Passenger Registration: A Challenge for Data Protection in the Tourism Sector 

The entry into force of Royal Decree 933/2021 has brought data protection in the tourism sector into the spotlight. The requirement to collect and retain a large volume of sensitive information about travelers for three years has raised concerns among experts, who warn of privacy risks and potential penalties.

A disproportionate measure?

The data that must be recorded includes personal, financial, and contractual information, such as national ID numbers, addresses, credit card numbers, and email addresses. This volume of information, combined with the requirement to store it for three years, increases the likelihood of data breaches and misuse. Furthermore, some of this data—such as credit card numbers—is highly sensitive, which increases the risk of identity theft in the event of a security breach.

Without robust safeguards, the risk of losing control over personal data is very high. Furthermore, this regulation could violate fundamental principles of the GDPR (General Data Protection Regulation), such as the principle of data minimization, which requires limiting data collection to the minimum necessary to achieve the intended purpose.

Administrative Burdens and Legal Risks for Businesses

Data protection is not only a concern for travelers but also a challenge for businesses. The decree imposes a significant administrative burden, especially on small businesses and the self-employed, who must implement technological systems to properly record, store, and protect information.

These investments are not only costly but also complex to implement in companies with limited resources, which can lead to unintentional noncompliance and, ultimately, penalties.

Fines can be substantial. Noncompliance with the GDPR due to issues such as data breaches, security failures, or misuse of information can result in penalties of up to 20 million euros or 4% of the company’s annual revenue, whichever is greater.

In addition, the decree establishes specific fines forviolations related to passenger registration, ranging from 100 to 30,000 euros, depending on the severity.

Equally important is the impact on day-to-day operations. Managing this data can slow down check-in processes, lead to conflicts with customers who refuse to provide additional information, and divert resources from other critical areas of the business. This is especially relevant in a highly competitive industry such as tourism, where any delay or problem can negatively affect the customer experience and, ultimately, the establishment’s reputation.

The Importance of Ensuring Data Proportionality

The precedent set by the Court of Justice of the European Union’s annulment of Directive 2006/24/EC, due to its indiscriminate nature, should serve as a warning. In the words of Ruth Benito, a data protection expert at Elzaburu: “The mass storage of personal data without proportionate measures or clear justification creates risks that may be irreversible for privacy.”

This scenario underscores the need to place data protection at the center of any measure involving the mass processing of personal information. Only a balanced approach—one that combines robust security safeguards with a clear and proportionate justification—will ensure both public safety and the fundamental rights of citizens. At the same time, it is crucial to protect the competitiveness of the tourism sector, one of Spain’s economic drivers.

Within this framework, companies must prepare to meet this challenge by investing in compliance and data protection systems that not only meet regulatory requirements but also strengthen travelers' trust.

Ruth Benito, Of Counsel. Privacy and Data Protection 

New Code of Conduct: A Step Forward in Data Protection in the Telecommunications Sector

The telecommunications sector in Spain is taking an important step toward self-regulation with the implementation of the new Code of Conduct. The AEPD and Autocontrol have launched a new mediation system, which took effect on December 17, to resolve data protection disputes within the sector through out-of-court settlement.

Greater representation of the sector, greater coverage for users

One of the main changes in the Code of Conduct is the expansion of its scope. The original operators that were part of the Protocol—Movistar, Orange, Vodafone, and MásMóvil, among others—are now joined by Euskaltel, Virgin Telco, R, and Telecable. This ensures greater representation of the sector, which directly benefits users by providing a common framework for resolving complaints related to data protection.

The Code also expands the types of cases covered under its scope of application. This means that more types of complaints can now be addressed through this mechanism, although those seeking financial compensation are expressly excluded. This approach reinforces the Code’s primary objective: to facilitate a swift, free, and effective resolution of issues related to privacy and data protection.

SELF-REGULATION: The Key Element in the Process of Promoting Swift and Flexible Agreements

To ensure impartiality, the Code designates the AUTOCONTROL Advertising Jury as the supervisory body. This independent third party is responsible for managing mediations between interested parties and participating operators.

Mediation typically lasts 30 days, but this period may be extended to up to three months if there are valid reasons. Although AUTOCONTROL’s proposed solutions are not binding, the agreement reached by both parties will be binding. In the event of a disagreement, the complainant may request that the complaint be referred to the AUTOCONTROL Panel, provided that the operator agrees.

A notable feature of the Code is its commitment to the confidentiality of proceedings, a crucial requirement given that many complaints may involve sensitive information. However, the Panel’s decisions are public, which brings transparency to the process and reinforces its credibility.

“Mediation, managed by an independent third party such as AUTOCONTROL, promotes swift and flexible agreements, although the non-binding nature of the proposed solutions may limit its effectiveness in certain cases. This is because, as is customary in any type of mediation, the proposed solutions offered by the mediator—in this case, the AUTOCONTROL Mediation Unit—are not binding. Only the agreement reached by the parties and the decision of the AUTOCONTROL Panel would be binding, should the parties voluntarily decide to submit the matter to the Panel,” Agustín Alguacil.

