Print

Opinions Prior Check and Prior Consultations

Some of the procedures that EU institutions put in place pose risks to the data protection rights and freedoms of individuals.

Under the old legal framework (Regulation (EC) 45/2001), EU institutions were obliged to notify us before putting in place risky data processing operations.

In general, our prior checking Opinions were public.

Regulation 2018/1725 builds on the old Regulation and mirrors the General Data Protection Regulation (EU) 2016/679 (GDPR) that applies to most organisations processing personal data in the Member States. Compared to the previous rules, Regulation 2018/1725 aligns documentation obligations more closely to the risks caused by processing personal data. This means for example that the documentation requirements for a EUI’s newsletter subscription will be lower than for a system using ‘intelligent CCTV’ covering publicly accessible space or a database profiling travellers for screening purposes.

Depending on the process at hand, EU institutions processing personal data ('controllers') may not have to go through all the steps below (these steps are described in the Accountability on the ground toolkit): 
• Generate basic documentation (called ‘records’) for all processes; 
• Check if the process is likely to result in high risks to the people whose data are processed and consult the DPO if it appears to do so; 
• If the EU institution needs to do a data protection impact assessment (DPIA), they analyse those risks in more detail and develop specific safeguards/controls to manage them; 
• If the results of the DPIA still indicate high residual data protection risks, the EU institution has to file a prior consultation with the EDPS (see Articles 40 and 90 of Regulation 2018/1725 respectively for administrative and operational personal data).

Article 39 of Regulation 2016/794 on Europol provides for an ad hoc prior consultation mechanism for new type of processing of operational data, namely data processed by Europol to support the Member States in preventing and combating serious crime and terrorism. Similarly, Article 72 of Regulation 2017/1939 on the European Public Prosecutor Office (EPPO) provides a specific prior consultation mechanism for the processing of operational data, namely data processed in the context of criminal investigations and prosecutions undertaken by the EPPO. Regulation 2018/1725, including the standard prior consultation mechanism, applies to Europol's and EPPO's processing of administrative data, which includes data on staff and visitors, for example.

Where an EU institution is unsure whether to notify us a data processing operation for prior consultation, their DPO can consult us for advice to confirm.

As for the old prior checking Opinions, in general the prior consultation Opinions are public, but we may delete sensitive elements where necessary, related to security for example. Some opinions, which are by nature sensitive, in particular in the police and justice area, may not be published. For the sake of transparency, these Opinions are summarised in our Annual Report.

Filters

3
Oct
2007

Attestation procedure - Court of Justice

Opinion of 3 October 2007 on the notification for prior checking concerning the attestation procedure (Case 2007-435)

The Court of Justice adopted the implementing rules for the attestation procedure by decision of the Court's Administrative Committee on 15 June 2005. Officials employed in categories C and D on 1 May 2004 are likely to have promotions capped at grades AST 7 and 5 respectively. These ceilings may be abolished, however, by an "attestation" procedure. This procedure is based on criteria relating to seniority, experience, merit and level of training and depends on the availability of posts in the AST function group.

The main recommendations made by the EDPS in his opinion on the attestation procedure concern data storage and the provision of information to data subjects.

Available languages: English, French
17
Sep
2007

Selection of senior officials - Commission

Opinion of 17 September 2007 on a notification for prior checking regarding the selection of senior officials (Case 2007-193)

DG ADMIN organises and manages the selection process of senior officials in the Commission in order to select the best suited candidates for a particular position. The positions are open to internal candidates and in some cases vacancies are also open to external candidates.  In order to select the best suited candidates, applicants have to follow various procedures (prior eligibility tests, interviews with pre-selection panel, analysis and opinion of the Consultative Committee on Appointments, etc). Such procedures entail the collection and further processing of candidates' personal data for the purposes of evaluating their competences for a given position.   
 
In his opinion, the EDPS concluded that the DG ADMIN has substantially followed all the principles of the Regulation. Nevertheless the EDPS recommended, among others, that DG ADMIN: 
  • Clarifies and reconsiders the storage periods.
  • Limits the amount of information transferred during the first phase of the procedure
  • Ensures that applicants have access to their file. 
  • Ensure that access to the data held by the sub-contractor is not limited to an "oral feedback ".   
  • Amend the privacy policy as recommended in the Opinion.
  • Raise awareness among DG ADMIN A5 and DG ADMIN CCN-Proc regarding the need to ensure the confidentiality of the information.
  • Implement as soon as possible the security measures intended to enhance the security of the information held and exchanged electronically.
Available languages: English, French
13
Sep
2007

Medical check-ups - EMCDDA

Opinion of 13 September 2007 on the notification for prior checking regarding pre-employment and annual medical check-ups (Case 2007-348)
At the EMCDDA, the medical check-ups (pre-employment medical check ups and annual medical check ups) are carried out by a qualified medical doctor, carrying out the medical examination on behalf of the EMCDDA. The results of these medical check ups are communicated by the doctor to the medical officer, member of staff at the EMCDDA. The medical files are kept by the EMCDDA medical officer.

