Article 29 Working Party Data Processing Agreement

The basic requirements for the effectiveness of valid legal consent are set out in Article 7 and specified in recital 32 of the GDPR. Consent must be given voluntarily, specifically, in an informative and unambiguous manner. In order to obtain voluntary consent, it must be given on a voluntary basis. The “free” element implies a real choice of the person concerned. Any element of unreasonable pressure or influence that could affect the outcome of this choice will void the consent. In doing so, the text of the law takes into account a certain imbalance between the controller and the data subject. For example, in an employer-employee relationship: the employee may fear that his refusal of consent could have serious negative consequences on his employment relationship, so that consent can only be a legal basis for processing in a few exceptional circumstances. In addition, a so-called “coupling prohibition” or “coupling or bonding prohibition” applies. Thus, the performance of a contract cannot be subject to consent to the processing of other personal data that are not necessary for the performance of this contract. The joint annual review of the Privacy Shield is being developed by the Commission and the Article 29 Working Party. WP29 sent a letter to the Commission detailing the fact-finding mission to the US in September and its scope, including the fact that they intend to have 8 members of the working group in the EU delegation who will attend the meetings in Washington. The press release notes that WP29 is particularly interested in posing: the existence of legal safeguards regarding automated decision-making or the existence of guidance provided by the DOC regarding the application of the Privacy Shield Principles to organizations acting as agents/processors; the definition of personal data; and the latest developments in U.S. privacy law and jurisprudence.

The Article 29 Working Party has published new guidelines on data processing in the workplace: Opinion 2/2017. The opinion reassesses the balance between the legitimate interests of employers and the reasonable expectations of workers for privacy by highlighting the risks posed by new technologies. The Group stresses, inter alia, that it is highly unlikely that consent will be a legal basis for the processing of data in the workplace, unless employees can refuse to do so without negative consequences. As you can see, consent is not a silver bullet when it comes to the processing of personal data. In particular, considering that the European data protection authorities have clarified “that if a controller relies on consent for part of the processing, he must be willing to respect that choice and to stop that part of the processing if a person withdraws his consent”. Strictly speaking, this means that the controller cannot move from the legal basis of consent to a legitimate interest once the data subject has withdrawn his or her consent. This also applies if there was initially a legitimate interest. Therefore, consent should always be chosen as the last option for the processing of personal data. WP29 adopted the final versions of three documents adopted in December 2016, formalising guidance on DPDs, data portability and lead authority. The Article 29 Working Group shared the results of the discussions [direct link .pdf] between European representatives of industry, civil society, academics and relevant associations, which took place during the second Fablab workshop on best practices and guidelines on valid consent, data breach reporting and profiling. The Working Party “Article 29” (Article 29 of the WP), fully known as the Working Party on the Protection of Individuals with regard to the Processing of Personal Data[1], was an advisory body composed of a representative of the data protection authority of each EU Member State, the European Data Protection Supervisor and the European Commission.

The use of EEA controller`s processor CTCs is not mandatory, and organisations may continue to use their own tailor-made data processing agreements to fulfil their obligations under Article 28 of the GDPR. However, EEA CONTROLLERS and Processors give a clear signal of the level of detail that the European Commission expects from these data processing agreements. The draft directive stipulates that consent expires when a child reaches the age of digital consent (16 years under the GDPR or less, depending on the national transposition legislation). The final guidelines state that children`s consent can be confirmed, amended and revoked once they reach the age of consent. In practice, this means that parental consent to the processing of personal data given before the age of digital consent remains a valid ground for processing, provided that the child does not take any action when he or she reaches the age of consent. WP29 states that consent is not given voluntarily when a controller claims that there is a choice between: (1) its service, which includes processing for additional purposes; and (2) an equivalent service offered by another controller. The “Berlin Group” (International Working Group on Data Protection in Telecommunications – a group that brings together technologists working for DSAs) published a working paper on e-learning platforms (the link downloads the pdf directly) following its last meeting, which took place in Washington DC in April. The document outlines the key risks to student privacy associated with e-learning platforms and makes recommendations to educational institutions, e-learning platform providers and data protection authorities. Explicit consent is required for the processing of special categories of data, the transfer of data in the absence of adequate GDPR safeguards and automated decision-making with legal or other important implications for data subjects. Explicit consent may be given in writing, but other options and examples are also given, including downloading signatures scanned in wet ink or a telephone conversation (provided that the information provided is fair, understandable and clear and that the controller requests specific confirmation from the data subject). This is another prerequisite for valid consent under the GDPR. WP29 states that controllers must avoid any ambiguity and ensure that the act for which online consent is given can be distinguished from other actions: “The mere continuation of the normal use of a website is not behaviour from which an expression of the will of the data subject can be derived in order to declare his or her consent to a planned processing operation”.

This addition seems to call into question the concept of continued use of a website that amounts to consent. According to the GDPR, consent must be given voluntarily, specifically, informed and unambiguously. Where a controller wishes to process personal data for purposes other than the provision of a requested service, data subjects should have the possibility to consent separately to or object to such processing. .