A system of penalties designed to act as a deterrent through referral to the Spanish Data Protection Agency (AEPD)

The Code reinforces its effectiveness through a system of penalties for noncompliant operators. Violations are classified as minor, serious, or very serious, and can result in penalties ranging from warnings to the temporary suspension of rights under the Code or even expulsion.

Although the sanctions do not include financial penalties, their deterrent effect lies in the reputational impact and in the referral of the decisions to the Spanish Data Protection Agency (AEPD). This mechanism complements the AEPD’s powers, ensuring that the self-regulatory system aligns with national and European regulations.

Overall, the Code of Conduct serves as an example of how the private sector can establish effective self-regulatory mechanisms, striking a balance between sectoral autonomy and the rights of stakeholders.

Agustín Alguacil, Associate, Legal Department. Business and Contracts

The EDPB's opinion on "pay or consent" could have a significant impact

The European Data Protection Board has finally weighed in on the controversy surroundingthe“pay or OK” policyintroduced in Europe last yearbyMeta, the company that owns Facebook and Instagram.

The Committee, known by the acronym EDPB, concludes that the procedure used by the tech giant in an attempt to comply with the General Data Protection Regulation (GDPR) is invalid.

First of all, it should be clear that this is neither a court decision nor new legislation, nor is it a binding resolution. What the EDPB has issued is an opinion in which, at the request of several European data protection authorities, it provides its interpretation of how “pay or ok” fits within data protection legislation.

However, the impact could be significant, especially for large platforms that, until recently, allowed access to their content completely free of charge. This is because, in practice, the EDPB report establishes as a general rule that paying a fee (whether a one-time payment or a subscription) cannot be offered as the sole alternative to cookies.

Thus, platforms that maintain the pure “pay or ok” model, without additional options, will be required to demonstrate that the system they have adopted does not force their users to accept cookies, but rather that users consent to them of their own free will—and this, given the assumptions contained in the EDPB’s opinion, is extremely complicated, if not impossible.

It is not new legislation, but the ruling must be taken into consideration

It is important to note that the EDPB is not issuing a ruling specifically and individually regarding Meta, even though that is the case underlying its opinion; however, this opinion must be taken into account not only by Meta but by all major web platforms.

Cookie legislation requires that cookies that are not strictly necessary for the website to function must be expressly consented to by users in order to be enabled. Among these cookies are behavioral advertising cookies, which are used to profile users in order to later target them with advertisements. And the consent that users provide must be given of their own free will.

A large part of the business of major platforms is based on selling brands the ability to target their advertising at users who, based on their profile, are more likely to purchase their products or services. But profiling as invasive as that carried out by many platforms—whether through cookies or any other system—requires user consent, and the EDPB understands, in essence, that if the only alternative to such consent is to pay a fee, it must be presumed that the consent is not freely given—especially if the fee is disproportionate and if the platform had previously offered its content or services for free for a long time.

Furthermore, it should be noted that the “pay or ok” approach also violates one of the conditions for valid consent, namely that consent must be specific to the particular data processing in question. If users’ consent is required both to track and profile them and to subsequently serve them advertisements, both types of consent should be requested separately rather than as a single, blanket consent, as is the case with Meta’s “pay or ok” system and others.

Among the possible solutions, the Committee suggests using “random” advertising

If Meta wanted to comply with the EDPB’s interpretation, it seems clear that it should avoid offering payment as the only alternative to profiling and behavioral advertising. The EDPB itself suggests, in addition to setting non-excessive amounts for the payment option, that companies also offer the alternative of “random” advertising or advertising that is less invasive of users’ privacy.

For example, by letting users themselves select, from a closed list of options, their interests or the topics for which they would like to see promotions and advertisements.

One possible solution would be for users to be able to choose from several options, such as: a) an ad-free payment plan, b) a free plan with ads tailored to the user’s preferences, c) a free plan with “random” ads without any profiling, and d) a free plan with behavioral advertising cookies.

Each of these options could entail some differences in terms of service provision or platform use, but in essence they should be equivalent so that the user does not feel compelled to choose just one of them, as doing so would otherwise cause unjustified or disproportionate harm. Furthermore, for any other cookies that also require user consent, such consent should be obtained separately.

However, the platforms—which understand their business and their users—will likely find other solutions or different models that are in line with the EDPB’s position. In some cases, it may be sufficient to lower the price charged, while in others, it may be necessary to adopt alternatives accompanied by some form of compensation or additional benefit for the user. However, the latter must be evaluated very carefully, bearing in mind that the EDPB also states that personal data cannot be used as a bargaining chip.

The Committee provides guidance on evaluating the criteria for informed, specific, and unambiguous consent that major online platforms must take into account when implementing “consent or pay” models

In addition to this opinion, the EDPB also announced that it will develop guidelines on “consent or compensation” models with a broader scope and will collaborate with stakeholders on these upcoming guidelines.

