Privacy First warns against overly broad DPIA exemptions
Participation in the consultation organised by the Dutch Data Protection Authority
This summer, Privacy First took part in the consultation from the Dutch Data Protection Authority (AP) on exemptions from the obligation to carry out a ‘data protection impact assessment’ (DPIA) in the case of high-risk processing of personal data. Privacy First recognises that small organisations need clarity on when a DPIA is mandatory, but fears that the proposed exemptions are too broad. As a result, processing operations posing a high privacy risk may wrongly fall outside the scope of the DPIA requirement. Privacy First advocates that DPIA exemptions should only apply to genuinely low-risk processing operations. Wherever monitoring, profiling, data sharing, transfers outside the EU/EEA, biometric data, health data or other sensitive processing operations are involved, a DPIA must, in principle, remain mandatory.
High-risk processing operations
The proposal under consultation sets out exceptions to the previous decision by the AP in which high-risk processing operations are identified. These include, amongst others:
- monitoring of financial data in order to assess creditworthiness, income or net worth, or spending patterns;
- large-scale processing of health data;
- CCTV;
- processing of location and communication data;
- behavioural profiling, observation and influence.
Privacy First comments
Although Privacy First understands the position of small organisations, this must not, however, lead to the protection of individuals against high-risk processing being undermined. Among other things, we have pointed out that the processing of ‘customer data in connection with business activities’ must not result in companies that are required by law to carry out anti-crime investigations (‘anti-money laundering’) being exempt from carrying out a DPIA. We have also made suggestions, amongst other things, regarding the proposed exemptions for self-employed healthcare providers and educational institutions. Our main recommendations are set out below:
General recommendations
- Combine the new draft decision with the existing DPIA decision from 2019, or provide a clear explanation for both.
- Avoid vague terms such as systematically, systematically and large-scale, as these give rise to differences in interpretation.
- Make it clear that, even where a DPIA exemption applies, all other GDPR obligations remain in force, including the careful selection of suppliers and the monitoring of suppliers.
- Lay down as a general condition for exemption that personal data must not be shared with third parties or transferred outside the EU/EEA.
Scope of the decision
Privacy First considers the concepts practitioner and a natural person not in employment not clear enough. As a result, even large organisations might be able to make use of exemptions intended for small organisations.
Key comments by category
Employee details
- Define ‘special categories of personal data’.
- Replace “systematic monitoring” with simply “monitoring”.
Customer details
- Explicitly exclude Wwft and AMLR customer due diligence from the exemption, as this actually entails high privacy risks.
- Please clarify what is meant by “large scale” and “vulnerable individuals”.
Website visits
- Please clarify what constitutes a simple website visit.
- Explain how quickly data is shared with third parties, for example through the use of Google Analytics or the embedding of YouTube videos.
Healthcare professionals working independently
- A separate, stricter set of rules must apply to healthcare due to the sensitive nature of health data.
- Exclude electronic patient records accessible to third parties, as well as the processing of biometric data (including DNA), from the exemption.
- Healthcare providers must also maintain technical control over who has access to patient data.
Self-employed professionals
- Please consider deleting this section entirely.
- Clarify ambiguous terms and strictly limit data sharing.
CCTV
- Privacy First warns against insecure CCTV solutions that use cloud storage and the commercial exploitation of footage.
- Do not allow audio recording.
- Not only should facial and voice recognition be banned, but every form of personal identification.
Educational institutions
- Sensitive pupil data must be kept strictly separate from standard pupil records.
- Do not share with third parties.
- Encourage a joint approach to privacy and DPIA across institutions.
Associations and foundations
- Process only data that is strictly necessary for the relationship with members or donors, and emphasise that sharing such data with third parties is not permitted.
Read HERE our full response to the consultation (PDF).