Blog Post

Twaalfde plenaire vergadering EDPB

  • door Maurits & Hömann
  • 10 jul, 2019

Op 9 en 10 juli 2019 zijn de Europese privacy toezichthouders weer bijeen om een aantal belangrijke privacy vraagstukken te bespreken.

gdpr avg edpb mauritshomann  privacy
Twaalfde vergadering EDPB | Maurits & Hömann
1. Adoption of the minutes and of the agenda
1.1 Minutes of the 11th EDPB meeting
1.2 Draft agenda of the 12th EDPB meeting

2. Current Focus of the EDPB
2.1 Art. 64 GDPR Opinion on Standard Contractual Clauses for processors under Art. 28.8 GDPR by DK SA
2.2 Art. 64 GDPR Opinionon Accreditation criteria for monitoring bodies of Codes of Conduct by AT SA
2.3 Art. 64 GDPR Opinion on continuance of the competence of a national authority in case of change in circumstances relating to the main or single establishment
2.4 EDPB-EDPS Joint consultation by the Commission on the processing of patients’ data in the eHealth Digital Service Infrastructure (eHDSI)
2.5 Art. 64 GDPR Opinion on CY Art. 35.4 DPIA list
2.6 Guidelines on Video Surveillance
2.7 Update by SA
2.8 EDPB Hearing before the CJEU on Schrems II case on 9July 2019
2.9 Reply to LIBE requeston the implications of the CLOUD Act
2.10 Art. 64 Opinion on Art 35.5 FR, ES & CZ lists
2.11 Recommendation on EDPS Art. 39.4 & 39.5 lists

3. FOR DISCUSSION AND/OR ADOPTION – Expert Subgroups and Secretariat 
3.1 BTLE ESG Pending issues
3.2 International Transfers ESG Internal process for the handling of BCRs
3.3 Key Provisions ESG and Technology ESG BEREC's request for guidance on review of net neutrality guidelines
3.4 Enforcement ESG 3.4.1 Investigating complaints
3.5 Finning Taskforce 3.5.1 Change in Coordinatorship of the Fining Taskforce
3.6 Secretariat
3.6.1 Outcome of the meeting of the Communication Officer Network in Vienna
3.6.2 EDPB Secondment Programme
3.6.3 Creation of a DPO Network

4. Miscellaneous

5. FOR INFORMATION–Expert Subgroups and Secretariat
5.1 Key Provisions ESG Recast of WP29’s Opinion on the concepts of controller and processor
5.2 Financial Matters ESG Guidelines on the interplay between the second Payment Service Directive (Directive (EU) 2015/2366) and the GDPR.

https://edpb.europa.eu/sites/edpb/files/files/file1/20190709_agenda_publicversion_en.pdf

Twelfth Plenary session: Guidelines on Video Surveillance, Implications of the US CLOUD Act, Opinion on SCCs for processors under Art.28.8 by DK, Opinion on Accreditation Criteria for monitoring bodies of Codes of Conduct by AT, Opinion on the competence

n July 9th and 10th, the EEA Data Protection Authorities and the European Data Protection Supervisor, assembled in the European Data Protection Board, met for their twelfth plenary session. During the plenary a wide range of topics were discussed.
 
Guidelines on Video Surveillance
The Board adopted Guidelines on Video Surveillance, which clarify how the GDPR applies to the processing of personal data when using video devices and aim to ensure the consistent application of the GDPR in this regard. The guidelines cover both traditional video devices and smart video devices. For the latter, the guidelines focus on the rules regarding processing of special categories of data. In addition, the guidelines cover, among others, the lawfulness of processing, the applicability of the household exemption and the disclosure of footage to third parties. The guidelines will be subject to public consultation.

EDPB-EDPS joint reply to the LIBE Committee on the implications of the US CLOUD Act
The EDPB adopted a joint EDPB-EDPS reply to the European Parliament Committee on Civil Liberties, Justice and Home Affairs’ (LIBE) request for a legal assessment regarding the impact of the US CLOUD Act on the EU legal data protection framework and the mandate for negotiating an EU-US agreement on cross-border access to electronic evidence for judicial cooperation in criminal matters. The CLOUD Act allows US law enforcement authorities to require the disclosure of data by service providers in the US, regardless of where the data is stored.

The EDPB and EDPS emphasize that a comprehensive EU-US agreement regarding cross-border access to electronic evidence, containing strong procedural and substantial safeguards for fundamental rights, appears the most appropriate instrument to ensure the necessary level of protection for EU data subjects and legal certainty for businesses.

Art.64 GDPR Opinion on Standard Contractual Clauses for processors under Art.28.8 GDPR by DK SA
The EDPB adopted its opinion on the draft Standard Contractual Clauses (SCCs) for framing the processing by a processor submitted to the Board by the Danish Supervisory Authority (SA). The opinion, which is the first one on this topic, aims to ensure the consistent application of Art 28 GDPR, relating to processors. In it, the Board made several recommendations that need to be taken into account in order for the draft SCCs of the Danish SA to be considered as Standard Contractual Clauses. If all recommendations are implemented, the Danish SA will be able to use this draft agreement as Standard Contractual Clauses pursuant to article 28.8 GDPR.

