Home / Finance / Personal Data and the Pandemic – Coronavirus Subjugated the Powerful GDPR That Was Once Feared

Personal Data and the Pandemic – Coronavirus Subjugated the Powerful GDPR That Was Once Feared

Europski odbor za zaštitu osobnih podataka dao je još prije mjesec dana odobrenje mjerodavnim zdravstvenim institucijama i poslodavcima da obrađuju osobne podatke pojedinaca u kontekstu krize prouzročene pandemijom
Europski odbor za zaštitu osobnih podataka dao je još prije mjesec dana odobrenje mjerodavnim zdravstvenim institucijama i poslodavcima da obrađuju osobne podatke pojedinaca u kontekstu krize prouzročene pandemijom / Image by: foto

The European Data Protection Board approved, a month ago, that relevant health institutions and employers process personal data of individuals in the context of the crisis caused by the pandemic. Of course, in accordance with national laws.

In the past, companies generally took the stance that it was more cost-effective to risk sanctions than to invest in the security of personal data of the respondents they processed. The General Data Protection Regulation (GDPR), which was adopted in April 2016 and came into effect in May 2018, has significantly changed this approach. By allowing regulators to impose very high monetary fines, the GDPR has encouraged society and companies to strongly advocate for and promote compliance, and consequently, to avoid monetary penalties.

— 

According to previous legislative frameworks governing the protection of personal data, it was considered that companies adequately process and protect personal data, even if they were unaware that they had lost it. However, the GDPR now places the respondent first and strictly prescribes the conditions under which personal data can be collected (the so-called legal basis) and how and by whom it can be processed. Following these significant regulatory changes and such a dramatic shift in data protection regulation, the first established personal data breaches occurred in the last year, and substantial monetary fines were imposed.

Two Most Serious Cases

However, two cases resonated the most precisely because of the amount of the imposed monetary fines. In both cases, the decision on the personal data breach and the monetary fine was made by the British regulator (Information Commissioner’s Office – ICO) in July 2019. In the first case, a fine of £183 million was imposed on British Airways due to inadequate technical and organizational measures that resulted in a breach of approximately 500,000 personal data of its service users due to a cyber attack the company was exposed to in September 2018.

In the second case, a fine of £99 million was imposed on the hotel corporation Marriott International. This corporation acquired Starwood, a hotel group that had previously been exposed to a cyber attack, in 2016. The British regulator justified its decision on the fine by stating that Marriott International did not adequately and sufficiently detail the business operations of the group it was acquiring. It is estimated that in this case, personal data of as many as 339 million guests were compromised.

New Guidelines

The two most serious cases of personal data breaches (and the highest imposed fines!) show that the GDPR requires companies to align all segments of their business with the requirements of personal data protection. Considering the wave of new high monetary fines imposed in the European Union and the current situation caused by the COVID-19 pandemic, it is important to reflect on the recent guidelines from relevant EU bodies for interpreting the application of the GDPR concerning personal data of individuals affected by COVID-19 processed by national governments and employers.

Namely, the European Data Protection Board (EDPB) issued guidelines for the processing of personal data as a professional response to the measures taken by numerous European governments and relevant national health institutions in the fight against the pandemic caused by COVID-19 (Guideline). In the introduction, the EDPB emphasizes that the GDPR, as the fundamental regulation governing the processing of personal data, does not necessarily and automatically prohibit measures that are adopted and applied in the fight against the pandemic, but emphasizes that data controllers and processors must adhere to the fundamental principles of personal data protection regardless of the pandemic; therefore, processing during these crisis times must be lawful, and the measures taken must be adapted to the circumstances.

Legality of Data Processing

The rules established by the GDPR regarding the processing of personal data are very broad and provide conditions for processing even in situations like this crisis caused by the coronavirus. It thus provides for the powers of relevant health institutions and employers to process personal data of individuals in the context of the pandemic crisis in accordance with national laws and the guidelines from the Guideline when such processing is necessary to protect the national interest of ensuring public health. In such exceptional cases, the obligation to rely on the consent of the respondent may be excluded, of course, provided that all other requirements for valid processing of personal data are met.

In cases where personal data are processed during the crisis by public bodies (e.g., public health institutions), including special categories of personal data (health data), the EDPB considers that processing is permitted within the legal mandate of the public body and in accordance with national laws and the fundamental principles of the GDPR. Thus, personal data related to health (and other special categories of personal data), which are otherwise not permitted to be processed, may be processed if such processing is necessary for the purpose of ensuring public health, preventing cross-border health threats, or ensuring high standards of quality and safety of healthcare and medicines and medical products, provided that such (extraordinary) measures are based on law.

Telecommunications Data

Regarding the processing of telecommunications data such as, for example, the location data of respondents, the obligation to comply with the ePrivacy Directive is emphasized. In this sense, the location data processed by the operator may only be used if they are anonymized or if the respondent has given consent for their processing. However, the Directive allows EU member states to adopt national laws that provide for public safety measures. These exceptional national regulations are only lawful if the measures for the use of location data are proportional to the measures for the protection of the democratic order. In cases of exceptional crisis situations, such as a pandemic and a crisis caused by the coronavirus, the measures must be strictly time-limited to the duration of the crisis for which they were introduced.

{embed_digitalno_izdanje}{/embed_digitalno_izdanje}