Ruth Benito, Of Counsel for Data Protection and Privacy at ELZABURU

AEPD Guide on Attendance Tracking Using Biometric Systems.

On November 24, the Spanish Data Protection Agency (AEPD) published its Guide on Attendance Tracking Using Biometric Systems. The truth is that, following several reports and guidelines from other supervisory authorities, the sector was eagerly awaiting the Agency’s definitive stance, as it had not previously issued such a comprehensive opinion on these processing activities. Specifically, we are referring to time-and-attendance systems (clocking in) and access control systems using biometric identification (such as clocking in with a fingerprint or gaining access via facial recognition, etc.).

The truth is that, after learning of the AEPD’s opinion, many would surely have preferred that it had not weighed in on the matter. The fact is that this guide is a direct blow to the very foundation of biometric identification systems in general, and particularly to attendance and access controls in the workplace. In it, the AEPD revises some of its previous criteria on the matter and clarifies some of the essential requirements that must be met when processing data.

We could oversimplify things and just say that, as of now, such activities cannot be carried out. But, even if only by a very small margin, that’s not exactly the case, so below we’ll outline the most important points from the Agency’s new guide. We promise to focus on what matters and explain it as simply as possible.

The General Data Protection Regulation (GDPR) generally prohibits the processing of special category data, which may be processed only in exceptional cases if any of the circumstances provided for in the Regulation itself apply. Biometric data constitutes special-category data when used to“uniquely identify a natural person.” Based on this mathematical concept of “uniqueness” associated with the purpose of identification, it appears that the AEPD initially interpreted that, if biometric data were used for identification purposes, it would be considered special-category data, but not if it were used in authentication systems. We will not delve further into this point, given that the European Data Protection Board has already clarified that, ultimately and to put it very simply, if an authentication process requires identification or if identification occurs simultaneously, the biometric data is being used to identify a specific natural person—and that is what matters in determining whether special-category data is being processed. This is one of the reassessments now being made by the AEPD.

It is therefore no longer possible to argue that what takes place during a time-and-attendance check or an access control check is authentication rather than identification, since it amounts to the same thing.

It is therefore necessary to determine whether the prohibition on the processing of biometric data can be waived under any of the exceptions set forth in the GDPR. Among the scenarios outlined in the Regulation for the processing of special-category data, only the following two would apply for the purposes discussed here:

  • If the employees' consent has been obtained, which must be informed and given unequivocally, specifically, and freely.
  • If necessary to fulfill obligations or exercise rights under labor law and social security and social protection laws. Note, however, that this is subject to authorization by a European or national regulation or a collective bargaining agreement that establishes adequate safeguards for the rights and interests—in this case, those of employees.

Limitations

And this is where the story starts to turn into such a horror movie that it puts “The Exorcist” or the entire “Saw” series to shame. Why? Because in this new guide, the AEPD practically, practically, practically shuts the door tight on these two options:

  • I previously understood that these processing activities could be justified by the existence of a legal provision that addressed them: Article 20.3 of the Workers’ Statute regarding access control and Article 34.9 regarding time tracking, attendance monitoring, or clocking in for the workday—whatever we choose to call it. Now, echoing the position of other data protection supervisory authorities, it has revised its stance and determined that those articles are insufficient because they do not expressly mention the processing of biometric data and because they do not include the safeguards that must be applied to protect employees’ privacy.
  • It also states that consent cannot serve as a legal basis for such processing either, since in an employer-employee relationship it must be presumed that the employee will not freely give consent, given the company’s dominant position.
  • Even if free consent were possible, this would imply that an alternative must be provided for those employees who do not consent to the processing of their biometric data; and if that alternative is less invasive of employees’ privacy, this implies that the processing of biometric data is not indispensable and, therefore, pursuant to the principle of data minimization (not processing data that is not strictly necessary), it is not proportionate and cannot be carried out.

Conclusion: It becomes extremely difficult, if not impossible, to rely on biometric identification systems for these purposes within the company.

Is there no solution? We very much fear that, as long as there is no European or Spanish regulation specifically governing these biometric checks, the only way to process this type of data in the workplace is to negotiate it and expressly include it in a collective bargaining agreement, along with the safeguards that companies must implement when adopting these systems to ensure their employees’ rights.

Furthermore, if—with a great deal of luck—you manage to overcome this first hurdle, you would then have to meet the rest of the requirements set forth by the AEPD in this guide. And be warned: these requirements are neither few in number nor easy to meet, and they extend to other possible uses of biometric data outside the workplace.

So, if by any chance lawmakers were to decide to regulate these biometric control systems, please—while they’re at it—don’t skip the data protection impact assessment process, as that will ultimately save companies money when it comes to adopting these systems.

Ruth Benito Martín, of Counsel at ELZABURU

Whistleblower Protection Act.

