CLV Partners

CLV-02

data protection

New guidelines of the EDPB on data controllers and data processors

The European Data Protection Board (“EDPB” or “Board”) has adopted the final version of guidelines no. 07/2020 on the concepts of controller and processor in the GDPR on its meeting of 7 July 2021, which renews and replaces the previous guidance no. 1/2010 of the Article 29 Data Protection Working Party on the same subject.

The definition of roles of data controller and data processor has been and continues to be the most controversial issue of data protection law, both during and prior to the entry into effect of the GDPR, as the assumed role determines the obligations and thus the corresponding responsibility. For this reason, the new EDPB guidelines are essential for all actors involved in data processing activities.

  1. Identifying the data controller

According to the GDPR, the person determining the purposes and means of the processing of personal data shall be considered the data controller. Among the elements of the concept, the new guideline explained the means of data processing in most detail, implementing a sharper distinction compared to the previous guidance.

In the opinion of the Board, when identifying the data controller, the means of data processing shall be understood only as the essential means, which are the following:

  • type of personal data which are processed
  • duration of the processing
  • the categories of recipients with access to the data (including transfers of data)
  • the categories of data subjects

The EDPB also emphasizes that actual access to personal data is not a requirement to be considered the data controller.

  1. Identifying the data processor

According to the GDPR, the data processor is the person who performs the processing operations on behalf of the data controller. The EDPB identified two explicit and one implied condition for the identification of the data processor. The two explicit conditions are as follows:

  • The data processor is a separate entity from the data controller;
  • The processing operations are performed solely on behalf of the data controller and the data are not processed for any purpose or interest other than those of the data controller.

In addition to the above, the third implied condition is that the discretion of the data processor includes the choice of non-essential means of data processing, such as the location of data storage, the software and methodology used for data processing operations.

There must be a written contract between the data controller and the data processor regarding the data processing, the absence of a contract constitutes an infringement of the GDPR on part of both actors.

The EDPB emphasized that the GDPR also imposes stricter obligations on data processors compared to the previous regulation. In addition, in the data processing agreement, the data controller may indirectly hold the data processor responsible for the performance of the data controller’s obligations under the GDPR, therefore, in order to limit the data controller’s liability, the most important thing is to select a responsible data processor, and conclude a processing agreement which duly takes into account all responsibilities.

  1. A person under the direct control of the data controller or data processor

Compared to the concepts of data controller and data processor, the role under the direct control of the data controller or data processor set out by Article 29 of the GDPR is less frequently discussed, but in practice the majority of natural persons perform data processing operations in this capacity.

This category includes a person who is not separate from the data controller or data processor. For example, neither the managing director nor a department of the company can be considered a separate entity from the company.

This category also includes a person who, although carrying out processing operations on behalf of the controller, has no independent decision-making power over these operations at all. Directly under the direct control are mainly workers and employees, but it is important to note that from the point of view of data protection law, not only workers employed under the Labour Code should be considered as employees, but also, where appropriate, staff employed under a service or agency contract.

When identifying direct control, in addition to the type of legal relationship, it is therefore necessary to examine the decision-making rights of the individual, his or her integration into the organization of the data controller or data processor, and the control exercised by the data controller or data processor.

For persons under direct control, the GDPR contains a single requirement that personal data may not be processed contrary to the instructions of the data controller. It is also possible and recommended in case of the persons under direct control to impose the obligations of the GDPR, as well as to sanction any conduct that infringes data protection law, in a contract or internal regulations.

Should you have any questions regarding the above, feel free to contact us.

CLV Partners news

 

blank

President of HDPA tempers position on thermometers!

The Head of the Hungarian Data Protection Authority in his interview made an announcement contrary to the Authority’s previous official position.

Unlike in Spring, in the current epidemiological situation in Hungary it is no longer disproportionate to implement body temperature measurement as a general measure, however, recording the results is still considered unjustifiable, because as health related data it would be considered a special category of personal data which should be especially protected.

The Head of the Hungarian Data Protection Authority in his interview made an announcement contrary to the Authority’s previous official position, that unlike in Spring, in the current epidemiological situation in Hungary it is no longer disproportionate to implement body temperature measurement as a general measure, however, recording the results is still considered unjustifiable, because as health related data it would be considered a special category of personal data which should be especially protected.

As a reminder, the Authority’s guidelines issued on 11 March 2020 and its confirmatory official position issued on 28 April 2020 considered disproportionate the requirement of screening tests with any diagnostic device (in particular, but not exclusively, with a thermometer), as the epidemiological situation in Spring did not warrant such measures.

