Seminar 11+12 - Data protection in the context of police and criminal justice Flashcards
What are the relevant provisions?
GDPR Art. 2: Scope
LED art. 1(1): Subject-matter
LED art. 2: Scope
LED art. 4: Principles
LED art. 8: Lawful grounds for processing
LED art. 10: Processing of special categories of personal data
LED art. 12-18: Rights of the data subject
LED art. 19: Obligations of the controller
LED art. 20: Data protection by design and by default
Is GDPR Art. 2(2)(d): GDPR applicable by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences?
No. That is instead governed by LED Directive 2016/680 (recital 19).
What is the main difference between GDPR and LED?
Whereas GDPR is a regulation and therefore has general application (is binding in its entirety and directly applicable in all Member States), the LED is a directive which has to be implemented in individual MS.
What is the purpose of the LED?
The LED deals with the processing of personal data by data controllers for ‘law enforcement purposes’.
Who is the compentent authority under LED?
Any public authority competent for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties
When does LED not apply?
○ a) outside the scope of Union law or
○ b) Union institutions and bodies
Does the LED contain the principle of transparency?
No, The directive does not contain the principle of transparency and the principles of data minimization and purpose limitation needs to be applied flexibly in security-related processing.
What are the grounds of Processing of personal data? (LED)
● Art. 8: Processing is lawful only when it occurs to the extent necessary to perform the relevant task (one option in LED, six options in GDPR)
What are the grounds of Processing of sensitive data? (LED)
● Art. 10: If sensitive personal data, it must be strictly necessary (three options in LED, ten options in GDPR)
What is the difference with regards ti consent in LED vs. GDPR?
Personal data cannot be processed on the basis of a consent (contrary to GDPR) – the legal basis must be found in LED art. 8 or 10
What is different with controllers in LED vs. GDPR?
Data controllers are competent public authorities (contrary to GDPR, where “everyone” can be a controller).
What is EU-US Umbrella Agreement?
● It covers all processing of personal data necessary for the prevention, investigation, detection, and prosecution of criminal offences, including terrorism.
What does the e-Privacy Directive apply to?
○ i) telecommunication operators,
○ ii) who transmit electronic communication between communicating parties and who are able to store and process data regarding this communication
Data Retention Directive was declared invalid under what case?
DRI case
In the absence of specific legislation on data retention, as an exception to the confidentiality of telecommunications data under Directive 2002/58/EC (E-Privacy Directive), telecommunications data can be retained, but must be solely for the purpose of what?
fighting serious crime, cf. E-Privacy Directive art. 15.