0% found this document useful (0 votes)
2 views21 pages

Cippe - Module 8

This module discusses compliance considerations for EU data protection law in contexts such as employment and monitoring. It outlines the legal bases for processing employee personal data, the handling of sensitive data, and the implications of Bring Your Own Device (BYOD) policies. Additionally, it emphasizes the importance of balancing employee rights with employer interests in monitoring practices and the necessity of transparency and proportionality in such activities.

Uploaded by

asd39499
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views21 pages

Cippe - Module 8

This module discusses compliance considerations for EU data protection law in contexts such as employment and monitoring. It outlines the legal bases for processing employee personal data, the handling of sensitive data, and the implications of Bring Your Own Device (BYOD) policies. Additionally, it emphasizes the importance of balancing employee rights with employer interests in monitoring practices and the necessity of transparency and proportionality in such activities.

Uploaded by

asd39499
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

EUROPEAN DATA PROTECTION

ONLINE TRAINING TRANSCRIPT


MODULE 8: COMPLIANCE CONSIDERATIONS

Introduction
This module examines special considerations for complying with EU data protection law and regulation,
specifically in the context of employment, surveillance activities, direct marketing, and internet
technology and communications.

Processing employee personal data


Processing employee personal data

The mix of EU data protection law with local employment law can make compliance relating to
employment complicated. Local employment law varies considerably across the EU, and, under Article
88 of the GDPR, member states may by law or collective agreements provide for more specific rules
around processing employees’ personal data. These rules must include suitable and specific measures
to safeguard the data subject’s:

Human dignity

Legitimate interests

And fundamental rights

with particular regard for:

Transparency of processing

Transfer of personal data within a group of undertakings or a group of enterprises engaged in


joint economic activity

And monitoring systems

Instructor video: Processing employee personal data

Here we are specifically looking at the employee context and what happens when as an organisation
you want to maintain an employment relationship. Now, inevitably, if you are going to have
employees, you are going to collect data about them, and that data, much of it, is going to be personal
data. It’s going to be information that relates to and identifies or is identifiable information and is
information about those employees, so it will be personal. As a consequence of that, there are a few
things you have to think about: The first is going to be, okay, if I am going to collect this data, if you
remember under the GDPR, you have to show there is lawful basis that allows you to collect and
process data. Here’s the question: What would be your lawful basis for collecting and using employee
data?

Legal grounds for processing employee personal data

©2023, International Association of Privacy Professionals, Inc. (IAPP)


2

Under the GDPR, first there must be a lawful basis for collecting and processing personal data. The
legal bases are the grounds employers may rely on to process employee personal data. Click on each
basis for examples of when they may be appropriate to use.

Fulfilment of an employment contract: Collecting and using bank account information to process
salaries.

Legal obligation: Sharing salary information with tax authorities. This must be an obligation
under EU or member state law.

Legitimate interests of the employer: Migrating employee information from one data
management system to another. The legitimate interest cannot be adverse to employees’ rights
and freedoms. And it cannot be used as grounds for processing special categories of data. Public
authorities may not rely on this ground.

Consent: Freely given consent is difficult to prove because of the unequal distribution of power
between the employer and employee. (Remember, consent must be a freely given, specific,
informed and unambiguous indication of the employee’s wishes, signifying agreement.)
Additionally, the processing of employee data may be unlawful or unfair under local law, even if
the employee has consented. Under some local labour laws, employers are obligated to obtain
consent from employees to process their personal data.

Processing sensitive employee data

When sensitive personal data on employees is collected and processed, employers must comply with
one of the exceptions specified in Article 9 of the GDPR. The first exception listed is explicit consent of
the individual, yet again, the employer should consider this a last resort, as employees may feel
pressured to provide their consent to maintain good relations with their employer.

Processing sensitive employee data may be necessary for the employer to establish, exercise or defend
legal claims, such as an employee’s claim of unfair dismissal.

Article 9(2) of the GDPR recognises that processing sensitive personal data may also be necessary for
the controller to carry out obligations and exercise specific rights under employment, social security
and social protection laws where authorised by EU or member state law, or by collective agreement. In
a number of jurisdictions, employment and labour laws restrict the extent to which sensitive employee
data can be processed.

However, local data protection authorities may issue authorisations for specific processing activities.

Storage of personnel records

From the moment an individual applies for a position, the prospective employer begins collecting
personal data. Employers process personal data throughout the employment life cycle for broad
reasons; however, records that contain personal data should not be kept longer than necessary.
Generally, after employment has been terminated, an organisation’s legitimate reason to retain an
individual’s data diminishes. Again, local laws may affect obligations, potentially requiring the employer
to retain employee data. For example, some health and safety laws require records relating to health
and safety checks on individuals who operate machinery to be retained for a specified period of time. If
an organisation is obligated to retain personal data on former employees based on deletion rules with a
legal basis, generally these records should be archived, and internal access should be limited.

Trade unions and works councils

In addition to following data protection law and local employment law, an employer may also be
obligated to communicate with a trade union or works council. In certain jurisdictions, works councils
have considerable power over the processing of employees' personal data. Compliance may require
notifying, consulting with, and seeking approval from works councils. Conversely, trade unions and
works councils may need to ensure they are in compliance with GDPR obligations.

Instructor video: Works councils

©2023, International Association of Privacy Professionals, Inc. (IAPP)


3

So, if you are not familiar with the concept, what a works council is, is it’s kind of like an internal trade
union, basically. In some countries, there is the ability for employees to get together and to create a
works council. And it’s most commonly seen in Germany, actually. If you have an internal works
council, then depending on the requirements under local law, there can be a duty to notify them on
any issues that may concern the rights of the employee and that extends to their privacy rights. And
so, one of the things you have to think about is that if you are going to be starting to collect additional
information from employees or rolling out new systems or whatever it happens to be that will have an
impact on the privacy of those employees, you may well need to have a conversation with your local
works council and, depending on the issue at hand, they may actually even need to give you an
authorisation for what you need to do. They serve like an internal check and balance that represents
the interest of the employees to make sure what you are doing is consistent with their interests. It is
fascinating, actually; it is so culturally dependent on the organisation how cooperative or not the local
works council may be. Some works councils can be extremely difficult to deal with, and if you are
trying to roll something out, it is best to engage in the conversation with them at a very early stage
because it will take a while to work through those negotiations. Other works councils can be more
cooperative with the business, and so you may be able to speak with them at a slightly later stage, but
if you work for an organisation that has a works council, keep in mind that you will need to speak with
them. Make sure you allow enough time for that.

BYOD

To comply with EU and member state data protection law, as well as local employment law, employers
should consider the entire employment life cycle, from application to termination and beyond. With
increased employee motivation, higher flexibility in work styles, and melting borders between work and
free time, bring your own device (BYOD) has become an issue relevant to every stage in the
employment life cycle.