On February 21, the long-awaited Whistleblower Protection Act (Law 2/2023 of February 20, regulating the protection of individuals who report regulatory violations and combat corruption) was published in the Official State Gazette (BOE).

This law transposes Directive 2019/1937 of October 23, 2019, on the protection against retaliation of persons who report violations of Union law, also known as the Whistleblowing Directive.

The law incorporates two objectives of the Directive itself: to protect whistleblowers and to establish minimum standards for reporting channels.

 

What is the scope of the law?

The law protects individuals who report violations of European Union law and serious or very serious criminal or administrative offenses under our legal system.

Therefore, the law focuses on investigations into violations that are considered to have the greatest impact on society as a whole.

What exclusions are provided for in the law?

The law shall not apply to information relating to classified information. Nor shall it affect the obligations arising from the protection of professional secrecy for medical and legal professionals, the duty of confidentiality of law enforcement agencies in the course of their duties, or the confidentiality of judicial deliberations.

Nor shall the law apply to information concerning violations in the conduct of procurement procedures that contains classified information or that has been designated as secret or confidential, or to those whose implementation must be accompanied by special security measures or where required to protect interests essential to national security.

Who are the protected individuals?

Protection extends to all individuals who have professional or employment ties to entities in both the public and private sectors, including those whose professional relationship has ended, as well as volunteers, interns, trainees, and even individuals currently in the hiring process.

Protection is expressly extended to individuals who may provide assistance to whistleblowers, to those in their circle, and to legal entities owned by the whistleblower.

Internal Information System?

The Internal Reporting System is considered the preferred channel for reporting information, since prompt and effective action within the organization itself could prevent the harmful consequences of the actions under investigation.

The internal reporting system must always consist of a channel, a person responsible for the system, and a specific procedure.

The channel must meet the requirements for accessibility, confidentiality, proper monitoring procedures, investigation, and protection of the whistleblower.

The administrative or governing body of each obligated entity or agency shall be responsible for implementing the internal information system and shall act as the controller of personal data.

The administrative or governing body must designate the person responsible for managing the system. The appointment must be reported to the Independent Whistleblower Protection Authority (A.A.I.).

The person responsible for the system must perform his or her duties independently and autonomously from the entity’s or agency’s other bodies; he or she may not receive instructions of any kind in the performance of those duties and must have all the necessary personnel and material resources to carry them out.

Channel management may be carried out within the organization itself or through an external third party, provided that independence, confidentiality, data protection, and the secrecy of communications are guaranteed.

Internal channels must allow for communication in writing (mail, electronic means) or verbally (telephone, voice messaging) or a combination of both. In-person meetings are also permitted at the request of the whistleblower.

Are anonymous complaints allowed?

The law permits the filing and processing of anonymous complaints, subject to the provisions of any national law, or when requested in the context of legal proceedings, or when it is argued that the court needs to know the complainant’s identity to ensure the right to a defense.

Which entities are required to have information systems in place?

All private-sector individuals or legal entities with more than 50 employees are required to have an information system in place.

Likewise, regardless of their number, political parties, labor unions, business organizations, and the foundations affiliated with them are required to comply, provided they receive public funds for their financing.

Regardless of their size, all public institutions and agencies must have an information system.

Private-sector legal entities with between 50 and 249 employees may share among themselves the Internal Information System and the resources allocated to the management and processing of communications, if they expressly so decide.

 

Is there any external communication system?

The law provides for the creation of an external reporting channel to complement the internal one, which would be administered by the Independent Whistleblower Protection Authority (A.A.I.), an independent administrative authority yet to be established.

This channel must be independent and autonomous.

Any individual may use this channel, either directly or after first filing a complaint through the internal communication channel.

The A.A.I. may accept the complaint for processing, reject it with a statement of reasons, immediately notify the Public Prosecutor’s Office if the conduct could constitute a crime, or refer it to another competent authority or agency.

The time limit for investigating the matter and responding to the whistleblower may not exceed three months from the date the report is entered into the registry. Whatever the decision, it will be communicated to the whistleblower, unless the whistleblower has waived this right or the report was submitted anonymously.

Decisions issued by the A.A.I. do not provide for any appeal, whether administrative or judicial, without prejudice to any administrative or contentious-administrative appeal that may be filed against any decision that concludes the disciplinary proceeding that may be initiated in connection with the facts described.

Rights and Protections Against Retaliation?

Whistleblowers who use internal and external channels will be covered by a specific protection program against retaliation.

Any conduct that could be classified as retaliation and that occurs within two years after the conclusion of the investigations is prohibited and shall be deemed null and void.

The following could be considered retaliation: suspension of the employment contract, dismissal, or termination of the employment or statutory relationship; nonrenewal or early termination of the employment contract; imposition of disciplinary measures; demotion; denial of promotions; etc.

 

Penalties?

