number of data subjects affected by the infringement is 18. Accordingly, the personal data of
18 data subjects were transferred to a third party, namely City Y, without there being a legitimate purpose and legal basis for it. The transfer by the controller took place during February and March 2024. Also, the controller did not inform its employees whose personal data were forwarded about the transfer in question, but they learned about it on 25 March 2024 at the Workers' Council of Primary School X.

Taking into account that the controller forwarded the personal data of its employees to third parties without having a legitimate purpose and legal basis, the Agency qualified the above circumstances as a serious breach of the provisions of the General Data Protection Regulation.

- Does the breach have the characteristics of intent or negligence (Article 83(2)(b);

In relation to the above, the controller's intention to violate the provisions of the General Data Protection Regulation

by the controller has not been established, but negligence has been established.

- Any action taken by the controller or processor to mitigate the damage suffered by the data subjects (Article 83(2)(c);

Given that in the present case it was not established that the data subjects suffered any damage, the same circumstance was not assessed as either mitigating or aggravating.

- The degree of responsibility of the controller or processor taking into account the technical and organisational measures implemented by them in accordance with Articles 25 and 32 (Article 83(2)(d);

Not applicable in the present case.

- Relevant previous infringements by the controller or processor (Article 83(2)(e);

The Agency has recorded previous relevant breaches of the provisions of the General Data Protection Regulation
by Primary School X, as the controller, regarding the processing of personal data of its students
on the YouTube channel (videos and photos of students), and regarding the failure to comply
with the consent form of the parents/legal guardians of students whose personal data it processes, in accordance with the conditions of consent as prescribed in Article 7 of the General Data Protection Regulation
. The controller was given a formal warning for breaching the provisions of Articles
6 and 7 of the General Data Protection Regulation.

11- Degree of cooperation with the supervisory authority to eliminate the infringement and mitigate the possible adverse effects of the infringement (Article 83(2)(f);

Primary School X, as the controller, responded appropriately to the requests of the supervisory authority during this administrative procedure.

- Categories of personal data affected by the infringement (Article 83(2)(g);

The personal data collected do not fall within the special categories of personal data referred to in Article

9 of the General Data Protection Regulation.

- The manner in which the supervisory authority became aware of the breach, in particular whether and to what extent the controller

or processor reported the breach (Article 83(2)(h);

The supervisory authority became aware of the breach in question through submissions received from

employees of Primary School X whose payrolls were forwarded to City Y and initiated proceedings
ex officio pursuant to Article 42 of the General Administrative Procedure Act.

- If measures referred to in Article 58(2) have previously been imposed on the controller or processor in relation to the same matter
, compliance with those measures (Article 83(2)(i);

Given that the controller has not previously been subject to a measure under Article 58(2) of the GDPR, this circumstance has not been taken into account when determining the amount of the administrative fine.

- Compliance with approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42 (Article 83(2)(j);

Not applicable in the case at hand.

- Any other aggravating or mitigating factors applicable to the circumstances of the case, such as

the financial gain gained from the infringement or the losses avoided, directly or indirectly, by that infringement

(Article 83(2)(k);

When determining the amount of the administrative fine, the Agency has not identified any other relevant

circumstances that should be considered as aggravating or mitigating.

A fine may be considered effective if it achieves the objectives for which it was imposed. This may be the re-establishment of compliance with the rules, the punishment of unlawful conduct, or both.

The Agency decided to impose an administrative fine as a corrective measure due to the high risk to the data subjects, which could have been prevented by exercising due diligence.

12 Namely, in the specific case, the controller forwarded the payroll of 18 of its employees to City Y, where it had neither a legal basis nor a purpose for such forwarding.

Therefore, the Agency considers that imposing an administrative fine as a corrective measure will lead to the controller properly fulfilling its obligations in the field of personal data protection in the future, and in particular to being aware of the necessity of respecting all the principles of personal data processing set out in Article 5 of the General Data Protection Regulation when collecting and further processing personal data of data subjects. The Agency also believes that the imposition of the fine will lead to the controller timely fulfilling its obligations in the field of personal data protection in the future, in particular with regard to the implementation of appropriate technical and organizational measures that enable the effective application of the data protection principles. Furthermore, bearing in mind that the fine should also be proportionate and dissuasive, the Agency believes that the fine imposed is not disproportionate to the objectives sought to be achieved, and that the amount of the fine imposed is proportionate to the violation, taking into account in particular the gravity of the violation, and that the amount of the fine imposed will not jeopardize the performance of public service. The Agency conducted the investigation in accordance with Articles 51 and 52 of the General Administrative Procedure Act and in accordance with all principles of administrative procedure prescribed by the Administrative Procedure Act, correctly established the facts, and based on the established facts, correctly applied the substantive law and drew a correct conclusion on the facts in the specific case. Its decision
is based on all relevant evidence and facts at its disposal and submitted as evidence by the controller. Likewise, taking into account all of the above, the Agency
considers that the corrective intention of the administrative fine is ineffective, proportionate
and dissuasive in this administrative matter, and that its amount is fully appropriate to the circumstances
of the specific case.

Based on all of the above, it has been decided as in the Operative Part of the Decision.

INSTRUCTIONS ON LEGAL REMEDY

No appeal is allowed against this decision, but an administrative dispute may be initiated before the Administrative

Court in __ within 30 days from the date of delivery of the decision.

SUBMIT:
1. Primary School X,
2. Filing, here

13