More and more employers are allowing and encouraging their employees to use their own devices,
such as smart phones, tablets and laptops, for work-related activities. While convenient and potentially
cost-effective to operations, BYOD poses certain data protection compliance issues, since the employer
remains responsible as a controller for any personal data processed on the employee’s device for work-
related purposes using the work email settings. BYOD programmes open the door to greater risks to
data protection, including data breaches, which could result in substantial penalties and fines under the
GDPR. To avoid this, as well as loss of trust and a tarnished reputation, effective management of bring
your own device programmes is imperative. This starts with a BYOD policy that explains to employees
how they can use BYOD and their responsibilities. Policy goals should:

Align with employment law and the GDPR

Aim to protect personal data of individuals, such as employees, customers, patients and
sponsors

Aim to protect organisational data, such as intellectual property, financial information and trade
secrets

Enable employee productivity

And mitigate network risks

In addition to creating a BYOD policy, companies introducing BYOD into the workplace should:

Know where the data processed via the device is stored and the measures required to keep the
data secure

Ensure the transfer of data from the device to the company’s server is secure to avoid
interceptions

Know how to manage data held on the device once the employee leaves the company or the
device is lost or stolen (for example, the use of mobile device management software to locate
devices and remove data on demand)

©2023, International Association of Privacy Professionals, Inc. (IAPP)


4

And provide notice to employees explaining the consequences of signing up for BYOD and
outlining the information the organisation will be able to access (again, the employer must have
a lawful basis for processing personal data)

Instructor video: BYOD

Bring your own device, the joy of information security people everywhere. Is everybody familiar with
what bring your own device is? Using your own personal device to receive corporate communications
and maybe use corporate apps and things like that. The idea was to reduce the cost, I suppose,
initially, of company IT assets because you could pull the whizzy stunt of rather having to buy people
assets, you could make them use their own. But, with that came a bit of an information security
nightmare because when you control the assets and hand them out to your employees, you know
exactly what the configuration is and how you settled the security on it and how you manage all that
stuff. When people are bringing in iPhones and Androids and Blackberrys and using all manner of
different devices, suddenly managing security across that becomes a lot more challenging. And it
becomes particularly challenging because you have got an inherent conflict there where you have the
organisation that wants to maintain security of the data that’s going onto the device, but, at the same
time, you have the individual, and probably there is no more personal and private asset that any of us
have nowadays than our phone.

Here is an interesting one. Do any of you work for organisations where BYOD is mandated? You did,
yes. I’ve had this with a couple of clients where they’ve said, well, we want to require all of our
employees to have BYOD. And that, I think, actually … quite aside from data privacy is quite an
onerous thing to ask of somebody because, first off, you get into a lot of practical issues about who
reimburses the carrier charges and the data costs. But, also, if you are going to require people to have
to use BYOD, you are basically requiring them to submit to a certain level of monitoring of their device
and, possibly, the remote/wipe, remote kill, of that device if the company feels they’re misusing
organisation assets. Consent, in that case, I would say, is basically impossible to get because you are
saying people have to take BYOD; they can’t really validly consent to that. I think if you want to show
that people have validly consented to BYOD, you have got to give them an alternative, and it has to be
the opportunity to use some kind of corporate provided device.

Think again about your employees; so, if you are going to allow them to use BYOD, you are going to be
doing a couple things in connection with that. You are going to be monitoring what it is that they put
on their phone, and, possibly, where they are, where they are going, where it is being used. You are
collecting information off that device; you are collecting information about the employee’s habits
maybe with that device. And, when you have a BYOD scheme, typically, you have that kind of situation
where if someone is leaving the organisation, you might want to take their phone off them because
you are concerned about the security risk. But, then, that is in direct conflict with the right they have;
first off, it is their phone and, second, the information on their phone. Equally, when you think about
remote kill or remote wiping technologies that exist for phones, you have to be very careful that you
are not wiping the individual’s personal information on the phone. Any kind of wiping really should be
restricted just to the corporate information.

So, you will hear people talk about sandboxing technologies, and the idea is that you install this kind of
software on the phone that basically ring-fences the corporate information to a specific area of the
phone, so that if you need to kill that information or remote wipe it, you wipe only that bit where the
organisation information is maintained and all the other personal information on the phone remains
unaffected.

Instructor video: Workplace monitoring

Sort of related a little bit to what we were just discussing, but there may be a number of different
circumstances where you want to do monitoring. They may range from investigations into employees
who you are suspecting of committing some kind of policy violation. I had one recently with a client
where they were wanting to put physical proximity sensors on desks. The idea was that they had an
open plan office with lots of desks and it was a hot desking environment. And they basically felt that
they were providing far more desks than they actually needed to provide and not using their
environments efficiently. So what they wanted to do was put little physical proximity sensors on the
desks that could basically tell when somebody was at the desk. The idea was to record, over a period

©2023, International Association of Privacy Professionals, Inc. (IAPP)


5

of a month, how often the desks were being used, so they could see which desks weren’t being used
and how they could consolidate the desks down and maybe open the space a bit more. Now, that was
kind of an interesting one because some employees got very concerned about it because they thought
it was basically recording whether they were at their desk working or not. And that really wasn’t the
intention of what this particular client was up to. That’s just another example of how it might be used.
You might even just have workplace monitoring through access to employees’ emails if they are away
on business or something like that. You many need to monitor their email box to respond to any
important emails that come in or things like that.

Lawful employee monitoring

Member state data protection law and local employment law may have specific requirements restricting
the use of employee monitoring systems.

Additionally, employees’ rights and freedoms must be balanced against the rights of the employer, and
alternatives to monitoring should always be considered. Prevention is often a better approach than
detection; for example, blocking websites the employer does not want the employee to visit.

Increasingly, organisations conduct background checks on potential and existing employees. One
reason for this increase is the need of organisations to protect themselves against data breaches
caused by unscrupulous employees. Types of background checks may range from verifying educational
background to checking past criminal activity. Employers must not use background checks to create
blacklists, which are generally illegal.

Another form of employee monitoring happens through the use of data loss prevention (DLP)
technology. DLP tools are used to protect IT infrastructure and confidential business information from
external and internal threats, but inevitably involve processing employee and other third-party
personal data since they operate on networks and systems used by employees. The overriding
intention of such tools, however, is preventing loss of an organisation’s data.

Personal data about employees collected through monitoring must be:

Held securely

Accessed only by those within the organisation with a legitimate reason to view it

And deleted when there is no longer a need to hold onto it (however, there may be a business
need to retain it)

To monitor employees lawfully, an employer must ensure that the monitoring is necessary,
proportional, transparent and legitimate. Click on each characteristic to reveal questions that the
employer should ask prior to monitoring.

Necessity: Can you demonstrate that the monitoring is really necessary?

Consider less intrusive methods first.

Under the GDPR, a data protection impact assessment (DPIA) may be required under
certain circumstances.

Legitimacy: Do you have lawful grounds for collecting and using the personal data? Is the
processing fair?

This will often mean relying on the legitimate interest balancing test.

Collection of sensitive data through monitoring is likely to be problematic.

Proportionality: Is the monitoring proportionate to the issue that the employer is dealing with?

This is linked to the GDPR’s principle of data minimization.

Collective bargaining agreements are useful markers for employers considering the
proportionality of monitoring activity.

Transparency: Have employees clearly been informed of the monitoring that will be carried out?

