




版權說明:本文檔由用戶提供并上傳,收益歸屬內容提供方,若內容存在侵權,請進行舉報或認領
文檔簡介
Adopted1
Opinion19/2024ontheEuroPrisecriteriaofcertification
regardingtheirapprovalbytheBoardasEuropeanData
ProtectionSealpursuanttoArticle42.5(GDPR)
Adoptedon16July2024
Adopted2
Contents
1.SUMMARYOFTHEFACTS 4
2.ASSESSMENT 5
2.1ScopeofthecertificationmechanismandTargetofEvaluation(ToE) 5
2.2Processingoperations 5
2.3Lawfulnessandprinciplesofdataprocessing 6
2.4Generalobligationsofcontrollersandprocessors 6
2.5Rightsofthedatasubjects 6
2.6Risksfortherightsandfreedom 6
2.7Technicalandorganisationalmeasuresguaranteeingprotection 6
2.8Criteriaforthepurposeofdemonstratingtheexistenceofappropriatesafeguardsfor
transferofpersonaldata 7
3.ADDITIONALCRITERIAFORAEUROPEANDATAPROTECTIONSEAL 7
CONCLUSIONS/RECOMMENDATIONS 7
FINALREMARKS 7
Adopted3
TheEuropeanDataProtectionBoard
HavingregardtoArticle63,Article64(2)andArticle42ofRegulation2016/679/EUoftheEuropeanParliamentandoftheCouncilof27April2016ontheprotectionofnaturalpersonswithregardtotheprocessingofpersonaldataandonthefreemovementofsuchdata,andrepealingDirective95/46/EC(hereinafter“GDPR”),
HavingregardtotheEuropeanEconomicArea(hereinafter“EEA”)AgreementandinparticulartoAnnexXIandProtocol37thereof,asamendedbytheDecisionoftheEEAjointCommitteeNo154/2018of6July201
81,
HavingregardtoArticles10and22ofitsRulesofProcedure.
(1)MemberStates,supervisoryauthorities,theEuropeanDataProtectionBoard(hereinafter“theEDPBortheBoard”)andtheEuropeanCommissionshallencourage,inparticularatUnionlevel,theestablishmentofdataprotectioncertificationmechanisms(hereinafter“certificationmechanisms”)andofdataprotectionsealsandmarks,forthepurposeofdemonstratingcompliancewiththeGDPRofprocessingoperationsbycontrollersandprocessors,takingintoaccountthespecificneedsofmicro,smallandmedium-sizedenterprises
.2
Inaddition,theestablishmentofcertificationmechanismscanenhancetransparencyandallowdatasubjectstoassessthelevelofdataprotectionofrelevantproductsandservices
.3
(2)Thecriteriaofcertificationformanintegralpartofacertificationmechanism.Consequently,theGDPRrequirestheapprovalofthecriteriaofanationalcertificationmechanismbythecompetentsupervisoryauthority(Articles42(5)and43(2)(b)GDPR),orinthecaseofaEuropeanDataProtectionSeal,bytheEDPB(Articles42(5)and70(1)(o)GDPR).
(3)Whenasupervisoryauthority(hereinafter“SA”)intendstoproposetheapprovalbytheEDPBofaEuropeandataprotectionsealpursuanttoarticle42(5)GDPR,theSAshouldstatetheintentionoftheschemeownertoofferthecertificationmechanisminallMemberStates.Inthiscase,themainroleoftheEDPBistoensuretheconsistentapplicationoftheGDPR,throughtheconsistencymechanismreferredtoinArticles63,64and65GDPR.Inthisframework,accordingtoArticle64(2)GDPR,theEDPBisapprovingthecriteriaofcertification.
(4)ThisOpinionaimstoensuretheconsistentapplicationoftheGDPR,includingbytheSAs,controllersandprocessorsinthelightofthecoreelements,whichcertificationmechanismshavetodevelop.Inparticular,theEDPBassessmentiscarriedoutonthebasis“Guidelines1/2018oncertificationandidentifyingcertificationcriteriainaccordancewithArticles42and43oftheRegulation”(hereinafterthe“Guidelines”)andtheirAddendumproviding“Guidanceoncertificationcriteriaassessment”(hereinafterthe“Addendum”),forwhichthepublicconsultationperiodexpiredon26May2021.
