edpb第202419號意見批準歐洲企業認證標準空氣保護密封(英)_第1頁
edpb第202419號意見批準歐洲企業認證標準空氣保護密封(英)_第2頁
edpb第202419號意見批準歐洲企業認證標準空氣保護密封(英)_第3頁
edpb第202419號意見批準歐洲企業認證標準空氣保護密封(英)_第4頁
edpb第202419號意見批準歐洲企業認證標準空氣保護密封(英)_第5頁
已閱讀5頁,還剩7頁未讀 繼續免費閱讀

下載本文檔

版權說明:本文檔由用戶提供并上傳,收益歸屬內容提供方,若內容存在侵權,請進行舉報或認領

文檔簡介

Adopted1

Opinion19/2024ontheEuroPrisecriteriaofcertification

regardingtheirapprovalbytheBoardasEuropeanData

ProtectionSealpursuanttoArticle42.5(GDPR)

Adoptedon16July2024

Adopted2

Contents

1.SUMMARYOFTHEFACTS 4

2.ASSESSMENT 5

2.1ScopeofthecertificationmechanismandTargetofEvaluation(ToE) 5

2.2Processingoperations 5

2.3Lawfulnessandprinciplesofdataprocessing 6

2.4Generalobligationsofcontrollersandprocessors 6

2.5Rightsofthedatasubjects 6

2.6Risksfortherightsandfreedom 6

2.7Technicalandorganisationalmeasuresguaranteeingprotection 6

2.8Criteriaforthepurposeofdemonstratingtheexistenceofappropriatesafeguardsfor

transferofpersonaldata 7

3.ADDITIONALCRITERIAFORAEUROPEANDATAPROTECTIONSEAL 7

CONCLUSIONS/RECOMMENDATIONS 7

FINALREMARKS 7

Adopted3

TheEuropeanDataProtectionBoard

HavingregardtoArticle63,Article64(2)andArticle42ofRegulation2016/679/EUoftheEuropeanParliamentandoftheCouncilof27April2016ontheprotectionofnaturalpersonswithregardtotheprocessingofpersonaldataandonthefreemovementofsuchdata,andrepealingDirective95/46/EC(hereinafter“GDPR”),

HavingregardtotheEuropeanEconomicArea(hereinafter“EEA”)AgreementandinparticulartoAnnexXIandProtocol37thereof,asamendedbytheDecisionoftheEEAjointCommitteeNo154/2018of6July201

81,

HavingregardtoArticles10and22ofitsRulesofProcedure.

(1)MemberStates,supervisoryauthorities,theEuropeanDataProtectionBoard(hereinafter“theEDPBortheBoard”)andtheEuropeanCommissionshallencourage,inparticularatUnionlevel,theestablishmentofdataprotectioncertificationmechanisms(hereinafter“certificationmechanisms”)andofdataprotectionsealsandmarks,forthepurposeofdemonstratingcompliancewiththeGDPRofprocessingoperationsbycontrollersandprocessors,takingintoaccountthespecificneedsofmicro,smallandmedium-sizedenterprises

.2

Inaddition,theestablishmentofcertificationmechanismscanenhancetransparencyandallowdatasubjectstoassessthelevelofdataprotectionofrelevantproductsandservices

.3

(2)Thecriteriaofcertificationformanintegralpartofacertificationmechanism.Consequently,theGDPRrequirestheapprovalofthecriteriaofanationalcertificationmechanismbythecompetentsupervisoryauthority(Articles42(5)and43(2)(b)GDPR),orinthecaseofaEuropeanDataProtectionSeal,bytheEDPB(Articles42(5)and70(1)(o)GDPR).

(3)Whenasupervisoryauthority(hereinafter“SA”)intendstoproposetheapprovalbytheEDPBofaEuropeandataprotectionsealpursuanttoarticle42(5)GDPR,theSAshouldstatetheintentionoftheschemeownertoofferthecertificationmechanisminallMemberStates.Inthiscase,themainroleoftheEDPBistoensuretheconsistentapplicationoftheGDPR,throughtheconsistencymechanismreferredtoinArticles63,64and65GDPR.Inthisframework,accordingtoArticle64(2)GDPR,theEDPBisapprovingthecriteriaofcertification.