©2023, International Association of Privacy Professionals, Inc. (IAPP)


6

Note, the employer cannot argue that lack of workplace privacy is acceptable because
employees have been warned.

Employers should introduce an acceptable use policy (AUP).

Instructor video: Lawful monitoring

So, what are the things you should be thinking about if you are going to engage in some form of
monitoring? Well, the first thing to think about is the necessity of that monitoring. The tool you’re
intending to use to monitor, the CCTV footage, the proximity sensor, whatever it happens to be. Is it
actually necessary or could you achieve the goal you are trying to achieve though a less invasive
method? So, ask yourself, first of all, is the monitoring necessary or could we do it another way? Next
thing to ask yourself is, is what we are proposing to do proportionate; it equates to, is it reasonable?
In that proximity sensor case I was talking about, what the client explained to me, in that case, was
that the sensors basically were, essentially, a very simple count; they didn’t keep records of which
employees were working at which desks or anything like that; it was just simply, is this desk being
used or is it not being used. Then, they wanted to aggregate all that information at the end of the
month and say only 60 percent of all desks are being utilised and 40 percent are being unutilised. In
that case, that seemed like a relatively proportionate way of doing it. It was minimising the amount of
data collected to the bare essentials just to be able to take a view on the utilisation of the workspace.

Another example of proportionality would be if you were using CCTV cameras in the building, you may
well want to capture video to see how people are behaving in particular areas, but do you also need to
record audio with that? Often, you would say you could get the information you need just from the
video alone. Actually, audio recording is particularly invasive because you won’t just pick up the people
that are immediately on the camera; you may pick up people in the background who are having private
conversations. Think about proportionality, too. I had a very interesting one a while back with a client
who, basically, had a series of retail shops around the UK. They noticed an enormous amount of their
stock—it was basically volunteer shops—and they noticed that a lot of their stock was going missing
because the volunteers actually had the mindset that because they were providing voluntary services,
they were entitled to help themselves to stuff that was in the stock room. So, they had to look if they
could start rolling out CCTV in the stock rooms to keep an eye on things and whether that was
proportionate or not.

Transparency. Of course, this might seem a little counterintuitive; you might think, if I’m going to
monitor somebody, say, in the context of employee investigations, the last thing I want to do is tell
them about that. Because, of course, it would just completely change their behaviour. Now, what we
mean by transparency is you have to at least alert people to the possibility of monitoring. So, you think
of the privacy notice you give people up front. You need to explain to them that maybe the monitoring
goes on in the organisation and the reasons for which you are doing it. We monitor the use of our
networks to assure appropriate use of our information assets. We may record this phone call for the
purposes of quality assurance and training, whatever it happens to be. But you have to provide that
kind of disclosure. If it is an employee investigation context, you don’t have to tell them, hey, you are
under investigation; we are going to monitor you for a period of time. But there should have been that
initial disclosure at the outset of the employment relationship, where you disclose the possibility you
might from time-to-time use employee monitoring tools to monitor an employee’s compliance with
policy.

And, finally, legitimacy. What would be your grounds for conducting employee monitoring? I would say
that there’s a couple you would probably rely on. One would be the legitimate interest, to begin with. If
what you are doing is necessary and proportionate and transparent—then I would say you have the
legitimate interest to protect your IT assets—and provide you have been necessary and proportionate
and transparent, then it’s maybe not inverse to the rights and freedoms of the individual within the
context. You might also, if it is in an investigation context, you might also say the exercise
establishment of the defence of legal claims, because if your employee is engaged in wrongdoing, then
it maybe that you are actually looking to investigate that to bring or defend a legal claim in connection
with it. Those are the kinds of things to have a thought towards.

Whistle-blowing schemes

©2023, International Association of Privacy Professionals, Inc. (IAPP)


7

Whistle-blowing schemes have increased in use since the passing of the U.S. Sarbanes-Oxley Act in
2002. Companies must have a system in place to receive anonymous complaints about potential
wrongdoing, including fraud, misappropriation of assets and material misstatements in financial
reporting. U.S. companies with EU subsidiaries or affiliates are bound by both U.S. and EU data
protection law, thus potentially leading to conflicting obligations, specifically in regard to protecting the
identity of the whistle-blower versus protecting the personal data of the employee accused of
wrongdoing (under EU data protection law).

Instructor video: Whistle-blowing

And whistle-blowing schemes—Sarbanes-Oxley. If you’re a U.S. publicly listed company, you have to
implement a whistle-blowing program. So, this one always raises a few issues because, for a long
period of time—we discussed this yesterday, but you might remember me saying that—France actually
refused to recognise that whistle-blowing schemes were lawful for a long period of time. So, you had
U.S. companies operating in France who had to have a whistle-blowing scheme and then the French
authorities saying that that was illegal. That’s been overcome now, but we have got quite extensive
guidance from the Article 29 Working Party about if you are going to implement a whistle-blowing
scheme what that scheme should look like. And there are a number of things you have to take into
account. The first off, again, is transparency. You should have some kind of whistle-blowing policy that
explains to people their ability to report violations, but, also, at the same time, how their information
will be treated in the context of a whistle-blowing report. You have to, obviously, to maintain the
security and the confidentiality of the reports that are submitted. But here’s one really interesting
thing. In a lot of U.S. whistle-blowing policies, you will often tell people that the reports they submit
will be anonymous. Now, under European law, we really, really, really strongly discourage anonymous
reporting. And in some countries, you’ll find that the local DPAs will just consider a whistle-blowing
scheme illegal if it mentions the ability to make anonymous reporting. And the reason there really is a
difference of mindset, the difference of culture with the U.S., the sort of grossly over-simplifying, the
U.S. mindset is more of a kind of ‘no smoke without fire’ type attitude; whereas, the European mindset
is much more along of the lines of sort of ‘innocence until proven guilty’. And what they’re concerned
about in the context of a whistle-blowing scheme is that if you allow anonymous reporting, then it may
encourage malicious reports to be made. Somebody who has a gripe with another employee may make
a malicious report under the whistle-blowing scheme, so what one employer has to do is to encourage
people who make reports, you can assure them that their report will be treated in confidence and kept
confidential, but that you actually ask them to identify themselves as part of making that whistle-
blowing report.

In practice, of course, you’re never ever going to ignore a serious report that’s submitted to you on an
anonymous basis. So the careful line you have to tread is that if you’re going to allow anonymous
reports, just try not to encourage them. Don’t have it up in bold letters in your whistle-blowing policy,
‘hey, you can submit anonymous reports’. If you’re going to mention it, say, ‘while we encourage you
to provide your details as part of submitting the whistle-blowing report, we acknowledge that, in some
cases, you may want to submit them anonymously’ or something along those lines. Don’t encourage it
but recognise that it might be possible.

Now, the other one is that … once a whistle-blowing report has been submitted, the idea under
European law is that the report should be investigated, but if it is not substantiated, if the person that
is alleged doing some wrongdoing, if the report can’t be proven, then the requirement is that that
report should be deleted after a period of time—and a fairly short period of time. The expectation is
around three to six months. And again, this goes back to … A lot of the clients I’ve worked with have
said, well, we know this guy is doing wrong; we just haven’t been able to prove it yet, but we’ve have
two, three, four reports where people are all saying the same thing, so we’re sure he’s up to
something. And while that may be a valid position to take, under European Union law, the basic
position is if you can’t prove it from the report, then, after a period of time, that report has to be
deleted. And that’s going back to the retaining data no longer than is necessary.

We also have some strict requirements about what can be reported through a whistle-blowing scheme
in Europe, so the Sarbanes-Oxley requirement is basically sort of reporting accounting or auditing
fraud-type activities, and under European law we recognise that is valid because it is required under
Sarbanes-Oxley, but a lot of companies will extend their whistle-blowing schemes to wider violations.

©2023, International Association of Privacy Professionals, Inc. (IAPP)


8

So they might include health and safety violations or discriminatory activities or things like that. Now,
this is where you get really, really, really wide diversions across all of the EU member states. Some
member states will allow, essentially, any form of whistle-blowing reporting. Others will limit it strictly
just to the Sarbanes-Oxley accounting and auditing fraud-type issues. So, if you’re rolling your whistle-
blowing scheme out in lots of different countries, you need to understand what can legally be reported
under each of those different countries’ requirements. And, again, that’s where working with a third-
party provider can be helpful. Because often those providers will know the local rules, and they will
limit what can and cannot be reported from each country. Each country, as well, can also have
different rules on who can be reported. Because, again, as a way of trying to keep it proportionate, the
data protection authorities in some countries take the view that, actually, the only people who should
be capable of being the subject of a whistle-blowing report are those who are in a position to cause
serious organisational harm or the kind, you know, the Enron-type style damage. So, some of them
will say they should be, at least, at a manager level if they’re going to be reported. And reporting some
guy on the shop floor who’s not packing boxes correctly is not proportionate and shouldn’t be the
subject of a whistle-blowing report.

One also that really tends to surprise people is that individuals … Remember, we have all these rights,
individuals—they have the right of access and correction and updating and deletion—well, those rights
also apply to whistle-blowing reports. So, if an individual has been the subject of a whistle-blowing
report, you have to tell them that they’ve been the subject of a report, but you don’t have to tell them
immediately, so if you’re thinking, my god, how are we going to secure evidence, you don’t actually
have to inform them at that point. You can take your time to secure the evidence and do the
investigation. But then, if it looks like the report is being substantiated, you’re going to have to
obviously communicate that to them, and then they get the ability to have access to the report and to
seek any corrections to it that they think are inaccurate. Now, remember that the right to access is
limited by your need to protect other people’s private information. So if, for example, the whistle-
blower’s named in that report, you do have the ability to blackline their name out of it if needs be, at
least for a period of time; obviously, if it goes to serious criminal investigation, at some point that
individual is going to need to be brought forward. But there is that general right of access. They do
have the right to request corrections if they think things are wrong in the report. So, you know, keep
that in mind as well. You’ll see, basically, that European law is quite protective. It really does try to
protect somebody who has been the subject of a report.

And, finally, the all-important thing, or two all-important things: a lot of those reports, typically, they’ll
be reported in Europe, but they’ll be collected and stored somewhere in the U.S. or maybe another
non-EU country. So, you’ve got an international transfer there. So, you need to be thinking about if
that’s an in-transfer within your organisation if you’re running your own whistle-blowing scheme. You
need to think about model clauses or binding corporate rules. If it’s going to a third-party service
provider who’s international, you’ll need to mind that they have model clauses with them. And, also,
you’ve got to maintain the security of that information. So, again, if you’re using a vendor to host
those reports, you need very strong security terms with them to make sure that they’re going to
maintain the security of the reports you’re getting.

So, a lot of things to think about if you’re rolling out a whistle-blowing scheme. It’s a significant data
protection project to embark upon.

Surveillance
Introduction to surveillance

Surveillance involves the observation of an individual or group of individuals. It may be covert or


carried out openly, conducted in real time or by access to stored material.

Developing technologies continue to break down barriers to surveillance. While public authorities and
private-sector entities may have lawful purposes for surveillance, the broadening landscape of
available data means broadening scope for invasion of privacy as well.

©2023, International Association of Privacy Professionals, Inc. (IAPP)


9

Examples of electronic surveillance include social networks analysis and mapping, data mining and
profiling, aerial surveillance, satellite imaging, telecommunications surveillance, CCTV cameras,
biometric surveillance, and geolocation technologies.

Surveillance may need to be conducted in a manner that overrides data subject rights. This need is
recognised by Article 23 of the GDPR, which permits EU or member state law to restrict the rights
granted in Chapter 3, ‘Rights of the data subject’. Such a restriction must respect ‘the essence of the
fundamental rights and freedoms’ and be a ‘necessary and proportionate measure in a democratic
society’ (as set out in the Charter and in the European Convention for the Protection of Human Rights
and Fundamental Freedoms).

Surveillance may be conducted by public and state agencies for national security or law enforcement
purposes or private entities for their purposes. Click on each to learn more.

• Public and state agencies for national security or law enforcement purposes: This type of
surveillance must be conducted in a manner to respect individual rights enshrined in the
Charter of Fundamental Rights, specifically the right to a private and family life (Article 7)
and protection of personal data (Article 8).

The particular requirements of law enforcement are recognised in the Law Enforcement Data
Protection Directive (LEDP Directive). Recital 66 of the LEDP Directive recognises that
although the processing of personal data must be lawful, fair and transparent, this should
not prevent law enforcement authorities from carrying out activities (e.g., covert
investigations and video surveillance) to:

• Prevent, investigate, detect and prosecute criminal offences

• Safeguard against and prevent threats to public security

▪ Key requirements: lawfulness, necessity, proportionality and regard for


legitimate interests of the natural person

Laws that fail to appropriately consider the rights and freedoms of data subjects may be
struck down by the Court of Justice of the European Union (CJEU).

• Private entities: Surveillance by private entities must be based on legitimate purposes. In


addition to the GDPR, it must comply with national laws concerning confidentiality, privacy,
data protection and other civil rights (e.g., employment law).

• EDPB “Guidelines 10/2020 Restrictions under Article 23 GDPR,” Adopted 13 October 2021

• Restriction of data subject rights can only occur when the following interests are at
stake and the restrictions safeguard such interests:

• National security, defence and public security

• Prevention, investigation, detection and prosecution of criminal offences or


the execution of criminal penalties

• Other important objectives of general public interest

• Protection of judicial independence and judicial proceedings

• Prevention, investigation, detection and prosecution of breaches of ethics for


regulated professions

• Monitoring

• Protection of data subject rights

• Enforcement of civil law claims

Communications data

©2023, International Association of Privacy Professionals, Inc. (IAPP)


10

Historically, communication surveillance has involved traditional surveillance activities, such as


interception of postal services and human spies; however, surveillance of electronic communications is
more prevalent today.

Personal data generated from electronic communications is categorised as either the content of a
communication or the metadata. Metadata is referred to as ‘data about data’ as it is information
generated or processed as a consequence of a communication’s transmission. While content data is
protected by the right to freedom of expression, recognised by laws around the world, including the
EU, metadata provides context to content. And because metadata can be used to identify an individual,
it falls within the GDPR’s definition of personal data.

Brainstorm examples of both content data and metadata; then compare your answers to an expert’s.

Content of a communication: a conversation between parties in a call, words comprising an SMS


message, an email subject line, words in the main body of an email, attachments to an email

Metadata (data about data)

Traffic data: calling and called numbers in relation to a telephone call

Location data: latitude, longitude and altitude of a user’s equipment; direction of travel;
level of accuracy of location information; identification of the network cell (Cell ID) in
which a user device is located at a certain time; the time and location information was
recorded

Subscriber data: the name of a subscriber, contact details and payment information

ePrivacy Directive

The ePrivacy Directive’s official title is Directive 2002/58, but it is known by different names including
the Cookie Directive and the Privacy and Electronic Communications Directive. It sets out rules
governing the processing of location, content and traffic data over a public electronic communications
network or publicly available communications system — in other words, data passing over public
telephone or internet carriers or services that use a public communications network.

For the collection of individuals’ precise location-based data, opt-in consent is generally required (with
the exception of carriers who need the data to provide the service).

Article 15(1) says the confidentiality of the content of communications must be ensured and cannot be
intercepted or disclosed to third parties unless there is consent from all users. Article 15(1) goes on to
say that member states can introduce some exemptions if necessary for very limited purposes, such as
national security and law enforcement.

Access to traffic data is limited; however, telecommunications carriers can process traffic data for the
purpose of conveying communication and possibly for some limited marketing activities with the user’s
consent. Otherwise, the use of traffic data is also very restricted under the ePrivacy Directive.

If data is passing over a private network — for example, a corporate intranet — ePrivacy rules do not
apply. Monitoring considerations, as discussed earlier in this module, are still relevant: necessity,
proportionality, legitimacy and transparency.

A provision within the ePrivacy Directive allows for the interception of a communication when an
organization has a lawful business purpose for accessing data going through their public networks.
Member states, under their individual laws, may pass legislation defining lawful business purposes.

Click here to learn more about the proposed ePrivacy Regulation

CCTV

Video surveillance of individuals, including closed-circuit television (CCTV), contains personal data,
such as images of individuals, which are considered biometric data under the GDPR. When collecting
such personal data, GDPR compliance considerations should include lawfulness of processing, a data
protection impact assessment (where applicable), prior checking, proportionality, information

©2023, International Association of Privacy Professionals, Inc. (IAPP)


11

provision, individual rights, and measures to protect the personal data and rights of individuals. Click
on each topic to learn more.

Lawfulness of processing: Prior to carrying out surveillance, the controller should determine the
lawfulness of processing (for example, legitimate interest; the establishment, exercise or
defence of legal claims; in the public interest for a public area; or in the exercise of public
authority, such as for monitoring traffic). Note that consent likely would not be possible. A
controller may need to rely on a provision in member state law to conduct video surveillance in
certain circumstances.

Because biometric data qualifies as a special category of personal data within the GDPR,
processing can only be carried out if one of the permitted conditions, as specified in Article 9,
applies.

Data protection impact assessment (DPIA): In some circumstances, a DPIA must be completed.
This is required if the video surveillance is considered to be high risk, if it involves the
systematic monitoring of a publicly accessibly area on a large scale, or if video surveillance has
been included by the relevant supervisory authority on a list of data processing operations that
require a DPIA. The decision to use CCTV should be made only if other, less intrusive solutions
that do not require image acquisition have been considered and found to be clearly inapplicable
or inadequate for the intended lawful purpose. The DPIA should document these investigations
and inadequacies. For more information on DPIA requirements, see Module 10.

Prior checking: In many countries, using CCTV triggers the requirement to notify the local
regulator, and in some circumstances, seek authorisation.

Proportionality: The selected system and technology used for surveillance should be
proportional to the purpose. For example, remote control, zooming functionality, facial-
recognition, and sound-recording may not be necessary. Additionally, key aspects of the CCTV
and processing of its footage must be proportionate to the purpose. These aspects include
operational and monitoring arrangements (such as the visual angle so that monitoring of
irrelevant spaces is minimised), retention of footage, the need to disclose footage to third
parties (such as the police), whether the footage will be combined with other information (in
particular, to identify individuals), and the surveillance of areas where people have high
expectations of privacy.

Information provision: For overt video surveillance, controllers must comply with the
transparency requirement of the GDPR, to the extent that is possible, in cases where the
controller may not have a direct relationship with the affected data subjects, such as where the
cameras cover a large, public space. As the information that may be made available via a sign
is unlikely to contain all the details prescribed by Articles 13 and 14 of the GDPR, the controller
should be prepared to provide the full information necessary when a data subject makes
contact.

Individual rights: Under the GDPR, data subjects have rights related to the processing of their
personal data. See Module 5 for more information on data subject rights. For example, an
individual may request access to a copy of a CCTV recording they are on. This may pose the
challenge of protecting others’ privacy, specifically those on the recording, while also fulfilling
the data subject’s right to access. Given that CCTV footage is usually only retained for short
periods of time, the right to access is normally of narrower scope compared to other contexts.

Measures to protect the personal data and rights of individuals: These may include staff
training, a CCTV policy, and regular reviews to ensure compliance.

Location data

Location-based services (LBS) utilise information about location to deliver a wide array of applications
and services.

LBS may be derived from satellite network-generated data, such as GPS; cell-based, mobile network-
generated data; and chip card-generated data.

©2023, International Association of Privacy Professionals, Inc. (IAPP)


12

Many app providers use LBS and have needed to adjust their terms and conditions according to GDPR
obligations. For example, Google has identified three main areas of location data that it uses to deliver
its services: implicit location information, such as search terms; internet traffic information, such as IP
addresses; and device-based location services, such as Google Maps.

Location data is referred to as an identifier in the GDPR’s definition of personal data. If location data
can be used alone or in combination with other information to identify someone, then it should be
considered personal data.

Biometric data

Biometrics data is defined in Article 4(14) of the GDPR as ‘personal data resulting from specific
technical processing relating to the physical, physiological or behavioural characteristics of a natural
person, which allow or confirm the unique identification of that natural person, such as facial images or
dactyloscopic data’. Examples include DNA, fingerprints, retina and eye patterns, voice, and gait.

The main uses of biometrics systems used in both the private and public sectors are:

Identification: Who are you? (e.g., photographs loaded up to social media; identification of
individuals through facial recognition)

Authentication: Are you who you claim to be? (e.g., fingerprint to authenticate identity when
accessing a mobile device or computer; palm print to access a secure building.)

For biometric data to be included as a special category, the purpose for processing must be for
uniquely identifying a natural person.

Direct marketing
Direct marketing definition

What is direct marketing? According to the former Article 29 Working Party, to fall under the scope of
direct marketing, a communication, by whatever means of advertising or marketing material, should
be directed toward specific individuals. Messages that do not process personal data to communicate
the marketing message or those that are purely service-related in nature are not considered direct
marketing.

Navigating the landscape of consent requirements may be difficult, yet this is crucial for avoiding risk
and brand damage, as well as for improving marketing communications. Do you know why direct
marketing is one of the most complex areas of data protection law? Write your answer and then click
submit to compare it with an expert’s opinion.

Direct marketing not only triggers data protection requirements but also other consumer
protection regulatory requirements that vary from country to country; therefore, controllers
must meet all national rules applicable to the direct marketing communications they send.

Direct marketing often involves using data collected from devices, such as location data from
smartphones and cookies.

Direct marketing is no longer limited to postal mail and email, but can now be sent via third
platform messages, push messages and in-app messaging.

Direct marketing rules

Direct marketing is regulated both by the GDPR and the ePrivacy Directive. The GDPR applies to all
direct marketing communications, regardless of channel. It also applies to online advertising targeted
at individuals based on their internet browsing history. The ePrivacy Directive applies to ‘digital’
marketing communications—direct marketing communicated over electronic communication networks,
such as by phone, fax, email and SMS or MMS. The ePrivacy Directive also specifies rules that impact
the use of online behavioural advertising.

©2023, International Association of Privacy Professionals, Inc. (IAPP)


13

The GDPR provides individuals the absolute right to object to any form of direct marketing at any time.
This right is already applicable to processing based on consent, as consent can be withdrawn at any
time. With direct marketing, it extends to processing based on legitimate interest as well. Under the
GDPR, controllers are required to:

Inform individuals, explicitly and clearly, of their right to opt out when they first communicate

Allow individuals to opt out across all marketing channels

Honour opt-out requests in a timely fashion and at no cost to the individual

And remove personal data and profiling after an individual has opted out (unless retention of
personal data is strictly required); however, controllers should suppress rather than delete
contact details because they do not want to risk reacquiring that individual’s details later and
beginning marketing to them again

And, as with any processing of personal data, direct marketers must ensure all compliance
requirements under the GDPR are met. These include:

Having a lawful basis to process personal data

Providing individuals with fair processing information explaining that their personal data will be
used for marketing purposes

Implementing appropriate technical and organisational measures to protect the personal data
processed

And not exporting personal data outside the EEA without adequate protection

In addition to GDPR obligations, some member states require controllers to amend their contact lists
against applicable national opt-out registers before sending direct marketing.

The ePrivacy Directive has different rules for different channels used for direct marketing. Also,
because the ePrivacy Directive does not have direct effects like the GDPR, but rather is implemented in
national laws, how it is interpreted and enforced differs greatly across member states. Generally, most
forms of digital marketing, other than person-to-person telephone marketing, require prior opt-in
consent. Click on each direct marketing channel to learn if opt-in consent is required.

• Postal marketing: Postal marketing is not subject to the ePrivacy Directive; however, marketers
must ensure they satisfy the general requirements under national data protection laws and the
GDPR, including opt-out requests. Some member states’ national rules mandate a requirement
for consent. In the absence of mandated consent, controllers may rely on legitimate interests
based on a careful balancing test that examines:

o Whether the individual is an existing customer

o The nature of the products and services

o Whether the data controller has previously told the individual that it will not send any
direct marketing communications

• Telephone marketing (telemarketing): As a form of digital marketing, telemarketing is subject


to the ePrivacy Directive. And, as with other forms of direct marketing, controllers must ensure
they satisfy the general compliance requirements of the GDPR.

Under the ePrivacy Directive, consent is not required for person-to-person telemarketing. It is,
however, required for marketing through automated calling systems. Article 13(3) of the
ePrivacy Directive allows member states to decide whether person-to-person telemarketing
should be conducted on an opt-in or opt-out basis. At a minimum, individuals must have a
means to opt out without an associated fee. As a result, most member states have implemented
national opt-out registers, which typically must be checked against the controller’s call lists.

Additional rules and best practices around telemarketing vary from country to country, including
the treatment and permissibility of business-to-business (B2B) direct telephone marketing.

©2023, International Association of Privacy Professionals, Inc. (IAPP)


14

Some member states do not distinguish between B2B and business-to-consumer (B2C)
marketing, while others apply a more relaxed approach to B2B marketing. Yet, as of 2009, the
ePrivacy Directive applies to both B2C and B2B communications.

• Electronic mail marketing: As a form of digital marketing, electronic mail marketing is subject to
the ePrivacy Directive. Again, as with other forms of direct marketing, controllers must ensure
they satisfy the general compliance requirements of the GDPR as well.

The ePrivacy Directive’s definition of electronic mail marketing includes email and SMS/MMS
communications. In general, it requires prior consent for these types of marketing.

The ePrivacy Directive allows a limited exemption from the strict opt-in requirement for direct
marketing by electronic mail to individuals whose details the data controller obtained ‘in the
context of the sale of a product or service’. For this exemption to be used:

o The controller must market its own similar products and services

o Individuals must have the ability to opt out at the time their contact details are collected

o Individuals must be reminded of their ability to opt out in each subsequent marketing
communication

The ePrivacy Directive stipulates specific information that must be provided to recipients of
direct marketing via electronic mail. This includes:

o A valid address to which they can send an opt-out request that is appropriate to the
medium of the marketing communication

o The clear identity of the sender

o Clear indication that the message is a commercial communication

o Clearly identified promotional offers with easily accessible, clear, unambiguous conditions
to qualify

o Clearly identified promotional competitions or games (if permitted in the member state)
with easily accessible, clear, unambiguous conditions for participation

As with telemarketing, the treatment of B2B direct electronic mail marketing varies across
member states, and the GDPR will apply when processing employees’ contact details.

Online behavioural advertising

Online behavioural advertising (OBA) is website advertising targeted at individuals based on the
observation of their behaviour over time. While OBA may be delivered by the website publisher itself,
such as when an online store recommends products based on past purchasing history, increasingly
OBA happens through third-party advertising networks. Third-party advertising networks have
relationships with partnering website publishers that enable them to place cookies on individuals’
computers with unique identifiers. As websites track individuals’ website activities, profiles are assigned
to unique identifiers, enabling ad networks to deliver advertising based on individuals’ interests.

The GDPR clearly identifies information collected for OBA purposes as personal data. Its definition of
personal data specifically provides ‘online identifier’ as an example.

Further, according to the Article 29 Working Party, all parties to a third-party ad network relationship
potentially may attract compliance responsibilities under the GDPR. These include the ad network itself,
which will often qualify as a controller; a website publisher, which may qualify as a joint controller; and
advertisers, which may qualify as independent controllers.

The ePrivacy Directive will generally apply to OBA regardless of whether or not OBA information
collected from individuals constitutes personal data. Article 5(3) of the ePrivacy Directive, as amended
in 2009, states that the use of cookies to store or access information in an individual’s computer is
allowed only on the condition that the individual concerned has given their consent, having been
provided with clear and comprehensive information.

©2023, International Association of Privacy Professionals, Inc. (IAPP)


15

Internet technology and communications


Cloud computing

Cloud computing is the provision of information technology services over the internet and may be used
for various purposes. It may provide infrastructure, platform, or application services, or these services
in combination. Commonalities among cloud computing services are that:

Infrastructure is shared among customers and accessible in numerous countries

Customer data is transferred around the infrastructure, according to capacity

And the supplier determines the location, security measures and service standards applicable to
the processing

Determining whether the GDPR applies to cloud computing services, as according to Article 3 of the
GDPR, may be challenging for cloud service providers. As covered in Module 4, Article 3 applies when
either:

The processing relates to the activities of an EU establishment of the controller

Or the processing relates to offering goods or services to individuals in the EU, or to monitoring
their behaviour, even when the controller or processor is not established in the EU

The EU does not have specific legislation regarding cloud computing; however, the technology-neutral
GDPR, where applicable, sets out controller and processor obligations.

Because a controller has significantly more obligations under the GDPR, distinguishing between the
controller and processor in the relationship between a customer and a cloud service provider is
essential. This distinction may not always be clear.

When may a cloud service provider be considered a controller?

In some circumstances, when it determines substantial and essential elements of the means of
processing; for example, data retention periods

When it processes data for its own purposes

And when it determines aspects of the processing outside the controller’s instructions

A cloud services supplier may determine technical and organisational means of processing (for
example, hardware) and remain a processor.

Even if the cloud provider is not directly subject to the GDPR, the cloud provider’s customer may be
subject to it, in which case the data processing contract should contain required controls and
obligations as set out in the GDPR.

Web cookies

As discussed earlier in this module, a web cookie is a text file stored on an individual’s computer by a
website for later use; it enables authentication of web visitors, personalisation of web content and
delivery of targeted advertising.

Cookies are particularly relevant to the discussion of protecting personal data collected online. Recital
30 of the GDPR says, ‘Natural persons may be associated with online identifiers provided by their
devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or
other identifiers ... This may leave traces which, in particular when combined with unique identifiers
and other information received by the servers, may be used to create profiles of the natural persons
and identify them’. Where the information collected from cookies is personal data, its collection and
analysis amount to processing subject to the GDPR.

Distinction should be drawn between first- and third-party cookies. First-party cookies are placed by
the operator of the website visited; therefore, the website operator is the controller of the personal

©2023, International Association of Privacy Professionals, Inc. (IAPP)


16

data gathered by its own first-party cookies. Third-party cookies, as discussed in this module, are sent
by an entity other than the website operator. When the third party determines the means and purposes
of processing the personal data gathered from its third-party cookies, it is a controller and must also
comply with the GDPR.

In addition to provisions under EU law, best practices around the use of cookies include:

Storing only encrypted personal data

Providing notice

Using persistent cookies only if justified by the need

And setting reasonable expiration dates for cookies

Many organisations now rely on consent to process personal data in the form of online identifiers. As
discussed in Module 4, consent is one of the lawful grounds for data processing under Article 6; it is
defined in Article 4 as any ‘freely given, specific, informed and unambiguous indication of a data
subject’s wishes’; and Article 7 requires that it be presented separate from other matters in ‘an
intelligible and easily accessible form, using clear and plain language’.

The ePrivacy Directive addresses cookies directly, requiring in Article 5(3) that (under member state
law) organisations obtain prior informed consent for storage or for access to information stored on a
user’s terminal equipment (for example, websites must ask users if they agree to accept cookies, web
beacons, etcetera, before they are placed). ‘Strictly necessary’ cookies and those used solely for
carrying out communication transmission are exempt from the consent requirement.

Prior to the GDPR, valid consent under the ePrivacy Directive—as implemented in member state laws—
was widely interpreted to be met with a visible pop-up notice announcing the use of cookies, followed
by the user’s continued use of the site. Whether this was legally sufficient was never officially
challenged, but post-GDPR, it is no longer popular to assume implied consent from ongoing use of the
website. Instead, given the GDPR’s requirement of ‘specific, informed, and unambiguous indication’ of
consent, many organisations are requiring users to affirmatively interact with the cookie banner, if not
also use a consent tool.

The CJEU recently clarified cookie consent requirements in that consent:

• Must be obtained through active behavior

• Applies to processing and storing nonpersonal data information

• Include information regarding cookie duration and access by third parties

Search engines

Search engines are services that find information on the internet. They process large volumes of data,
routinely including user IP addresses, cookies, user log files and third-party web pages.

Because search engines determine the purposes and means of processing data about their users, they
are controllers of that personal data. In 2014, the CJEU ruled on the Google v. AEPD case, which
required that Google remove (from its search results) links to a 1998 newspaper article about the
plaintiff’s foreclosed house. This case established that search engines are also controllers of the
personal data contained in third-party web pages. Because of the Google v. AEPD decision, search
engines outside the EU are also likely subject to the GDPR in respect of their processing of personal
data contained in third-party web pages if they have an EU establishment whose activities are
economically linked to the search engine’s core activities.

When web traffic data is processed by search engines and provided as analytics—such as Google
Analytics—to search engine marketers that fall within the scope of the GDPR, the organisations
conducting the search engine marketing are also controllers. However, search engine marketers can
take certain steps to ensure that aspects of the web traffic analysis process are anonymised, such as
ensuring that data, including IP addresses, is not stored in Google Analytics even after the user has

©2023, International Association of Privacy Professionals, Inc. (IAPP)


17

accepted the placement of cookies and anonymising IP addresses before storage or processing takes
place.

Click here for EDPB “Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search
engines cases under the GDPR,” Adopted 7 July 2020 Guidelines 5/2019 lists:

• Grounds of the right to request delisting including unlawful processing, legal obligation,
personal data is no longer necessary in relation to the processing

• Exceptions to the right to request delisting including freed of expression and information,
public interest in the area of public health, legal claims.

Read the full guidelines here.

Social media platforms

Social media platforms create opportunities for various parties and individuals to collect and use
personal data. As a result, there may be multiple controllers. SMPs themselves are controllers because
they provide platforms for publishing and exchanging personal information, as well as determining the
use of personal information for advertising purposes.

Authors of applications designed for SMPs that provide services in addition to the SMP may be
considered controllers as well.

Users who act on behalf of an organization, or knowingly extend access to personal data beyond
selected contacts, may be controllers.

SMP providers should be open and transparent about the processing of personal data by providing:

Where relevant, notice if the personal data will be used for marketing purposes, along with the
right to opt out

Notice if the personal data will be shared with specific third parties

An explanation of any profiling that will be conducted

Information about the processing of sensitive personal data

Warnings about risks to privacy

And a warning that if an individual uploads a third party’s personal data, such as photographs,
the consent of the third party should be obtained

Sensitive personal data, third-party personal data and children’s personal data require special
considerations for processing via an SMP. Click on each to learn more:

Sensitive personal data: Explicit consent usually is required to publish personal data on the
internet, unless it is published by the data subject. An SMP requesting personal data (for
example, an individual’s profile) must ensure the individual knows that provision of the data is
voluntary.

Third-party personal data: If third-party individuals’ personal data is published (for example,
photo tags), the SMP must have a legal basis for processing that personal data. According to the
former Article 29 Working Party, third-party data of individuals who are not members of the SMP
may not be aggregated to form profiles of those individuals.

Children’s data: As discussed in Module 4, processing children’s data on the basis of consent
requires parental consent. This applies to children under 16 years old; member states may lower
this age limit to 13 years old. Additionally, processing on the grounds of legitimate interest may
not be possible (GDPR, Article 6[f]). According to the Article 29 Working party, a controller
should have regard for the best interests of the child.

EDPB Guidelines: “Guidelines 8/2020 on the targeting of social media users,” Adopted 13 April 2021

• Identifies the actors and roles of social media: Users, social media providers, targeters

©2023, International Association of Privacy Professionals, Inc. (IAPP)


18

and other relevant actors (e.g., marketing service providers, ad networks, data brokers,
data analytics companies)

• Users may be targeted on the basis of:

o Provided data

▪ Must be able to demonstrate a legal basis for processing via consent or


legitimate interest

o Observed data

▪ Users must be provided with clear and comprehensive information about


the purposes of processing prior to giving consent

o Inferred data

▪ Typically involves profiling. In order for processing to be lawful, the


controller must conduct a case-by-case assessment (will targeting have a
“similarly significant effect” on a data subject), obtain consent and ensure
requirements of Article 5 are observed.

Dark patterns

The term "dark patterns" refers to all practices aimed at manipulating users, leading them to
unintentionally and unwillingly make specific decisions regarding the processing of their personal data.
These deceptive tactics aim to influence user behavior and can hinder their ability to safeguard their
personal information and make informed choices in order to benefit the data controller.

Examples of dark patterns include:

• Skipping: Designing the interface to lead users not to focus on the data protection aspects or
the impact of their choices.

• Stirring: Appealing to the emotions or using visual nudges, such as specific shapes and colors to
nudge the user to make a certain choice.

• Hindering: Obstructing or blocking users in their process of becoming informed or managing


their data by making the action hard or impossible to achieve

• Fickling: Designing an interface in an unclear fashion, making it hard for the user to navigate
data protection control tools and understand the purpose of the processing.

Especially in Europe, dark patterns are considered widely irrespective of the user’s right to privacy
starting from violating the principle of fair processing to additional principles such as transparency,
data minimization, and accountability as well as purpose limitation and consent, which may come into
play during assessment. Furthermore, adhering to the requirements of data protection by design and
default is essential as it helps social media providers prevent the use of dark patterns from the outset
by incorporating them into the interface design process.

Select each square to review dark pattern examples.

Artificial intelligence

Artificial intelligence is the simulation of human intelligence created by machines and computers. With
the ability to learn, reason and evaluate, artificial intelligence can replace humans and act on its own to
make automated decisions. Provisions within the GDPR affect the AI functions of automated decision-
making. Article 22, discussed in Module 5, highlights data subject rights in connection with profiling
and automated decision-making.

Organizations implementing AI technology will want to ensure privacy regulations are being met in
conjunction with the technology. The EU initiative on AI includes:

©2023, International Association of Privacy Professionals, Inc. (IAPP)


19

• Boosting the technological and industrial capacity and AI uptake across the public and private
sectors

• Preparing for socio-economic changes as AI modernizes education, training, labour markets and
social protection systems

• Ensuring ethical and legal frameworks

Machine learning

Machine learning, a type of AI, is driven by available data. The machine learns to identify patterns
in the data and applies that to new data. This enables better understanding of human behaviors
and activities.

Ethical issues

The European Commission states that AI systems will be developed, deployed and used in a way
that adheres to the ethical principles of: Respect for human autonomy, prevention of harm, fairness
and explicability.

EU Artificial Intelligence Act

The EU Artificial Intelligence Act is currently undergoing a Trilogue Procedure: Negotiations between
the Commission, the Council and the Parliament to determine the final version of the Act. The
extraterritorial scope of the Act includes all providers (those who develop or sell AI products) and users
(those who utilize AI products or services) situated in EU member states, providers not located in the
EU but providing products for use in the EU and users located outside of the EU producing output to be
used in the EU. While exemptions are still being negotiated, the Act is anticipated to have a global
impact, similar to the GDPR’s impact on the processing of personal data.

The main purposes of the Act are to regulate AI, address potential harms and ensure legal certainty to
promote investment and innovation. Additionally, the Act aims to align the organizations’ use of AIand
ensure AI systems reflect EU core values and rights of individuals such as protecting individuals from
harm and providing organizations with legal bases for using AI in its current state and as the
technology advances. The Act will take a risk-based approach as to how different types of AI will be
regulated.

Resources
EU AI Act – European Commission’s original proposal: [Link]
content/EN/TXT/HTML/?uri=CELEX:52021PC0206
EU AI Act – Council of the EU’s general approach: [Link]
14954-2022-INIT/en/pdf

EU AI Act – European Parliament’s compromise text:


[Link]
The EU Artificial Intelligence Act – Cyber Risk GmbH: [Link]

Quiz
1. Which types of laws should be considered when processing employees’ personal data? Select all
that apply.

Local employment law

EU data protection law

Member state data protection law

©2023, International Association of Privacy Professionals, Inc. (IAPP)


20

2. True or false: Some employers may be required to consult with works councils and/or trade unions
to process employees’ personal data.

3. True or false: BYOD policies are designed to protect employees’ personal data only.

4. True or false: Less intrusive alternatives to employee monitoring should always be considered first.

5. What U.S. act requires companies to have a system in place to receive anonymous complaints
about potential wrongdoing?

Washington’s Whistle-blowing Act (WOW)

Young-Underthorn Act (YOU)

Sarbanes-Oxley Act (SOX)

Barnes-Laramey Act (BLAME)

6. True or false: The ePrivacy Directive governs the processing of data through both private and public
carriers and communications networks.

7. Which of the following is not a data protection consideration associated with collecting personal
data via CCTV?

Prior checking

Duration of the video

Lawfulness

Proportionality

Individuals’ rights

Information provision

8. True or false: Under the GDPR, individuals have the absolute right to object to any form of direct
marketing at any time.

9. Which forms of marketing are subject to the ePrivacy Directive? Select all that apply.

Postal marketing

Telephone marketing

Electronic mail marketing

10. Which of the following parties involved in online behavioural advertising may qualify as a data
controller? Select all that apply.

An ad network

A website publisher

An advertiser

11. True or false: A cloud service supplier may determine technical and organisational means of
processing and remain a processor.

12. How can social media platform providers be open and transparent about the processing of personal
data?

Provide notice to third parties that personal data may be shared with them

Provide notice to lead supervisory authorities regarding applications that process personal data

Provide notice to individuals about the processing of their personal data

©2023, International Association of Privacy Professionals, Inc. (IAPP)


21

Provide notice to SMP users that the SMP provider is not a controller of personal data shared
with plug-ins

Quiz answers
1. Member state data protection law, EU data protection law, Local employment law

2. True

3. False

4. True

5. Sarbanes-Oxley Act (SOX)

6. False

7. Duration of the video

8. True

9. Telephone marketing, Electronic mail marketing

10. An ad network, A website publisher, An advertiser

11. True

12. Provide notice to individuals about the processing of their personal data

*Quiz questions are intended to help reinforce key topics covered in the module. They are not meant to
represent actual certification exam questions.

©2023, International Association of Privacy Professionals, Inc. (IAPP)

You might also like