{"id":1694,"date":"2022-06-02T12:42:18","date_gmt":"2022-06-02T09:42:18","guid":{"rendered":"https:\/\/fzmayuxbif.wpdns.site\/?p=1694"},"modified":"2023-07-07T13:04:39","modified_gmt":"2023-07-07T10:04:39","slug":"general-data-protection-regulation-4-years-since-the-implementation-of-the-gdpr","status":"publish","type":"post","link":"https:\/\/www.kyprianou.com\/de\/general-data-protection-regulation-4-years-since-the-implementation-of-the-gdpr\/","title":{"rendered":"General Data Protection Regulation &#8211; 4 years since the implementation of the GDPR"},"content":{"rendered":"<div class=\"ed_body\">\n<p>The General Data Protection Regulation 2016\/679 (the \u201cGDPR\u201d and\/or the \u201cRegulation\u201d) has been implemented as of 25 May 2018. As per the\u00a0<a href=\"https:\/\/ec.europa.eu\/info\/law\/law-topic\/data-protection\/data-protection-eu_en\">European Commission\u2019s descriptions<\/a>\u00a0of the legislative framework, the GDPR\u00a0<em>is an essential step to strengthen individuals\u2019 fundamental rights in the digital age and facilitate business by clarifying rules for companies and public bodies in the digital single market<\/em>.<\/p>\n<p>Following an\u00a0<a href=\"https:\/\/www.dataprotection.gov.cy\/dataprotection\/dataprotection.nsf\/All\/A9BD0A2D32A17116C225884C003D6B27?OpenDocument\">announcement<\/a>\u00a0made on 24 May 2022, the Cyprus Commissioner for the Protection of Personal Data has identified the importance of the GDPR and the benefits offered to businesses, applying a common rule and enjoying a reduction in their administrative expenses because of this common framework. The Commissioner\u2019s announcement also identified the number and value of administrative penalties imposed during these four years, since the GDPR\u2019s implementation.<\/p>\n<p>One of the most interesting cases examined by the Commissioner\u2019s office was in November 2021. An administrative fine of\u00a0<a href=\"https:\/\/www.dataprotection.gov.cy\/dataprotection\/dataprotection.nsf\/All\/D7D2A1120DDE670AC225878B0040D4E7?OpenDocument\">\u20ac 925,000<\/a>\u00a0was imposed on a company in respect of the violation of Art. 5(1) of the GDPR. This case is interesting because of the value of the administrative penalty imposed as it is the highest administrative penalty imposed in Cyprus in relation to the violation of the provisions of the GDPR by the Commissioner\u2019s office up to date. It is also significant because of the circumstances and facts of what actually happened. The fine concerns the violation of the principle of legality, fairness and transparency.<\/p>\n<p>On its own initiative the Commissioner\u2019s Office undertook the investigation into the matter, together with the police\u2019s cooperation. After the completion of the relevant criminal investigation by the police and the preparation of the file submitted to the Law Office of the Republic, the company was notified of the relevant findings. The company in turn notified the Commissioner\u2019s Office that it admitted to the violation of the provisions of the GDPR.<\/p>\n<p>The said company\u2019s business operations included the collection of MAC Address (Media Access Control Address) and IMSI (International Mobile Subscriber Identity) data from a number of devices. The users of the said devices were not aware that such data were collected. The Commissioner, with her decision, clarified that MAC Addresses are unique numbers that identify a device when connected with the internet. The IMSI is also a unique number included in SIM cards (Subscriber Identity Module) that can recognize a subscriber when connected with its provider\u2019s network. These data in combination with the geo\u2013location of a device, at different times, may lead to the identification of the user of the device. This fact was the basis of the Commissioner\u2019s decision, after having taken into consideration all relevant aggravating and mitigating factors. The Commissioner noted that there was no device monitoring or intercepting any private communication.<\/p>\n<p>As stipulated in the\u00a0<a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A02016R0679-20160504&amp;qid=1532348683434\">GDPR (Art. 5(1))<\/a>, the first principle is that personal data shall be\u00a0<em>processed lawfully, fairly and in a transparent manner in relation to the data subject<\/em>. This principle in effect requires that the controller must, amongst others:<\/p>\n<ul>\n<li>identify valid grounds (\u201clawful basis\u201d) under the GDPR for collecting and using (processing) personal data;<\/li>\n<li>ensure that the personal data are not used (processed) in breach of any other laws;<\/li>\n<li>ensure that the personal data are used only in a way that is fair; and<\/li>\n<li>ensure that the use (processing) of the data is transparent, i.e. there is clarity, honesty and transparency as to the processing of the personal data.<\/li>\n<\/ul>\n<p>It can be argued that one of the GDPR\u2019s first principles may be considered as a \u201ccatch-all\u201d provision. All three elements must be satisfied in order for the principle to be considered as fulfilled. It is not enough for a controller to show that they only satisfy part of these elements.