Take-Aways (AI)
  • The Euro­pean Data Pro­tec­tion Board (EDPB) review­ed natio­nal black­lists and calls for their ali­gnment with the Art. 29 gui­de­lines for the uni­form appli­ca­ti­on of the GDPR.
  • Cer­tain types of data (bio­me­tric, gene­tic) or com­bi­na­ti­ons of cri­te­ria always trig­ger a data pro­tec­tion impact assess­ment; other pro­ce­s­ses alo­ne never do.

Sin­ce the GDPR ente­red into force on May 25, 2018, the data pro­tec­tion aut­ho­ri­ties of 22 EU mem­ber sta­tes have drawn up so-cal­led “black lists” regar­ding the cri­te­ria for car­ry­ing out data pro­tec­tion impact assess­ments pur­su­ant to Art. 35 GDPR. The­se lists include cri­te­ria which are likely to lead to a high risk to the rights and free­doms of data sub­jects in the case of data pro­ce­s­sing ope­ra­ti­ons and thus requi­re a data pro­tec­tion impact assess­ment. With regard to cer­tain data pro­ce­s­sing ope­ra­ti­ons, name­ly tho­se rela­ted to the offer of goods and ser­vices to data sub­jects or to beha­vi­oral moni­to­ring of such data sub­jects, as well as pro­ce­s­sing ope­ra­ti­ons that could signi­fi­cant­ly rest­rict the “free move­ment of data”, such lists must be exami­ned in advan­ce as part of the con­si­sten­cy pro­ce­du­re. The pri­ma­ry pur­po­se of such a pro­ce­du­re is for the data pro­tec­tion aut­ho­ri­ties of the Mem­ber Sta­tes to coope­ra­te on fun­da­men­tal issues in order to ensu­re the uni­form appli­ca­ti­on of the GDPR in the indi­vi­du­al Mem­ber Sta­tes and thus to take the best pos­si­ble account of the goal of a sin­gle mar­ket in data pro­tec­tion law.

Against this back­ground, the Euro­pean Data Pro­tec­tion Board (“EDSA”), the so-cal­led suc­ces­sor of the Art. 29 Working Par­ty, has exami­ned the­se “black lists” and published its opi­ni­ons on the indi­vi­du­al lists. An over­view of the indi­vi­du­al reports can be found here: https://edpb.europa.eu/our-work-tools/consistency-findings/opinions_de. The EDSA has not yet for­mu­la­ted its own cri­te­ria for a risk assess­ment in con­nec­tion with data pro­tec­tion impact assess­ments. Howe­ver, the fol­lo­wing prin­ci­ples can be deri­ved from the indi­vi­du­al opinions:

  1. Gene­ral principles
  • With regard to the con­cept of data pro­tec­tion impact assess­ment, the gui­de­lines issued by the Art. 29 Working Par­ty in Working Paper 248 https://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=611236 The EDSA encou­ra­ges Mem­ber Sta­tes to men­ti­on this fact in their lists and to sta­te that their lists are to be under­s­tood as imple­men­ting pro­vi­si­ons of the Gui­de­lines. The EDSA encou­ra­ges Mem­ber Sta­tes to men­ti­on this fact in their lists and to sta­te that their lists are to be under­s­tood as imple­men­ting pro­vi­si­ons to the Guidelines.
  • Against this back­drop, the cri­te­ria for­mu­la­ted in the gui­de­lines regar­ding the assess­ment of the neces­si­ty of a data pro­tec­tion impact assess­ment are to be decisi­ve for the fur­ther deve­lo­p­ment of the lists. The so-cal­led “black” and “white” lists are the­r­e­fo­re to be drawn up on the basis of the­se, wher­eby a data pro­tec­tion impact assess­ment must always be car­ri­ed out if two cri­te­ria are met.
  • Even if the lists are to be drawn up against the back­ground of the goal of as uni­form an imple­men­ta­ti­on as pos­si­ble, this does not mean that they have to be the same; the natio­nal data pro­tec­tion aut­ho­ri­ties must nevert­hel­ess be given suf­fi­ci­ent dis­creti­on in dra­wing up their lists when it comes to taking natio­nal spe­ci­fics into account; the pri­ma­ry goal should be to avo­id signi­fi­cant incon­si­sten­ci­es in the imple­men­ta­ti­on of Art. 35 GDPR, which could result in dif­fe­rent levels of pro­tec­tion for the data sub­jects concerned.

2.  Cri­te­ria-spe­ci­fic principles

  • Cer­tain data pro­ce­s­sing ope­ra­ti­ons requi­re under given cir­cum­stances not­wi­th­stan­ding the requi­re­ments of Art. 35 (3) GDPR a data pro­tec­tion impact assess­ment. In par­ti­cu­lar, this is the case for data pro­ce­s­sing in con­nec­tion with bio­me­tric or gene­tic data. The EDSA has thus sta­ted in its opi­ni­ons that a data pro­tec­tion impact assess­ment must be car­ri­ed out for the rele­vant pro­ce­s­sing ope­ra­ti­ons when such data are pre­sent in con­junc­tion with ano­ther cri­ter­ion. 
  • Howe­ver, cer­tain data pro­ce­s­sing ope­ra­ti­ons are never suf­fi­ci­ent in them­sel­ves to trig­ger an obli­ga­ti­on for a data pro­tec­tion impact assess­ment. This applies, for exam­p­le, to con­stel­la­ti­ons of joint con­trol­lers in which data from dif­fer­ent­ly mer­ged sources are fur­ther pro­ce­s­sed or when data pro­ce­s­sing is rela­ted to inter­faces of per­so­nal elec­tro­nic devices.
  • Fur­ther­mo­re, a data pro­tec­tion impact assess­ment is requi­red for cer­tain data pro­ce­s­sing acti­vi­ties. only The data pro­tec­tion aut­ho­ri­ties must then check if at least one fur­ther cri­ter­ion is given in addi­ti­on to the type of data pro­ce­s­sed. This is the case, for exam­p­le, with the pro­ce­s­sing of so-cal­led “geo­da­ta” (“loca­ti­on data”) as well as with data pro­ce­s­sing that has been coll­ec­ted by third par­ties. Both con­stel­la­ti­ons requi­re at least one addi­tio­nal cri­ter­ion in order to trig­ger a data pro­tec­tion impact assess­ment if necessary.
  • The EDSA is also of the opi­ni­on that employee moni­to­ring mea­su­res may trig­ger a data pro­tec­tion impact assess­ment if they meet the cri­ter­ion of “par­ti­cu­lar­ly vul­nerable data sub­jects” as well as that of “syste­ma­tic moni­to­ring”. He encou­ra­ges Mem­ber Sta­tes to expli­ci­t­ly include the­se two cri­te­ria in the list when it comes to employee moni­to­ring mea­su­res and stres­ses – for the sake of con­si­sten­cy – that the inter­pre­ta­ti­on of “syste­ma­tic moni­to­ring” must be based on the Guidelines.