According to the European Commission, the Digital COVID Certificate (DCC) is a digital credential that will help ensure that currently in-effect restrictions can be lifted in a coordinated manner, facilitating the mobility of European Union citizens. This certificate will include only the necessary key information, such as name, date of birth, date of issuance, relevant information about the vaccine, test, or recovery, and a unique identifier. In principle, the Spanish government intends to have it implemented by June of this year, so that it will be fully functional in time for the summer months.

Since this is a project that has generated some controversy, Ruth Benito, Of Counsel at ELZABURU and a specialist in personal data protection and privacy law, provides the following analysis of the privacy requirements expected of this certificate upon its implementation:
1. Data Protection and Security by Design and by Default
This is the first point for two main reasons:
- Contrary to popular belief, applying privacy and security criteria from the outset of any project helps ensure its success in terms of both the project’s effectiveness and individuals’ trust, reduces risks to those individuals, and avoids the need for subsequent adjustments.
- We are concerned that the proposed European Regulation on the Digital Green Certificate (DGC) states that no impact assessment was conducted due to the urgency of the matter, even though such assessments are one of the tools that can instill the most confidence in the public.
2. Complete transparency
We, as European citizens, have the right to know exactly what information this certificate will contain about us, how it will be handled, and who is involved in that process.
The future publication of the CVD Regulation (currently only a proposal) will provide a great deal of information on this subject, but there will still be many specifics unique to each Member State, particularly with regard to companies, technology, and the security measures implemented in each case.
3. Non-discrimination
One point that several countries have emphasized is that this CVD must not allow for any form of discrimination.
This Certificate is designed to facilitate the safe free movement of European citizens among EU Member States. Therefore, it must be ensured that it will be used solely for this purpose and not for other matters that could involve discrimination—not even by the certificate holder themselves—such as if it were used in job recruitment processes.
It is worth asking whether the CVD is already inherently discriminatory to some extent, given that those who have not yet been vaccinated or had the disease will have to pay for diagnostic tests—the results of which may be included in the certificate or verified through other means—in order to be able to travel.
4. Actual usefulness and effectiveness
The information contained in the CVD must be up to date at all times, but it must also be appropriate for the intended purpose. This is an issue that does not appear to have been fully resolved at this time, as there is still no scientific evidence that immunized individuals—whether because they have had the disease or because they have been vaccinated—do not transmit the disease; in other words, that they cannot infect others.
Furthermore, since it is still too early to tell, it is also unknown how long that immunity will last. Consequently, the information does not appear to be as reliable as would be desirable for the intended purposes, which may conflict with the principle of data accuracy. We understand that progress must be made on this issue and that scientific conclusions and evidence will be taken into account to make the necessary adjustments to the system to ensure its maximum effectiveness while ensuring the proper use of our personal data.
5. Minimize data
Both the data processed “behind the scenes” by the CVD and the data ultimately displayed in the app or on paper when traveling should be limited to the minimum truly necessary to achieve the intended goal.
We do not yet know exactly what information will be displayed when the passport is used, but this is something that must be analyzed in detail. For example, a simple “Approved” or “Not Approved” status might be sufficient for travel, if it were not necessary to know the specific circumstances that qualify the person (being vaccinated, having recovered from the disease, or having a negative diagnostic test result), or it might be necessary to know the specific qualifying circumstance but not, for the purposes of granting entry into the country, to know which specific vaccine was administered or what type of test was performed, etc.
6. Keep an eye on your travel companions
National authorities must assess whether providers of technology, infrastructure, storage, etc., offer sufficient guarantees to ensure that the handling of such sensitive personal information is carried out with appropriate security measures and that there will be no unjustified interference with the rights of European citizens. In any case, we understand that the company or companies selected, with regard to Spain, must comply with the measures required under the National Security Framework.
7. Interoperability
As already stated in the proposed European regulation, uniform conditions must be in place for the issuance, verification, and acceptance of certificates in all EU countries. Otherwise, the mobility of Europeans within the Union would not truly be facilitated.
8. Universal and free of charge
The proposed regulation also rightly stipulates that the CVD must be universal and free of charge, which does not mean that it has to allow us to travel for free all over the world (we wish!), but rather that all Europeans must be able to access the certificate free of charge.
Free access is indeed a prerequisite for the CVD to be universal. However, it must also be ensured that certain vulnerable groups—such as minors (who, moreover, are not currently receiving the vaccine), people with disabilities (accessibility), and those disadvantaged by the digital divide—can effectively benefit from it.
9. Whoever starts it and stirs it up gets a slap in the face
This is not a pie that can be sliced up. Therefore, the authorities and companies involved in the CVD may not, outside of its intended purposes, share Europeans’ health information or exploit it in any way, and cross-border passenger transport service operators that need access to the certificates should not create their own databases containing that information.
10. Don't come here to stay
The CVD only makes sense—and is therefore justified and legitimate—for as long as the pandemic and/or public health emergency lasts. Therefore, once that situation has passed (hopefully sooner rather than later), both the certificate and the technology behind it must be discontinued, and the health information of Europeans that has been stored in the CVD’s systems must be deleted.
Previously published in Confilegal, by Luis Javier Sánchez.
For more information, you can listen to the interview with Ruth Benito on Capital Radio's "Ventaja Legal."
Author: Ruth Benito