<\/p>\n<p>Lawfulness is usually satisfied by identifying the specific legal grounds for which a controller processes personal data. At least one of the following must apply:<\/p>\n<ul>\n<li>consent \u2013 must always be specific, informed and unambiguous as to the data subject\u2019s intention; or<\/li>\n<li>performance of a contract\u00a0\u2013 whereby the data subject is a party at the time or prior to entering into such a contractual arrangement with the data subject; or<\/li>\n<li>legal obligation\u00a0\u2013 the processing of the data is necessary for compliance with legislative provisions; or<\/li>\n<li>vital interests\u00a0\u2013 processing of the data is necessary for the protection of the data subject\u2019s or of another natural person\u2019s life;<\/li>\n<li>public interest \u2013 the processing is necessary for the performance of a task in the public interest or in the exercise of official authority vested in the controller;<\/li>\n<li>legitimate interests \u2013 the processing is necessary to pursue the controller\u2019s legitimate interests provided that these interests are not overridden by the interests or the fundamental rights and freedoms of a data subject.<\/li>\n<\/ul>\n<p>On its own fairness is also a general term. Fairness refers to the obligation to handle personal data in ways that they would be reasonably perceived as fair. The intention of the lawmakers of the GDPR was obviously to ensure that the controller would not withhold information as to the reasons why personal data are being collected and that such data are not misused or unfairly used.<\/p>\n<p>Similarly, transparency is linked to lawfulness and fairness. The underlying purpose is for the controllers to provide clear, open, transparent and honest information with the data subjects as to who, why and how their personal data are being processed.<\/p>\n<p>The aforementioned are only a part of the basic principles of the GDPR. As the intention of the GDPR is to set out the data controllers\u2019 and data processors\u2019 responsibilities, and to ensure that all processing activities and business practices that are being followed, from an organization\u2019s design stage to the fulfilment of their data processing, are correctly implemented and in accordance with the Regulation.<\/p>\n<p>It is therefore evident that the Office of the Data Commissioner fairly and rightfully, as it is within its discretionary powers, has applied such a high penalty to the company which failed to comply with the most basic principle of the GDPR. It only remains to be seen whether any other administrative penalties exceeding this penalty will be imposed. It is worth mentioning that Art. 83(4) of the Regulation provides for administrative fines of up to \u20ac10,000,000 (ten million Euros) or up to 2% of an undertaking\u2019s worldwide annual turnover of the preceding financial years, whichever is the higher.<\/p>\n<p><em>The content of this article is valid as at the date of its first publication. It is intended to provide a general guide to the subject matter and does not constitute legal advice. We recommend that you seek professional advice on a specific matter before acting on any information provided.<\/em><\/p>\n<p><em>For further information, please contact\u00a0<a href=\"https:\/\/www.kyprianou.com\/en\/people\/ioanna-solomou\/ppp-501\/6\/\">Ioanna Solomou<\/a>, Partner at Michael Kyprianou &amp; Co LLC, via email at\u00a0<\/em><a href=\"mailto:ioanna.solomou@kyprianou.com\">ioanna.solomou@kyprianou.com<\/a><em>\u00a0or by\u00a0<\/em><em>telephone +357 25 363685.<\/em><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The General Data Protection Regulation 2016\/679 (the \u201cGDPR\u201d and\/or the \u201cRegulation\u201d) has been implemented as of 25 May 2018. As per the\u00a0European Commission\u2019s descriptions\u00a0of the legislative framework, the GDPR\u00a0is an essential step to strengthen individuals\u2019 fundamental rights in the digital age and facilitate business by clarifying rules for companies and public bodies in the digital [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1707,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_analysis_target_kw":"","site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[592],"tags":[],"location":[342],"expertises":[768],"key_contact":[335],"class_list":["post-1694","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dimosiefseis","location-kypros","expertises-prostasia-prosopikon-dedomenon-idiotikotita-kypros","key_contact-ioanna-solomou-el"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/posts\/1694","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/comments?post=1694"}],"version-history":[{"count":0,"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/posts\/1694\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/media\/1707"}],"wp:attachment":[{"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/media?parent=1694"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/categories?post=1694"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/tags?post=1694"},{"taxonomy":"location","embeddable":true,"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/location?post=1694"},{"taxonomy":"expertises","embeddable":true,"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/expertises?post=1694"},{"taxonomy":"key_contact","embeddable":true,"href":"https:\/\/www.kyprianou.com\/de\/wp-json\/wp\/v2\/key_contact?post=1694"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}