HomeInsightsEuropean Data Protection Board adopts final version of Guidelines on Data Protection by Design & Default following consultation


Contact

On 20 October 2020 the EDPB met for its 40th plenary session during which it adopted the final version of the Guidelines on Data Protection by Design & Default following consultation. The guidelines focus on the obligation of data protection by design and by default (DPbDD) as set out in Article 25 of the GDPR. The core obligation enshrined in Article 25 is the effective implementation of the data protection principles and data subjects’ rights and freedoms by design and by default. This means that controllers have to implement appropriate technical and organisational measures, as well as the necessary safeguards, to implement data protection principles and protect the rights and freedoms of data subjects. In addition, controllers should be able to demonstrate that the implemented measures are effective.

The Guidelines also contain guidance on how to effectively implement the data protection principles in Article 5 of the GDPR, listing key design and default elements, as well as practical cases for illustration. They also provide recommendations on how controllers, processors and producers can cooperate to achieve DPbDD. The Guidelines contain updated wording and further legal reasoning in order to address comments and feedback received during the public consultation.

During the plenary session, the EDPB also decided to set up a Coordinated Enforcement Framework (CEF). The CEF will provide a structure to co-ordinate the regular annual activities of EDPB Supervisory Authorities (SAs). The objective of the CEF is to facilitate joint action in a flexible and co-ordinated manner, ranging from joint awareness raising and information gathering to enforcement and joint investigations.

The EDPB also adopted a letter in response to the Europäische Akademie für Informationsfreiheit und Datenschutz concerning the data protection implications of Article 17 of the Directive on Copyright in the Digital Single Market, in particular concerning upload filters. In the letter, the EDPB states that any processing of personal data for the purpose of upload filters must be proportionate and necessary and that, as far possible, no personal data should be processed when Article 17 is implemented. Where the processing of personal data is necessary, such as for the redress mechanism, such data should only concern data necessary for this specific purpose, while applying all the other principles of the GDPR. The EDPB further highlighted that it is in continuous exchange with the European Commission on this topic and that it has indicated its availability for further collaboration. To read the EDPB’s press release in full, click here.

Expertise