(4)ThisOpinionaimstoensuretheconsistentapplicationoftheGDPR,includingbytheSAs,controllersandprocessorsinthelightofthecoreelements,whichcertificationmechanismshavetodevelop.Inparticular,theEDPBassessmentiscarriedoutonthebasis“Guidelines1/2018oncertificationandidentifyingcertificationcriteriainaccordancewithArticles42and43oftheRegulation”(hereinafterthe“Guidelines”)andtheirAddendumproviding“Guidanceoncertificationcriteriaassessment”(hereinafterthe“Addendum”),forwhichthepublicconsultationperiodexpiredon26May2021.

(5)Accordingly,theEDPBacknowledgesthateachcertificationmechanismshouldbeaddressedindividuallyandiswithoutprejudicetotheassessmentofanyothercertificationmechanism.

1Referencesto“MemberStates”madethroughoutthisOpinionshouldbeunderstoodasreferencesto“EEAMemberStates”.

2Article42(1)GDPR.

3Recital100GDPR.

Adopted4

(6)CertificationmechanismsshouldenablecontrollersandprocessorstodemonstratecompliancewiththeGDPR.Therefore,itscriteriashouldproperlyreflecttherequirementsandprinciplesconcerningtheprotectionofpersonaldatalaiddownintheGDPRandcontributetoitsconsistentapplication.

(7)Atthesametime,schemeownershouldensurethealignmentandconformityofthecertificationmechanismwithanyincludedorleveragedISOstandardsandcertificationpractices.

(8)Asaresult,certificationsshouldaddvaluetocontrollersandprocessorsbyhelpingtoimplementstandardizedandspecifiedorganizationalandtechnicalmeasuresthatdemonstrablyfacilitateandenhanceprocessingoperationcompliancetotheGDPR,takingaccountofsector-specificrequirements.

(9)TheEDPBwelcomestheeffortsmadebyschemeownerstoelaboratecertificationmechanisms,whicharepracticalandpotentiallycost-effectivetoolstoensuregreaterconsistencywiththeGDPRandfostertherighttoprivacyanddataprotectionofdatasubjectsbyincreasingtransparency.

(10)TheEDPBrecallsthatcertificationsarevoluntaryaccountabilitytools,andthattheadherencetoacertificationmechanismdoesnotreducetheresponsibilityofcontrollersorprocessorsforcompliancewiththeGDPRorpreventsupervisoryauthoritiesfromexercisingtheirtasksandpowerspursuanttotheGDPRandtherelevantnationallaws.

(11)InthisOpinion,theEDPBaddressesissues,suchasthescopeofthecriteria,theapplicabilityandrelevanceofthecriteriainallMemberStates.

(12)ThisOpinionfocussesonthecertificationcriteria.IncasetheEDPBrequireshighlevelinformationontheevaluationmethodsinordertobeabletothoroughlyassesstheauditabilityofthecriteriainthecontextofitsOpinionthereof,thelatterdoesnotencompassanykindofapprovalofsuchevaluationmethods.

(13)TheOpinionoftheEDPBshallbeadopted,pursuanttoArticle64(2)GDPRinconjunctionwithArticle10(2)oftheEDPBRulesofProcedure,withineightweeksfromthefirstworkingdayaftertheChairandthecompetentsupervisoryauthorityhavedecidedthatthefileiscomplete.UpondecisionoftheChair,thisperiodmaybeextendedbyafurthersixweekstakingintoaccountthecomplexityofthesubjectmatter.IftheopinionoftheEDPBconcludesthatthecriteriacannotbeapprovedatstake,theSAmayresubmitthecriteriaforapprovalwhentheconcernsexpressedintheinitialEDPBOpinion

areaddressed.

HASADOPTEDTHEFOLLOWINGOPINION:

1.SUMMARYOFTHEFACTS

1.InaccordancewithArticle42(5)GDPRandtheGuidelines,thedraft“EuroPriSeCriteriaCatalogueforthecertificationofprocessingoperationsbyprocessors(scope:EU)v1.5”(hereinafterthe“draftcertificationcriteria”,“certificationcriteria”or“criteria”)wasdraftedbyEuroPriSeCertGmbH(hereinafterthe“schemeowner”),alegalentityinGermany,andsubmittedtotheLandesbeauftragtefürDatenschutzundInformationsfreiheitNordrhein-Westfalen,thecompetentGermansupervisoryauthorityinNorthRhine-Westphalia(hereinafter“DE-NRWSA”).