The law provides for penalties in both the public and private sectors in the event of violations, which include, as very serious violations, violations of confidentiality and anonymity guarantees; actions intended to reveal the whistleblower’s identity; breaches of the duty of confidentiality regarding the information; publicly communicating or disclosing information while knowing it to be false; and failure to comply with the obligation to have an internal reporting system in place, among others.

Fines for legal entities can amount to a maximum of 1,000,000 euros for very serious violations.

When does the law take effect, and what is the deadline for its implementation?

The law will take effect 20 days after its publication. The deadline for establishing internal reporting systems is three months from the law’s effective date.

As an exception, for private-sector legal entities with 249 employees or fewer, as well as municipalities with fewer than 10,000 residents, the deadline will be extended to December 1, 2023.

 

Tránsito Ruiz, Associate at ELZABURU.

 

Whistleblower Protection Act: Key Data-Related Issues.

After months of uncertainty following the release of the draft bill and several amendments in the Senate, the Whistleblower Protection Act was published in the Official State Gazette on February 21, 2023, as Law 2/2023 of February 20, regulating the protection of individuals who report regulatory violations and combat corruption. Thus, Directive 2019/1937 on the protection of persons who report breaches of Union law—commonly known as the WhistleblowingDirective—has finally been transposed into Spanish law.

This Law, which takes effect 20 days after its publication in the Official State Gazette (BOE), provides for the proper implementation of a whistleblower system—or, in the terms of the Law, an “internal reporting system”—as an essential tool for companies to provide adequate protection to whistleblowers. By their very nature, these systems involve the processing of personal data that presents certain specific considerations that must be taken into account; for this reason, the Act devotes its entire Title VI to the protection of personal data.

In this post, we analyze the most significant legislative developments regarding data protection in whistleblower systems following the publication of this law in the Official State Gazette (BOE):

  • Data Limited to the Intended Purposes: Personal data that is not relevant to the investigation of the complaint within the scope of this law must not be collected; if such data is collected by mistake, it must be deleted without undue delay.
  • Lawfulness of Data Processing: Data processing that is necessary to comply with this Act is presumed to be lawful. The appropriate legal bases are legal obligation and public interest. For these purposes, special category data may be processed in the complaint system, as it is necessary for the purposes of the corresponding investigation and in accordance with Article 9.2.g) of the GDPR: because it is necessary for reasons of substantial public interest, provided that the processing of the data is proportionate to the objective pursued, essentially respects the right to data protection, and appropriate and specific measures have been taken to protect the fundamental rights and interests of the data subject.
  • Duty to Provide Information: Data subjects (including both the organization’s own employees and third parties) must be provided with information regarding the processing of their data in accordance with the provisions of the GDPR; however, confidentiality must be maintained regarding the complainant’s data, whose identity must remain confidential and under no circumstances may be disclosed to the respondent. The identity of the whistleblower—when known because the complaint was not filed anonymously—may only be disclosed to the judicial authority, the Public Prosecutor’s Office, or the competent administrative authority in the context of a criminal, disciplinary, or sanctioning investigation.
  • Exercising Rights: Individuals whose data is processed in the complaint system have all the rights provided for in the GDPR, with the sole exception that if the person against whom the complaint is filed exercises the right to object, it is presumed—unless proven otherwise—that there are compelling legitimate grounds justifying the processing of their data; therefore, their request may be denied.
  • Access to Personal Data: Only the following individuals may access personal data in the reporting system:
  • The person responsible for the system itself and who manages it directly.
  • The human resources manager or the appropriate authority when disciplinary action may be taken against an employee.
  • The head of the legal department when legal action is warranted.
  • Data controllers who need the data to provide their services.
  • The Data Protection Officer.

In addition, the information may be shared with other individuals or third parties when necessary to implement corrective measures within the organization or to carry out any applicable disciplinary or criminal proceedings.

  • Data Retention Period in the Reporting System: The general rule is that personal data contained in the reporting system shall be retained therein only for as long as necessary to determine whether an investigation should be opened. In any case, if three months have passed without an investigation having been initiated, the data must be deleted from the reporting system, unless it has been anonymized or the purpose of retention is to provide evidence of the system’s operation.
  • Data Protection Officer: Notwithstanding the provisions set forth above in the Draft Bill, it is confirmed that the requirement to appoint a Data Protection Officer has ultimately been eliminated for companies that were required to implement an internal reporting system solely because they were subject to this obligation, without prejudice to the fact that they will have to appoint one if it applies to them in accordance with the provisions of the General Data Protection Regulation and/or the Organic Law on Data Protection and the Guarantee of Digital Rights.
  • Joint Control. In cases where there is joint control over the management of a complaint-handling system (for example, because a group of companies shares a single system that they manage jointly), the Law expressly mentions the obligation to enter into a joint control agreement in accordance with the provisions of Article 26 of the GDPR.
  • Security Measures: Obviously, every reporting channel must have robust security measures in place to ensure, to the greatest extent possible, above all the confidentiality of data, as well as its integrity and availability.