The HDPA president’s statement did not affect the rest of the previously issued guidelines and official position, therefore all data processing in connection with the novel coronavirus epidemic such as body temperature measurement may only be introduced in the legitimate interest of the employer, substantiated by a proportionality test and the measurement shall be conducted by healthcare professionals or under their professional supervision under Article 9 (3) of the GDPR.

The Authority invariably requires employers to prefer measures which do not require the processing of personal data (basic hygiene, provision of disinfectants, adequate cleaning, provision of protective equipment, distance between workers).

Should you have any questions regarding the above, feel free to contact us.

blank

Enormous data protection fine imposed by the HDPA

On 18 May 2020, the Hungarian Data Protection Authority („HDPA” or „Authority”) has imposed a fine of HUF 100 000 000 on DIGI Távközlési és Szolgáltató Korlátolt Felelősségű Társaság („Digi” or „Company”).
The decision has been published by the Authority today, which is by far the highest amount imposed since the GDPR’s entry into force and the existence of the HDPA. The facts leading to the fine and the subsequent decision of the Authority are summarized as follows:

Facts of the case

1. Due to a prior loss of data, Digi created a test database for the purposes of mitigating errors, which the Company filled with existing personal data. The test database was originally available on the Company’s website only with appropriate authorization.

2. The content management system (‘CMS’) applied by the Company had a vulnerability, which has been detected more than 9 years ago. This vulnerability can also be detected and amended automatically by adequate tools and applications. Through this vulnerability, anyone could view the test database without access authorization.

3. Exploiting this vulnerability, an ethical hacker gained access to the test database, where the personal data of a significant number of clients were stored in plain text without any encryption. These data included all personal identifying data, ID card numbers, and in some cases personal identification numbers, e-mail addresses, telephone numbers and bank account numbers were also included.

4. In addition to the above, data of newsletter subscribers and full access system administrators were also accessible through the vulnerability, which could have been used by an attacker to take over complete control of the website and access any personal data or trade secret available on the website.

Findings of the HDPA

The categories of personal data involved made identity theft possible for a potential attacker.

• It is also an aggravating circumstance that the number of people affected by the data protection incident is significant, even in relation to the entire population of Hungary, the Company’s market position would have justified the application of more serious data security measures.

• The vulnerability in the open source content management system has been known for a long time, and a fix is available to fix this vulnerability for free.

• Lack of encryption increased the risk of the incident, even though the Company would also have had the opportunity to encrypt its data for an insignificant cost.

Leaking access credentials for full system administrators severely increases security risk.

• The maintenance of the test database violated the principles of the GDPR, as the test database should have been permanently deleted once its purpose has been fulfilled.

• The Company has also violated the provisions of its own internal regulations.

In light of all of the above, the Authority considered that the warning would not have had sufficient deterrent effect and that a fine, the exceptionally high amount of which was explained by a number of aggravating circumstances, was justified.

blank

Statement of the EDPB on data processing during the coronavirus epidemic

The European Data Protection Board (“EDPB”) has issued a statement on its website on data processing during the coronavirus epidemic.Please find our summary of the statement below:
1. The conditions of processing health data, as special category of data shall be specified by the national law in accordance with the GDPR. In this regard, the GDPR requires that the lawmaker defines specific measures and the suitable safeguards of the rights of the data subjects.

2. As per the position of the Hungarian Data Protection Authority emphasized, in the event of medical examinations such as body temperature measurement, this safeguard is the presence of a healthcare professional, therefore it is still not possible to implement such measurement at the workplace without the presence of a professional.

3. According to the EDPB’s position, the employers should inform employees if a coronavirus infected person has been identified at the workplace (to take the necessary protective measures), without revealing the identity of said person. The concerned employees shall be informed in advance and their dignity and shall be protected. Information on the infection should be first and foremost disclosed to those entitled to process these data, such as authorities and treating physicians if requested.

As the GDPR allows for a wide range of derogations in national law, we can expect a more detailed regulation of the data processing in relation to the epidemic.

The content of this article is not exhaustive and does not constitute a legal advice. Should you have any specific questions regarding any issues investigated by our articles, please contact us and we will be happy to be at your disposal.

blank

ON THE DATA PROCESSING RELATED TO THE CORONAVIRUS EPIDEMIC

The Hungarian Data Protection Authority („HDPA”, „Authority”) has issued on its website a briefing regarding data processing related to the coronavirus epidemic, also including certain general legal obligations beyond data protection. We have summarized the most important details as follows:
1. It is not only a vital interest but also a legal obligation of employers to provide a healthy and safe workplace.