2.TheSupervisoryAuthorityofGermany(hereinafterthe“DESA”)hassubmittedthedraftcertificationcriteriatotheEDPBforapprovalpursuanttoArticle64(2)GDPRon29April2024.Thedecisiononthecompletenessofthefilewastakenon29May2024.

Adopted5

3.TheEuroPrisecertificationmechanismisnotacertificationaccordingtoarticle46(2)(f)GDPRmeantforinternationaltransfersofpersonaldataandthereforedoesnotprovideappropriatesafeguardswithintheframeworkoftransfersofpersonaldatatothirdcountriesorinternationalorganisationsunderthetermsreferredtoinletter(f)ofArticle46(2).Indeed,anytransferofpersonaldatatoathirdcountryortoaninternationalorganisation,shalltakeplaceonlyiftheprovisionsofChapterVGDPR

arerespected.

2.ASSESSMENT

4.TheEDPBhasconducteditsassessmentofthecriteriaofcertificationfortheirapprovalunderArticles42(5)GDPRinlinewiththestructureforeseeninAnnex2totheGuidelines(hereinafter“Annex”)anditsAddendum.

2.1ScopeofthecertificationmechanismandTargetofEvaluation(ToE)

5.TheEuroPrisecertificationmechanismcontainscertificationcriteriaofanEU-widecertificationschemeforthecertificationofprocessingbyprocessors.Thesubjectofcertificationstowhichthecriteriacatalogueappliesareprocessingoperationsperformedinproducts,processesandservicesorwiththeaidof(alsoseveral)productsandservicesandwithregardtowhichthecertificationapplicantisactingasaprocessor.Themaincriteriaofthiscertificationmechanismaredividedintothethreesetsofrequirements,namely:fromalegalperspective(set1),fromatechnicalandorganisationalmeasuresperspective(set2),andfromtherightsofthedatasubjectsperspective(set3).

6.Certificationapplicantsunderthisschememustbeprocessors.ThisincludesprocessorswhoaredirectlyentrustedwiththeprocessingofpersonaldatabyacontrollerwithinthemeaningofArticle4(7)GDPR.However,certificationapplicantsmayalsobeprocessorswithinthemeaningofArticle28(2)and(4)GDPR(sub-processors).

7.Whenaprocessor-certifiedundertheEuroPrisecertificationscheme-usesasub-processor,thelattercannotclaimthatithasbeencertifiedunderEuroPrisecertificationscheme.Onlyprocessingoperationsperformedbytheinitialandcertifiedprocessorarecoveredbythecertificationinsuchacase.However,sub-processorscanalsoapplyforcertification,whichwouldresultinastand-aloneandindependentprocedure.

8.TheBoardnotesinthedocumentationrelatedtothescopeofthecertificationmechanismprovidedbytheDESAthattheEuroPriseschemeappliestoprocessorsestablishedintheEuropeanUnion(EU)orintheEuropeanEconomicArea(EEA).

2.2Processingoperations

9.Thescopeofthesecriteriaisnotlimitedtocertaintypesofprocessingoperations.ItisratherthemethodologyunderlyingaEuroPriseevaluation,whichallowsforcertificationofanyprocessingoperationsbyprocessors.Itis,therefore,auniversalmethodologicalapproachonthebasisofwhichalargenumberofverydifferentprocessingoperationscanbecertified.Hence,itisoffundamentalimportancethatthemethodologicalrequirementsareadheredto,asthisistheonlywaytoensureauniformapplicationofthecertificationcriteriaandacomparableleveloftestingacrossdifferentcertificationprocedures.Theaimistoensurecomparabilityandreproducibilityofthecertificationsissuedandtheirresults.