 

Eduardo Oliveros Caballero, attorney at ELZABURU.

Please note: The deadline for bringing existing contracts into compliance with the GDPR is approaching.

It will soon be four years since the General Data Protection Regulation (GDPR or the Regulation) has been fully in effect. Specifically, on May 25, 2022. This will certainly be a good time for companies to assess their progress and their actual compliance status, if they have not already done so over the past few years.

But that date also marks the end of a grace period that, according to some interpretations, was granted to us by our Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPD GDD). And I say it was granted to us because, unlike the Regulation itself—which says nothing expressly on the matter— Transitional Provision 5 of our national law established that data processor agreements entered into prior to the GDPR’s entry into force—in accordance with the requirements of the previous Organic Law on Data Protection—could remain in effect for the term agreed upon therein and, if entered into for an indefinite term, until May 25, 2022.

Since the Regulation took effect, any of these contracts that are newly signed—or that renew the provision of services—must include, at a minimum, the commitments that Article 28 of the GDPR requires to be included in them. These commitments are more stringent than those required by our previous Data Protection Act (LOPD) and, in practice, have resulted in longer contracts. Contracts that had already been signed prior to the Regulation’s entry into force had to be brought into compliance with it, and this is where the deadline comes into play—a deadline that, for open-ended or indefinite-term contracts, is about to expire.

Consequently, any contract entered into for an indefinite term with a vendor that will process personal data as a data processor must be fully compliant with the GDPR by May 25 at the latest.

To determine this, it is best to analyze each case individually. It is not strictly necessary to enter into a new service agreement—or master agreement—if the existing one remains in effect and is not to be amended. A new engagement agreement may not even be entirely necessary; in some cases, it may be sufficient to add an addendum—either to the master agreement or to the engagement agreement, as appropriate—containing the necessary provisions in accordance with the Regulation.

In any case, let us remember that the GDPR requires the data controller to select only data processors that provide guarantees that they will respect the rights and freedoms of data subjects in the processing of personal data. In other words, companies must evaluate those of their suppliers who will process personal data under their responsibility. Furthermore, as the Spanish Data Protection Agency has already indicated in some of its rulings, this evaluation cannot be limited to the time of contracting but must be repeated periodically. Neither the Regulation nor our national legislation specifies the frequency with which this assessment must be conducted, and an organization may very well assess its data processors at different intervals, depending on the risk associated with the processing, the risk associated with the data processor, or other reasons or criteria.

In any case, now is a good time to evaluate those data processors with whom contracts dating from before May 25, 2018, are still in effect, if this has not been done during this entire period. Ideally, this should be done using a system or procedure that is as objective as possible and that is embedded within the supplier approval process—if the organization has such a process in place (data protection by design and by default)—but which, at the same time, for the reasons stated, can be activated independently to carry out the relevant periodic reviews.

Furthermore, if the data processor—or any of its entities involved in data processing—is located outside the European Economic Area (EEA) in a jurisdiction that has not been designated a safe haven through an appropriate adequacy decision by the European Commission, the risk associated with this international data transfer must be assessed. This is done through assessments known as TIA (transfer impact assessment), in which the ideal approach is to analyze the risk associated with four elements: the data exporter, the characteristics of the transfer itself, the legal framework of the data’s destination, and the data importer or recipient.

Finally, it is important to remember that the obligation to enter into a data processing agreement—or to include equivalent provisions in the main contract itself—rests with both the data controller and the data processor, and that such an agreement or legal instrument must be in writing, whether in physical or digital format.

Bonus track: For the purposes of both interpreting the contract and providing evidence in the event of potential claims and/or disputes between the parties, it is very useful to include, as annexes to the data processing agreement, the questionnaire that the data processor was required to complete for evaluation and, where applicable, to assess the risk of an international data transfer, as well as—if not included in said questionnaire— the specific security measures that the processor declares to have implemented in connection with the data processing it will carry out on behalf of the data controller.

 

By Ruth Benito 

The role of Data Protection Officer will be mandatory for medium-sized companies.

The preliminary draft bill transposing the Whistleblowing Directive establishes the requirement that all companies with more than 50 employees appoint a Data Protection Officer

 

On March 4, the Preliminary Draft Bill regulating the protection of individuals who report regulatory violations and combat corruption was approved, transposing Directive 2019/1937—known as the Whistleblowing Directive—into Spanish law. One of the transposed obligations is to implement an internal reporting system, or whistleblowing channel, which will be mandatory for all companies with more than 50 employees. This obligation has raised a significant issue that goes beyond the scope of criminal compliance and affects compliance with data protection regulations.

 

The Role of the Data Protection Officer

Article 34 of the Draft Bill establishes that all companies required to have a whistleblower channel will also be required to appoint a Data Protection Officer (or DPO, for short). Thus,all companies with more than 50 employees will be required to appoint a DPO, unless they were already required to do so under applicable data protection regulations. The DPO will, of course, perform their duties with respect to all data processing carried out by the organization, not just the processing of data arising from a whistleblower channel.

