Print

Opinions Prior Check and Prior Consultations

Some of the procedures that EU institutions put in place pose risks to the data protection rights and freedoms of individuals.

Under the old legal framework (Regulation (EC) 45/2001), EU institutions were obliged to notify us before putting in place risky data processing operations.

In general, our prior checking Opinions were public.

Regulation 2018/1725 builds on the old Regulation and mirrors the General Data Protection Regulation (EU) 2016/679 (GDPR) that applies to most organisations processing personal data in the Member States. Compared to the previous rules, Regulation 2018/1725 aligns documentation obligations more closely to the risks caused by processing personal data. This means for example that the documentation requirements for a EUI’s newsletter subscription will be lower than for a system using ‘intelligent CCTV’ covering publicly accessible space or a database profiling travellers for screening purposes.

Depending on the process at hand, EU institutions processing personal data ('controllers') may not have to go through all the steps below (these steps are described in the Accountability on the ground toolkit): 
• Generate basic documentation (called ‘records’) for all processes; 
• Check if the process is likely to result in high risks to the people whose data are processed and consult the DPO if it appears to do so; 
• If the EU institution needs to do a data protection impact assessment (DPIA), they analyse those risks in more detail and develop specific safeguards/controls to manage them; 
• If the results of the DPIA still indicate high residual data protection risks, the EU institution has to file a prior consultation with the EDPS (see Articles 40 and 90 of Regulation 2018/1725 respectively for administrative and operational personal data).

Article 39 of Regulation 2016/794 on Europol provides for an ad hoc prior consultation mechanism for new type of processing of operational data, namely data processed by Europol to support the Member States in preventing and combating serious crime and terrorism. Similarly, Article 72 of Regulation 2017/1939 on the European Public Prosecutor Office (EPPO) provides a specific prior consultation mechanism for the processing of operational data, namely data processed in the context of criminal investigations and prosecutions undertaken by the EPPO. Regulation 2018/1725, including the standard prior consultation mechanism, applies to Europol's and EPPO's processing of administrative data, which includes data on staff and visitors, for example.

Where an EU institution is unsure whether to notify us a data processing operation for prior consultation, their DPO can consult us for advice to confirm.

As for the old prior checking Opinions, in general the prior consultation Opinions are public, but we may delete sensitive elements where necessary, related to security for example. Some opinions, which are by nature sensitive, in particular in the police and justice area, may not be published. For the sake of transparency, these Opinions are summarised in our Annual Report.

Filters

25
Nov
2008

Probationary period reports - OHIM

Opinion of 25 November 2008 on a notification for prior checking concerning "Probationary Period Reports" (Case 2008-432)

OHIM Reporting Officers draft Probationary Period Reports and Management Capacities Assessments which aim to assess the performance of newly recruited officials and temporary/contractual agents as well as the management competences of officials appointed in management positions. The processing is carried out under the responsibility of OHIM Career and Development Sector which is part of the OHIM Human Resources Department.

The Prior Check Opinion gives recommendations to ensure full compliance with Regulation 45/2001, in particular, among others, it suggests that OHIIM (i) sets out an appropriate time-limit for the storage of the personal files; (ii) reminds all recipients of their obligation not to use the data received for any further purpose than the one for which they were transmitted and, (iii) inserts in the "Probation Period Report" data protection information in light of Article 12 of the Regulation as suggested in this Opinion.

Available languages: English, French
25
Nov
2008

Attestation - Economic and Social Committee

Opinion of 25 November 2008 on a notification for prior checking on the attestation procedure (Case 2008-476)

The Economic and Social Committee is organising a selection procedure for officials authorised to follow the attestation exercise. The attestation procedure comprises three stages: publication of a call for applications; establishment of a list of applicants admitted to the attestation procedure; attestation in posts recognised as being of "Qualified Assistant" level.

The EDPS has examined the processing of personal data in the attestation procedure and has concluded that it does not appear to involve any infringement of the provisions of Regulation (EC) No 45/2001, if certain recommendations are followed, in particular if the responsible department changes the period for which data are stored, establishes a procedure to be followed in the event of a request for access or rectification, and provides information to data subjects in accordance with Articles 11 and 12 of the Regulation.

Available languages: English, French
19
Nov
2008

Recording the line reserved for calls to the dispatch centre for technical services - Commission

Opinion of 19 November 2008 on the notification for prior checking from the Data Protection Officer of the European Commission in relation to the dossier on recording the line reserved for calls to the dispatch centre for technical services in European Commission buildings in Brussels (Case 2008-491)

Available languages: English, French
19
Nov
2008

Invalidity procedure - EESC

Opinion of 19 November 2008 on the notification for prior checking on the invalidity procedure (Case 2008-555)

Article 59(4) of the Staff Regulations of Officials of the European Communities provides that "The Appointing Authority may refer to the Invalidity Committee the case of any official whose sick leave totals more than 12 months in any period of three years". Based on that Article, the European Economic and Social Committee has established a procedure to obtain a decision from the Invalidity Committee as to whether the official concerned should be granted invalidity or should resume professional activities. In fact the procedure concerns not only officials but also temporary and contract staff.

The proposed processing would not appear to involve any infringement of the provisions of Regulation (EC) No 45/2001 provided that the EESC gives appropriate guarantees regarding long term data storage, informs recipients that they may not use the data for other purposes, revises the information provided and the arrangements for providing it, and finally clarifies the rights of access granted to data subjects.

Available languages: English, French
18
Nov
2008

Individual medical files - Commission

Opinion of 18 November 2008 on the notification for prior checking regarding the "management of individual medical files - Brussels, Luxembourg" case (Case 2004-225)

The opinion of the EDPS concerns the management of medical files by the European Commission. The medical service manages numerous medical files arising from a variety of medical activities to monitor the health of staff and fulfil its obligations to staff under the Staff Regulations.

After thorough analysis in the light of Regulation (EC) No 45/2001, the EDPS has concluded that the processing proposed does not involve any breach of the provisions of Regulation (EC) No 45/2001 provided, in particular, that the Commission:

  • Adopts the pre-employment medical examination form as  adopted by the Interinstitutional Medical Board;
  • States on the annual medical check up form that there is no obligation to take the HIV test;
  • Reviews the annual medical check-up form that records the results of the physical examination and the list of tests required in the light of the principles of adequacy and proportionality;
  • Adopts as a point of good practice the principle that the results of medical examinations carried out by a doctor chosen by the data subject will be passed on to the Commission medical service only with the freely given and informed consent of the employee;
  • Sets a limited period for storing data on persons who are not recruited;
  • Introduces a data access procedure for persons not recruited or others (temporary staff, private employees and scholarship holders working at the Commission in Luxembourg and in the JRCs) in respect of whom medical information has been recorded and who are also entitled to access under Article 13 of Regulation (EC) No 45/2001.
Available languages: English, French