Article 67 GDPR: Difference between revisions

From GDPRhub
Line 197: Line 197:
== Commentary ==
== Commentary ==


''You can help us fill this section!''
This provisions grants the power to adopt an implementing act to the Commission for the exchange of information not only between the SAs, but also between the SAs and the EDPB.
 
The necessity of a reliable and efficient system to communicate, in particular under the cooperation procedure (between SAs) and the consistency mechanism (under the consistency procedure) is vital for the good functioning of the cooperation between the SAs and the EDPB, considering the strict deadlines and the need for enhanced cooperation.
 
IMI (Internal Market Information System) was chosen as the IT platform to support cooperation and consistency procedures under the GDPR. IMI helps public authorities across the EU to cooperate and exchange information.
 
IMI has been developed by the European Commission’s DG GROW and was adapted to cater for the needs of the GDPR, in close cooperation with the Secretariat of the EDPB and the national supervisory authorities.<ref>See State of Play on the EDPB website of 27 June 2018, available [https://edpb.europa.eu/news/news/2018/state-play-imi-gdpr-purposes_en here].</ref>
 
The IMI system is therefore used to initiate various procedure under the GDPR, such as the identification of the LSA, mutual assistance procedures, or one-stop-shop procedures.<ref>See 2019 Annual report of the EDPB, Section 4.3.1, available [https://edpb.europa.eu/sites/default/files/files/file1/edpb_annual_report_2019_en.pdf here].</ref>
 
The Commission also adopted an implementing decision on a pilot project to implement the administrative cooperation provisions of the GDPR.<ref>Commission Implementing [https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32018D0743 Decision] (EU) 2018/743 of 16 May 2018 on a pilot project to implement the administrative cooperation provisions set out in Regulation (EU) 2016/679 of the European Parliament and of the Council by means of the Internal Market Information System.</ref> This decision refers to the Administrative cooperation between supervisory authorities (covering cooperation under Articles 56, 60, 61 and 62) and the administrative cooperation between supervisory authorities, the Board and the Commission (covering Articles 645 to 66 GDPR). For the purposes of the pilot project, the supervisory authorities referred to in Article 51 GDPR and the EDPB shall be considered as “competent authorities” under the IMI Regulation.<ref>The EDPS is not a competent authority under the GDPR, which seems to excludes it from the pilot project.</ref>
 
The IMI Regulation has also been modified to extend the list of IMI actors (beside the “competent authorities, IMI coordinators and the Commission”) to the “Union bodies, offices and agencies” and to add the GDPR to the Annex listing the provisions on administrative cooperation in union acts that are implemented by means of IMI.<ref>See Article 5(g) of [https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02012R1024-20190216 Regulation] (EU) No 1024/2012 of the European Parliament and of the Council of 25 October 2012 on administrative cooperation through the Internal Market Information System and repealing Commission Decision 2008/49/EC (‘the IMI Regulation’), as modified by [https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32018R1724 Regulation] (EU) 2018/1724 of the European Parliament and of the Council of 2 October 2018 establishing a single digital gateway to provide access to information, to procedures and to assistance and problem-solving services and amending Regulation (EU) No 1024/2012.</ref>
 
Article 17 of the EDPB RoP refers to the use of an “Internal information and communication system”, “''in particular to support the electronic exchange of documents within the cooperation and the consistency mechanisms''”. Article 10 11(1) of the EDPB RoP require the competent SA to send the relevant documents to the secretariat of the EDPB via the IMI IT system.
 
The use of the IMI system to communicated between SAs is therefore made mandatory. Ignoring this requirement can have consequences, since the EDPB already considered that the urgency could not be presumed under Article 61(8) GDPR if the request for mutual assistance was not made under the formal IMI procedure to send a request for mutual assistance to the Irish SA.<ref>EDPB, Urgent Binding [https://edpb.europa.eu/system/files/2021-07/edpb_urgentbindingdecision_20210712_requesthh_fbireland_en.pdf Decision] 01/2021 on the request under Article 66(2) GDPR from the Hamburg (German) Supervisory Authority for ordering the adoption of final measures regarding Facebook Ireland Limited, 12 July 2021, p.42, section 4.2.1</ref>


== Decisions ==
== Decisions ==

Revision as of 14:43, 20 August 2021

Article 67 - Exchange of information
Gdpricon.png
Chapter 10: Delegated and implementing acts

Legal Text


Article 67 - Exchange of information


The Commission may adopt implementing acts of general scope in order to specify the arrangements for the exchange of information by electronic means between supervisory authorities, and between supervisory authorities and the Board, in particular the standardised format referred to in Article 64.

Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2).

Relevant Recitals

Recital 167: Implementing Acts
In order to ensure uniform conditions for the implementation of this Regulation, implementing powers should be conferred on the Commission when provided for by this Regulation. Those powers should be exercised in accordance with Regulation (EU) No 182/2011. In that context, the Commission should consider specific measures for micro, small and medium-sized enterprises.

Recital 168: Examination Procedure
The examination procedure should be used for the adoption of implementing acts on standard contractual clauses between controllers and processors and between processors; codes of conduct; technical standards and mechanisms for certification; the adequate level of protection afforded by a third country, a territory or a specified sector within that third country, or an international organisation; standard protection clauses; formats and procedures for the exchange of information by electronic means between controllers, processors and supervisory authorities for binding corporate rules; mutual assistance; and arrangements for the exchange of information by electronic means between supervisory authorities, and between supervisory authorities and the Board.

Commentary

This provisions grants the power to adopt an implementing act to the Commission for the exchange of information not only between the SAs, but also between the SAs and the EDPB.

The necessity of a reliable and efficient system to communicate, in particular under the cooperation procedure (between SAs) and the consistency mechanism (under the consistency procedure) is vital for the good functioning of the cooperation between the SAs and the EDPB, considering the strict deadlines and the need for enhanced cooperation.

IMI (Internal Market Information System) was chosen as the IT platform to support cooperation and consistency procedures under the GDPR. IMI helps public authorities across the EU to cooperate and exchange information.

IMI has been developed by the European Commission’s DG GROW and was adapted to cater for the needs of the GDPR, in close cooperation with the Secretariat of the EDPB and the national supervisory authorities.[1]

The IMI system is therefore used to initiate various procedure under the GDPR, such as the identification of the LSA, mutual assistance procedures, or one-stop-shop procedures.[2]

The Commission also adopted an implementing decision on a pilot project to implement the administrative cooperation provisions of the GDPR.[3] This decision refers to the Administrative cooperation between supervisory authorities (covering cooperation under Articles 56, 60, 61 and 62) and the administrative cooperation between supervisory authorities, the Board and the Commission (covering Articles 645 to 66 GDPR). For the purposes of the pilot project, the supervisory authorities referred to in Article 51 GDPR and the EDPB shall be considered as “competent authorities” under the IMI Regulation.[4]

The IMI Regulation has also been modified to extend the list of IMI actors (beside the “competent authorities, IMI coordinators and the Commission”) to the “Union bodies, offices and agencies” and to add the GDPR to the Annex listing the provisions on administrative cooperation in union acts that are implemented by means of IMI.[5]

Article 17 of the EDPB RoP refers to the use of an “Internal information and communication system”, “in particular to support the electronic exchange of documents within the cooperation and the consistency mechanisms”. Article 10 11(1) of the EDPB RoP require the competent SA to send the relevant documents to the secretariat of the EDPB via the IMI IT system.

The use of the IMI system to communicated between SAs is therefore made mandatory. Ignoring this requirement can have consequences, since the EDPB already considered that the urgency could not be presumed under Article 61(8) GDPR if the request for mutual assistance was not made under the formal IMI procedure to send a request for mutual assistance to the Irish SA.[6]

Decisions

→ You can find all related decisions in Category:Article 67 GDPR

References

  1. See State of Play on the EDPB website of 27 June 2018, available here.
  2. See 2019 Annual report of the EDPB, Section 4.3.1, available here.
  3. Commission Implementing Decision (EU) 2018/743 of 16 May 2018 on a pilot project to implement the administrative cooperation provisions set out in Regulation (EU) 2016/679 of the European Parliament and of the Council by means of the Internal Market Information System.
  4. The EDPS is not a competent authority under the GDPR, which seems to excludes it from the pilot project.
  5. See Article 5(g) of Regulation (EU) No 1024/2012 of the European Parliament and of the Council of 25 October 2012 on administrative cooperation through the Internal Market Information System and repealing Commission Decision 2008/49/EC (‘the IMI Regulation’), as modified by Regulation (EU) 2018/1724 of the European Parliament and of the Council of 2 October 2018 establishing a single digital gateway to provide access to information, to procedures and to assistance and problem-solving services and amending Regulation (EU) No 1024/2012.
  6. EDPB, Urgent Binding Decision 01/2021 on the request under Article 66(2) GDPR from the Hamburg (German) Supervisory Authority for ordering the adoption of final measures regarding Facebook Ireland Limited, 12 July 2021, p.42, section 4.2.1