The Data Protection Officer is a professional role established under both European (GDPR) and national (LOPD GDD) legislation. This role may be filled by a natural person or a legal entity, either internal or external to the company, but must always be independent.

Its functions include, among others:

  • provide information, offer guidance, and monitor compliance with data protection regulations.
  • serve as the point of contact for the supervisory authority—in the case of Spain, the Spanish Data Protection Agency.

New Requirements for Medium-Sized Businesses

If this new draft bill is approved, the number of companies that would be required to appoint a Data Protection Officer (DPO) would be immense, causing a surge in demand for these types of services from companies, which are not always prepared to handle these functions internally due to the high level of specialized knowledge required of a DPO.

In the coming months, it will be crucial to pay close attention to the development of this draft bill in order to identify potential changes and—if it is approved as currently drafted—to ensure that all medium-sized companies are properly prepared to assume these new obligations and have a Data Protection Officer in place.

 

Author: Eduardo Oliveros

Legal Protection of Databases

Judgment of the Court of Justice (Fifth Chamber), Case C-762/19

The Court of Justice of the European Union (hereinafter the“CJEU”) has ruled, in Case C‑762/19, on the prohibition against any third party “extracting” or “reusing,” without the manufacturer’s authorization, all or a substantial part of the contents of the database.

database, icons, blue

 

The issue at hand concerns the compatibility of the operation of a specialized search engine with thesui generisright set forth in Directive 96/9, a matter that the Riga Regional Court has referred to the CJEU through two preliminary rulings, seeking to clarify, on the one hand, whether the display, in the list of results generated by a specialized search engine, of a hyperlink that directs the user of that search engine to a website provided by a third party—where the content of a database of job listings can be viewed—falls within the definition of “reuse” set forth in Article 7, paragraph 2(b) of Directive 96/9, and, second, whether the information derived from the meta tags of that website displayed by the search engine should be interpreted as falling within the definition of “extraction” set forth in Article 7, paragraph 2(a), of the aforementioned Directive.

To address these issues, we must first clarify the scope and purpose ofsui generis protection. The purpose of the sui generis right is to ensure the protection of a substantial investment in the creation, verification, or presentation of the contents of a database by granting the maker of that database the ability to prevent the unauthorized extraction or reuse of all or a substantial part of the contents, so that the person who took the initiative and assumed the risk of making a substantial investment may be rewarded for it.

It should also be noted that, pursuant to Article 7 of Directive 96/9, the protection of a database under the sui generis right is justified only if the gathering, verification, or arrangement of the contents of that database represent asubstantial investment from a quantitative or qualitative standpoint.

With regard to the criteria for determining whether a user’s act constitutes “extraction” or “reuse” within the meaning of Directive 96/9, “extraction” is defined as “the permanent or temporary transfer of the entire contents or a substantial part of the contents of a database to another medium, regardless of the means used or the manner in which it is carried out.” As for “reuse,” it encompasses “any form of making available to the public the entire contents or a substantial part of the contents of the database through the distribution of copies, rental, online transmission, or other means.” Both concepts must be interpreted to mean any act that consists of appropriating or making available to the public, without the consent of the person who created the database, the results of that person’s investment, thereby depriving them of the revenue that is supposed to allow them to recoup the cost of such investment.

The search engine at issue in this case allows users to search the entire contents of several databases simultaneously—including the plaintiff’s database—through a method different from that provided by the manufacturer of the database in question, thereby making that content available to its own users. By offering the ability to search multiple databases simultaneously, this specialized search engine allows users to access, on its own website, job listings contained in those third-party databases. In this way, users are provided with access to the full content of third-party databases through a method other than that intended by their creators.

In light of the foregoing considerations, the answer to the questions referred for a preliminary ruling is that Article 7, paragraphs 1 and 2, of Directive 96/9 must be interpreted as meaning that an Internet search engine specializing in searching the content of databases, which copies or indexes all or a substantial part of a database freely accessible on the Internet and then allows its users to search that database on its own website according to criteria relevant to its content, engages in “extraction” and “reuse” of that content, within the meaning of that provision, which the maker of that database may prohibit to the extent that such acts cause harm to its investment in the collection, verification, or presentation of that content—that is, provided that they pose a risk to the ability to recoup that investment through the normal exploitation of the database in question.