Adopted6

2.3Lawfulnessandprinciplesofdataprocessing

10.Thecriteriarequiretheexaminationofwhethertheprocessingoperationstobecertifiedcomplywiththeprinciplesofdataprotectionbydesignandbydefault(section1.5ofthecriteria),entailingtheparticipationoftheapplicantinassistingthecontrollerintheimplementationoftheseprinciples.ThisallowsassessingcompliancewithArticle25GDPR,readinconjunctionwithArticle5GDPR.WhilethereisnocriteriadirectlyaimingatcompliancewithArticle6GDPR-giventhefactthatthecontrollerisresponsibleforthelawfulnessoftheprocessing-thecriteriaaimatensuringthatprocessors-applicantsdesigntheprocessingoperationstobecertifiedinawaythatfacilitatescontrollers’implementationofArticle5GDPRdataprotectionprinciples,includingtheprincipleoflawfulnessofprocessing.

2.4Generalobligationsofcontrollersandprocessors

11.Thecriteriareflecttherelationshipbetweentheprocessorandthecontroller.Inparticular,thecriteriaprovidetheobligationoftheprocessortohaveinplaceatemplateofdataprocessingagreementwiththecontroller,whichincludesalltherequirementsofArticle28GDPR(section1.2ofthecriteria).

12.ThecriteriarequireapplicantstoappointaDataProtectionOfficer(DPO)accordingtoArticle37GDPRandprovideaproofoftheappointmentoftheDPO(e.g.certificateofappointment).ThecriteriacheckthattheDPOmeettherequirementsunderArticles37to39(set1,section1.1ofthecriteria).

13.ThecriteriacheckthecontentoftherecordsofprocessingofactivitiesinaccordancewithArticle30GDPR(set1,section1.1ofthecriteria).

2.5Rightsofthedatasubjects

14.Thecriteriaadequatelyaddressdatasubject’srighttoinformationinaccordancewithChapterIIIGDPRandrequirerespectivemeasurestobeputinplace.Thecriteriaalsorequiremeasuresputinplaceprovidingforthepossibilitytointerveneintheprocessingoperationinordertoguaranteedatasubjects’rightsandallowcorrections,erasureorrestrictions(set3ofthecriteria).

2.6Risksfortherightsandfreedom

15.ThecriteriarequiretheprocessortobeawareofthepossibleriskstotherightsandfreedomsofnaturalpersonsforthedataprocessinginvolvedintheToE.Iftheprocessingofpersonaldataislikelytoresultinahighrisktotherightsandfreedomsofnaturalpersons,severalcriteriaensurethattheapplicantdemonstratesthattherequirementsofArticle35GDPRarefulfilledinaccordancewithArticle35GDPR(section1.2.2ofthecriteria,requirementn°6,section1.3.2ofthecriteria,section1.3.3ofthecriteria,section

2.1.5.1

ofthecriteria,section

2.1.5.9

pfthecriteria).

2.7Technicalandorganisationalmeasuresguaranteeingprotection

16.Thecriteriarequiretheapplicationoftechnicalandorganisationalmeasuresprovidingforconfidentiality,integrityandavailabilityofprocessingoperations.ThecriteriaalsorequiretheapplicationoftechnicalmeasurestoimplementdataprotectionbydesignandbydefaultinaccordancewithArticle25andArticle32GDPR(section1.5ofthecriteria,section2.1ofthecriteria/otherdocuments).

17.ThecriteriarequiretheapplicationofmeasuretoensurethatpersonaldatabreachnotificationdutiesarecarriedoutinduetimeandscopeinaccordancewithArticle33GDPR(section1.2.2ofthecriteria,requirementn°6).

Adopted7

2.8Criteriaforthepurposeofdemonstratingtheexistenceofappropriatesafeguardsfortransferofpersonaldata

18.Thecriteriarequireidentifyingall

溫馨提示

  • 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯系上傳者。文件的所有權益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網頁內容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
  • 4. 未經權益所有人同意不得將文件中的內容挪作商業或盈利用途。
  • 5. 人人文庫網僅提供信息存儲空間,僅對用戶上傳內容的表現方式做保護處理,對用戶上傳分享的文檔內容本身不做任何修改或編輯,并不能對任何下載內容負責。
  • 6. 下載文件中如有侵權或不適當內容,請與我們聯系,我們立即糾正。
  • 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。

評論

0/150

提交評論