Where We Work
Central and Eastern Europe
Russia and the CIS
Southeast Europe and Turkey
Switzerland and Austria
Czech Republic & Slovakia
United Arab Emirates
Banking & Finance
Competition & EU Law
International HR Services
Privacy and Data Protection
Public Projects and Procurement
Regulatory and Administrative
Restructuring and Insolvency
Trade and Customs
Aerospace, Defence & Security
Energy & Utilities
Life Sciences and Healthcare
Media, Entertainment and Sport
Retail and Consumer
Technology & Communications
News & Events
Bird & Bird
General Data Protection Regulation
Any other areas under discussion
Any other areas under discussion
Any other areas under discussion
Austrian Data Protection Act:
Besides the already outlined specialties, the ADPA especially provides for the following exceptional provisions as regards certain data processing activities:
Temporary exception from the right to rectification and the right to erasure: If the rectification or erasure of personal data cannot be carried out immediately due to economic or technical reasons, the processing shall be restricted according to Art 18 GDPR until rectification or erasure is possible.
Special provisions concerning image processing: The new rules of Sec 12 and 13 ADPA apply to all data processing activities regarding images (especially photographs and CCTV)). Thus, taking pictures is usually permitted in case (i) the data subject renders its consent or (ii) the processing is required for legitimate interests of the controller or a third party (especially the protection of private property as well as the surveillance of public areas). Further, the ADPA provides for special data security measures and labelling obligations for image processing activities.
In addition to the ADPA, various Austrian laws contain special data protection provisions, which particularize the general data protection laws set for specific areas.
Austrian Telecommunications Act:
Further, the provisions of the Austrian Telecommunications Act ("TKG") are highly relevant for the processing of personal data for (electronic) marketing purposes: In general, consent is required before sending electronic messages to customers for marketing purposes (Sec 107 TKG). Further, consent is required before contacting customers via phone for marketing purposes (Sec 107 TKG).
Additionally, collecting personal data via cookies that are not strictly necessary for the functionality of the online service requires the consent of the data subject (usually gathered through a cookie banner) based on sufficient information about this data use (Sec 96 (3) TKG).
§ 5(3) provides that public auhthorities may process personal data for other purposes than the purpose for which the data originally were collected despite the purposes being incompatible; if health data or genetic data, the purposes must however be compatible. When public authorities make use of this rule, they are excempted from the obligation in GDPR art. 13(3) and 14(4) to inform the data subject of this further processing unless the processing is for control purposes, c.f. § 23.
The French Digital Republic act already established the right to data portability to anticipate the implementation of the GDPR. However, the right, as provided by the GDPR, seems to be more limited than the right provided by the French Digital act. Indeed, the French Digital act provides for a right to data portability (right for a data subject to be provided with the totality of his/her personal data in a portable format) in “any circumstances”. The GDPR provides a right to data portability for cases where the processing of data is based on the data subject’s consent or on a contract.
However, the French right to data portability does not include the right for a data subject to ask the controller to transmit his/her personal data to another controller of his/her choice when technically possible.
Various German Federal laws contain special data protection provisions, which particularize the general data protection laws set for specific areas. Sector-specific data protection will continue to be important in the future.
Telemedia Act (“Telemediengesetz”, “TMG”)
The TMG contains special data protection regulations for providers of Information Society Services (“Telemedia”) in Germany. According to the public information provided by the Federal Ministry of the Interior (BMI), the Ministry is currently not planning to propose a change of the TMG. This means that it will be subject to legal interpretation (in an individual case) which data protection provisions will be superseded by the GDPR and which will remain applicable. Companies operating on the Internet are strongly recommended to keep an eye on further developments.
Telecommunications Act (“Telekommunikationsgesetz”, “TKG”)
The Federal Ministry of the Interior (BMI) has announced that it will provide a proposal for a law that will adapt the Telecommunications Act to the GDPR, but this proposal is not yet public.
The TKG will likely be changed substantially in its provisions that lay down sector-specific data protection rules for the telecommunications sector (sections 91-107 TKG). These provisions will have to be changed whenever they lay down rules that conflict with GDPR provisions and that cannot be based on the ePrivacy Directive in conjunction with the exception clause of Article 95 GDPR. This means that there will likely be substantial changes of this part of the TKG. Details are not yet published.
Under the Act, the Data Protection Commission is replaced with a new legal entity known as the Data Protection Commission.
The Act provides for a new action, to be known as a ‘data protection action’, whereby an individual may bring a claim for infringement of their rights under the GDPR or the Act and seek an injunction or declaration, or compensation for damage suffered.
There is a proposed new criminal offence relating to direct marketing, profiling or micro-targeting children, which is in the Act but has not been brought into force as it is under consideration by the Irish government.
The Garante Guide notes that:
• Controllers and Processors should use symbols and icons suggested by DPA's Decisions on CCTV systems and banks, together with a complete and exhaustive privacy notice;
• DPA will provide guidance on meaning of "reasonable fees" and security measures for processing sensitive data;
• measures appointing staff to process and track bank users' activity should be maintained; and
• records of processing activities for organisations with fewer than 250 persons employed should be maintained.
UAVG stipulates that:
• Article 22 GDPR does not apply where automated processing/profiling is necessary for compliance with a legal obligation or if processing is necessary for the performance of a task carried out in the public interest. This exception only applies if there is a specific legal basis for profiling.
• A legal obligation to take into account the needs of micro, small and medium-sized enterprises was added to the UAVG (art. 2a UAVG).
• The prohibition to subject data subjects to automated decision-making does not apply if the law makes this compulsory. This may indirectly enable 'big data' applications (art. 40 UAVG).
PDPA provides an administrative and a civil procedure for data subjects to pursue their rights.
I. Credit Information Systems
Article 20 of the Spanish Data Protection Draft Bill regulates the credit information systems. The processing of personal data by credit information systems in relation to a breach of financial, monetary or credit obligations will be lawful as long as the following including but not limited requirements are met:
a) The data have been provided by the creditor;
b) The data are related to a true, due and payable doubt;
c) The creditor has informed the data subject in their agreement or when claiming the payment about the possibilities of the debtor to be included in these lists; and
d) The data are kept in the system during a 5 years period and only as long as the breach is not remedied.
II. Data Processing Agreements
The data processing agreements executed before the 25th May 2018, will be effective during the term contained therein; in case of data processing agreements of indeterminate length, they will be effective four years after they were entered into.
III. Blocking of Personal Data
The draft allows data controllers to block personal data when the data subject has previously exercised the rectification or erasure right. Thus, the data controller may keep such personal data dully blocked during the statute of limitations of any liabilities that may arise as a consequence of the processing.
In contrast to article 2.2 (a)-(b) of GDPR, the proposal provides that GDPR and the new Data Protection Act shall be applicable to the processing of personal data in the course of an activity (i) which falls outside the scope of Union law or (ii) which falls within the scope of Chapter 2 of Title V of the TEU.
Derogation for automated decision taking to be implemented (examples given are financial services related).
Controllers must include additional information in their record of processing activity, including indication of lawful basis and details of profiling where applicable (Art.61).
The ICO is retaining annual fees and registrations, and is substantially upping these (controllers with turnover over £36million or 250+ employees face annual fees of £2900) - this power is contained in the Digital Economy Act 2017.