Print

Privacy in the EU Institutions

Regulation (EU) 2018/1725 lays down the data protection obligations for the EU institutions, bodies and agencies when they process personal data and develop new policies. This regulation also defines the obligations of the EDPS, including his role as an independent supervisory authority of EU institutions and bodies when they process personal data, and to advise on policies and legislation which affect privacy and cooperate with similar authorities to ensure consistent data protection.

 

 

 

Filters

19
May
2008

CCTV System - OLAF

Opinion of 19 May 2008 on the notification for prior checking regarding OLAF's CCTV system (Case 2007-634)
This prior checking opinion concerns the closed-circuit television system (CCTV system) operated by the European Anti-Fraud Office (OLAF) within its premises in Brussels for security purposes. The case is the first among the EDPS opinions involving video-surveillance and constitutes a true prior checking case where the EDPS issued his opinion before OLAF started to operate the system.

On the whole, the EDPS was satisfied with the proportionality of the CCTV system and the data protection safeguards implemented by OLAF.

The positive outcome of the EDPS proportionality analysis was based primarily on the grounds that (i) the purposes of the system are clearly delineated, relatively limited, and legitimate and (ii) the location, field of coverage and resolution, and other aspects of the set-up of the CCTV system appear to be adequate, relevant and not excessive in relation to achieving the specified purposes, taking into consideration also the sensitivity of the information held by OLAF.

In particular, the main purpose of OLAF’s CCTV system is protection against unauthorized physical access, in particular, to sensitive operational information and IT equipment. Cameras are only located near exit and entry points to the OLAF secure area and at certain other strategic locations such as certain unattended IT rooms and the OLAF Document Management Centre.

None of the cameras monitor areas where staff would be continuously present and there are no instances where a staff member working in a certain area would be constantly in the field of vision of a camera. There are also no cameras in individual offices, in the cafeteria/kitchen areas, near or in restrooms, or in other areas where staff members and visitors would expect a high degree of privacy. Neither is the cameras' field of vision directed towards parts of the Commission building occupied by others than OLAF. Finally, the cameras' field of vision is also not directed to any areas outside the building on Belgian territory, with a view of neighbouring streets, buildings or other private or public areas.

Nevertheless, the EDPS made important recommendations. First and foremost, it recommended OLAF to reconsider the planned conservation period to ensure that data are kept no longer than necessary for the purposes initially contemplated.

In addition, although OLAF made significant efforts to set appropriate data protection safeguards, improvements could still be made, primarily in the way these safeguards are documented and communicated to data subjects. Importantly, the EDPS recommended that OLAF adopts an internal document describing its CCTV system and providing for appropriate data protection safeguards.

Finally, whereas the EDPS also welcomed OLAF's efforts to provide a layered notice in a user-friendly manner, he further encouraged OLAF to provide more specific and accurate information to data subjects regarding some items listed under Article 12 of the Regulation.

Available languages: English, French
15
May
2008

2007 Annual Report - Enhanced data protection needs to be delivered in practice

The report runs through the main features of the EDPS activities in 2007, notably with regard to his supervisory and consultative tasks.
The report highlights a considerable increase in the number of prior-checks relating to processing operations of personal data in Community institutions and bodies. The EDPS also gave further effect to his advisory role on new EU legislative proposals having an impact on data protection with the publication of 12 opinions. 
2007 saw the signing of the Lisbon Treaty that provides for an enhanced protection of personal data and whose impact for data protection will be closely monitored.

You can obtain a paper version of this Annual Report on EU Bookshop.

Full text of the Annual Report:
Available languages: German, English, Spanish, French, Italian, Polish
Summary:
Available languages: Bulgarian, Czech, Danish, German, Estonian, Greek, English, Spanish, French, Irish, Italian, Latvian, Lithuanian, Hungarian, Maltese, Dutch, Polish, Portuguese, Romanian, Slovak, Slovenian, Finnish, Swedish
14
May
2008

General report "Spring 2007"

General report on "Measuring compliance with Regulation (EC) 45/2001 in EU institutions and bodies"

According to Article 41, paragraph 2 of Regulation (EC) 45/2001, the European Data Protection Supervisor is responsible for monitoring and ensuring the application of the Regulation. In March 2007, the EDPS launched a procedure known as "Spring 2007" as part of an effort to measure compliance with the Regulation in the various institutions and agencies and to take stock of the progress made so far.

Available languages: English, French