
Privacy in the EU Institutions

Regulation (EU) 2018/1725 lays down the data protection obligations for the EU institutions, bodies and agencies when they process personal data and develop new policies. This regulation also defines the obligations of the EDPS, including his role as an independent supervisory authority of EU institutions and bodies when they process personal data, and to advise on policies and legislation which affect privacy and cooperate with similar authorities to ensure consistent data protection.






Time and absence management - ECDC

Opinion of 22 June 2009 on the notification for prior checking concerning "Time and absence management" (Case 2009-072)
On 22 June 2009, the EDPS adopted an opinion on time and absence management at the European Center for Disease Prevention and Control (ECDC). The EDPS considers that the processing is lawful to the extent that it is limited to the purpose of time and absence management and that it does not lead to monitor on a regular basis the staff to evaluate personal aspects of the data subject, such as his/her ability, efficiency or conduct. Specific guarantees should be implemented as regards the processing of sensitive data, and in particular the ECDC should ensure that certificates containing medical data are sent by data subjects to an external medical service. The EDPS stresses that the right of an individual to access and rectify personal data concerning him or her should be ensured to all data subjects whom data are processed including trainees and family members, whatever the format in which such data are processed. The EDPS insists that ECDC must determine appropriate periods for the conservation of personal data.

Available languages: English, French