(5)Accordingly,theEDPBacknowledgesthateachcertificationmechanismshouldbeaddressedindividuallyandiswithoutprejudicetotheassessmentofanyothercertificationmechanism.
1Referencesto“MemberStates”madethroughoutthisOpinionshouldbeunderstoodasreferencesto“EEAMemberStates”.
2Article42(1)GDPR.
3Recital100GDPR.
Adopted4
(6)CertificationmechanismsshouldenablecontrollersandprocessorstodemonstratecompliancewiththeGDPR.Therefore,itscriteriashouldproperlyreflecttherequirementsandprinciplesconcerningtheprotectionofpersonaldatalaiddownintheGDPRandcontributetoitsconsistentapplication.
(7)Atthesametime,schemeownershouldensurethealignmentandconformityofthecertificationmechanismwithanyincludedorleveragedISOstandardsandcertificationpractices.
(8)Asaresult,certificationsshouldaddvaluetocontrollersandprocessorsbyhelpingtoimplementstandardizedandspecifiedorganizationalandtechnicalmeasuresthatdemonstrablyfacilitateandenhanceprocessingoperationcompliancetotheGDPR,takingaccountofsector-specificrequirements.
(9)TheEDPBwelcomestheeffortsmadebyschemeownerstoelaboratecertificationmechanisms,whicharepracticalandpotentiallycost-effectivetoolstoensuregreaterconsistencywiththeGDPRandfostertherighttoprivacyanddataprotectionofdatasubjectsbyincreasingtransparency.
(10)TheEDPBrecallsthatcertificationsarevoluntaryaccountabilitytools,andthattheadherencetoacertificationmechanismdoesnotreducetheresponsibilityofcontrollersorprocessorsforcompliancewiththeGDPRorpreventsupervisoryauthoritiesfromexercisingtheirtasksandpowerspursuanttotheGDPRandtherelevantnationallaws.
(11)InthisOpinion,theEDPBaddressesissues,suchasthescopeofthecriteria,theapplicabilityandrelevanceofthecriteriainallMemberStates.
(12)ThisOpinionfocussesonthecertificationcriteria.IncasetheEDPBrequireshighlevelinformationontheevaluationmethodsinordertobeabletothoroughlyassesstheauditabilityofthecriteriainthecontextofitsOpinionthereof,thelatterdoesnotencompassanykindofapprovalofsuchevaluationmethods.
(13)TheOpinionoftheEDPBshallbeadopted,pursuanttoArticle64(2)GDPRinconjunctionwithArticle10(2)oftheEDPBRulesofProcedure,withineightweeksfromthefirstworkingdayaftertheChairandthecompetentsupervisoryauthorityhavedecidedthatthefileiscomplete.UpondecisionoftheChair,thisperiodmaybeextendedbyafurthersixweekstakingintoaccountthecomplexityofthesubjectmatter.IftheopinionoftheEDPBconcludesthatthecriteriacannotbeapprovedatstake,theSAmayresubmitthecriteriaforapprovalwhentheconcernsexpressedintheinitialEDPBOpinion
areaddressed.
HASADOPTEDTHEFOLLOWINGOPINION:
1.SUMMARYOFTHEFACTS
1.InaccordancewithArticle42(5)GDPRandtheGuidelines,thedraft“EuroPriSeCriteriaCatalogueforthecertificationofprocessingoperationsbyprocessors(scope:EU)v1.5”(hereinafterthe“draftcertificationcriteria”,“certificationcriteria”or“criteria”)wasdraftedbyEuroPriSeCertGmbH(hereinafterthe“schemeowner”),alegalentityinGermany,andsubmittedtotheLandesbeauftragtefürDatenschutzundInformationsfreiheitNordrhein-Westfalen,thecompetentGermansupervisoryauthorityinNorthRhine-Westphalia(hereinafter“DE-NRWSA”).
2.TheSupervisoryAuthorityofGermany(hereinafterthe“DESA”)hassubmittedthedraftcertificationcriteriatotheEDPBforapprovalpursuanttoArticle64(2)GDPRon29April2024.Thedecisiononthecompletenessofthefilewastakenon29May2024.