2. Prior to any data processing, employers may be expected to create an epidemic action plan (preventive measures, allowing alternative working conditions (“home office”), procedure to be followed if the infection appears, assignment of responsible personnel within the company, implementation of a reporting system).

3. As a preventive measure within the action plan, it is recommended to provide employees with all necessary details, especially on the most critical information on the coronavirus (rules of hygiene, symptoms, who to report to within the company). The document titled “Procedure regarding the novel coronavirus identified in the year 2020” published on the website of the National Public Health Center could provide helpful for employers when wording the information.

4. According to the Labour Code, the employees shall report to the employer if they have knowledge of a risk of infection, including the risk of their own illness. With regards to this, the reporting system shall be implemented in a way that allows for confidential processing of data.

5. In the event of a report or suspicion of infection the HDPA considers filling out a questionnaire appropriate. Particular attention shall be paid to data minimisation. Employers shall not process the data of the suspected employee related to the epidemic beyond the questionnaire. The Authority specifically notes that data related to medical history or medical documentation shall not be requested or processed by the employer!

6. It needs to be emphasized that the employer shall not begin contact investigation, this should be entrusted with the investigating authority having jurisdiction!

7. Also important to note, the employer shall not conduct medical examination (i.e. use of thermometer), however, the professional examination of employees may be initiated through the involvement of healthcare professionals (first and foremost the company doctor).

8. The legal ground for the above data processing is based on the employer’s legitimate interest, if the medical examination of employees becomes necessary, the exceptional purpose of processing shall be in the interest of providing a healthy workplace.

9. It is recommended for employers to favour measures that do not result in the processing of data (following basic hygiene, providing disinfectants, proper cleaning). We would also like to note that the legislation does not allow for employers to distribute vitamins, medicine or immune-boosting products, etc. among its employees, therefore these are not legally possible as a preventive measure.

blank

GPDR after Brexit – Data transfers outside the EU

After years of negotiations the United Kingdom has officially left the European Union, therefore the UK has become a “third country”. We would like to take this opportunity to point out the special rules concerning the UK and data transfers outside the EU in general.
Data transfer to the UK

As we have noted in our latest article on Brexit, some changes need time to enter into force. According to the withdrawal agreement concluded between the UK and the EU, there will be a transition period until 31 December 2020. In this transition period, the GDPR is still applicable in the UK, so the UK would not be considered as a third country until the end of this year.

What happens after the transition period?

It is very important to note that any data processed before the end of the transition period shall continue to be processed in accordance with the GDPR. Thus, personal data transferred to the UK during the transition period shall be guaranteed the same level of safety as currently provided by the GDPR and data subjects have no cause to worry about their right to privacy.

After the transition period, the UK and the EU still need to iron out the specifics of data protection. Certainly, for most data controllers that would be most convenient if the UK continued to apply the GDPR.

However, in the event of a “no-deal” Brexit or if the “deal” excludes data protection, the rules of transferring data outside the EU would have to be applied to the UK.

Data transfers outside the EU

One of the most emphasized general rule of the GDPR is that transferring data outside the EU is not allowed only with a very few exceptions. There are three categories of these exceptions, “adequacy decisions” in Article 45, “appropriate safeguards” in Article 46 and “derogations for specific situations” in Article 49.

Adequacy decisions

With regards to Brexit, the second best scenario would be an EU Commission adequacy decision. Data may be transferred without any special rules or authorizations to third countries deemed to provide an adequate level of data protection. While the decision falls to the discretion of the Commission, we expect this to be a very likely outcome, as the UK has high standards of data protection in their national legislation.

Appropriate safeguards

Should the UK not be found adequate, the next option is for the data controller or processor to provide appropriate safeguards. These safeguards are subject to the approval/ adoption of the Commission and/or the supervisory authority. The most relevant of these safeguards are as follows:

• binding corporate rules (BCR) of a corporate group (approved by the supervisory authority);
• standard data protection clauses (adopted by the Commission);
• standard data protection clauses (adopted by a supervisory authority and approved by the Commission);
• an approved code of conduct together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects’ rights;
• an approved certification mechanism together with binding and enforceable commitments of the controller or processor in the third country to apply the appropriate safeguards, including as regards data subjects’ rights.