The pre-employment medical check-up is carried out only after the candidate has already received a formal offer of employment. To this effect these candidates receive a standard letter convening them to a pre-employment medical examination with the medical doctor carrying out the examination on behalf of the EMCDDA. A medical questionnaire is attached to this letter, to be completed in part by the candidate and duly signed by him/her. In addition, the medical doctor carrying out the medical examination on behalf of the EMCDDA, performs a direct physical examination and completes the medical overview form. The results of the medical exam are communicated to the person concerned and to the medical officer of the EMCDDA. The HR Management sector only receives a medical certificate stipulating the person's ability or inability or ability with a reserve clause.
 
As in the case of the pre-employment medical check-up, during the annual medical check-up, the medical doctor carries out a direct physical examination. Should a member of the staff decide to have the annual medical check-up performed by a doctor of his choice he will receive the list of exams to be carried out from HR and go for the tests and the visit. The staff member is requested to send a copy of the outcome to the EMCDDA, not the results of the specific tests that remain with him/her. The only information circulated to the financial services is the list of the exams and the relative costs as invoiced for the tests.
 

After examining the case, the EDPS concluded that there is no reason to believe that there is a breach of the provisions of Regulation 45/2001 providing that certain considerations are fully taken into account. Notably certain data in the medical questionnaire must be re-assessed in the light of the principles of adequacy, relevance, and proportionality for purposes of assessment of fitness for service and assistance in determination of limitations with respect to death or invalidity benefits for the first five years of service; the EMCDDA evaluates to what extent and for what purposes the content of a medical file needs to be kept and determines a conservation period concerning data relating to persons who have been submitted to a medical exam, but who then refuse employment; and that the EMCDDA reconsiders the procedure of communication of data relating to the medical exams undertaken with a private doctor to the financial services with the aim of reconciling the data subject's right to privacy and the obligations of the financial services.

Available languages: English, French
11
Sep
2007

Conflict of interest of special advisers - Commission

Opinion of 11 September 2007 on a notification for prior checking on verification of lack of conflict of interest of special advisers and its publication on Europa website (Case 2007-294)

The European Commission can engage a special adviser who, by reason of his/her special qualifications, assists the Commission either regularly or for a specified period. Before the engagement, the Commission analyses the activities of special advisers in order to avoid conflict of interest with their future activity as special advisers. Then, the special advisers' name, CV, photo, mandate as well as the declaration on honour will be published on the Europa website.
 
The EDPS has issued an opinion on the verification of lack of conflict of interest of special advisers and on publication of their personal data on Europa website. The EDPS concludes that on a general basis the procedure complies with the principles established in the data protection regulation. However the EDPS did make some recommendations mainly as concerns raising awareness regarding the publication of potentially sensible personal data on the Europa website. The EDPS suggested that the publication of the special advisers' photo should be optional and that the Commission staff should verify, before the publication on the Europa website, if the data included by the special adviser in his/her Curriculum Vitae are not irrelevant or excessive in relation to the purpose of the processing.
Available languages: English, French
10
Sep
2007

Medical service - Commission

Opinion of 10 September 2007 on the notification for prior checking on the "Management of the activities of the Medical Service in Brussels and Luxembourg, in particular via the SERMED computer application" (Case 2004-232)

The Medical Services in Brussels and Luxembourg use the SERMED database for the day-to-day management of their activities. This database supports the management of medical activities in the fields of preventive and occupational medicine as well as medical check-ups. SERMED can be used to record certain information necessary for the procedures which the Medical Service must carry out: medical examinations, the management of medical absences and check-ups, invalidity procedures and occupational accidents. This information is sorted into lists over a certain period of time (the "reporting" module). As well as SERMED, the Medical Service in Brussels uses another application (DREC) to follow up requests for the reimbursement of additional tests and other medical expenses.

The EDPS concluded in his prior checking that the proposed processing operation does not appear to involve any infringement of the provisions of Regulation (EC) No 45/2001 provided account is taken of the comments made below. In particular, this implies that the Commission:

  • having regard to the particularly sensitive nature of the information included in SERMED, should remind persons having access to SERMED of the confidentiality requirement;
  • should point out to SERMED users that the field "comment" must contain only administrative data;
  • should remove the reference to the doctor's specialisation as indicated on the medical certificate in SERMED;
  • should keep the EDPS informed of the introduction of the module facilitating access to information relating to the person concerned.
Available languages: English, French