Art. 64 GDPR Opinion on Accreditation Criteria for monitoring bodies of Codes of Conduct by AT SA
Following submission by the Austrian SA of its draft decision on the Accreditation Criteria for Codes of Conduct monitoring bodies, the Board adopted its opinion. The Board agreed that all codes covering non-public authorities and bodies are required to have accredited monitoring bodies in accordance with the GDPR.

Art. 64 GDPR Opinion on the competence of a supervisory authority in case of a change in circumstances relating to the main or single establishment
The Board adopted an opinion on the competence of a supervisory authority when the circumstances relating to the main or single establishment change. This can occur when the main establishment is relocated within the EEA, a main establishment is moved to the EEA from a third country, or when there no longer is a main or single establishment in the EEA. In such circumstances, the Board is of the opinion that the competence of the lead supervisory authority (LSA) can switch to another SA. In this case, the cooperation procedure set forth under Art. 60 will continue to apply and the new LSA will be obligated to cooperate with the former LSA and with the other concerned SAs in an endeavour to reach consensus. The switch can take place as long as no final decision has been reached by the competent supervisory authority.

EDPB-EDPS Joint Opinion on the eHDSI
The Board adopted a joint EDPB-EDPS opinion on the personal data protection aspects of the processing of patients’ data in the eHealth Digital Service Infrastructure (eHDSI). It is the first joint opinion by the EDPB and the EDPS adopted in response to a request from the European Commission under Article 42(2) of Regulation 2018/1725 on data protection for EU institutions and bodies. In their opinion, the EDPB and EDPS consider that, in this specific situation, and for the concrete processing of patients’ data within the eHDSI, there is no reason to dissent from the European Commission’s assessment of its role as a processor within the eHDSI. Furthermore, the joint opinion stresses the need to ensure that all the processor duties of the Commission, in this processing operation, as specified in the applicable data protection legislation, are clearly set out in the relevant Implementing Act.  

DPIA List Cyprus
The EDPB adopted an opinion on the Data Protection Impact Assessment (DPIA) list submitted to the Board by Cyprus. DPIA lists form an important tool for the consistent application of the GDPR across the EEA. DPIA is a process to help identify and mitigate data protection risks that could affect the rights and freedoms of individuals.

Art. 64 GDPR Opinion on Art 35.5 lists FR, ES & CZ (DPIA exemption)
The EDPB adopted its opinion on the Art. 35.5 lists submitted to the Board by the French, Spanish and Czech SAs.

Recommendation on EDPS list pursuant to Art. 39.4 Regulation 2018/1725 (DPIA list)
The Board has adopted a recommendation on the Art. 39.4 list submitted to the Board by the EDPS. The EDPS has to consult the EDPB prior to adoption of these lists insofar as these “refer to processing operations by a controller acting jointly with one or more controllers other than Union institutions and bodies” (Article 39(6) of Regulation (EU) 2018/1725). Similar to GDPR DPIA lists, the EDPS list informs controllers about processing activities which require a DPIA.


https://edpb.europa.eu/news/news/2019/twelfth-plenary-session-guidelines-video-surveillance-implications-us-cloud-act_nl

door Maurits & Hömann 17 dec, 2019
Agenda en notulen van de zestiende vergadering EDPB
door Maurits & Hömann 17 dec, 2019
Agenda en notulen van de vijftiende vergadering EDPB
door Maurits & Hömann 17 dec, 2019
De agenda en notulen van de veertiende vergadering
door Maurits & Hömann 03 jul, 2019
Banken teruggefloten door Autoriteit Persoonsgegevens met betrekking tot gebruik betaalgegevens voor direct-marketing aanbiedingen.
door Maurits & Hömann 17 jun, 2019
Wet arbeidsmarkt in balans (WAB) in aantocht
door 81934671b872bb5f26d278f492cab802591830ed 04 jun, 2019
4 juni 2019 komen de Europese Privacy waakhonden weer bijeen om een aantal belangrijke privacy vraagstukken te bespreken
door Maurits & Hömann 03 jun, 2019
Hoewel de boete bescheiden is, is de boodschap dat niet: de bescherming van gegevens is een zaak van ons allen maar de verwerkingsverantwoordelijken moeten hun verantwoordelijkheid nemen, vooral als zij een overheidsmandaat hebben.
door mr. S. Hömann 23 mei, 2019
In dit artikel wordt de mogelijkheid besproken om schadevergoeding te vorderen bij de burgerlijke rechter.
door mr. S. Hömann 21 mei, 2019
Doorgifte van persoonsgegevens buiten de Europese Unie mogelijk door gebruikmaking van modelcontracten/
door Maurits & Hömann 15 mei, 2019
14 en 15 mei komen de Europese Privacy waakhonden weer bijeen om een aantal belangrijke privacy vraagstukken te bespreken
Meer posts
Share by: