Print

Privatsphäre in den EU-Organen

Die Verordnung (EU) 2018/1725 legt die Datenschutzverpflichtungen für die Organe, Einrichtungen und Agenturen der EU fest, wenn sie personenbezogene Daten verarbeiten und neue Strategien entwickeln. Darüber hinaus führt die Verordnung die Pflichten des EDSB auf. Diese umfassen seine Aufgaben als unabhängige Kontrollbehörde für die Organe und Einrichtungen der EU, wenn diese personenbezogene Daten verarbeiten, die Beratung zu politischen Maßnahmen und Rechtsvorschriften, die sich auf den Schutz der Privatsphäre auswirken, und die Zusammenarbeit mit vergleichbaren Behörden zur Gewährleistung eines kohärenten Datenschutzes.

Hier finden sich die EDSB-Dokumente über Privatsphäre und Datenschutz in Bezug auf die Verarbeitung personenbezogener Daten durch die Einrichtungen und Organe der EU, z. B. bei Mitarbeiterbewertung, Akkreditierung externer Besucher oder Zugangskontrolle.

Filters

10
Nov
2008

Internet monitoring - Court of Auditors

Opinion of 10 November 2008 on a notification for prior checking related to Internt monitoring (Case 2008-284)

The Court of Auditors engages in the monitoring of the Court's of its Internet infrastructure for the following purposes: (i) to ensure the functionality of the network and avoid security breaches and also (ii) to verify whether Court's users employ the Internet in accordance with the allowed uses laid down in the Internet Security Policy.

The EDPS has issued an opinion relating to Court of Auditors Internet monitoring practices which assesses  the extent to which such monitoring  complies with Regulation 45/2001.  The EDPS concludes that the intended data processing activities give rise to doubts about their compatibility with necessity and proportionality principles laid down in Regulation 45/2001. To address this problem, the EDPS recommends, among others, the following:

(i) In the absence of an adequate suspicion, to abstain from monitoring URLs of visited Web sites unless there is a justified reason for such an activity, namely, in case of extremely long URLs, and  dangerous sites as specified in SANS, CERT, and similar publications; (ii) To consider using other indicators (volume of data downloaded, time spent, and other off line indicators) to discover abuse.

The Opinion contains other recommendations regarding other aspects of the data processing (provision of information, security, transfers of information, etc).

Verfügbare Sprachen: Englisch, Französisch
7
Nov
2008

Promotion of Officials and Regrading of Temporary Agents - OHIM

Opinion of 7 November 2008 on the notification for prior checking regarding the Internal Promotion of Officials and Regrading of Temporary Agents (Case 2008-095)

The purpose of the processingis to conduct the yearly internal promotion/regrading exercise for members of staff. At the beginning of each yearly exercise, the lists of the staff members eligible for promotion and regrading are published on the OHIM's Intranet. A database of staff members to whom promotion/regrading points may be awarded is set up containing administrative data synchronised from a human resources module. The database is made accessible for the respective Directors for a limited period of time so that they can attribute the promotion/regrading points. The members of the Management Committee have to agree on a proposal of points to be awarded. An individual notification of the proposed points is sent to the staff members concerned who may lodge an appeal against the notification within ten working days to the Joint Evaluation and Promotion Committee (JEPC). Before the Appointing Authority takes a formal decision concerning promotions, the JEPC shall examine and issue an opinion on the list of candidates for promotion. It shall also issue an opinion on the overall awarding of promotion points. Wherever relevant, it shall formulate recommendations to the Appointing Authority. The final promotion/regrading points are awarded by the Appointing Authority and notified to the staff member concerned. The lists of promoted/regraded staff members are published on OHIM's Intranet.
 
The EDPS examined the procedure and concluded that there is no reason to believe that there is a breach of the provisions of Regulation (EC) 45/2001 provided that certain considerations are taken into account notably that the conservation period be reassessed after the first ten years based on practical experience; the recipients be made aware that they shall process the personal data they receive in the course of the promotions procedure only for that purpose; and that information is provided on categories of data processed, notably in the data base, and the recipients of the data other than the Management Committee and the HRD's Personnel Administration Sector.
Verfügbare Sprachen: Englisch, Französisch
5
Nov
2008

Radiation exposure - Commission

Opinion of 5 November 2008 on the notification for prior checking regarding occupational radiation exposure data (Case 2007-0383)

In order to ensure the legitimate performance of radiological surveillance and the implementation of fundamental principles governing operational protection of exposed workers the DG TREN Health Protection Cell (DG TREN H4) is processing personal data of staff members who are occupationally exposed to ionising radiation in the course of their work. Under special service contracts, approved laboratories deliver the results of occupational protection monitoring concerning staff members classified as occupationally exposed to ionising radiation.
 
The radiological surveillance and occupational monitoring data are entered manually into the Microsoft ACCESS bases Personal Dosimetry database of DG TREN H4. Data relevant to the personal radiology protection and surveillance are registered in individual radiation pass books. Following an occupational health examination, the medical service of the Commission submits information (yes/no) concerning the individual physical fitness of the staff members.
 
The EDPS delivered a prior checking opinion considering that there is no reason to believe that there is a breach of the provisions of the Regulation provided notably that the right of access and rectification of personal data of the persons concerned is not conditioned to "specific circumstances"; information is provided on the categories of recipients and right to have recourse to EDPS at any time; individuals receive the information listed in Article 12 (privacy statement) before the processing operation is launched; and that the confidentiality and security of communications is guaranteed when information is transferred between subcontractors and the DG TREN-H4, and between DG TREN-H4 and the national competent authorities.
Verfügbare Sprachen: Englisch, Französisch
3
Nov
2008

Traffic violations - Commission

Opinion of 3 November 2008 on the notification for prior checking on "Traffic violations with official vehicles of the Commission managed by the Infrastructure and Logistics Office - Brussels (OIB)" (Case 2008-395)

Within the European Commission, the Mobility and Supplies Unit, which is responsible for managing the car pool, deals with offences against the highway code committed by the drivers of official Commission vehicles managed by the OIB. The purposes of the processing operation are to examine whether, when traffic violations are committed by the drivers of official Commission vehicles, the immunity granted by the Protocol on Privileges and Immunities can be invoked, and to provide administration and follow-up.

The proposed data processing operation complies with Regulation (CE) No 45/2001, if the Commission:

  • reminds anyone who receives or processes data in the context of the procedure for handling penalty notices that the data may not be used for other purposes;
  • complies with Articles 8 and 9 as regards the transfer of data to the competent authorities;
  • as well as publishing the privacy statement on the internet, sends it to all data subjects concerned by this processing operation at the same time as the document on the procedure for forwarding the penalty notice;
  • updates the "Information for the attention of drivers of official Commission vehicles" to make the necessary changes (name of the controller and details of the data recipients).
Verfügbare Sprachen: Englisch, Französisch