Showing posts with label art. Show all posts
Showing posts with label art. Show all posts

Thursday, 7 December 2017

GDPR - Fines

















Jane Lambert

This is the last of my articles on the GDPR for the time being. I have decided to discuss fines because it is one of the topics that has received most publicity recently.  The prospect of eye-watering fines has been used by some to raise awareness of data protection and to encourage good practices which must be good but it has also been used more cynically to boost sales of systems and services that may or may not be needed which is not so good.

Art 24 of the Data Protective Directive required member states to "adopt suitable measures to ensure the full implementation of the provisions" of the directive and, in particular, to lay down the sanctions to be imposed in case of infringement of the provisions adopted pursuant to the directive. However, it left it to the authorities in the member states to lay down what those sanctions should be. In the UK, the Information Commissioner has power to impose monetary penalties under s.55A of the Data Protection Act 1998.  S.55A (1) provides:
"The Commissioner may serve a data controller with a monetary penalty notice if the Commissioner is satisfied that—
(a) there has been a serious contravention of section 4 (4) by the data controller,
(b) the contravention was of a kind likely to cause substantial damage or substantial distress, and
(c) subsection (2) or (3) applies."
S.55A (2) applies if the contravention was deliberate and s.55A (3) if the data controller knew or ought to have known that there was a risk that the contravention would occur, and that such a contravention would be of a kind likely to cause substantial damage or substantial distress, but failed to take reasonable steps to prevent the contravention. S.55A (5) limits the amount of the monetary penalty to "the prescribed amount" which is set at £500,000 by reg 2 of The Data Protection (Monetary Penalties) (Maximum Penalty and Notices) Regulations 2010 (SI 2010 No 31). The Commissioner has given some guidance about the issue of monetary penalties prepared and issued under section 55C (1) of the Data Protection Act 1998. The Information Commissioner will continue to have the power to impose fines under art 58 (2) (i) of the GDPR in accordance with guidelines to be drawn up by the European Data Protection Board (a body consisting of representatives of the EU and national data protection supervising authorities) pursuant to art 70 (1) (k).


The Information Commissioner's power to fine will increase greatly as a result of art 83 of the GDPR. She will have power to impose administrative fines up to €20 million or up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher in the circumstances prescribed in art 83 (5). However, any fine that she does impose under that provision must be effective, proportionate and dissuasive. Paragraph (148) of the recitals provides the following guidance as to how the power to fine should be exercised:
"In order to strengthen the enforcement of the rules of this Regulation, penalties including administrative fines should be imposed for any infringement of this Regulation, in addition to, or instead of appropriate measures imposed by the supervisory authority pursuant to this Regulation. In a case of a minor infringement or if the fine likely to be imposed would constitute a disproportionate burden to a natural person, a reprimand may be issued instead of a fine. Due regard should however be given to the nature, gravity and duration of the infringement, the intentional character of the infringement, actions taken to mitigate the damage suffered, degree of responsibility or any relevant previous infringements, the manner in which the infringement became known to the supervisory authority, compliance with measures ordered against the controller or processor, adherence to a code of conduct and any other aggravating or mitigating factor. The imposition of penalties including administrative fines should be subject to appropriate procedural safeguards in accordance with the general principles of Union law and the Charter, including effective judicial protection and due process."
Paragraph (150) provides the following additional guidance
"In order to strengthen and harmonise administrative penalties for infringements of this Regulation, each supervisory authority should have the power to impose administrative fines. This Regulation should indicate infringements and the upper limit and criteria for setting the related administrative fines, which should be determined by the competent supervisory authority in each individual case, taking into account all relevant circumstances of the specific situation, with due regard in particular to the nature, gravity and duration of the infringement and of its consequences and the measures taken to ensure compliance with the obligations under this Regulation and to prevent or mitigate the consequences of the infringement. Where administrative fines are imposed on an undertaking, an undertaking should be understood to be an undertaking in accordance with Articles 101 and 102 TFEU for those purposes. Where administrative fines are imposed on persons that are not an undertaking, the supervisory authority should take account of the general level of income in the Member State as well as the economic situation of the person in considering the appropriate amount of the fine. The consistency mechanism may also be used to promote a consistent application of administrative fines. It should be for the Member States to determine whether and to which extent public authorities should be subject to administrative fines. Imposing an administrative fine or giving a warning does not affect the application of other powers of the supervisory authorities or of other penalties under this Regulation."
The representatives of the national data protection supervising authorities who will constitute the European Data Protection Board after 25 May 2018 adopted Guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679 on 3 Oct 2017 which can be downloaded from What's New section of the Information Commissioner's website.