Adopted5
3.TheEuroPrisecertificationmechanismisnotacertificationaccordingtoarticle46(2)(f)GDPRmeantforinternationaltransfersofpersonaldataandthereforedoesnotprovideappropriatesafeguardswithintheframeworkoftransfersofpersonaldatatothirdcountriesorinternationalorganisationsunderthetermsreferredtoinletter(f)ofArticle46(2).Indeed,anytransferofpersonaldatatoathirdcountryortoaninternationalorganisation,shalltakeplaceonlyiftheprovisionsofChapterVGDPR
arerespected.
2.ASSESSMENT
4.TheEDPBhasconducteditsassessmentofthecriteriaofcertificationfortheirapprovalunderArticles42(5)GDPRinlinewiththestructureforeseeninAnnex2totheGuidelines(hereinafter“Annex”)anditsAddendum.
2.1ScopeofthecertificationmechanismandTargetofEvaluation(ToE)
5.TheEuroPrisecertificationmechanismcontainscertificationcriteriaofanEU-widecertificationschemeforthecertificationofprocessingbyprocessors.Thesubjectofcertificationstowhichthecriteriacatalogueappliesareprocessingoperationsperformedinproducts,processesandservicesorwiththeaidof(alsoseveral)productsandservicesandwithregardtowhichthecertificationapplicantisactingasaprocessor.Themaincriteriaofthiscertificationmechanismaredividedintothethreesetsofrequirements,namely:fromalegalperspective(set1),fromatechnicalandorganisationalmeasuresperspective(set2),andfromtherightsofthedatasubjectsperspective(set3).
6.Certificationapplicantsunderthisschememustbeprocessors.ThisincludesprocessorswhoaredirectlyentrustedwiththeprocessingofpersonaldatabyacontrollerwithinthemeaningofArticle4(7)GDPR.However,certificationapplicantsmayalsobeprocessorswithinthemeaningofArticle28(2)and(4)GDPR(sub-processors).
7.Whenaprocessor-certifiedundertheEuroPrisecertificationscheme-usesasub-processor,thelattercannotclaimthatithasbeencertifiedunderEuroPrisecertificationscheme.Onlyprocessingoperationsperformedbytheinitialandcertifiedprocessorarecoveredbythecertificationinsuchacase.However,sub-processorscanalsoapplyforcertification,whichwouldresultinastand-aloneandindependentprocedure.
8.TheBoardnotesinthedocumentationrelatedtothescopeofthecertificationmechanismprovidedbytheDESAthattheEuroPriseschemeappliestoprocessorsestablishedintheEuropeanUnion(EU)orintheEuropeanEconomicArea(EEA).
2.2Processingoperations
9.Thescopeofthesecriteriaisnotlimitedtocertaintypesofprocessingoperations.ItisratherthemethodologyunderlyingaEuroPriseevaluation,whichallowsforcertificationofanyprocessingoperationsbyprocessors.Itis,therefore,auniversalmethodologicalapproachonthebasisofwhichalargenumberofverydifferentprocessingoperationscanbecertified.Hence,itisoffundamentalimportancethatthemethodologicalrequirementsareadheredto,asthisistheonlywaytoensureauniformapplicationofthecertificationcriteriaandacomparableleveloftestingacrossdifferentcertificationprocedures.Theaimistoensurecomparabilityandreproducibilityofthecertificationsissuedandtheirresults.
Adopted6
2.3Lawfulnessandprinciplesofdataprocessing
10.Thecriteriarequiretheexaminationofwhethertheprocessingoperationstobecertifiedcomplywiththeprinciplesofdataprotectionbydesignandbydefault(section1.5ofthecriteria),entailingtheparticipationoftheapplicantinassistingthecontrollerintheimplementationoftheseprinciples.ThisallowsassessingcompliancewithArticle25GDPR,readinconjunctionwithArticle5GDPR.WhilethereisnocriteriadirectlyaimingatcompliancewithArticle6GDPR-giventhefactthatthecontrollerisresponsibleforthelawfulnessoftheprocessing-thecriteriaaimatensuringthatprocessors-applicantsdesigntheprocessingoperationstobecertifiedinawaythatfacilitatescontrollers’implementationofArticle5GDPRdataprotectionprinciples,includingtheprincipleoflawfulnessofprocessing.
2.4Generalobligationsofcontrollersandprocessors
11.Thecriteriareflecttherelationshipbetweentheprocessorandthecontroller.Inparticular,thecriteriaprovidetheobligationoftheprocessortohaveinplaceatemplateofdataprocessingagreementwiththecontroller,whichincludesalltherequirementsofArticle28GDPR(section1.2ofthecriteria).