The abovementioned options require either significant effort from the data controller (i.e. drafting BCRs or codes of conduct) or a proactive supervisory authority (i.e. drafting and adopting standard clauses). Since the GDPR’s entry into force, no standard clauses have been adopted yet. Consequently, most data controllers might find appropriate safeguards a barrier too high to entry.

Derogations for specific situations

The last option is derogations for specific situations, to be applied for exceptional cases and will not serve as legal basis for systematic or regular transferring of personal data. The most relevant of these situations are as follows:

• explicit consent of a data subject informed of the risks of transfer to the third country;
• transfer is necessary for the performance of a contract between the data subject and the data controller or a contract concluded in the interest of the data subject;
• transfer is necessary for the establishment, exercise or defence of legal claims;
• transfer is necessary in order to protect the vital interests of the data subject or of other persons, where the data subject is physically or legally incapable of giving consent.

In any event, if the data controller uses these derogations as basis for data transfer outside the EU, the transfer may only take place if it is not repetitive and concerns only a limited number of data subjects, in addition the controller must demonstrate a compelling legitimate interest and inform the supervisory authority as well as the data subject. This is considered the least favourable option for data controllers because of their obligations to inform.

blank

HDPA issues statement on the monitoring of employee e-mails

At the end of last year, the Hungarian Data Protection Authority (HDPA) issued a statement, in which the HDPA commits itself to take all possible actions and use all available means – including adequate legal consequences to prevent further infringements – to stop the widespread practices of unlawful processing of employee e-mails. 
How does personal data enter the picture?

Even if an e-mail address was provided for the purposes of working, it might eventually be used by the employee for personal matters, or third parties might send personal e-mails to the address, which turns this into a question of data privacy. Although some advisable steps can be taken to prevent the personal use of work e-mail addresses (i.e. the prohibition of personal use of work assets), it is not seemingly possible to fully separate the two uses, since receiving a personal e-mail from a third party is generally outside the employer’s or employee’s control. It is also important to note that if an employee uses the work e-mail address for personal matters despite possible explicit prohibitions set in place, such an act will still be attributed to the employer’s data processing, thus the processing of personal data is unavoidable.

What is expected of the employers?

First and foremost, employers should determine the lawful ground of the processing. The HDPA highlighted storing, archiving and searching/ indexing as the most common processing actions performed on employee e-mails. Naturally, employers have a vested interest in the monitoring of employee e-mails, as it is necessary to control and maintain the work flow, therefore the lawful ground must be substantiated by a thorough balancing test prior to the processing. Once the lawful ground is established, it is advisable to prepare an SOP on the monitoring process.

The employer must duly inform the employees about the monitoring of work e-mails, the data processing and whether or not personal use of work e-mails is permitted or prohibited at the workplace.

Before or during the monitoring, the employer must take all reasonable steps to separate work related and private e-mails. In accordance with the principle of accountability, the employer should maintain a record of the steps taken during monitoring.

Considering the fact that almost every employer provides its employees with an e-mail address for work purposes, this statement is important to all employers who wish to be compliant with the GDPR and employees interested in the protection of their private lives.

GDPR – One Year On

As 25 May 2018 approached, many organisations faced these new European privacy rules with increasing concern. One of the main reasons for this was undoubtedly the extremely high fines that can be imposed for breaches of the GDPR: the majority of infringements can be punished by a fine of up to EUR 20 million or 4% of total worldwide annual turnover for the previous financial year (the higher of the two).
The level of fine imposed will depend on an assessment by the national data protection authority (DPA) of mitigating or aggravating circumstances listed in the GDPR including the nature, seriousness and duration of the infringement, whether the data involved was sensitive and any previous breaches.
A year on, with the first wave of decisions and fines now issued by a number of DPAs and investigations ongoing in others, it is interesting to examine the initial effects of the GDPR in the EU. Has it managed to enhance protection for people’s privacy? Did the concern expressed at its potential impact turn out to be justified? Are different trends emerging in different EU countries? These and other questions are discussed below.

Several companies involved in Hungarian Data Protection Authority (NAIH) procedures have been fined. The usual amount of the fine is between HUF 500,000 and HUF 1 million, (approximately EUR 1500 and EUR 3000).
In one of its most relevant recent decisions, the NAIH imposed a fine of HUF 1 million on a company with a turnover of HUF 15 million, which it considered a symbolic amount, for not restricting and issuing copies of camera recordings, despite a request from a data subject. The data subject wanted to use the recordings as evidence in legal proceedings, as stated in the request. The company justified its decision on several grounds, including the fact that the data subject did not indicate how deleting the recording would infringe his or her legitimate interest, and in connection with what legal proceedings he or she made the request (although required to do so under Hungarian law).
According to NAIH, the company violated the data subject’s right to restrict data processing. Under Article 18 (1) (c) of the GDPR, it is sufficient for the data subject to argue that restricting processing is necessary for the submission and enforcement of legal claims. There is no need to justify the right and the legitimate interest further than that. The conflicting Hungarian legal provision has been amended by the GDPR implementation law mentioned below.

