- The European Data Protection Board (EDPB) reviewed national blacklists and calls for their alignment with the Art. 29 guidelines for the uniform application of the GDPR.
- Certain types of data (biometric, genetic) or combinations of criteria always trigger a data protection impact assessment; other processes alone never do.
Since the GDPR entered into force on May 25, 2018, the data protection authorities of 22 EU member states have drawn up so-called “black lists” regarding the criteria for carrying out data protection impact assessments pursuant to Art. 35 GDPR. These lists include criteria which are likely to lead to a high risk to the rights and freedoms of data subjects in the case of data processing operations and thus require a data protection impact assessment. With regard to certain data processing operations, namely those related to the offer of goods and services to data subjects or to behavioral monitoring of such data subjects, as well as processing operations that could significantly restrict the “free movement of data”, such lists must be examined in advance as part of the consistency procedure. The primary purpose of such a procedure is for the data protection authorities of the Member States to cooperate on fundamental issues in order to ensure the uniform application of the GDPR in the individual Member States and thus to take the best possible account of the goal of a single market in data protection law.
Against this background, the European Data Protection Board (“EDSA”), the so-called successor of the Art. 29 Working Party, has examined these “black lists” and published its opinions on the individual lists. An overview of the individual reports can be found here: https://edpb.europa.eu/our-work-tools/consistency-findings/opinions_de. The EDSA has not yet formulated its own criteria for a risk assessment in connection with data protection impact assessments. However, the following principles can be derived from the individual opinions:
- General principles
- With regard to the concept of data protection impact assessment, the guidelines issued by the Art. 29 Working Party in Working Paper 248 https://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=611236 The EDSA encourages Member States to mention this fact in their lists and to state that their lists are to be understood as implementing provisions of the Guidelines. The EDSA encourages Member States to mention this fact in their lists and to state that their lists are to be understood as implementing provisions to the Guidelines.
- Against this backdrop, the criteria formulated in the guidelines regarding the assessment of the necessity of a data protection impact assessment are to be decisive for the further development of the lists. The so-called “black” and “white” lists are therefore to be drawn up on the basis of these, whereby a data protection impact assessment must always be carried out if two criteria are met.
- Even if the lists are to be drawn up against the background of the goal of as uniform an implementation as possible, this does not mean that they have to be the same; the national data protection authorities must nevertheless be given sufficient discretion in drawing up their lists when it comes to taking national specifics into account; the primary goal should be to avoid significant inconsistencies in the implementation of Art. 35 GDPR, which could result in different levels of protection for the data subjects concerned.
2. Criteria-specific principles
- Certain data processing operations require under given circumstances notwithstanding the requirements of Art. 35 (3) GDPR a data protection impact assessment. In particular, this is the case for data processing in connection with biometric or genetic data. The EDSA has thus stated in its opinions that a data protection impact assessment must be carried out for the relevant processing operations when such data are present in conjunction with another criterion.
- However, certain data processing operations are never sufficient in themselves to trigger an obligation for a data protection impact assessment. This applies, for example, to constellations of joint controllers in which data from differently merged sources are further processed or when data processing is related to interfaces of personal electronic devices.
- Furthermore, a data protection impact assessment is required for certain data processing activities. only The data protection authorities must then check if at least one further criterion is given in addition to the type of data processed. This is the case, for example, with the processing of so-called “geodata” (“location data”) as well as with data processing that has been collected by third parties. Both constellations require at least one additional criterion in order to trigger a data protection impact assessment if necessary.
- The EDSA is also of the opinion that employee monitoring measures may trigger a data protection impact assessment if they meet the criterion of “particularly vulnerable data subjects” as well as that of “systematic monitoring”. He encourages Member States to explicitly include these two criteria in the list when it comes to employee monitoring measures and stresses – for the sake of consistency – that the interpretation of “systematic monitoring” must be based on the Guidelines.