12.ThecriteriarequireapplicantstoappointaDataProtectionOfficer(DPO)accordingtoArticle37GDPRandprovideaproofoftheappointmentoftheDPO(e.g.certificateofappointment).ThecriteriacheckthattheDPOmeettherequirementsunderArticles37to39(set1,section1.1ofthecriteria).
13.ThecriteriacheckthecontentoftherecordsofprocessingofactivitiesinaccordancewithArticle30GDPR(set1,section1.1ofthecriteria).
2.5Rightsofthedatasubjects
14.Thecriteriaadequatelyaddressdatasubject’srighttoinformationinaccordancewithChapterIIIGDPRandrequirerespectivemeasurestobeputinplace.Thecriteriaalsorequiremeasuresputinplaceprovidingforthepossibilitytointerveneintheprocessingoperationinordertoguaranteedatasubjects’rightsandallowcorrections,erasureorrestrictions(set3ofthecriteria).
2.6Risksfortherightsandfreedom
15.ThecriteriarequiretheprocessortobeawareofthepossibleriskstotherightsandfreedomsofnaturalpersonsforthedataprocessinginvolvedintheToE.Iftheprocessingofpersonaldataislikelytoresultinahighrisktotherightsandfreedomsofnaturalpersons,severalcriteriaensurethattheapplicantdemonstratesthattherequirementsofArticle35GDPRarefulfilledinaccordancewithArticle35GDPR(section1.2.2ofthecriteria,requirementn°6,section1.3.2ofthecriteria,section1.3.3ofthecriteria,section
2.1.5.1
ofthecriteria,section
2.1.5.9
pfthecriteria).
2.7Technicalandorganisationalmeasuresguaranteeingprotection
16.Thecriteriarequiretheapplicationoftechnicalandorganisationalmeasuresprovidingforconfidentiality,integrityandavailabilityofprocessingoperations.ThecriteriaalsorequiretheapplicationoftechnicalmeasurestoimplementdataprotectionbydesignandbydefaultinaccordancewithArticle25andArticle32GDPR(section1.5ofthecriteria,section2.1ofthecriteria/otherdocuments).
17.ThecriteriarequiretheapplicationofmeasuretoensurethatpersonaldatabreachnotificationdutiesarecarriedoutinduetimeandscopeinaccordancewithArticle33GDPR(section1.2.2ofthecriteria,requirementn°6).
Adopted7
2.8Criteriaforthepurposeofdemonstratingtheexistenceofappropriatesafeguardsfortransferofpersonaldata
18.Thecriteriarequireidentifyingall
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯系上傳者。文件的所有權益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網頁內容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
- 4. 未經權益所有人同意不得將文件中的內容挪作商業或盈利用途。
- 5. 人人文庫網僅提供信息存儲空間,僅對用戶上傳內容的表現方式做保護處理,對用戶上傳分享的文檔內容本身不做任何修改或編輯,并不能對任何下載內容負責。
- 6. 下載文件中如有侵權或不適當內容,請與我們聯系,我們立即糾正。
- 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 公司組拔河比賽活動方案
- 公司春游野餐活動方案
- 公司特色聚餐活動方案
- 公司美食節擺攤活動方案
- 公司自制壽司活動方案
- 公司組織種地活動方案
- 公司沙灘拓展活動方案
- 公司組織拓展活動方案
- 2025年智能制造工程師職業考試題及答案
- 2025年營養學與食品安全的考試試卷及答案
- 施工費用控制管理制度
- 律師事務所數據管理制度
- 2025年衛生系統招聘考試《職業能力傾向測試》新版真題卷(附詳細解析)
- 大學生心理健康教育導論
- 河南省洛陽市2024-2025學年高二下學期6月期末質檢物理試卷(含答案)
- 浙江理工大學《統計學與R語言》2023-2024學年第二學期期末試卷
- 安全生產獎罰管理制度
- 《資治通鑒》與為將之道知到課后答案智慧樹章節測試答案2025年春武警指揮學院
- 計算機網絡課程設計小型公司網絡
- 中考考前注意事項講稿
- 朗讀技巧之重音、停連、語速、語調、語氣、節奏要領方法指導
評論
0/150
提交評論