In addition, the company failed to inform the data subject about the reasons for its decision and the legal remedies available to the data subject.
In imposing the fine, the authority assessed the nature of the infringement as an aggravating circumstance, as it violated the applicant’s rights. The refusal of the request also led to the deletion of the recordings, which cannot be restored. It was a mitigating circumstance that the company committed the infringement for the first time, and also that the conflicting national legal provision. was still in force, which could have misled the company in its decision to deny the data subject’s request.

Hungary has implemented the GDPR with an implementation act came into force on 26 April 2019. The aim of the amendments is the harmonisation of sectoral laws in order to apply the GDPR. The GDPR implementation act amends 86 acts to comply with the GDPR, including the Labour Code. As a result, employees’ documents, the processing of the criminal records and the agreements relating to the use of work-related IT equipment must be reviewed.
Experience has shown that the NAIH is active; several proceedings have been initiated checking the data processing practices of operators and assessing compliance.

blank

GDPR „OMNIBUS” Act overwrites the usual HR process

On 26 April 2019, Hungary’s new ‘Omnibus Act’ implementing provisions of the GDPR took effect. This article examines its significant impact on employers and the continuing uncertainty surrounding some of the changes it introduces.

Only a few months ago, employers were required to readjust their processes in preparation for GDPR implementation and now the new so-called ‘Omnibus’ act that amends the Labour Code, among other changes has entered into force (on 26 April 2019). The new regulation requires immediate and very significant work from HR departments, while there are several open issues to be jointly interpreted by labour lawyers together with HR and data protection professionals on how to ensure their daily practice is compliant with the new but ambiguous regulations.

The bottleneck is a result of the fact that Hungarian lawmakers were well behind schedule with implementation of GDPR, leaving employers only a few days to review the new processes, since all employers must comply with all requirements from day one. There is a strong hope that (as has happened in several previous cases) the Omnibus Act will very shortly be corrected by a new amendment.

The GDPR ‘Omnibus’ Act amends 86 acts including the Labour Code in order to comply with GDPR regulations.

This amendment requires the review of labour contracts, HR processes and significant HR policies such as recruitment, selection, new employees’ induction process, operations, the data management of access control systems and use of employer’s devices, just to mention the most common areas concerned.

Employers and all organisations should have complied with the new regulations within a couple of days of entry into force.

Although the new requirements contain more details than the published draft bill, there are still several open issues on how to implement them in practice. For example what is the meaning of, and what are the criteria for the necessity and proportionality test contained in the new regulations in relation to limitations on employees’ personal human rights (in connection with e-mail, internet, device or video surveillance, etc.)? The GDPR only includes the privacy impact assessment and the ‘balancing test’ for ‘legitimate interest’.

The usual process of recording a new employee’s data is basically overridden by the new rule that the employer may only request presentation of an ID card and other personal documents, but no copies can be made, even with the consent of the employee. This will mean that proper identification of the employee would be difficult. The provision of false data by the employee may result in annulment of employment, but with a lack of proper evidence and documentation, the employer may not be in a position to act.

Handling of criminal data records is more strictly regulated, and in the future the basic rule is that no criminal record clearance may be requested from employees. Exceptional and very strict criteria are set for cases when the employer may require an employee to present criminal record clearance, but the precise criteria can be decided by the employer if a serious business risk for the organisation would arise from an employee with undisclosed criminal record working for it.

Finally, the amendment relating to data managed by the biometric access control systems (digital fingerprint, iris/retina scanning, face identification systems), and also the use of the employers’ devices is based on new principles, meaning that a review of internal policies relating to these issues must be conducted.

blank

Amendments with regard to the GDPR has been published

The amendments with regards to the GDPR, which was adopted by the Hungarian Parliament on the 1st of April, was officially published today.

In order to harmonize with the GDPR, the amendments modifies over 80 sectorial law, including provisions of the Labour Code.

The majority of the amendments will come into effect at the end of April, but the modifications regarding the national accreditation and the protection of inventions by patents will come into force in May.