Art 85 (2) provides that administrative fines shall be imposed in addition to, or instead of, the other sanctions that are available to the Information Commissioner under art 58 (2). When deciding whether or not to impose an administrative fine and, if so, the amount due regard must be given to the following considerations:
"(a) the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;
(b) the intentional or negligent character of the infringement;
(c) any action taken by the controller or processor to mitigate the damage suffered by data subjects;
(d) the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;
(e) any relevant previous infringements by the controller or processor;
(f) the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;
(g) the categories of personal data affected by the infringement;
(h) the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement;
(i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;
(j) adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and
(k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement."
In other words, only the most egregious infringements are likely to attract the heaviest fines. Art 85 (4) limits the fine for certain infringements such as failure to obtain the appropriate consent in relation to a child to €10 million or 2% of turnover. In the case of all others, the maximum penalty is €20 million or 4%,

It is important to note that art 83 (8) GDPR subjects the exercise by the Information Commissioner of her powers to "appropriate procedural safeguards in accordance with Union and Member State law, including effective judicial remedy and due process." In other words, the Commissioner will have to follow due process when imposing a fine and there will be a right of appeal against her decisions probably to the General Regulatory Chamber and from there to the civil courts. Also, for so long as the UK remains in the European Union points of EU law can be referred to the Court of Justice of the European Union,

Should anyone wish to discuss this article, fines, the GDPR or data protection generally he or she should call me on 020 7404 5252 or send me a message through my contact form.

Further Reading

Date
Author and Title
Publication
1 Dec 2017
NIPC Data Protection
11 Aug 2017
NIPC Data Protection

Tuesday, 5 December 2017

GDPR - Lawfulness of Processing and Consent

Jane Lambert











Yesterday I gave a talk on the GDPR to some 132 local authority personnel. The audience included the chief executive, heads of service, in-house legal advisers and managers and officials of all the council's departments. There were so many that the council chamber was the only room big enough to hold us all.  Some knew a lot about data protection in general and the GDPR in particular. Others wanted some basic information and it was for them that I wrote my Introduction to the GDPR and How the GDPR works.

"You've got them for two hours" said the head of legal before the talk, "tell them a few jokes to stop them falling asleep." As all my clean jokes are about Yorkshire and Yorkshire folk, I thought about telling them how the first Yorkshire pudding was made which, incidentally, was once made into a lovely dance by Jonathan Watkins for Northern Ballet (see  Sapphire 15 March 2015 Terpsichore).  However, we never got that far as the audience turned out to be quite lively and talkative.  What they wanted to talk about most was the legality of processing and consent.

To recap, I wrote on Sunday in How the GDPR works that there are 6 GDPR principles (or 7 if you include "accountability") that are set out in art 5 of the regulation.  The first of these is the "lawfulness, fairness and transparency" principle which is as follows:
"Personal data shall be:
(a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);"
 Art 6 (1) sets out the circumstances in which data can be lawfully processed:
"Processing shall be lawful only if and to the extent that at least one of the following applies:
(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
(b)  processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
(c) processing is necessary for compliance with a legal obligation to which the controller is subject;
(d) processing is necessary in order to protect the vital interests of the data subject or of another natural person;
(e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Point (f) of the first subparagraph shall not apply to processing carried out by public authorities in the performance of their tasks."
The audience knew that processing could be justified by "consent" but did such consent have to be in writing and was it necessary to ask members of the public who had already given their consent for a particular purpose (say a mailing list for a newsletter about tourist attractions) for their consent again just to comply with the GDPR?

Well, paragraph (32) of the recitals assists here:
"Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject's acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent. Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided."
So consent does not have to be written and signed but, if it is given orally. it does need to be recorded because art 7 (1) requires data controllers to be able to demonstrate that the data subject has consented to processing of his or her personal data. In answer to the other question, there is nothing in the GDPR that requires data controllers to mither their data subjects for confirmation of consent that they have already given for a specific purpose so long as the consent that they already have is genuine, informed and freely given.

A few other points to remember: -

  • Art 6 (1) (a) requires consent to be given for one or more specific purposes. Data subjects must know exactly and precisely what they are consenting to.
  • If a data subject's consent is given in the context of a written declaration which also concerns other matters, art 7 (2) requires any request for such consent to be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language.
  • Art 7 (4) provides that "utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract" when assessing whether consent is freely given.
Readers should also remember that other rules in relation to consent apply in relation to children and young people and particularly sensitive categories of data which I shall discuss in future articles. In the meantime, if you have any questions in relation to consent, lawful processing, the GDPR or data protection generally, call me on 020 7404 5252 during office hours or send me a message through my contact form.

Further Reading


Date
Author and Title
Publication
1 Dec 2017
NIPC Data Protection
11 Aug 2017
NIPC Data Protection