European Data Protection Supervisor
   HOME

TheInfoList



OR:

The European Data Protection Supervisor (EDPS) is an independent supervisory authority whose primary objective is to monitor and ensure that European institutions and bodies respect the right to
privacy Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively. The domain of privacy partially overlaps with security, which can include the concepts of ...
and
data protection Information privacy is the relationship between the collection and dissemination of data, technology, the public expectation of privacy, contextual information norms, and the legal and political issues surrounding them. It is also known as data p ...
when they process
personal data Personal data, also known as personal information or personally identifiable information (PII), is any information related to an identifiable person. The abbreviation PII is widely accepted in the United States, but the phrase it abbreviates ha ...
and develop new policies. Wojciech Wiewiórowski has been appointed European Data Protection Supervisor (EDPS) by a joint decision of the European Parliament and the Council. Appointed for a five-year term, he took office on 6 December 2019. Regulation (EU) 2018/1725 describes the duties and powers of the European Data Protection Supervisor (Chapter VI) as well as the institutional independence of the EDPS as a supervisory authority. It also lays down the rules for data protection in the EU institutions.


Activities

The duties and powers of the EDPS, as well as the institutional independence of the supervisory authority, are set out in the "Data Protection Regulation". In practice the EDPS' activities can be divided into three main roles: supervision, consultation, and cooperation.


Supervision

In the "supervisory" role the EDPS' core task is to monitor the processing of personal data in European institutions and bodies. The EDPS does so in cooperation with the data protection officers (DPO) present in each European institution and body. The DPO has to notify the EDPS about any processing operations involving sensitive personal data or likely to pose other specific risks. The EDPS then analyses this processing in relation to the Data Protection Regulation and issues a "prior check" opinion. In most cases, this exercise leads to a set of recommendations that the institution or body needs to implement so as to ensure compliance with data protection rules. In 2009, for instance, the EDPS adopted more than a hundred prior check opinions, mainly covering issues such as health data, staff evaluation, recruitment, time management, telephone recording performance tools, and security investigations. These opinions are published on the EDPS website and their implementation is followed up systematically. The implementation of the Data Protection Regulation in the EU administration is also closely monitored by regular stock-taking of performance indicators, involving all EU institutions and bodies. In addition to this general monitoring exercise, the EDPS also carries out on-site inspections to measure compliance in practice. The supervisory role of the EDPS also involves investigating complaints lodged by EU staff members or any other individual who feels that their personal data have been mishandled by a European institution or body. Examples of complaints include alleged violations of confidentiality, access to data, the right of rectification, erasure of data, and excessive collection or illegal use of data by the controller. The EDPS has also developed other forms of supervision, such as advice on administrative measures and the drafting of thematic guidelines.


Consultation

In the "consultative" role the EDPS advises the
European Commission The European Commission (EC) is the executive of the European Union (EU). It operates as a cabinet government, with 27 members of the Commission (informally known as "Commissioners") headed by a President. It includes an administrative body ...
, the
European Parliament The European Parliament (EP) is one of the Legislature, legislative bodies of the European Union and one of its seven Institutions of the European Union, institutions. Together with the Council of the European Union (known as the Council and in ...
, and the
Council of the European Union The Council of the European Union, often referred to in the treaties and other official documents simply as the Council, and informally known as the Council of Ministers, is the third of the seven Institutions of the European Union (EU) as ...
on data protection issues in a range of policy areas. This consultative role relates to proposals for new legislation as well as other initiatives that may affect personal data protection in the EU. It usually results in a formal opinion, but the EDPS may also provide guidance in the form of comments or policy papers. Technological developments having an impact on data protection are also monitored as part of this activity. Some recent significant issues to which the EDPS has given special attention include international data transfers, internet governance, rebuilding trust between the EU and the US, eCommunications, cybersecurity, and the future of the area of freedom, security, and justice (
Stockholm Programme The Stockholm Programme is a five-year plan with guidelines for justice and home affairs of the member states of the European Union for the years 2010 through 2014. Contents The programme contains guidelines for a common politics on the topics of ...
). The EDPS is also closely following the ongoing review of the legal framework for data protection aimed at modernising the
Data Protection Directive The Data Protection Directive, officially Directive 95/46/EC, enacted in October 1995, is a European Union directive which regulates the processing of personal data within the European Union (EU) and the free movement of such data. The Data Pro ...
in response to new globalisation and technological challenges. Realising this critical objective will be the dominant item on the EDPS' agenda over the coming years. As part of his consultative role, the EDPS also intervenes in cases before the
European Court of Justice The European Court of Justice (ECJ, french: Cour de Justice européenne), formally just the Court of Justice, is the supreme court of the European Union in matters of European Union law. As a part of the Court of Justice of the European U ...
that are relevant to his tasks. In June 2009 for instance, he intervened in a case concerning the relationship between transparency and data protection – the so-called "Bavarian Lager" case.


Cooperation

The EDPS cooperates with other data protection authorities in order to promote a consistent approach to data protection throughout Europe. The main platform for cooperation between data protection authorities in Europe is the Article 29 Data Protection Working Party. The EDPS takes part in the activities of the Working Party, which plays an important role in the uniform application of the Data Protection Directive and the superseding
General Data Protection Regulation The General Data Protection Regulation (GDPR) is a European Union regulation on data protection and privacy in the EU and the European Economic Area (EEA). The GDPR is an important component of EU privacy law and of human rights law, in par ...
(GDPR). The EDPS and the Working Party have cooperated effectively on a range of subjects, but particularly on the implementation of the Data Protection Directive and on the challenges raised by new technologies. The EDPS also strongly supported initiatives taken to ensure that international data flows respect European data protection principles One of the most important cooperative tasks of the EDPS involves
Eurodac European Dactyloscopy (Eurodac) is the European Union (EU) fingerprint database for identifying asylum seekers and irregular border-crossers. After the European Parliament approved the last EURODAC reform poposed by far-right party Vox (December 2 ...
where the responsibilities for supervision are shared with
national data protection authorities There are several National data protection authorities across the world, tasked with protecting information privacy. In the European Union and the EFTA member countries, their status was formalized by the Data Protection Directive and they were ...
. The EDPS cooperates with data protection authorities in the former "third pillar" – the area of police and judicial cooperation – and with the Working Party on Police and Justice. Cooperation also takes place through participation in two major annual data protection conferences: a European Conference that gathers data protection authorities from the EU Member States and the Council of Europe, and an International conference attended by a wide range of data protection experts, both from the public and private sectors.


List of European Data Protection Supervisors


See also

* Article 29 Data Protection Working Party


References


Legal texts


Regulation (EC) No 45/2001
of the European Parliament and of the Council of 18 December 2000 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data (OJ L 8, 12.1.2001, p. 1–22) *
Data Protection Directive The Data Protection Directive, officially Directive 95/46/EC, enacted in October 1995, is a European Union directive which regulates the processing of personal data within the European Union (EU) and the free movement of such data. The Data Pro ...

Directive 95/46/EC
of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (OJ L 281, 23.11.1995, p. 31–50)


EDPS materials


EDPS website

EDPS prior check opinionsEDPS legislative opinionsEDPS Annual ReportEDPS Information brochures


Other relevant materials


Website of the European Commission Data protection officerData protection page of the European ParliamentData protection page of the Council of the European UnionList of national data protection authoritiesList of data protection officers


External links

* {{Authority control Data protection authorities Information technology organizations based in Europe Political offices of the European Union Non-institutional bodies of the European Union