Author: Claudia Pérez Moneu

 

Ten Privacy Requirements That the Digital Green Certificate Must Meet

According to the European Commission, the Digital COVID Certificate (DCC) is a digital credential that will help ensure that currently in-effect restrictions can be lifted in a coordinated manner, facilitating the mobility of European Union citizens. This certificate will include only the necessary key information, such as name, date of birth, date of issuance, relevant information about the vaccine, test, or recovery, and a unique identifier. In principle, the Spanish government intends to have it implemented by June of this year, so that it will be fully functional in time for the summer months.

airport, people, suitcases

 

Since this is a project that has generated some controversy, Ruth Benito, Of Counsel at ELZABURU and a specialist in personal data protection and privacy law, provides the following analysis of the privacy requirements expected of this certificate upon its implementation:

1. Data Protection and Security by Design and by Default

This is the first point for two main reasons:

  1. Contrary to popular belief, applying privacy and security criteria from the outset of any project helps ensure its success in terms of both the project’s effectiveness and individuals’ trust, reduces risks to those individuals, and avoids the need for subsequent adjustments.
  2. We are concerned that the proposed European Regulation on the Digital Green Certificate (DGC) states that no impact assessment was conducted due to the urgency of the matter, even though such assessments are one of the tools that can instill the most confidence in the public.

2. Complete transparency

We, as European citizens, have the right to know exactly what information this certificate will contain about us, how it will be handled, and who is involved in that process.

The future publication of the CVD Regulation (currently only a proposal) will provide a great deal of information on this subject, but there will still be many specifics unique to each Member State, particularly with regard to companies, technology, and the security measures implemented in each case.

3. Non-discrimination

One point that several countries have emphasized is that this CVD must not allow for any form of discrimination.

This Certificate is designed to facilitate the safe free movement of European citizens among EU Member States. Therefore, it must be ensured that it will be used solely for this purpose and not for other matters that could involve discrimination—not even by the certificate holder themselves—such as if it were used in job recruitment processes.

It is worth asking whether the CVD is already inherently discriminatory to some extent, given that those who have not yet been vaccinated or had the disease will have to pay for diagnostic tests—the results of which may be included in the certificate or verified through other means—in order to be able to travel.

4. Actual usefulness and effectiveness

The information contained in the CVD must be up to date at all times, but it must also be appropriate for the intended purpose. This is an issue that does not appear to have been fully resolved at this time, as there is still no scientific evidence that immunized individuals—whether because they have had the disease or because they have been vaccinated—do not transmit the disease; in other words, that they cannot infect others.

Furthermore, since it is still too early to tell, it is also unknown how long that immunity will last. Consequently, the information does not appear to be as reliable as would be desirable for the intended purposes, which may conflict with the principle of data accuracy. We understand that progress must be made on this issue and that scientific conclusions and evidence will be taken into account to make the necessary adjustments to the system to ensure its maximum effectiveness while ensuring the proper use of our personal data.

5. Minimize data

Both the data processed “behind the scenes” by the CVD and the data ultimately displayed in the app or on paper when traveling should be limited to the minimum truly necessary to achieve the intended goal.

We do not yet know exactly what information will be displayed when the passport is used, but this is something that must be analyzed in detail. For example, a simple “Approved” or “Not Approved” status might be sufficient for travel, if it were not necessary to know the specific circumstances that qualify the person (being vaccinated, having recovered from the disease, or having a negative diagnostic test result), or it might be necessary to know the specific qualifying circumstance but not, for the purposes of granting entry into the country, to know which specific vaccine was administered or what type of test was performed, etc.

6. Keep an eye on your travel companions

National authorities must assess whether providers of technology, infrastructure, storage, etc., offer sufficient guarantees to ensure that the handling of such sensitive personal information is carried out with appropriate security measures and that there will be no unjustified interference with the rights of European citizens. In any case, we understand that the company or companies selected, with regard to Spain, must comply with the measures required under the National Security Framework.

7. Interoperability

As already stated in the proposed European regulation, uniform conditions must be in place for the issuance, verification, and acceptance of certificates in all EU countries. Otherwise, the mobility of Europeans within the Union would not truly be facilitated.

8. Universal and free of charge

The proposed regulation also rightly stipulates that the CVD must be universal and free of charge, which does not mean that it has to allow us to travel for free all over the world (we wish!), but rather that all Europeans must be able to access the certificate free of charge.

Free access is indeed a prerequisite for the CVD to be universal. However, it must also be ensured that certain vulnerable groups—such as minors (who, moreover, are not currently receiving the vaccine), people with disabilities (accessibility), and those disadvantaged by the digital divide—can effectively benefit from it.

9. Whoever starts it and stirs it up gets a slap in the face

This is not a pie that can be sliced up. Therefore, the authorities and companies involved in the CVD may not, outside of its intended purposes, share Europeans’ health information or exploit it in any way, and cross-border passenger transport service operators that need access to the certificates should not create their own databases containing that information.

10. Don't come here to stay

The CVD only makes sense—and is therefore justified and legitimate—for as long as the pandemic and/or public health emergency lasts. Therefore, once that situation has passed (hopefully sooner rather than later), both the certificate and the technology behind it must be discontinued, and the health information of Europeans that has been stored in the CVD’s systems must be deleted.

 

Previously published in Confilegal, by Luis Javier Sánchez.

For more information, you can listen to the interview with Ruth Benito on Capital Radio's "Ventaja Legal."

Author: Ruth Benito